Skip to main content
Platform Review
PricingSign in
← All platforms
Developer / Coding · lovable.dev

Lovable

Graded against 804 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskHIGHReviewed 2026-08-28
Creator: medium · GRC: high · Counsel: medium
creator band
Severe
enterprise · Severe
Dealbreaker · Third-party sublicensing
Exhibit A · Privacy Policy · verbatim

We do not use raw or identifiable Personal Data for training but may anonymize/aggregate it for any lawful purpose. To opt out of using your Customer Data for model training, contact us at privacy@lovable.dev or upgrade to a Business plan with enhanced controls.

highest-risk verified finding on training use — tap for the citation
264 verified findings13 policy surfaces2/2 core docs verified
Risk triage

Watch: Data retention

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
75
medium
189
low
2/2
docs
Trains on your data?
Training possible — conditions or opt-outs apply
from 3 cited findings
Who owns outputs?
You own your outputs
from 3 cited findings
Commercial use?
Commercial use allowed — with conditions
from 4 cited findings
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →

How to read this page: Overall risk rates what Lovable's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Creator lens
Your prompts, your outputs, your IP
SEVERE
Dealbreaker — Third-party sublicensing. Rights in your content can be passed on to third parties beyond service operation. see the clause

Based on 344 verified, verbatim-cited findings below — read the citations.

Enterprise lens
Data use, retention, subprocessors, audit
SEVERE
Dealbreaker — Third-party sublicensing. Rights in your content can be passed on to third parties beyond service operation. see the clause

Based on 381 verified, verbatim-cited findings below — read the citations.

Automated assessment against a published rubric — not legal advice.

Fully verifiedDeveloper / Coding

Fully verified — complete core corpus captured and read in full.

Document status
  • Terms of Service
    Verified - read in full - 141 citationsstaticLast captured 2026-08-28
  • Privacy Policy
    Verified - read in full - 123 citationsLast captured 2026-08-07
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Training on your content

This clause restricts Lovable from using raw or identifiable Personal Data for model training, permits use of anonymized or aggregated data for any lawful purpose, and provides an opt-out mechanism for Customer Data training use via email or a Business plan upgrade, directly governing training data rights and restrictions.

" We do not use raw or identifiable Personal Data for training but may anonymize/aggregate it for any lawful purpose. To opt out of using your Customer Data for model training, contact us at privacy@lovable.dev or upgrade to a Business plan ..."
📍 Privacy Policy › “Data Usage”Jump to exact text →
plan language
Training on your content

Grants users the right to opt out of customer data use for model training or other business purposes by contacting the provider or upgrading to a Business plan, and identifies plan tier as a mechanism for obtaining enhanced data-handling controls.

" If you do not want your Customer Data used for model training or other business purposes, you may opt out by contacting us or by upgrading to a Business plan that provides enhanced data-handling controls."
📍 Terms of Service › “Rights in Customer Data”Jump to exact text →
plan language
Training on your content

Creates an exception to PII protections by permitting the provider to anonymize and aggregate PII and then use it without restriction for any business purpose, carving out anonymized data from the general PII use limitations.

" We will not use raw or identifiable PII for model training. We do not sell PII and we do not share it with third parties for advertising or marketing. However, we may anonymize and aggregate PII, and once anonymized and aggregated, we may ..."
📍 Terms of Service › “Use of PII”Jump to exact text →
plan language
Commercial use

Grants the user a limited, personal, non-exclusive, non-transferable, revocable license to access and use the Services for personal or internal business purposes as permitted by the subscription plan; reserves all other rights to Lovable and terminates the license upon violation or account termination.

" Subject to these Terms, we grant you a limited, personal, non-exclusive, non-transferable, revocable license to access and use the Services for your personal or internal business purposes, as permitted by your subscription plan. This licen..."
📍 Terms of Service › “License to Use Our Services”Jump to exact text →
plan language
Commercial use

Prohibits affiliates from bidding on the provider's brand or variations in paid search ads, and prescribes specific enforcement consequences including commission forfeiture, permanent exclusion from commissions for affected users, and possible account deactivation.

" Affiliates may not bid on "Lovable" or any misspellings or variations of the brand in paid search ads (e.g., Google Ads). Violations will result in forfeiture of all commissions in the month where a violation occurred, permanent exclusion ..."
📍 Terms of Service › “No Brand Bidding”Jump to exact text →
plan language
Privacy & data use

The enumerated data categories include 'prompts submitted' and 'code generated' under Internet/network activity, and 'project information you upload' as a separate category. This means user inputs and outputs are explicitly collected as personal data. Inferences drawn to personalise the platform further expand the processing scope. Users in the EEA/UK have GDPR rights but the breadth of collection is still notable.

"Lovable collects the personal information categories below when you use the Services: Identifiers such as name, business-e-mail, phone number, user ID, and IP address (city-level location only). Commercial information such as subscri..."
📍 Privacy Policy › “Governing Law & Venue”Jump to exact text →
plan language
Privacy & data use

Creates an exception for Lovable Desktop whereby local device processing that does not transmit data to Lovable's servers is not considered a submission of customer data and is not subject to the policy, limiting the policy's territorial scope to server-side processing.

" Data Handling In Lovable Desktop : If you access Lovable through our desktop app (' Lovable Desktop' ) the data handling of Integrations applies. Certain actions may be taken locally on your device. Where no data is transmitted to Lovable'..."
📍 Privacy Policy › “Collection and Use of Information”Jump to exact text →
plan language
Privacy & data use

Defines 'Personal Data' by reference to GDPR, UK GDPR, PIPEDA, Swiss FADP, and US state privacy statutes, and provides examples of covered data types, establishing the scope of data subject to all protective obligations in the policy.

