Bolt.new changed two things in the past three months that most reviews haven't caught up with. In August it added a security audit that reviews your whole project for free on paid plans, which is more than most competitors offer. And on October 7, 2026, its updated privacy policy took effect for existing accounts, letting StackBlitz train AI models on what you build unless you switch it off. A review written in the spring tells you neither. This one covers both, along with pricing, exit, and what users actually complain about.
TL;DR
Bolt.new is a fast JavaScript app builder with a better exit than most: zip export, two-way GitHub sync, and a Supabase-backed database you can claim into your own account on paid plans. The weak spots are cost and data use. Tokens burn per AI action, and its Trustpilot score sits at 1.6 out of 5, mostly over fix loops and support. Training on your new projects is on by default outside Europe. On security it's better equipped than its peers, but the browser still talks straight to the database. Our rating: 3.3 out of 5.
Our Verdict
Use with Caution| What we scored | Score | Why |
|---|---|---|
| Speed to a working app | 4/5 | Users praise how fast small sites and prototypes come together; larger projects slow down as fix loops grow |
| Code ownership and exit | 4/5 | Zip download, GitHub sync, CSV/JSON data export. Claiming the database into Supabase needs Pro or Teams |
| Pricing predictability | 2/5 | Per-action tokens and a 300K daily cap on free. Two-month rollover on paid plans softens it a little |
| Security defaults | 3/5 | Free database check, paid security audit that doesn't cost tokens, but RLS is the only thing between the browser and your data |
| Overall | 3.3/5 |
What's Good
- Security audit on paid plans, up to 30 a day, and it doesn't use tokens
- Database security check on every plan, including free
- Download any project as a zip, or sync both ways with GitHub
- Bolt Database runs on Supabase, so you can claim it into your own account (Pro or Teams)
- Unused paid tokens roll over for two months
What to Watch
- Token burn on fix loops is the top complaint by a wide margin
- Training on your new content is on by default outside the EEA, UK and Switzerland
- Free sites go offline for the rest of the month if they hit the request cap
- No custom domains on the free plan
- The browser-to-database model means one loose RLS policy exposes a table
How we reviewed this. We worked from Bolt's pricing page, its support docs and release notes, the StackBlitz privacy policy, and public user reviews on Trustpilot, all read on 2026-10-09, plus the code patterns from our Bolt.new security analysis. We haven't yet run a timed hands-on build or scanned a fresh Bolt app for this page, so the speed score reflects what users report, not our stopwatch. Bolt didn't sponsor or review this page.
What Bolt Actually Builds
You describe an app and an agent writes it in the browser. Bolt's docs say it "focuses on JavaScript-based web technologies" with Node.js on the backend, and that Python or PHP backends aren't supported. Put "mobile app" in your first prompt and it builds with Expo instead.
Since late 2025, a project that needs a backend gets a Bolt Database automatically. Supabase's own launch post says every Bolt Cloud project that needs a backend "is powered by Supabase", so under the hood it's Postgres with row-level security (RLS), plus built-in auth. Hosting is on Bolt's own bolt.host domains, with custom domains on paid plans. Netlify is still an option, but once you publish to Bolt hosting the project can't be moved to Netlify.
That Supabase base matters for everything below. Unlike Emergent, which puts a FastAPI backend between the browser and the database, a Bolt app's frontend usually queries the database directly and relies on RLS policies to say no.
Pricing and Tokens
Here's what Bolt's pricing page lists as of 2026-10-09. It changes often (an invite-only $9 "Bolt Lite" plan showed up in September release notes and has since disappeared from the page), so check before you buy.
| Plan | Monthly | Tokens | Notable limits |
|---|---|---|---|
| Free | $0 | 1M per month | 300K per day, Bolt branding, sites capped at about 333K requests a month |
| Pro | $25 | Starts at 10M per month | No daily cap, custom domains, 1M requests |
| Teams | $30 per member | Per-member allotment, not shared | Everything in Pro |
| Enterprise | Custom | Custom |
Yearly billing saves up to 28%. Paid tokens that you don't use roll over and stay valid for two months, which is more forgiving than builders where credits vanish at month end. Free tokens don't roll over, and cancelling forfeits everything at the end of the billing cycle.
One limit catches people out. Bolt's hosting docs say the free plan's bandwidth and request limits are hard limits: go over and the site is offline for the rest of the month. That's fine for a prototype. It's a bad surprise for an app you've shown to customers.
Token burn is the complaint that won't go away. Bolt's Trustpilot page shows a TrustScore of 1.6 from 204 reviews, 83% of them one-star, and the theme repeats: an error, a fix that doesn't fix it, another try, and the balance drains. One reviewer put it as tokens "gobbled up faster than a starving pirranha". If you're on Pro, stop the agent the second time it fails on the same bug and read the error yourself.
Code Ownership and Leaving
Bolt's exit is better than its reputation.
- Code. Any project downloads as a zip from the Export menu. GitHub sync is two-way: Bolt checks for changes every 30 seconds, though merging branches has to happen in GitHub.
- Data. Table rows export as CSV or JSON from the database view.
- The database itself. On Pro or Teams you can claim a Bolt Database into your own Supabase account, which gets you SQL editing, monitoring and a clean way out. Free users can't claim.
Two caveats. Projects started before September 30, 2025 used your own Supabase account and can't be converted to Bolt Database. And Bolt's docs warn that version history doesn't restore the database, so rolling back a bad AI change brings back old code against current data.
The Training Default
This is the newest change and the one to act on today.
