[{"data":1,"prerenderedAt":467},["ShallowReactive",2],{"blog-how-to/lovable-training-opt-out":3},{"id":4,"title":5,"body":6,"category":431,"date":432,"dateModified":432,"description":433,"draft":434,"extension":435,"faq":436,"featured":434,"headerVariant":449,"image":450,"keywords":451,"meta":452,"navigation":455,"ogDescription":456,"ogTitle":450,"path":457,"readTime":458,"schemaOrg":459,"schemaType":460,"seo":461,"sitemap":462,"stem":463,"tags":464,"twitterCard":465,"__hash__":466},"blog/blog/how-to/lovable-training-opt-out.md","Does Lovable Train on Your Code? The September 9, 2026 Change",{"type":7,"value":8,"toc":418},"minimark",[9,18,21,27,32,43,49,62,65,71,77,81,84,91,94,98,101,104,121,124,136,140,159,171,183,189,192,196,199,202,205,208,212,215,220,223,226,262,265,269,272,275,281,287,296,301,304,313,317,320,344,353,387,406],[10,11,12,13,17],"p",{},"Lovable announced on 2026-07-31, with formal notice given on 2026-08-05, that from ",[14,15,16],"strong",{},"September 9, 2026"," it may use customer data from the Free and Pro plans to train its AI models. That is six days from this post. The opt-out is free, takes about ten seconds, and most people building on Lovable have not heard about it.",[10,19,20],{},"The part worth acting on today is the timing. Opting out before the 9th and opting out after the 9th produce different outcomes, and Lovable says so plainly.",[22,23,24],"tldr",{},[10,25,26],{},"Free and Pro are opted in by default from September 9, 2026. The toggle is in Settings, then Your account, it costs nothing, and it doesn't degrade any AI feature. Two things people get wrong: opting out only counts going forward, so doing it before the 9th is the only version where your content is never used at all, and the setting is per person rather than per workspace. If you are on Business, check the setting rather than trusting the summary; Lovable's own docs disagree with each other about your default.",[28,29,31],"h2",{"id":30},"what-is-in-scope","What is in scope",[10,33,34,35,42],{},"Lovable's ",[36,37,41],"a",{"href":38,"rel":39},"https://docs.lovable.dev/features/business/data-opt-out",[40],"nofollow","data opt-out documentation"," defines customer data like this:",[44,45,46],"blockquote",{},[10,47,48],{},"prompts (including images and files you attach), code, project files, hosted applications, configurations, and generated outputs",[10,50,51,52,57,58,61],{},"Its FAQ and the ",[36,53,56],{"href":54,"rel":55},"https://lovable.dev/legal/privacypolicyaugust2026",[40],"Summary of Changes"," give a slightly different list: the same items minus \"hosted applications\" and \"configurations\", plus ",[14,59,60],{},"usage data",". Three descriptions from the same company, three lists. Take the union rather than the flattering subset, since nothing says the shorter lists are narrowing anything.",[10,63,64],{},"Two entries deserve a second read.",[10,66,67,70],{},[14,68,69],{},"\"prompts (including images and files you attach).\""," Not just the code Lovable wrote for you. The things you typed at it, and the things you dragged into the chat. Think about what that has actually included over the life of your project: an error message pasted straight out of a terminal, a screenshot of a dashboard, a CSV you attached so the model could infer a schema.",[10,72,73,76],{},[14,74,75],{},"\"configurations.\""," Configuration is where connection strings live.",[28,78,80],{"id":79},"what-is-not-in-scope","What is not in scope",[10,82,83],{},"Worth stating as clearly as the risks, because the alarming version of this story is wrong.",[10,85,86,87,90],{},"Lovable excludes ",[14,88,89],{},"end-user data",". Its wording: \"information your apps' visitors or customers submit stays in your project's own database and storage, and is not used to train our models.\" Account and billing details are excluded too.",[10,92,93],{},"So this covers what you put into Lovable while building. Not what your customers put into the thing you shipped.",[28,95,97],{"id":96},"if-you-are-on-business-do-not-trust-the-summary","If you are on Business, do not trust the summary",[10,99,100],{},"This is the one place Lovable's documentation contradicts itself, and it matters because it decides whether you need to do anything at all.",[10,102,103],{},"The opt-out page says Business and Enterprise workspace data \"is excluded from model training by default. No opt-out is needed.\"",[10,105,106,107,112,113,117,118],{},"The ",[36,108,111],{"href":109,"rel":110},"https://docs.lovable.dev/features/privacy-and-security-settings",[40],"privacy and security settings reference"," describes a workspace-level toggle called ",[114,115,116],"code",{},"Use workspace content for model training"," and lists its default as: ",[14,119,120],{},"\"Enabled on Business, Disabled on Enterprise.