
Lovable
Formerly GPT Engineer, Lovable is an AI software creation platform where you describe an app in plain language and it builds, hosts and ships it, with a built-in backend, payments and automatic security scanning.
What is Lovable?
Lovable is an AI software creation platform: you describe what you want in plain language and its agent builds a working web application around that description. The company positions it as an AI software engineer rather than a mockup tool, and what it produces is real, deployable code that can be synced out to GitHub or GitLab at any point.
The history is worth knowing, because the name changed. In mid-2023 the founders released gpt-engineer, an open-source command-line project that became one of the fastest-starred repositories on GitHub, now past 50,000 stars. They then built a commercial web version at gptengineer.app for people who did not live in a terminal, founded the company in late 2023, and relaunched the platform as Lovable in November 2024. The old address now redirects permanently to lovable.dev, and existing projects and deployments carried over unchanged.
What distinguishes Lovable is how much of the stack it absorbs. Beyond generating the interface, it provides Lovable Cloud, a built-in backend with a database, authentication, file storage and serverless functions; managed hosting with SSL; an AI gateway so published apps can offer AI features without separate API keys; and payment handling with currency conversion and tax compliance across more than 200 countries and territories. A connector catalogue links projects to tools such as Slack, Notion, HubSpot, Google Workspace and Supabase, and anything missing can be added as a custom REST connector, a custom MCP server, or written in directly by prompt.
Security sits inside the publishing flow. A basic scan runs automatically on every publish in roughly ten to fifteen seconds, a deeper on-demand scan analyses the full codebase in about three minutes, and workspace admins can auto-fix non-breaking findings or block publishing on critical ones. For larger organisations Lovable adds SSO through SAML and OIDC, SCIM provisioning, server-side role-based access control and audit logs, and states that it is certified to SOC 2 Type II and ISO 27001.
Scale is substantial: the company reports 60 million projects built, 1.2 million new ones each week, and over 900 million monthly visits to Lovable-built applications.
What it does
- Build a full-stack web application from a plain-language description
- Add a backend with database, authentication, file storage and serverless functions, with no setup
- Publish and host the result, with SSL and a domain, straight from the platform
- Connect external tools such as Slack, Notion, HubSpot or Google Workspace, or integrate any REST API
- Run an automatic security scan before every publish, and a deep codebase scan on demand
- Sync the generated code two ways with GitHub or GitLab
- Take payments in more than 200 countries, with currency conversion and tax compliance handled
When to use Lovable / When not to
A quick filter to help you decide if Lovable is the right fit.
When to use Lovable
- Founders and solo entrepreneurs who need a working product, not a mockup, and have no engineering team to hand it to
- Product managers and designers who want interactive prototypes they can put in front of users the same day
- Operations, HR and sales teams building internal tools to replace SaaS subscriptions they no longer want to pay for
- Engineering teams happy to delegate scaffolding but who insist on owning the code, thanks to two-way GitHub and GitLab sync
- Students and educators, who get a discounted plan and can share one workspace and credit pool across a whole class
When not to use Lovable
- Anyone under 18, who is barred by the terms of service outright
- Teams handling regulated sensitive data: HIPAA health information, financial account numbers, payment card data, government identifiers and biometrics are contractually excluded
- Organisations wanting an AI agent inside their existing repositories or CI/CD pipelines, which Lovable explicitly does not do
- Buyers who need a fixed, predictable monthly bill, since cost tracks credit consumption rather than headcount
- Procurement teams that require a published subprocessor list and named hosting countries before signing, as neither is public
How to use Lovable
A typical end-to-end flow, from setup to results.
