Lovable now trains its AI on your prompts and code by default

Stani Mihov

Founder & CEO

·

TL;DR

What changed:

  • Prompts, code, and project files on Free and Pro plans now train Lovable's AI by default, including models it may offer to other customers.

  • The old promise that project content would never train general-purpose models for other customers without permission was deleted.

  • You can opt out in account settings for free, but only for future training.

  • Lovable now shares pseudonymized identifiers with Meta and Google for ads, which it says may count as a "sale" under some US state laws.

  • Companies can now claim Lovable accounts created with their email domain.

What to do: If your team uses Lovable on Free or Pro plans, turn off "Use my Lovable content for model training" in each account's settings, or move company work to a Business plan, where training is excluded.

The change

Lovable, the AI app builder that turns plain-language prompts into working apps, replaced its privacy policy with a rewritten version that took effect on September 9, 2026. Lovable announced the change ahead of time and published instructions for opting out before the new policy took effect.

Most of the rewrite is reorganization and new definitions. A handful of changes stand out for any company whose people build with Lovable. Venpo flagged the new version on September 10, and the redline is on the public change page.

What changed

  • Training by default. On Free and Pro plans, Lovable now uses Customer Content, meaning prompts, code, project files, configurations, and generated outputs, along with usage data, to "train, develop, fine-tune, and improve our AI models," unless you opt out.

  • The old promise is gone. The previous policy said project content was "never used to train general-purpose AI models that benefit other customers without your permission." That sentence was deleted.

  • Ad platforms. Lovable now shares pseudonymized identifiers with advertising platforms such as Meta and Google. The old policy said Lovable "does not sell or share personal information as defined under U.S. privacy laws."

  • Account claims. An organization can now claim Lovable accounts that were created with an email address on its domain.

  • Fewer specific security promises. The old commitment to notify affected customers "within 72 hours" of confirming a notifiable breach was replaced with notice "within the timeframes the law requires."

From "never" to "by default"

The old policy drew a firm line. Project content was used to serve your workspace and, once anonymized or aggregated, to improve Lovable's models, but it would never train general-purpose models that benefit other customers without your permission. It also said Lovable did not use raw or identifiable personal data for training.

The new policy moves that line in three ways. Training is now on by default for Free and Pro plans. The content used "may include Personal Data." And the models it can train include "models we may make available to customers through Lovable products such as the AI Gateway," which means models other customers can use. The policy also says trained members of Lovable's team may review this content to check model quality.

The opt-out only works going forward

Lovable offers a real way out. Any user can turn off the "Use my Lovable content for model training" setting in their account, on any plan, at no cost, and without losing AI features.

The timing matters, though. The policy says opting out "does not retract content from training datasets assembled, or models trained, before you opted out." Deleting your account works the same way. A user who switched the setting off before September 9 kept their content out from the start. A user who switches it off today only protects what comes next.

Your identifiers now go to Meta and Google

The new advertising section describes three uses for pseudonymized identifiers shared with platforms like Meta and Google: excluding existing customers from Lovable ads, showing Lovable ads to its contacts, and building lookalike audiences to reach people who resemble its customers. The policy says the contents of your projects are not shared for this.

The policy also acknowledges that under some US state laws, this sharing "may constitute a 'sale' or 'sharing' of personal information." US users can opt out through the "Do Not Sell or Share My Personal Information" link, their privacy settings, or a Global Privacy Control signal. In the EEA, UK, Switzerland, and Brazil, Lovable says it does this only with consent.

Your company can claim your account

This change cuts both ways for companies. If an employee signed up for Lovable with a work email, the company can verify it owns the domain and claim that account. Its administrators first see limited details: email address, display name, number of workspaces and projects, and last active date. The employee is notified and can either join the organization or switch the account to a personal email. If they do neither, the account transfers to the company on the date in the notice.

For a company worried about who is building what on Lovable, this is a practical tool: it shows which accounts exist on the company domain and brings them under company control.

What did not change

Several limits stay in place. Business and Enterprise workspaces are excluded from training, and Lovable's Data Processing Agreement states that customer personal data is not used to train AI models. Data from the end users of apps built on Lovable, and account and billing details, are not used for training either. Lovable says its agreements with third-party model providers restrict their use of your content, and that session recordings mask what is typed into project chat and are not used for training.