\"",[10,122,123],{},"Enabled means use the workspace's content for training. So one page says Business is excluded by default and another says the Business default is on.",[125,126,127,133],"warning-box",{},[10,128,129,132],{},[14,130,131],{},"We are not going to guess which is authoritative."," There's a reading where both are true, in which the contractual agreement governs and the toggle just lets an admin state the choice explicitly, and Lovable's settings page gestures at that. But it is an inference, not something either page states, and \"your enterprise agreement probably covers it\" is a thin thing to rest customer code on.",[10,134,135],{},"If you administer a Business workspace, open Settings, then Privacy and security, and look at the actual state of that toggle. Then you know. Enterprise appears unambiguous; Business does not, and the two are not interchangeable here.",[28,137,139],{"id":138},"how-to-opt-out","How to opt out",[141,142,144],"step",{"number":143},"1",[10,145,146,147,150,151,154,155,158],{},"Open Lovable and go to ",[14,148,149],{},"Settings",", then ",[14,152,153],{},"Your account",", then the ",[14,156,157],{},"AI model training"," section.",[141,160,162],{"number":161},"2",[10,163,164,165,170],{},"Turn the content-training toggle off. Go by the section, not the label: Lovable's ",[36,166,169],{"href":167,"rel":168},"https://docs.lovable.dev/introduction/lovable-account-settings",[40],"account settings docs"," call it \"Use my Lovable content for model training\", while the 2026-08-07 changelog entry renaming these settings calls it \"On Your Customer Content\". There is one toggle and two published names for it.",[141,172,174],{"number":173},"3",[10,175,176,177,150,179,182],{},"If you administer a Business or Enterprise workspace, check the separate workspace-level control under ",[14,178,149],{},[14,180,181],{},"Privacy and security",", per the section above. Lovable states that an account-level opt-out always applies regardless of the workspace setting, so your personal toggle is not overridden by it either way.",[141,184,186],{"number":185},"4",[10,187,188],{},"Get everyone else who works on the project to do step 1 and 2 for themselves. The next section is why that is not optional.",[10,190,191],{},"Two reassurances from Lovable's own docs, so nobody talks themselves out of it: the setting is \"available on any plan\", and turning it off \"is free and doesn't affect your use of AI features.\" No paywall, no feature penalty.",[28,193,195],{"id":194},"the-bit-almost-nobody-notices-it-is-per-person","The bit almost nobody notices: it is per person",[10,197,198],{},"From Lovable's account settings documentation, the setting \"covers only your own data and does not change the setting for other members of a workspace you belong to.\"",[10,200,201],{},"Read that again if you work with anyone.",[10,203,204],{},"You can opt out, feel done, and still have your project's code in scope because your co-founder never touched their own toggle. Or the contractor you onboarded for three weeks in June. Their prompts are about the same codebase, and their attachments are your project files. The opt-out protects your account, not your project.",[10,206,207],{},"For Free and Pro there is no documented admin switch that does this on everyone's behalf. It's a conversation you have to have with each person.",[28,209,211],{"id":210},"why-the-date-matters-more-than-the-toggle","Why the date matters more than the toggle",[10,213,214],{},"Here's the asymmetry that makes this a this-week job. Lovable's documentation says opting out",[44,216,217],{},[10,218,219],{},"takes effect going forward: your content is excluded from all training data assembled after your opt-out takes effect. It does not retract content from training datasets assembled, or models trained, before then.",[10,221,222],{},"\"Or models trained\" is the half worth noticing. A dataset can in principle be rebuilt. A model that has already been trained is not something an opt-out reaches into.",[10,224,225],{},"And for people who move before the deadline: \"If you opt out before September 9, 2026, training under the updated policy will not have started, so your content is not used for training at all.\"",[227,228,229,242],"table",{},[230,231,232],"thead",{},[233,234,235,239],"tr",{},[236,237,238],"th",{},"When you opt out",[236,240,241],{},"What happens",[243,244,245,254],"tbody",{},[233,246,247,251],{},[248,249,250],"td",{},"Before 2026-09-09",[248,252,253],{},"Training under the new policy hasn't started, so your content isn't used at all",[233,255,256,259],{},[248,257,258],{},"After 2026-09-09",[248,260,261],{},"Excluded going forward. Datasets already assembled, and models already trained, stay as they are",[10,263,264],{},"Nothing about the second row is unreasonable, and it is how nearly every training opt-out works. It just isn't reversible, which makes this a deadline rather than a setting.",[28,266,268],{"id":267},"the-secrets-question-answered-carefully","The secrets question, answered carefully",[10,270,271],{},"The obvious worry: you pasted an API key into a Lovable chat six weeks ago while debugging a webhook. Is that