- Create an account and open the dashboard
- Describe the project you want in the prompt box, in ordinary language
- Choose how the agent works: Default Mode, where credit cost varies with task complexity, or Plan Mode at one credit per message
- Watch the build happen live, then refine it by continuing the conversation
- Check what each message cost by hovering the three dots in the message history
- Add a backend with Lovable Cloud, or connect your own Supabase project instead
- Add connectors from the catalogue, picking between app-and-chat, chat (MCP) and app-user connection types
- Publish the project, which automatically triggers a basic security scan
- Sync the codebase to GitHub or GitLab if you want to take the code into your own pipeline
- Carry on from the desktop apps for tabs and local MCPs, or the iOS and Android apps to capture ideas on the move
Pros & Cons
Pros
- Covers the whole chain in one place: generation, backend, hosting, payments and publishing
- You own the code and can sync it to GitHub or GitLab, so there is a way out
- Billed by credits rather than per seat, with unlimited members in a workspace
- A genuinely permanent free plan, not a countdown trial
- Serious compliance posture for the category: SOC 2 Type II, ISO 27001, a public DPA and a DORA addendum
- Regional data residency across the EU, the US and Asia-Pacific, with no cross-region movement by default
- Real multi-platform reach: web, macOS and Windows desktop, iOS, Android, a Figma plugin and an MCP server
Cons
- Credit pricing is hard to forecast: a credit's value and burn rate both change with the plan and the feature used
- Credits expire and are never refundable, and the free plan's daily build credits run out after about six days each month
- The pricing page renders no amounts in HTML and prices are regionalised, so what you are quoted depends on your country
- The subprocessor list is not published: the page points to a Trust Center that shows nothing without a request
- On Free and Pro plans, your content is used for model training unless you go and switch it off
- Delaware law and exclusive jurisdiction, with jury-trial and class-action waivers, despite the EU-facing entity being Swedish
- No Article 27 GDPR representative, and two contradictory 'Representative' names between the privacy policy and the DPA
Pricing & Plans
There is a permanent free plan, which grants 5 build credits per day capped at 30 per calendar month, plus 20 Cloud credits and 4 AI credits monthly. The lowest paid entry point is the Pro plan at USD 25.00 per month for 100 monthly credits, falling to USD 21.00 per month on annual billing; Business starts at USD 50.00 per month for the same credit allowance. Higher tiers scale to USD 2,250 per month on Pro and USD 4,300 per month on Business, and Enterprise pricing is volume-based and not published. These amounts were read from the official documentation in US dollars on 24 August 2026; the pricing page itself publishes no figures in HTML and applies a regional currency.
- 5 build credits per day capped at 30 per calendar month
- plus 20 Cloud credits and 4 AI credits monthly
- intended for trying Lovable and smaller projects
- from USD 25.00 per month for 100 credits
- or USD 21.00 per month billed annually
- scaling to USD 2
- 250 per month for 10
- 000 credits
- adds credit top-ups at USD 15 per 50 credits and per-member credit limits
- from USD 50.00 per month for 100 credits
- or USD 42.00 per month billed annually
- scaling to USD 4
- 300 per month for 10
- 000 credits
- adds advanced controls and governance
- personal projects inside a workspace
- scheduled deep security scans and top-ups at USD 30 per 50 credits
- volume-based credit pricing agreed by contract
- without the daily build credits or the monthly Cloud and AI grants included on the other plans
Data, GDPR & hosting
A consolidated view of how Lovable handles your data.
GDPR overview
Concrete and documented, though never phrased as a flat claim of compliance: Lovable says it supports GDPR compliance. It publishes a signable Data Processing Agreement, effective November 2025, covering the GDPR, UK GDPR, CCPA and the EU-US Data Privacy Framework with its UK and Swiss extensions. A Data Protection Officer is appointed and reachable at dpo@lovable.dev, an EU address is published in Stockholm, and the company states it keeps an Article 30(2) record of processing activities and runs regular risk assessments. Verified data-subject requests are answered within about thirty days, and the policy names the Irish Data Protection Commission, the UK ICO and the Swiss FDPIC as escalation routes. A DORA addendum is available. One gap stands out: no Article 27 representative is identified, and the two 'Representative' names shown on the site contradict each other.
Who owns the data?
Under the terms you own what you make: the apps, websites and other projects you build, the customer data stored in Lovable, and the AI output you generate, subject to any third-party rights in the underlying models. Lovable retains ownership of the platform itself, including Lovable Cloud, the AI gateway and all underlying software, models and interfaces. It also owns all usage data your activity generates and may use it for monitoring, analytics, benchmarking and product development. Separately, it may create de-identified, anonymised or aggregated data from your content and keep that on a perpetual basis for any lawful business purpose. Under a managed organisational account, an administrator can access, retain, suspend or delete the account and its contents.
Reuse rights
You can reuse what you build without asking permission. The licence covers creating, deploying, operating and making available the applications and websites you produce, and letting your own end users access them, for personal or internal business purposes. Because ownership of the output stays with you, commercial use is not gated behind a separate approval. Two limits matter. You may not copy, modify, sell, lease, sublicense or otherwise exploit the Lovable platform or Lovable's own materials beyond what the terms allow, and your licence to the Services ends immediately if the account is terminated. Rights in the underlying AI models stay with their owners, which qualifies your ownership of generated output.