"b. " Personal Data ": For purposes of this Policy, Personal Data (also called personal information under the California Consumer Privacy Act/Privacy Rights Act and similar U.S. state laws) means any information that relates to an identified..."
📍 Privacy Policy › “Definitions”Jump to exact text →
Conflicting provisions (7)
  • Clause A states that billing and metering data is anonymized where possible, while Clause B describes usage data collected for credit metering, which inherently requires it to be linked to a specific user and thus not anonymized, creating a conflicting claim about the data's privacy status.

    " Information Collected Automatically : When you interact with the Services, we automatically collect technical data such as IP address, browser type, operating system, device identifiers, pages visited, timestamps, and error logs. Service Data is processed by Lovable as an independent controller for security, billing, analytics, and product-improvement purposes. Billing and Metering Data: Telemetry on service usage (e.g., compute hours in Lovable Cloud, API requests via AI Gateway) is collected to generate monthly invoices showing consumption by service. This data is anonymized where possible and shared with Stripe for payment processing and revenue recognition. "
    " Information You Provide Directly : When you create an account, purchase a subscription, open a support ticket, apply for a role, or otherwise use our Services, you may supply Personal Data such as your name, business-email address, phone number, payment information (processed via Stripe; see Stripe's privacy policy at stripe.com/privacy for details on how they handle your card details and transaction data). For usage-based services like Lovable Cloud and AI Gateway, we collect and process Usage Data (e.g., API calls, storage usage, prompt volumes) to meter consumption against your Credits (prepaid balances). These Credits are tracked in separate balances per service, with metering reliant on Stripe and third-party providers. We do not store full payment card details; Stripe serves as the source of truth for billing records, which may include anonymized usage metrics shared with us for invoicing, and project artefacts (for example, natural-language prompts, code snippets, or deployment configurations). These artifacts are used only to serve your workspace and, once anonymized or aggregated, to improve our models; they are never used to train general-purpose AI models that benefit other customers without your permission. "
    Within one document
  • Clause A states that billing and metering data is anonymized where possible, while Clause B describes processing usage data to meter individual consumption against credits, which implies it is linked to a specific user and therefore not anonymized.

    " Information Collected Automatically : When you interact with the Services, we automatically collect technical data such as IP address, browser type, operating system, device identifiers, pages visited, timestamps, and error logs. Service Data is processed by Lovable as an independent controller for security, billing, analytics, and product-improvement purposes. Billing and Metering Data: Telemetry on service usage (e.g., compute hours in Lovable Cloud, API requests via AI Gateway) is collected to generate monthly invoices showing consumption by service. This data is anonymized where possible and shared with Stripe for payment processing and revenue recognition. "
    " Information You Provide Directly : When you create an account, purchase a subscription, open a support ticket, apply for a role, or otherwise use our Services, you may supply Personal Data such as your name, business-email address, phone number, payment information (processed via Stripe; see Stripe's privacy policy at stripe.com/privacy for details on how they handle your card details and transaction data). For usage-based services like Lovable Cloud and AI Gateway, we collect and process Usage Data (e.g., API calls, storage usage, prompt volumes) to meter consumption against your Credits (prepaid balances). These Credits are tracked in separate balances per service, with metering reliant on Stripe and third-party providers. We do not store full payment card details; Stripe serves as the source of truth for billing records, which may include anonymized usage metrics shared with us for invoicing, and project artefacts (for example, natural-language prompts, code snippets, or deployment configurations). These artifacts are used only to serve your workspace and, once anonymized or aggregated, to improve our models; they are never used to train general-purpose AI models that benefit other customers without your permission. "
    Within one document
  • Clause A describes 'Usage Data' for metering without mentioning anonymization, implying it may be identifiable, while Clause B explicitly states that 'Billing and Metering Data' (which is service usage telemetry) is anonymized where possible.

    " Information You Provide Directly : When you create an account, purchase a subscription, open a support ticket, apply for a role, or otherwise use our Services, you may supply Personal Data such as your name, business-email address, phone number, payment information (processed via Stripe; see Stripe's privacy policy at stripe.com/privacy for details on how they handle your card details and transaction data). For usage-based services like Lovable Cloud and AI Gateway, we collect and process Usage Data (e.g., API calls, storage usage, prompt volumes) to meter consumption against your Credits (prepaid balances). These Credits are tracked in separate balances per service, with metering reliant on Stripe and third-party providers. We do not store full payment card details; Stripe serves as the source of truth for billing records, which may include anonymized usage metrics shared with us for invoicing, and project artefacts (for example, natural-language prompts, code snippets, or deployment configurations). These artifacts are used only to serve your workspace and, once anonymized or aggregated, to improve our models; they are never used to train general-purpose AI models that benefit other customers without your permission. "
    " Information Collected Automatically : When you interact with the Services, we automatically collect technical data such as IP address, browser type, operating system, device identifiers, pages visited, timestamps, and error logs. Service Data is processed by Lovable as an independent controller for security, billing, analytics, and product-improvement purposes. Billing and Metering Data: Telemetry on service usage (e.g., compute hours in Lovable Cloud, API requests via AI Gateway) is collected to generate monthly invoices showing consumption by service. This data is anonymized where possible and shared with Stripe for payment processing and revenue recognition. "
    Within one document
  • Clause A describes 'Usage Data' for metering without mentioning anonymization, implying it may be identifiable, while Clause B explicitly states that 'Billing and Metering Data' (which is service usage telemetry) is anonymized where possible.