now training data?",[10,273,274],{},"Being precise here matters, so two separate things.",[10,276,277,280],{},[14,278,279],{},"What the documentation says."," Nothing in Lovable's opt-out page, settings reference, Summary of Changes, security page or changelog commits to filtering, redacting or scrubbing credentials out of training data on Free or Pro. That's an absence, not an admission. But prompts are in scope by Lovable's own definition, and a pasted key sits in a prompt.",[10,282,283,286],{},[14,284,285],{},"What we could not check."," The operative text is Section 5 of the updated Privacy Policy, which takes effect on the 9th and is not publicly readable today. We tried. So the honest statement is that Lovable's published documentation contains no commitment to filter secrets from training data, not that Lovable will train on your API keys. Those are different claims and only the first one is sourced.",[10,288,289,290,295],{},"There is one more detail that sharpens this, from Lovable's own ",[36,291,294],{"href":292,"rel":293},"https://docs.lovable.dev/features/sensitive-data-scanning",[40],"sensitive data scanning"," docs. Lovable does ship machinery for exactly this problem: it detects \"Passwords, API keys, and other authentication secrets\" and can redact them before a chat message is sent. Its prerequisites are one line long:",[44,297,298],{},[10,299,300],{},"To use sensitive data scanning, you need: An Enterprise plan.",[10,302,303],{},"So the documented mechanism for keeping a pasted credential out of chat history is available on the one tier whose data is least likely to be training material anyway.",[305,306,307],"danger-box",{},[10,308,309,312],{},[14,310,311],{},"The action item doesn't depend on any of the above."," Rotate every credential you have ever pasted into a chat window, in any tool. A secret that has been through a chat log has more copies than you can account for: your session history, the provider's logs, your own scrollback, and whatever the model did with it. This deadline is just the nudge to finally do it.",[28,314,316],{"id":315},"the-five-minutes-actually-worth-spending","The five minutes actually worth spending",[10,318,319],{},"Opting out is the easy part. If you are already in there, the more valuable pass is working out what you have handed over in chat.",[321,322,323,328,332,336,340],"checklist-section",{},[324,325],"checklist-item",{"description":326,"label":327},"Per person, not per workspace. One unopted teammate covers the same codebase.","Opt out, then get every collaborator to opt out",[324,329],{"description":330,"label":331},"Lovable's docs give two different answers for the Business default. Reading the setting is the only way to know yours.","If you run a Business workspace, look at the workspace toggle",[324,333],{"description":334,"label":335},"Search for sk_, eyJ, postgres:// and the word key. Debugging sessions are where these end up.","Scroll back through chat history for pasted secrets",[324,337],{"description":338,"label":339},"Chat logs are not a place a live credential should ever have been.","Rotate anything you find, whatever the policy says",[324,341],{"description":342,"label":343},"This policy covers build-time content. Your live bundle is a separate and usually larger exposure.","Confirm what your deployed app exposes right now",[345,346,347],"info-box",{},[10,348,349,352],{},[14,350,351],{},"Where we sit."," CheckYourVibe scans deployed apps, so we have no visibility into anyone's Lovable account settings and nothing to sell you on this page. We wrote it because the failure next door, a credential that reached somewhere it should not have, is what we see constantly.",[354,355,356,363,369,375,381],"faq-section",{},[357,358,360],"faq-item",{"question":359},"Does Lovable train its AI models on my code?",[10,361,362],{},"From September 9, 2026, on Free and Pro, yes, unless you opt out. Lovable's notice covers customer data, which it defines as \"prompts (including images and files you attach), code, project files, hosted applications, configurations, and generated outputs\". Two of its three published descriptions also list usage data.",[357,364,366],{"question":365},"How do I opt out of Lovable AI model training?",[10,367,368],{},"Settings, then Your account, then the AI model training section, then turn the content-training toggle off. Go by the section rather than the label, because Lovable's docs and its August 7 changelog name that toggle differently. It is available on any plan, it is free, and Lovable says it \"doesn't affect your use of AI features\".",[357,370,372],{"question":371},"Does opting out remove data Lovable already has?",[10,373,374],{},"No. Lovable says opting out \"takes effect going forward\" and \"does not retract content from training datasets assembled, or models trained, before then\". Opting out before September 9, 2026 is the only route where your content is not used at all.",[357,376,378],{"question":377},"Does my opt-out