Why this matters

Lovable is not only an engineering tool. Product managers, marketers, and founders use it to build internal tools and prototypes, often on individual Pro plans. The prompts behind those projects can include customer details, internal specs, pricing, and real code. Under the new policy, that material can be used for training by default, including for models other customers may use, and switching the setting off later does not pull it back.

AI training terms are among the clauses we see change most often, as when GitBook deleted a one-sentence promise from its AI policy and Mixpanel removed its AI data opt-in. Knowing which AI tools touch company data, and on what terms, is the same work as monitoring AI subprocessors.

Potential impact

For a SaaS company whose people use Lovable, the update raises four practical questions:

  • Who at your company builds with Lovable, and on which plan?

  • Have the Free and Pro users turned off model training in their account settings, and did they do it before September 9?

  • Do you want to claim the Lovable accounts created with your company's email domain?

  • Does your internal AI policy allow customer data in prompts to tools that train on it by default?

Changes like this land without any change to the product itself, which is the hidden risk of vendor legal changes.

How Venpo detected it

Venpo monitors Lovable's legal pages as part of continuous vendor risk monitoring. On September 10, the day after the new policy took effect, it flagged the rewrite and separated the training, advertising, account-claim, and security changes from the large amount of reorganization around them. The full redline is on the Lovable change page, and every monitored Lovable document is listed on the Lovable vendor profile.

Business outcome

Teams that track Lovable got a plain-English summary of the new policy, with the deleted "never" sentence quoted next to the new training clause. That leaves time to find every Lovable account on the company domain, switch off training where needed, and decide whether company work belongs on a Business plan. The alternative is learning about default training after the prompts are already in a dataset.

Key takeaway

Lovable moved from promising that project content would never train models for other customers to training on it by default, with an opt-out that only protects what comes next. When the protection is off by default and cannot be applied backward, the only real safeguard is knowing about the change in time, which is why automated monitoring beats checking terms once a year.

The change

Lovable, the AI app builder that turns plain-language prompts into working apps, replaced its privacy policy with a rewritten version that took effect on September 9, 2026. Lovable announced the change ahead of time and published instructions for opting out before the new policy took effect.

Most of the rewrite is reorganization and new definitions. A handful of changes stand out for any company whose people build with Lovable. Venpo flagged the new version on September 10, and the redline is on the public change page.

What changed

  • Training by default. On Free and Pro plans, Lovable now uses Customer Content, meaning prompts, code, project files, configurations, and generated outputs, along with usage data, to "train, develop, fine-tune, and improve our AI models," unless you opt out.

  • The old promise is gone. The previous policy said project content was "never used to train general-purpose AI models that benefit other customers without your permission." That sentence was deleted.

  • Ad platforms. Lovable now shares pseudonymized identifiers with advertising platforms such as Meta and Google. The old policy said Lovable "does not sell or share personal information as defined under U.S. privacy laws."

  • Account claims. An organization can now claim Lovable accounts that were created with an email address on its domain.

  • Fewer specific security promises. The old commitment to notify affected customers "within 72 hours" of confirming a notifiable breach was replaced with notice "within the timeframes the law requires."

From "never" to "by default"

The old policy drew a firm line. Project content was used to serve your workspace and, once anonymized or aggregated, to improve Lovable's models, but it would never train general-purpose models that benefit other customers without your permission. It also said Lovable did not use raw or identifiable personal data for training.

The new policy moves that line in three ways. Training is now on by default for Free and Pro plans. The content used "may include Personal Data." And the models it can train include "models we may make available to customers through Lovable products such as the AI Gateway," which means models other customers can use. The policy also says trained members of Lovable's team may review this content to check model quality.

The opt-out only works going forward

Lovable offers a real way out. Any user can turn off the "Use my Lovable content for model training" setting in their account, on any plan, at no cost, and without losing AI features.

The timing matters, though. The policy says opting out "does not retract content from training datasets assembled, or models trained, before you opted out." Deleting your account works the same way. A user who switched the setting off before September 9 kept their content out from the start. A user who switches it off today only protects what comes next.

Your identifiers now go to Meta and Google

The new advertising section describes three uses for pseudonymized identifiers shared with platforms like Meta and Google: excluding existing customers from Lovable ads, showing Lovable ads to its contacts, and building lookalike audiences to reach people who resemble its customers. The policy says the contents of your projects are not shared for this.