    " Information You Provide Directly : When you create an account, purchase a subscription, open a support ticket, apply for a role, or otherwise use our Services, you may supply Personal Data such as your name, business-email address, phone number, payment information (processed via Stripe; see Stripe's privacy policy at stripe.com/privacy for details on how they handle your card details and transaction data). For usage-based services like Lovable Cloud and AI Gateway, we collect and process Usage Data (e.g., API calls, storage usage, prompt volumes) to meter consumption against your Credits (prepaid balances). These Credits are tracked in separate balances per service, with metering reliant on Stripe and third-party providers. We do not store full payment card details; Stripe serves as the source of truth for billing records, which may include anonymized usage metrics shared with us for invoicing, and project artefacts (for example, natural-language prompts, code snippets, or deployment configurations). These artifacts are used only to serve your workspace and, once anonymized or aggregated, to improve our models; they are never used to train general-purpose AI models that benefit other customers without your permission. "
    " Information Collected Automatically : When you interact with the Services, we automatically collect technical data such as IP address, browser type, operating system, device identifiers, pages visited, timestamps, and error logs. Service Data is processed by Lovable as an independent controller for security, billing, analytics, and product-improvement purposes. Billing and Metering Data: Telemetry on service usage (e.g., compute hours in Lovable Cloud, API requests via AI Gateway) is collected to generate monthly invoices showing consumption by service. This data is anonymized where possible and shared with Stripe for payment processing and revenue recognition. "
    Within one document
  • Clause A states that billing and metering data is anonymized where possible, while Clause B describes processing usage data to meter individual consumption against credits, which implies it is linked to a specific user and therefore not anonymized.

    " Information Collected Automatically : When you interact with the Services, we automatically collect technical data such as IP address, browser type, operating system, device identifiers, pages visited, timestamps, and error logs. Service Data is processed by Lovable as an independent controller for security, billing, analytics, and product-improvement purposes. Billing and Metering Data: Telemetry on service usage (e.g., compute hours in Lovable Cloud, API requests via AI Gateway) is collected to generate monthly invoices showing consumption by service. This data is anonymized where possible and shared with Stripe for payment processing and revenue recognition. "
    " Information You Provide Directly : When you create an account, purchase a subscription, open a support ticket, apply for a role, or otherwise use our Services, you may supply Personal Data such as your name, business-email address, phone number, payment information (processed via Stripe; see Stripe's privacy policy at stripe.com/privacy for details on how they handle your card details and transaction data). For usage-based services like Lovable Cloud and AI Gateway, we collect and process Usage Data (e.g., API calls, storage usage, prompt volumes) to meter consumption against your Credits (prepaid balances). These Credits are tracked in separate balances per service, with metering reliant on Stripe and third-party providers. We do not store full payment card details; Stripe serves as the source of truth for billing records, which may include anonymized usage metrics shared with us for invoicing, and project artefacts (for example, natural-language prompts, code snippets, or deployment configurations). These artifacts are used only to serve your workspace and, once anonymized or aggregated, to improve our models; they are never used to train general-purpose AI models that benefit other customers without your permission. "
    Within one document
  • Clause A states that billing and metering data is anonymized where possible, while Clause B describes usage data collected for credit metering, which inherently requires it to be linked to a specific user and thus not anonymized, creating a conflicting claim about the data's privacy status.

    " Information Collected Automatically : When you interact with the Services, we automatically collect technical data such as IP address, browser type, operating system, device identifiers, pages visited, timestamps, and error logs. Service Data is processed by Lovable as an independent controller for security, billing, analytics, and product-improvement purposes. Billing and Metering Data: Telemetry on service usage (e.g., compute hours in Lovable Cloud, API requests via AI Gateway) is collected to generate monthly invoices showing consumption by service. This data is anonymized where possible and shared with Stripe for payment processing and revenue recognition. "
    " Information You Provide Directly : When you create an account, purchase a subscription, open a support ticket, apply for a role, or otherwise use our Services, you may supply Personal Data such as your name, business-email address, phone number, payment information (processed via Stripe; see Stripe's privacy policy at stripe.com/privacy for details on how they handle your card details and transaction data). For usage-based services like Lovable Cloud and AI Gateway, we collect and process Usage Data (e.g., API calls, storage usage, prompt volumes) to meter consumption against your Credits (prepaid balances). These Credits are tracked in separate balances per service, with metering reliant on Stripe and third-party providers. We do not store full payment card details; Stripe serves as the source of truth for billing records, which may include anonymized usage metrics shared with us for invoicing, and project artefacts (for example, natural-language prompts, code snippets, or deployment configurations). These artifacts are used only to serve your workspace and, once anonymized or aggregated, to improve our models; they are never used to train general-purpose AI models that benefit other customers without your permission. "
    Within one document
  • Clause A describes 'Usage Data' for metering without mentioning anonymization, implying it may be identifiable, while Clause B explicitly states that 'Billing and Metering Data' (which is service usage telemetry) is anonymized where possible.