cover my whole team?",[10,379,380],{},"No. Lovable's account settings docs say the setting \"covers only your own data and does not change the setting for other members of a workspace you belong to\". Everyone on the project has to do it themselves.",[357,382,384],{"question":383},"Is Business or Enterprise excluded by default?",[10,385,386],{},"Enterprise clearly is. Business is ambiguous in Lovable's own documentation: the opt-out page says Business and Enterprise are \"excluded from model training by default\", while the privacy and security settings reference gives the workspace training toggle a default of \"Enabled on Business, Disabled on Enterprise\". On Business, open the setting and look.",[388,389,390,396,401],"related-articles",{},[391,392],"related-card",{"description":393,"href":394,"title":395},"The wider picture: what Lovable gets right, and the defaults worth changing before launch.","/blog/is-safe/lovable","Is Lovable Safe? A Security Review",[391,397],{"description":398,"href":399,"title":400},"The rotation and damage-control steps for a credential that has already left your machine.","/blog/how-to/ai-api-key-stolen","What to Do When an AI Tool Leaks Your API Key",[391,402],{"description":403,"href":404,"title":405},"The RLS policies and key split a Lovable app should ship with.","/blog/blueprints/lovable-supabase","Lovable + Supabase Security Blueprint",[407,408,411,415],"cta-box",{"href":409,"label":410},"/","Start Free Scan",[28,412,414],{"id":413},"your-settings-are-one-half-of-it","Your settings are one half of it",[10,416,417],{},"Scan your deployed Lovable app and see the keys, headers and endpoints it hands to anyone who loads the page.",{"title":419,"searchDepth":420,"depth":420,"links":421},"",2,[422,423,424,425,426,427,428,429,430],{"id":30,"depth":420,"text":31},{"id":79,"depth":420,"text":80},{"id":96,"depth":420,"text":97},{"id":138,"depth":420,"text":139},{"id":194,"depth":420,"text":195},{"id":210,"depth":420,"text":211},{"id":267,"depth":420,"text":268},{"id":315,"depth":420,"text":316},{"id":413,"depth":420,"text":414},"how-to","2026-09-03","From September 9, Lovable may use Free and Pro prompts, code and project files for model training. The opt-out is free, per person, and only counts forward.",false,"md",[437,439,441,444,447],{"question":359,"answer":438},"From September 9, 2026, on the Free and Pro plans, yes, unless you opt out. Lovable's notice says customer data from Free and Pro plans may be used to train, develop and improve its AI models. Its definition of customer data covers prompts (including images and files you attach), code, project files, hosted applications, configurations and generated outputs, and two of its three descriptions also list usage data.",{"question":365,"answer":440},"Open Settings, then Your account, find the AI model training section and turn the content-training toggle off. Lovable's docs and its August 7 changelog give that toggle two different names, so go by the section rather than the label. The setting is available on any plan, it is free, and Lovable says it does not affect your use of AI features.",{"question":442,"answer":443},"Does opting out remove my old data from Lovable's training set?","No. Lovable says opting out takes effect going forward and does not retract content from training datasets assembled, or models trained, before then. Opting out before September 9, 2026 is the only path where your content is not used for training at all.",{"question":445,"answer":446},"Does opting out cover my whole team?","No, and this is the part people miss. Lovable's account settings documentation says the setting covers only your own data and does not change the setting for other members of a workspace you belong to. Each person opts out for themselves, so one teammate who never touches the toggle keeps their prompts about your project in scope.",{"question":383,"answer":448},"Enterprise clearly is. Business is genuinely ambiguous in Lovable's own documentation: the opt-out page says Business and Enterprise workspace data is excluded from model training by default with no opt-out needed, while the privacy and security settings reference lists the workspace training toggle as Enabled on Business, Disabled on Enterprise. If you are on Business, open the setting and look rather than assuming.","yellow",null,"does lovable train on my code, lovable ai model training opt out, lovable data opt out, lovable privacy, lovable september 9 2026, is lovable safe for private code",{"trendTrigger":453,"trendDate":454},"lovable-model-training-free-and-pro-opt-in-effective-2026-09-09","2026-07-31",true,"The opt-out is free and takes ten seconds. Doing it before September 9 and doing it after are two different outcomes.","/blog/how-to/lovable-training-opt-out","8 min read","[object Object]","HowTo",{"title":5,"description":433},{"loc":457},"blog/how-to/lovable-training-opt-out",[],"summary_large_image","8cqQh1d0QmXx0xpTDwdusMT_2Jz9HPrv3eWlD9pM_oA",1789672859730]