Vespez Research — October 2026
We scanned 100 Lovable apps for GDPR and security. Not one came back clean.
Every single app that could be scanned had at least 3 likely issues. The median app had 6. Here is what we found.
How we did it
100 apps were taken from the public Lovable showcase. Each was scanned on its public pages only — no logins, no databases, nothing behind authentication. Vespez assigned each app a security score and a GDPR score (0–100), plus a count of findings. Every result below is a "likely issue." Automated scanners can be wrong, and findings have not been individually verified by hand. We are publishing totals only — no app names — because the point is the pattern. Where we found something serious, we contacted the owner privately.
14 of 100 couldn't be scanned
13 apps didn't respond at all. 1 was only reachable over plain http://. That leaves 86 apps scanned.
GDPR: this is where it falls apart
A score of 0 means the scanner found the basics missing: a privacy policy, a cookie consent flow, trackers loading before consent. These aren't exotic findings. They are the first things a regulator or a client's lawyer looks at.
Security: mostly average, with a long tail
59 of 86 apps landed on exactly 80 — which suggests one common issue that most apps share. Only 5 scored 90 or higher.
96% of scanned apps had no Content-Security-Policy header — meaning the browser has no instruction on what scripts or resources the page is allowed to load.
Findings per app
- Average likely issues per app (range: 3–13)
- Had 10 or more findings (15 apps)
- Had 4 or fewer findings (20 apps)
Custom domains did worse on GDPR
lovable.app subdomains
Custom domains
Small samples, so treat it as a pattern worth checking, not a law. Apps on their own domain are more likely to be real businesses with real visitors — which makes the gaps matter more, not less.
What this means
AI builders make it easy to ship something that looks finished. They don't prompt you to think about consent banners, privacy policies, or what a tracker does before the visitor says yes. If you build apps for clients, that gap becomes your problem at handover.
A quick pre-launch checklist:
- Is there a privacy policy, and does it say how to contact you?
- Does anything analytics-related load before the visitor consents?
- Do you have a cookie banner that actually blocks things until accepted?
- Are any API keys or tokens visible in the frontend source?
- Is the site on HTTPS with sensible security headers?
Limits of this study
100 apps from one showcase is not all of Lovable. Showcase apps skew toward hobby projects. The scores come from Vespez, so they reflect what Vespez checks. These are likely issues, not confirmed violations — some will be false positives.