    " Information You Provide Directly : When you create an account, purchase a subscription, open a support ticket, apply for a role, or otherwise use our Services, you may supply Personal Data such as your name, business-email address, phone number, payment information (processed via Stripe; see Stripe's privacy policy at stripe.com/privacy for details on how they handle your card details and transaction data). For usage-based services like Lovable Cloud and AI Gateway, we collect and process Usage Data (e.g., API calls, storage usage, prompt volumes) to meter consumption against your Credits (prepaid balances). These Credits are tracked in separate balances per service, with metering reliant on Stripe and third-party providers. We do not store full payment card details; Stripe serves as the source of truth for billing records, which may include anonymized usage metrics shared with us for invoicing, and project artefacts (for example, natural-language prompts, code snippets, or deployment configurations). These artifacts are used only to serve your workspace and, once anonymized or aggregated, to improve our models; they are never used to train general-purpose AI models that benefit other customers without your permission. "
    " Information Collected Automatically : When you interact with the Services, we automatically collect technical data such as IP address, browser type, operating system, device identifiers, pages visited, timestamps, and error logs. Service Data is processed by Lovable as an independent controller for security, billing, analytics, and product-improvement purposes. Billing and Metering Data: Telemetry on service usage (e.g., compute hours in Lovable Cloud, API requests via AI Gateway) is collected to generate monthly invoices showing consumption by service. This data is anonymized where possible and shared with Stripe for payment processing and revenue recognition. "
    Within one document

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 75
Tier-specific - 10
Total citations - 264
Severity
Surface
Document
Tier
Tier differences
High
" may be limited to specific Services (for example, only the AI Gateway);"
Terms of Service › “Restrictions”Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Restricts the use of promotional credits and offers to specific designated Services, limiting their applicability to only those services identified in the promotion.

AI-generated interpretation, not legal advice.

Tier differences
High
"Please note: This Privacy Policy applies to Free and Pro plans. This does not include Business and Enterprise plans which are governed by our terms and Data Processing Agreement found here ."
Privacy Policy › “Last Updated: April 14th, 2026”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

This clause explicitly scopes the Privacy Policy to Free and Pro tiers, excluding Business and Enterprise. Enterprise customers typically negotiate DPAs with stronger deletion, audit, and sub-processor obligations. Free/Pro users lack those contractual mechanisms.

AI-generated interpretation, not legal advice.

Training on your content
High
" We do not use raw or identifiable Personal Data for training but may anonymize/aggregate it for any lawful purpose. To opt out of using your Customer Data for model training, contact us at privacy@lovable.dev or upgrade to a Business plan with enhanced controls."
Privacy Policy › “Data Usage”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

This clause restricts Lovable from using raw or identifiable Personal Data for model training, permits use of anonymized or aggregated data for any lawful purpose, and provides an opt-out mechanism for Customer Data training use via email or a Business plan upgrade, directly governing training data rights and restrictions.

AI-generated interpretation, not legal advice.

Training on your content
High
" We will not use raw or identifiable PII for model training. We do not sell PII and we do not share it with third parties for advertising or marketing. However, we may anonymize and aggregate PII, and once anonymized and aggregated, we may use it for any business purpose without restriction."
Terms of Service › “Use of PII”Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Creates an exception to PII protections by permitting the provider to anonymize and aggregate PII and then use it without restriction for any business purpose, carving out anonymized data from the general PII use limitations.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"Lovable collects the personal information categories below when you use the Services: Identifiers such as name, business-e-mail, phone number, user ID, and IP address (city-level location only). Commercial information such as subscription tier and purchase history; full payment-card numbers are processed solely by our PCI-compliant provider and are never stored by Lovable. Internet / network activity such as log-in events, feature usage, prompts submitted, code generated, and telemetry. Inferences drawn to personalize the platform. Project information you upload (e.g., repositories and configuration files)."
Privacy Policy › “Governing Law & Venue”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

The enumerated data categories include 'prompts submitted' and 'code generated' under Internet/network activity, and 'project information you upload' as a separate category. This means user inputs and outputs are explicitly collected as personal data. Inferences drawn to personalise the platform further expand the processing scope. Users in the EEA/UK have GDPR rights but the breadth of collection is still notable.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Sensitive Personal Information is not intentionally collected, and customers are instructed not to upload sensitive data (for example, Social-Security numbers or precise geolocation). No sensitive data (e.g., HIPAA-protected health info, financial accounts) should be uploaded; our Services are not designed for it, and we disclaim responsibility if submitted."
Privacy Policy › “Governing Law & Venue”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Restricts collection of sensitive personal information, instructs customers not to upload sensitive data such as SSNs or health information, and disclaims responsibility if such data is submitted, combining a behavioral restriction on users with a liability disclaimer for the platform.

AI-generated interpretation, not legal advice.

Moderation & enforcement
High
"we reserve the right to reclaim subdomains immediately without notice when necessary to address urgent issues, including but not limited to violations of our Platform Rules , legal requirements, security threats, or abuse."
Terms of Service › “Subdomain Usage and Management”Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

The emergency reclamation right is triggered by Lovable's unilateral determination of urgency across broad categories. Users have no procedural protections and no recourse for sudden loss of a deployed application's domain.

AI-generated interpretation, not legal advice.

Moderation & enforcement
High
"We may terminate your account or access to the Services for convenience by providing you with advance notice, or as otherwise provided in the " Suspension and Termination for Breach" section. We may also discontinue or modify the Services in whole or in part at any time by providing you with advance notice."
Terms of Service › “Term and Termination”Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

The platform can terminate any account for any reason (convenience) or no reason, and can alter or shut down the service entirely. The lack of a defined notice period weakens user protections.

