ACTIVATED HUMAN/ ai

Lovable can train AI on my prompts and code unless I opt out. What should I do?

Lovable gave notice on August 5, 2026 that from September 9, 2026 it may use the prompts, attached files, code, project files and generated output of Free and Pro workspaces to train its AI models. You can opt out at any time in Account Settings under Privacy, on any plan, at no cost. The data your app's own users submit is excluded, and Business and Enterprise workspaces are excluded by default.

So the first thing to do takes a minute: open Account Settings, Privacy, and turn on Data collection opt out. Lovable's policy says the opt-out works going forward and 'does not retract content from training datasets assembled, or models trained, before you opted out', so the sooner the better.

The larger question is the one the notice raises for every founder on a hosted builder: who holds your code and your customers' data, and under whose terms. For most Lovable projects, the opt-out answers the training question and nothing else needs to change. For an app with paying customers, this is a fair moment to put the code in your own repository and the data in an account in your name.

In founders’ words

“Point 3 is the most important, but the fact that it's opt-out rather than opt-in is a trick that tech companies should stop using. There must be explicit consent, not the opposite.”

Hacker News, August 2026 · source

What changed, in Lovable's words

Lovable's summary page says that 'Starting on the effective date, we may use Customer Content' and 'usage data from Free and Pro plans to train, develop, and improve our AI models and AI-powered features'. It defines that content as 'your prompts (including images and files you attach), code, project files, and generated outputs'. Notice was given August 5, 2026 with an effective date of September 9, 2026. The policy now posted at lovable.dev/privacy is marked effective September 15, 2026.

The opt-out, from the same page: 'If you are on a Free or Pro plan, log in and open Account Settings → Privacy and enable Data collection opt out to exclude your own personal data from model training. If you opt out before the effective date, your data is not used for training; if you opt out later, your data is excluded going forward.' The policy adds that opting out is available 'on any plan, at no cost, and it does not affect your use of AI features'.

What is excluded: data inside your apps, meaning what your end users submit, 'will not be used for model training and is held in your project's own database and storage'. Account and billing details are not used. Business and Enterprise workspace data 'remains covered by your organization's existing agreements and is excluded from training by default'. Separately, Lovable may share pseudonymized identifiers with advertising platforms such as Meta and Google, 'not your project content, prompts, code, or your apps' end-user data', with consent in the EEA, UK, Switzerland and Brazil and an opt-out in the United States.

Lovable's terms, last updated August 28, 2026, carry the same license: 'We may use your Customer Data to develop and train artificial intelligence and machine learning models', with a request to stop honored 'for prospective use, free of charge and regardless of your plan'. Sources: lovable.dev/legal/privacypolicyaugust2026, lovable.dev/privacy and lovable.dev/terms, read on October 2, 2026.

What it means for your app and your customers

For your customers, by Lovable's own text, nothing: what they submit to your app stays in your project's database and storage and is not training data. That is a meaningful line, and it is better drawn than on some other platforms, where form submissions sit inside the training license.

For you, the content at stake is what you built: your prompts, your code, the files you dragged into the chat, and the output. If that includes a spreadsheet of customers, a contract, a product plan or a key, it is Customer Content, and until you opt out it can be used for training. The policy also says trained Lovable staff may review that content to check model quality, under its confidentiality safeguards.

We are not lawyers. What to read: the summary page, Section 5 of the policy, and Section 8 on what the third-party model providers may do with content sent to them. What to ask Lovable in writing, if it matters to your business: whether content created before you opted out has already been used, and what 'legitimate interests' means for a user in your country.

Your options, honestly

  • Opt out and stay. One setting, any plan, no cost, and your app's users were never included. For most Free and Pro projects this is the whole answer.
  • Move to Business. Excluded by default under a Data Processing Agreement, which is the document a customer's privacy review will ask for. Worth it when a customer asks, not before.
  • Hold your own copies and stay. Git sync on all plans puts the code in a repository you own; a Cloud export puts the data in your hands. The project still lives on Lovable, but a terms change can no longer surprise you.
  • Move the app to accounts you own. Code in your repository on your host, database and files in a Supabase project or a server in your name, secrets in your own settings, AI calls on your own key. Lovable's content license then covers what remains on Lovable, which can be nothing.