The policy also acknowledges that under some US state laws, this sharing "may constitute a 'sale' or 'sharing' of personal information." US users can opt out through the "Do Not Sell or Share My Personal Information" link, their privacy settings, or a Global Privacy Control signal. In the EEA, UK, Switzerland, and Brazil, Lovable says it does this only with consent.

Your company can claim your account

This change cuts both ways for companies. If an employee signed up for Lovable with a work email, the company can verify it owns the domain and claim that account. Its administrators first see limited details: email address, display name, number of workspaces and projects, and last active date. The employee is notified and can either join the organization or switch the account to a personal email. If they do neither, the account transfers to the company on the date in the notice.

For a company worried about who is building what on Lovable, this is a practical tool: it shows which accounts exist on the company domain and brings them under company control.

What did not change

Several limits stay in place. Business and Enterprise workspaces are excluded from training, and Lovable's Data Processing Agreement states that customer personal data is not used to train AI models. Data from the end users of apps built on Lovable, and account and billing details, are not used for training either. Lovable says its agreements with third-party model providers restrict their use of your content, and that session recordings mask what is typed into project chat and are not used for training.

Why this matters

Lovable is not only an engineering tool. Product managers, marketers, and founders use it to build internal tools and prototypes, often on individual Pro plans. The prompts behind those projects can include customer details, internal specs, pricing, and real code. Under the new policy, that material can be used for training by default, including for models other customers may use, and switching the setting off later does not pull it back.

AI training terms are among the clauses we see change most often, as when GitBook deleted a one-sentence promise from its AI policy and Mixpanel removed its AI data opt-in. Knowing which AI tools touch company data, and on what terms, is the same work as monitoring AI subprocessors.

Potential impact

For a SaaS company whose people use Lovable, the update raises four practical questions:

  • Who at your company builds with Lovable, and on which plan?

  • Have the Free and Pro users turned off model training in their account settings, and did they do it before September 9?

  • Do you want to claim the Lovable accounts created with your company's email domain?

  • Does your internal AI policy allow customer data in prompts to tools that train on it by default?

Changes like this land without any change to the product itself, which is the hidden risk of vendor legal changes.

How Venpo detected it

Venpo monitors Lovable's legal pages as part of continuous vendor risk monitoring. On September 10, the day after the new policy took effect, it flagged the rewrite and separated the training, advertising, account-claim, and security changes from the large amount of reorganization around them. The full redline is on the Lovable change page, and every monitored Lovable document is listed on the Lovable vendor profile.

Business outcome

Teams that track Lovable got a plain-English summary of the new policy, with the deleted "never" sentence quoted next to the new training clause. That leaves time to find every Lovable account on the company domain, switch off training where needed, and decide whether company work belongs on a Business plan. The alternative is learning about default training after the prompts are already in a dataset.

Key takeaway

Lovable moved from promising that project content would never train models for other customers to training on it by default, with an opt-out that only protects what comes next. When the protection is off by default and cannot be applied backward, the only real safeguard is knowing about the change in time, which is why automated monitoring beats checking terms once a year.

Real-time change notifications

Stay ahead of every legal change

Get updates, product news and expert tips on navigating legal changes

Stripe updated Terms of Service

Dispute resolution clause now requires mandatory arbitration in all regions

High Impact2 hours ago
AWS modified Privacy Policy

Data retention period extended from 2 years to 5 years for all services

Medium Impact5 hours ago
Shopify revised Acceptable Use Policy

New restrictions on AI-generated content in product descriptions

Review1 day ago
Slack changed Data Processing Agreement

Third-party data sharing expanded to include analytics partners

High Impact1 day ago

Real-time change notifications

Stay ahead of every legal change

Get updates, product news and expert tips on navigating legal changes

Stripe updated Terms of Service

Dispute resolution clause now requires mandatory arbitration in all regions

High Impact2 hours ago
AWS modified Privacy Policy

Data retention period extended from 2 years to 5 years for all services

Medium Impact5 hours ago
Shopify revised Acceptable Use Policy

New restrictions on AI-generated content in product descriptions

Review1 day ago
Slack changed Data Processing Agreement

Third-party data sharing expanded to include analytics partners

High Impact1 day ago