AI-generated interpretation, not legal advice.

Moderation & enforcement
High
" Credits are prepaid, non-refundable, and non-redeemable for cash or any other value. Credits represent only a limited license to access the Services and are not deposits, stored value, or financial instruments. For rollover and expiration rules, see the " Credit Rollover and Expiration" section above. For forfeiture rules, see the " Refunds and Termination" section."
Terms of Service › “No Refunds; Not a Financial Instrument”Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Restricts credits to non-refundable, non-redeemable prepaid access rights, defines them as a limited license rather than a financial instrument, and cross-incorporates rollover and forfeiture rules from other sections.

AI-generated interpretation, not legal advice.

Data retention
High
" We can retain PII as long as reasonably necessary to provide the Services."
Terms of Service › “Retention and Deletion”Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Creates an exception to deletion or account closure obligations by permitting continued retention of specific PII after account closure for fraud prevention, legal defense, or compliance with legal obligations.

AI-generated interpretation, not legal advice.

Data retention
High
" We may also retain specific PII, after account closure or deletion requests, for fraud prevention, legal defense, or to comply with our legal obligations."
Terms of Service › “Retention and Deletion”Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Establishes an exception to immediate deletion by permitting deleted data to persist in backups for a limited time before permanent removal, qualifying the scope of deletion commitments.

AI-generated interpretation, not legal advice.

Data retention
High
" Deleted data may persist in backups for a limited time before being permanently removed."
Terms of Service › “Retention and Deletion”Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Establishes an exception to immediate deletion by permitting deleted data to persist in backups for a limited time before permanent removal, qualifying the scope of deletion commitments.

AI-generated interpretation, not legal advice.

Indemnity & liability
High
" TO THE FULLEST EXTENT PERMITTED BY LAW, WE AND OUR LICENSORS, PROVIDERS, AFFILIATES, AND OFFICERS WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, INCLUDING LOST PROFITS, LOST DATA, BUSINESS INTERRUPTION, OR LOSS OF GOODWILL, ARISING OUT OF OR RELATING TO THE SERVICES OR THESE TERMS, EVEN IF WE WERE ADVISED OF THE POSSIBILITY OF SUCH DAMAGES, EXCEPT TO THE EXTENT SUCH LIABILITY CANNOT BE LIMITED UNDER APPLICABLE LAW. WITHOUT LIMITING THE FOREGOING, WE WILL NOT BE LIABLE FOR ANY DOWNTIME, FAILURES, DELAYS, OR OTHER ISSUES CAUSED BY INFRASTRUCTURE PROVIDERS, THIRD-PARTY AI PROVIDERS, OR OTHER THIRD PARTIES; FOR ERRORS OR INACCURACIES IN AI OUTPUT; FOR ANY ACT OR OMISSION BY YOU, YOUR USERS, OR ANYONE USING YOUR ACCOUNT; OR FOR LOSS OF CUSTOMER DATA, EXCEPT TO THE EXTENT CAUSED BY OUR GROSS NEGLIGENCE OR WILLFUL MISCONDUCT. IN NO EVENT WILL OUR TOTAL LIABILITY FOR ALL CLAIMS ARISING OUT OF OR RELATING TO THE SERVICES OR THESE TERMS, WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, OR ANY OTHER LEGAL THEORY, EXCEED THE AMOUNT YOU PAID US FOR THE SERVICES IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE CLAIM, EXCEPT TO THE EXTENT SUCH LIABILITY CANNOT BE LIMITED UNDER APPLICABLE LAW. "
Terms of Service › “Limitation of Liability”Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Excludes the platform and its affiliates from liability for indirect, incidental, special, consequential, exemplary, or punitive damages including lost profits, lost data, and business interruption, and specifically disclaims liability for downtime or infrastructure failures, to the fullest extent permitted by law.

AI-generated interpretation, not legal advice.

Indemnity & liability
High
"NCLUDING NEGLIGENCE), STRICT LIABILITY, OR ANY OTHER LEGAL THEORY, EXCEED THE AMOUNT YOU PAID US FOR THE SERVICES IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE CLAIM, EXCEPT TO THE EXTENT SUCH LIABILITY CANNOT BE LIMITED UNDER APPLICABLE LAW."
Terms of Service › “Limitation of Liability”Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

This is a standard but aggressive liability cap. For free-tier users who have paid nothing, the cap would be $0, leaving them with no practical remedy for platform-caused harm. Even paid users are limited to a relatively modest 12-month fee amount regardless of actual damages.

AI-generated interpretation, not legal advice.

Indemnity & liability
High
" Except where required by law, all fees are non-refundable."
Terms of Service › “No Refunds”Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Restricts customers from obtaining refunds on fees paid, establishing that all fees are non-refundable except where required by applicable law, limiting the provider's financial liability for reversals.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
"By using Lovable Cloud, you consent to the transfer, storage, and processing of your Customer Data by Supabase under their privacy policy (available at supabase.com/privacy )."
Privacy Policy › “Collection and Use of Information”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Implied consent through service usage is a legally contestable basis for international data transfers under GDPR. Lovable should rely on SCCs or adequacy decisions for transfers to Supabase, not user consent, since consent as a transfer mechanism is disfavored by regulators (EDPB Guidelines 05/2021).