Data retention & training
Hosting summary
Customer data lives in Lovable Cloud, with a choice of region between the European Union, the United States and Asia-Pacific. Data stays in the region you select and does not cross regional boundaries by default. No individual country is ever named, only these three regions, so exact data-centre locations are not public. The underlying facilities are described as SOC 2 and ISO 27001 certified, with 24/7 guards, biometric access, CCTV and environmental safeguards. Infrastructure protections include a web application firewall, network isolation, encryption at rest and adaptive rate limiting at IP, user and workspace level. The platform is multi-tenant with logical isolation between workspaces and projects, enforced at both the application and infrastructure layers, and secrets are encrypted at rest, scoped to environments and never exposed in plaintext in logs or interfaces. Transfers outside the EEA are governed by the Data Processing Agreement, which cites the EU-US Data Privacy Framework and its UK and Swiss extensions. Note that the resolved server address is a Cloudflare anycast IP and indicates nothing about where data actually rests.
Things to keep in mind
Risks and trade-offs to weigh before adopting Lovable.
- Credit-based pricing invites overspending: the cost of a prompt is only visible after the fact, and a frustrating afternoon of retries burns credits with nothing to show for it
- On Free and Pro plans your prompts and code feed model training by default, so the privacy-protective choice is the one you have to go and find
- Building software you cannot read is a real hazard: shipping an app whose logic you never reviewed makes you responsible for behaviour you do not understand
- The subprocessor list is not published and the Trust Center returns nothing without a request, so you cannot see who else touches your data before you commit
- Legal exposure sits further away than the Stockholm address suggests: Delaware law, exclusive Delaware jurisdiction, a jury-trial waiver, a class-action waiver and liability capped at twelve months of fees
- Making software this easy encourages replacing vetted SaaS with tools nobody maintains; several published case studies celebrate retiring dozens of systems, which is also dozens of new things to keep alive
- The brand logos on the homepage are companies whose staff use the tool, which is not the same as enterprise customers endorsing it
Setup & Integrations
Technical difficulty
Very low to begin. Nothing is installed: create an account, open the dashboard and type a prompt in the browser. Hosting, SSL, the backend and payments are all supplied, so there is no infrastructure work, and the company states that no technical knowledge is needed. The difficulty arrives later rather than at setup: understanding how credits are consumed, choosing between the three connector types, and judging when to sync code out to Git. For a company-wide rollout, configuring SSO, SCIM and role-based access control is an administrator's task rather than an end user's.
Deployment
Apps stores
Integrations
Supported languages
Behind Lovable
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Lovable.
Frequently asked questions
Does gptengineer.app still work?
Do I need to know how to code?
Who owns the code and the projects I build?
Is there a free plan, and how much does the first paid plan cost?
Am I billed per user?
Do credits expire?
Is my data used to train AI models?
Where is my data hosted?
Is there an API, and are there apps?
What is the minimum age, and how do I reach support?
Should you pick Lovable?
Lovable is one of the most complete tools in the AI app-building category, and one of the best funded: USD 400 million raised in August 2026 at a USD 13.3 billion valuation. Its real differentiator is not code generation, which many rivals now do, but how much of the surrounding stack it absorbs. Backend, hosting, payments, integrations, security scanning and enterprise access controls all come from the same place, and the code stays yours with a two-way sync to GitHub or GitLab if you ever want to leave. For the category, the compliance posture is unusually solid: SOC 2 Type II, ISO 27001, a public Data Processing Agreement, a DORA addendum and a genuine choice of data region.
The reservations are real, though. Credit pricing is opaque enough that budgeting is guesswork until you have used the product for a month, and credits expire without refund. The subprocessor list is not published, which will stop some procurement teams outright. On the Free and Pro plans your content trains models unless you find the switch and turn it off, which is the wrong default. And the legal framing is oddly split: a Swedish address and a Swedish operating entity, but Delaware law, Delaware courts and a jury-trial waiver, with no Article 27 GDPR representative and two contradictory 'Representative' names across the privacy policy and the DPA.
One practical note. This directory entry points at gptengineer.app, which no longer serves anything: it redirects permanently to lovable.dev. GPT Engineer was the earlier name of this same platform, rebranded in November 2024. If you are looking for GPT Engineer, Lovable is what you have found.
- Choosing a selection results in a full page refresh.
- Opens in a new window.