Why this can be a good moment to move

Nothing in this policy forces a move; the opt-out is real and free. What the notice does is make visible that the code, the chat and the data of your product live under terms someone else writes and can rewrite with thirty-five days' notice. On infrastructure you own (an AWS or Google Cloud account in your name, a small server, or Cloudflare), the terms over your data are the ones you agreed with your database provider, and they do not change because the builder you used changed its model strategy.

What it takes is listed below, and Lovable's own migration guide covers most of it in detail. For a Cloud-backed app the destination (Supabase) matches the source, so the move is export, apply, restore, test, switch. With the right guidance this is days to a few weeks with the old app live throughout, which makes it more approachable than it sounds from outside. Our free call reads the app and tells you which pieces, if any, are worth moving.

What a move involves, step by step

  • Code. Turn on Git sync so a repository you own holds the app and its migration files. Run it on your own computer from the clone before anything else.
  • Database and files. Export project data from Cloud's advanced settings (full database, including user accounts with password hashes; not storage files, functions or secrets). Download storage files separately. Create a Supabase project in your account, or self-hosted Supabase on your server, apply the migrations in order, restore the export, upload the files.
  • Sign-in and users. Users keep their passwords after the restore. Sign-in providers and redirect URLs are configured again at the destination; signed-in users sign in again.
  • Secrets. Function secrets and API keys are entered by hand at the destination. Rotate anything that was ever pasted into chat, since chat is Customer Content.
  • Payments. Stripe is already yours; the webhook endpoint and handler move with the server code. Test in test mode.
  • Domains and email. Point the custom domain last. Set up sending from your own domain early.
  • AI providers. Model calls that ran through Lovable's AI gateway become calls on your own provider key, under that provider's training terms, which you then read once.
  • Test before switching. A temporary URL, sign in and out, reads, writes, uploads, a server-rendered page if your app has one. Then a final export during a short pause in writes, restore, switch, and unpublish on Lovable when the lovable.app address should stop.

When you may not need to move

If you are on Free or Pro and the opt-out is on, your app's users were never in scope, and no customer has asked where their data lives, there is nothing more to do this month. Keep Git sync on and take an export now and then.

Move when customers pay and ask, when your prompts and files hold material you would not want reviewed by anyone outside your company, when a Business plan is more than the app earns, or when you had already decided the app needs tests, staging and a deployment you control. The policy change is a reason to look; what you find in the app decides.

What Lovable's September 2026 policy covers, read on October 2, 2026
ContentFree and ProBusiness and EnterpriseAfter a move to your own accounts
Prompts, attached files, code, project files, generated outputMay be used for training unless you opt outExcluded by default under the DPALovable holds only what you leave on Lovable
Data your app's users submitNot used for trainingNot used for trainingIn a database you own
Account and billing detailsNot used for trainingNot used for trainingUnchanged
Content already in training sets before you opt outNot retracted, per the policyNot applicableNot applicable
Pseudonymized identifiers to ad platformsConsent in EEA/UK/CH/BR; opt-out in the USSameUnchanged while you keep an account
Where to actAccount Settings, Privacy, Data collection opt outYour DPAYour providers' terms

Questions

Where is the Lovable opt-out?

Log in, open Account Settings, then Privacy, and enable Data collection opt out. Lovable's page says this works on any plan, at no cost, and does not affect AI features. It applies going forward.

Does opting out remove what Lovable already used?

No. The policy says opting out 'does not retract content from training datasets assembled, or models trained, before you opted out'. If that matters to you, ask Lovable in writing what was used from your workspace.

Is my customers' data being used to train Lovable's models?

Lovable's policy says no: data your app's end users submit stays in your project's database and storage and is not used for training. Your own prompts, files and code are the content in scope.

Is this the same as what Base44 did?

No. Base44's privacy page says there is no opt-out on any plan below Enterprise and that form submissions are inside the license. Lovable offers a free opt-out on every plan and excludes end-user data. Read both pages yourself before deciding anything.

If I move my app, does Lovable still have a license to it?

The license in Lovable's terms covers Customer Data you provide to the service. What that means for content you remove or for a closed account is a legal question; ask Lovable in writing and show the answer to a lawyer. Moving the live app and data to your own accounts settles where they live from that point on.

Working with us
  1. First look, $750. After a free call, we read your whole product and tell you what is finished, what is not, and what to do first.

  2. Setup, $3,000 fixed. We make it ready for real customers, in accounts you own.

  3. Partner, $2,500 a month. We review what your coding agent writes and keep the checks and tests current. Month to month.

Related questions