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
"Your Personal Data may be shared with: The applicable registry operator; ICANN; Any ICANN-authorised escrow service provider; and Other third parties as required or permitted by applicable ICANN policies or law"
Privacy Policy › “Collection and Use of Information”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Sharing personal data with 'other third parties as required or permitted by applicable ICANN policies or law' is an open-ended disclosure that may not satisfy GDPR Art. 13/14 requirements for specific identification of recipients or categories of recipients at the time of collection.

AI-generated interpretation, not legal advice.

Governing law & disputes
High
" You may not assign, delegate, or transfer these Terms, by operation of law or otherwise, without our prior written consent. We may assign, delegate, or transfer these Terms, in whole or in part, without restriction. Any attempt to assign in violation of this section is void."
Terms of Service › “Assignment”Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Restricts users from assigning or transferring the Terms without prior written consent, while granting the platform an unrestricted right to assign, delegate, or transfer the Terms; declares any unauthorized assignment void, establishing both a user restriction and a platform right.

AI-generated interpretation, not legal advice.

Common questions about Lovable's policies

Does Lovable train its AI models on your data?
Training possible — conditions or opt-outs apply — based on 3 verified findings from Lovable's published policy. Informational only, not legal advice.
Who owns the content you create with Lovable?
You own your outputs — based on 3 verified findings from Lovable's published policy. Informational only, not legal advice.
Can you use Lovable's output commercially?
Commercial use allowed — with conditions — based on 4 verified findings from Lovable's published policy. Informational only, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from Lovable's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

47 verified clauses

Clauses in Lovable's policies that work in your favour — commitments the platform made to you.

  • Governing law & disputesarbitration & class-action waiver
    This Policy is governed by and governed in accordance with the laws of the State of Delaware, United States, without regard to its conflict-of-law principles. However, if you are located in a jurisdiction that grants you mandatory consumer protection or data p…

    Designates Delaware law as the governing law for the Policy, preserves mandatory local consumer and data protection rights for users in other jurisdictions, and specifies Irish law and Dublin courts as the governing fram…

    📍 Privacy Policy › “Governing Law & Venue”Jump to exact text →
  • Governing law & disputes
    This Policy is governed by and governed in accordance with the laws of the State of Delaware, United States, without regard to its conflict-of-law principles. However, if you are located in a jurisdiction that grants you mandatory consumer protection or data p…

    Delaware law and Wilmington courts are designated as the default exclusive forum. While mandatory consumer/data protection laws in the user's jurisdiction are preserved, this requires users to identify and assert those r…

    📍 Privacy Policy › “Governing Law & Venue”Jump to exact text →
  • Privacy & data usebreach notification promises
    You may access, correct, or request deletion of your Personal Data at any time by contacting us at privacy@lovable.dev , as described in this Policy. Lovable and its registrar partners take reasonable technical and organisational precautions to protect your Pe…

    Grants users the right to access, correct, or request deletion of personal data, establishes security obligations for Lovable and its registrar partners, and creates a procedure for data portability/continuity obligation…

    • Designated security contact: privacy@lovable.dev
    📍 Privacy Policy › “Any ICANN-authorised escrow service provider; and”Jump to exact text →
  • Data retentiondeletion rights & post-termination survival
    Resolving disputes or enforcing agreements. Customer data is retained for up to ninety (90) days, unless required by law, after which it is deleted or isolated. To cancel your account or request data deletion, contact us as outlined in the Policy. Upon account…

    Specifies a 90-day customer data retention limit, a 30-day post-termination deletion obligation, exceptions for fraud prevention and legal compliance, a 90-day backup retention allowance, and a procedure for requesting d…

    • Designated security contact: privacy@lovable.dev
    📍 Privacy Policy › “Retention of Your Information”Jump to exact text →
  • Subprocessors & data sharing
    We engage third-party sub-processors to support our Services, such as: Hosting and maintaining our platform, website, and databases. Processing payments through secure third-party payment processors. Providing technical support, customer service, and…

    The platform shares data with a broad category of sub-processors. The 10 business day objection window is relatively short and standard practice does not guarantee users can exit the service if they object. The non-selli…

    📍 Privacy Policy › “Data Processing and Sub-Processors”Jump to exact text →
  • Privacy & data usechildren's data
    Children's Data : Lovable's Services are not intended for individuals under the age of eighteen (18), and we do not knowingly collect or solicit Personal Data from anyone under this age, unless as part of a program with a partner, the child has obtained consen…

    Restricts collection of personal data from individuals under 18, establishes a representation warranty by users regarding their age, and imposes an obligation to promptly delete personal data collected from minors withou…

    • Designated security contact: privacy@lovable.dev
    📍 Privacy Policy › “Any ICANN-authorised escrow service provider; and”Jump to exact text →

+ 41 more verified clauses of this kind on this platform, cited in full in the report.

📋 Rules you must follow

29 verified clauses

What Lovable requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

  • Moderation & enforcement
    You may not use the Services if you are located in, or acting on behalf of a person or entity located in, a country or territory that is subject to U.S. government embargoes or sanctions (including Cuba, Iran, North Korea, Russia, Syria, and the Crimea, Donets…

    Restricts use of the Services by persons or entities located in U.S.-sanctioned countries or territories, or those on U.S. restricted-party lists, and requires users to represent and warrant compliance with export contro…

    📍 Terms of Service › “Export Controls and Sanctions”Jump to exact text →
  • Commercial useconduct restrictions
    Affiliates may not bid on "Lovable" or any misspellings or variations of the brand in paid search ads (e.g., Google Ads). Violations will result in forfeiture of all commissions in the month where a violation occurred, permanent exclusion from affiliate commis…

    Prohibits affiliates from bidding on the provider's brand or variations in paid search ads, and prescribes specific enforcement consequences including commission forfeiture, permanent exclusion from commissions for affec…

    📍 Terms of Service › “No Brand Bidding”Jump to exact text →
  • Moderation & enforcement
    You agree not to upload, input, or otherwise provide any protected health information under HIPAA, or any other sensitive categories of data (such as financial account numbers, government identifiers, or biometric data). Our Services are not designed to handle…

    Prohibits users from uploading HIPAA-protected health information or other sensitive data categories such as financial account numbers, government identifiers, or biometric data, and disclaims all provider responsibility…

    📍 Terms of Service › “No Sensitive Data”Jump to exact text →
  • Moderation & enforcement
    You are responsible for ensuring that your use of the Services, including transfers of Customer Data through the Platform, Lovable Cloud, the AI Gateway, or any model or service you connect, complies with applicable data protection and privacy laws.

    Imposes a legal obligation on the customer to ensure that their use of the Services, including all data transfers through the platform and connected services, complies with applicable data protection and privacy laws.

    📍 Terms of Service › “Customer Responsibility”Jump to exact text →
  • Moderation & enforcementconduct restrictions
    Affiliates may not use spammy tactics, misleading claims, or false endorsements in promoting Lovable. This includes fake discounts, deceptive landing pages, or unauthorized use of brand assets.

    Prohibits affiliates from using spam, misleading claims, false endorsements, fake discounts, deceptive landing pages, or unauthorized brand assets in promoting the provider, establishing conduct standards enforceable aga…

    📍 Terms of Service › “No Spam or Misleading Promotions”Jump to exact text →

+ 24 more verified clauses of this kind on this platform, cited in full in the report.

What the policies actually cover

17 topics
  • Product telemetry & usage tracking24 clauses
  • Advertising & tracking3 protective8 clauses
  • Sale or sharing of personal data2 protective2 clauses
  • Sensitive data (biometric, location, health)1 protective2 clauses
  • Children's data2 protective3 clauses
  • Government & law-enforcement disclosure2 protective6 clauses
  • Data shared with other AI providers7 clauses
  • Does not train on your content1 clause
  • Trains by default, opt-out available2 clauses
  • Arbitration & class-action waiver1 protective1 clause
  • Damages & liability cap5 clauses
  • Indemnity direction6 clauses
  • Terms can change at any time3 protective6 clauses
  • Deletion rights & post-termination survival4 protective10 clauses
  • Auto-renewal & cancel window4 clauses
  • Breach-notification promises4 protective5 clauses
  • Conduct restrictions12 obligations12 clauses

160 further verified clauses are cited on this page but not yet assigned a topic.

Cross-clause notes

Cross-referenceacross documents

Two verified clauses intersect on the same subject matter: the Terms of Service, Terms of Service › “Retention and Deletion” addresses how long content is retained, and the Privacy Policy, Privacy Policy › “Data Usage” addresses use of content in connection with model training or service improvement. Both clauses are in force at the same time — read them together.

Cross-referenceacross documents

The Privacy Policy, Privacy Policy › “Data Usage” describes a way to decline model training, and the Terms of Service, Terms of Service › “Restrictions” states that terms differ by plan or tier. Whether the opt-out applies on every tier is determined by those clauses together — read both before relying on the opt-out.

Ambiguity — Caution

Verified retention clauses point in different directions: the Terms of Service, Terms of Service › “Retention and Deletion” describes broad or open-ended retention, while the Terms of Service, Terms of Service › “Retention and Deletion” describes deletion or erasure. Which clause controls in a given situation is not resolved by the documents' text alone — this is surfaced as an ambiguity, treated as Caution.

Automated cross-reference against the published rubric — not legal advice.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

687
clauses
114
patterns
114
stances
training use · 21ip ownership · 20privacy sharing · 19tier conditionality · 19ip license · 18data retention · 12
data retentionMEDIUMPrivacy Policy › “Retention of Your Information”

The clause allows indefinite, perpetual, or necessity-based retention.

We retain Personal Data only as long as necessary to fulfill the purposes outlined in this Policy or as required by applicable law, including:
Open source citation
data retentionMEDIUMTerms of Service › “Rights in Customer Data”

The clause allows indefinite, perpetual, or necessity-based retention.

We may also create de-identified, anonymized, or aggregated data from your Customer Data, and we may retain and use that data on a perpetual basis for any lawful business purpose; such data does not identify you and is no longer your Customer Data. This license is granted notwithstanding any confidentiality obligations in these Terms and survives to the extent needed to give effect to the purposes above. Our handl...
Open source citation
data retentionMEDIUMPrivacy Policy › “Retention of Your Information”

The clause allows indefinite, perpetual, or necessity-based retention.

We retain Personal Data only as long as necessary to fulfill the purposes outlined in this Policy or as required by applicable law, including:
Open source citation
data retentionMEDIUMPrivacy Policy › “Retention of Your Information”

The clause allows indefinite, perpetual, or necessity-based retention.

We retain Personal Data only as long as necessary to fulfill the purposes outlined in this Policy or as required by applicable law, including:
Open source citation
data retentionMEDIUMTerms of Service › “Rights in Customer Data”

The clause allows indefinite, perpetual, or necessity-based retention.

We may also create de-identified, anonymized, or aggregated data from your Customer Data, and we may retain and use that data on a perpetual basis for any lawful business purpose; such data does not identify you and is no longer your Customer Data. This license is granted notwithstanding any confidentiality obligations in these Terms and survives to the extent needed to give effect to the purposes above. Our handl...
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tierscommercial useworsensHIGH1
All applicable tiersdata retentionconditionalMEDIUM9
All applicable tiersmoderation enforcementworsensHIGH10
All applicable tiersoutput ownershipimprovesLOW1
All applicable tiersprompt ownershipworsensHIGH1
All applicable tierstier differencesworsensHIGH1
Freeprivacy data useconditionalMEDIUM3
Freetraining useconditionalMEDIUM1
Standardgoverning law disputesimprovesLOW1
Standardoutput ownershipimprovesLOW3
Team / Businesscommercial useworsensHIGH5
Team / Businessdata retentionconditionalMEDIUM3

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

worsenedhigh materialityAug 7Aug 28, 2026

model training worsened from medium/training with opt out to high/training permitted.

Before · medium
We do not use raw or identifiable Personal Data for training but may anonymize/aggregate it for any lawful purpose. To opt out of using your Customer Data for model training, contact us at privacy@lovable.dev or upgrade to a Business plan with enhanced controls.
Before citation
After · high
developing and training artificial intelligence and machine learning models;
After citation
improvedhigh materialityJul 22Aug 7, 2026

model training improved from high/training permitted to medium/training with opt out.

Before · high
use the Services, AI Output, or prompts to train, develop, or improve competing AI models.
Before citation
After · medium
We do not use raw or identifiable Personal Data for training but may anonymize/aggregate it for any lawful purpose. To opt out of using your Customer Data for model training, contact us at privacy@lovable.dev or upgrade to a Business plan with enhanced controls.
After citation
worsenedhigh materialityJul 22Jul 22, 2026

model training worsened from medium/training with opt out to high/training permitted.

Before · medium
We do not use raw or identifiable Personal Data for training but may anonymize/aggregate it for any lawful purpose. To opt out of using your Customer Data for model training, contact us at privacy@lovable.dev or upgrade to a Business plan with enhanced controls.
Before citation
After · high
use the Services, AI Output, or prompts to train, develop, or improve competing AI models.
After citation
improvedhigh materialityJul 10Jul 10, 2026

model training improved from high/training permitted to medium/training with opt out.

Before · high
developing and training artificial intelligence and machine learning models;
Before citation
After · medium
We do not use raw or identifiable Personal Data for training but may anonymize/aggregate it for any lawful purpose. To opt out of using your Customer Data for model training, contact us at privacy@lovable.dev or upgrade to a Business plan with enhanced controls.
After citation
worsenedhigh materialityJun 17Jul 10, 2026

model training worsened from medium/training with opt out to high/training permitted.

Before · medium
We do not use raw or identifiable Personal Data for training but may anonymize/aggregate it for any lawful purpose. To opt out of using your Customer Data for model training, contact us at privacy@lovable.dev or upgrade to a Business plan with enhanced controls.
Before citation
After · high
developing and training artificial intelligence and machine learning models;
After citation
improvedhigh materialityJun 17Jun 17, 2026

model training improved from high/training permitted to medium/training with opt out.

Before · high
use the Services, AI Output, or prompts to train, develop, or improve competing AI models.
Before citation
After · medium
We do not use raw or identifiable Personal Data for training but may anonymize/aggregate it for any lawful purpose. To opt out of using your Customer Data for model training, contact us at privacy@lovable.dev or upgrade to a Business plan with enhanced controls.
After citation
Aug 28, 2026model trainingHIGH

Latest stance: training permitted on training use

We may use your Customer Data to develop and train artificial intelligence and machine learning models. You may tell us at any time that you do not want your Customer Data used for model training or the other business purposes described above, and we will honor that request for prospective use, free of charge and regardless of your plan.
Open timeline citation
Aug 28, 2026content licenseMEDIUM

Latest stance: broad license on privacy data use

You grant us a worldwide, perpetual, royalty-free license to use, copy, modify, process, analyze, and otherwise exploit your Customer Data for our business purposes, including without limitation:
Open timeline citation
Aug 28, 2026content ownershipHIGH

Latest stance: platform claims or reserves rights on moderation enforcement

If you create a username on the Platform, you acknowledge and agree that we reserve the right, at our sole discretion, to reclaim, reassign, or terminate any username at any time and for any reason, including but not limited to: (a) usernames that are inappropriate, offensive, or violate our Platform Rules ; (b) usernames that impersonate or could be confused with official Lovable pages, features, or routes (such as "home," "projects," "settings," or similar); or (c) usernames that impersonate another company, brand, or individual. You have no proprietary or ongoing rights to any specific username, and reclamation of a username does not entitle you to a refund or any other compensation.
Open timeline citation
Aug 28, 2026content ownershipHIGH

Latest stance: platform claims or reserves rights on moderation enforcement

We reserve the right, at our sole discretion, to reclaim, reassign, redirect, suspend, or terminate any subdomain at any time and for any reason, including but not limited to: enabling the subdomain to be used by another user or for another purpose that better serves the Lovable community;
Open timeline citation

Capture recency

  • Terms of Service:Last captured 2026-08-28· verified 2026-08-28
  • Privacy Policy:Last captured 2026-08-07· verified 2026-08-07

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

↑ 34 more findings this quarter vs last (363 vs 329). First scan: June 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Lovable's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Every finding above is a verbatim quote from Lovable's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.