StackBlitz's privacy policy, last updated September 22, 2026 and effective for existing accounts from October 7, says that "unless you opt out", it may use Bolt content to train, fine-tune and evaluate AI models built by or for StackBlitz. Bolt's release notes confirm the new model-training setting is on by default.
The details that matter:
- It doesn't apply to accounts in the EEA, the UK or Switzerland.
- Content from before October 7, 2026 isn't used.
- You can opt out for free on any plan, in account settings or by emailing privacy@stackblitz.com. The policy says opt-outs take effect within 15 days.
- Bolt Forge is separate. If you turn it on, your de-identified prompts and code go to partners training open-source models, and your opt-out doesn't cover Forge content while it's enabled.
If your project holds client code, customer data in prompts, or anything under an NDA, switch the setting off before your next session.
Security: The Short Version
Our Bolt.new security analysis walks through the vulnerable patterns in detail. Here's what matters for a buying decision.
The good part. Bolt has more built-in security tooling than most builders. Its security docs describe two layers:
- A database security check on every plan, described as "a lightweight review" that flags things like a table anyone can read.
- A security audit on paid plans that reviews code and database together: who can see and change data, what the app makes public, sign-in, input handling, and keys. You can run up to 30 a day, and "neither the audit nor its fixes use your tokens".
Use the Run security audit button in the Publish menu, not a chat prompt. Bolt's docs say prompting it to audit your project costs tokens; the button doesn't.
The missing part. The architecture hasn't changed. The browser talks to a Supabase database, and RLS policies are the only thing deciding who sees which rows. A policy that checks "is logged in" instead of "owns this row" passes a casual look and returns everyone's data. Free users get only the lightweight check, and Bolt's own docs warn that audit fixes can change things you didn't want changed.
Two things to check by hand on every Bolt app, audit or not. First, open the deployed site, view source, and search the JavaScript for sk_, secret and service_role. Bolt apps are Vite projects, and Vite inlines every VITE_ variable into the bundle the browser downloads. Bolt's Secrets tab exists to keep keys server-side; a key typed into a .env as VITE_STRIPE_SECRET skips it entirely. Second, sign in as a second test user and try to load the first user's records. That five-minute test catches the broken-access-control bug an "authenticated users can read" policy creates. Our guide to fixing Bolt API key exposure covers the first in detail.
Since June 2026, new Bolt databases have leaked-password protection on by default, and Bolt's security page says it is SOC 2 Type 2 certified. We found no public CVE, advisory or reported breach specific to the Bolt.new platform as of this writing.
What Users Say
Praised: speed on small projects, and an approachable interface. One reviewer built a multi-page site with a full menu "in under an hour"; another says they've made "thousands of dollars" from apps they built on it.
Complained about: token drain, support tickets that go unanswered, day-to-day platform bugs (GitHub connection loops come up more than once), and billing, including a charge after a confirmed cancellation. A September reviewer noted support had started replying faster, while being unsure it would last.
What's missing from both lists is the same thing we noticed reviewing Emergent and Lovable: almost nobody mentions access control or exposed data. That's not a sign it's fine. It's a sign people aren't testing it.
Who Bolt Is For
A good fit if you want a JavaScript web app or Expo prototype quickly, you're on a paid plan so you get the audit and the database claim, and you're willing to read your RLS policies.
A poor fit if you need a Python backend, a fixed monthly cost, or you're putting sensitive client work into prompts and won't change the training setting.
Bolt.new Alternatives
People most often weigh Bolt against Lovable, v0, Replit, Base44 and Emergent.
- Lovable uses the same Supabase-and-RLS model, with Git sync and its own security scanning. Our Lovable review covers it the same way, and the Bolt vs Lovable comparison puts their defaults side by side.
- Emergent is the structural opposite: a FastAPI backend sits between browser and database, so there's no direct database exposure, but also no row-level backstop. See our Emergent review.
If you can work in an editor, Cursor or Claude Code give you more control than any app builder, at the cost of wiring up hosting and a database yourself.
Is Bolt.new worth it?
It's worth it for getting a JavaScript web app or prototype live quickly, and its exit is better than most: zip download, two-way GitHub sync, and on paid plans you can claim the database into your own Supabase account. It's a weaker deal if you need predictable costs, because tokens are spent per AI action and users consistently report fix loops draining them.
How much does Bolt.new cost?
Bolt's pricing page lists a free plan with 1M tokens a month and a 300K daily cap, Pro from $25 a month starting at 10M tokens, and Teams at $30 per member a month. Yearly billing saves up to 28%. Unused paid tokens roll over for two months; free tokens don't roll over.
Can I export my code from Bolt.new?
Yes. You can download any project as a zip, or connect GitHub for two-way sync. Table data exports as CSV or JSON. To move the whole Bolt Database into your own Supabase account you need Pro or Teams, since claiming isn't available on the free plan.
Is Bolt.new safe?
Bolt ships more security tooling than most builders: a database check on every plan, and a full security audit on paid plans that doesn't use tokens. The apps still follow the browser-to-database model, so a weak row-level security policy exposes data directly. Free users only get the lightweight check, so read your policies yourself before launch. Our security analysis covers the details.
Does Bolt.new train AI on my code?
By default, yes, for new content outside the EEA, UK and Switzerland. StackBlitz's privacy policy, effective for existing accounts on October 7, 2026, lets it train models on Bolt content unless you opt out in account settings or by emailing privacy@stackblitz.com. Content from before that date isn't used.
Built something on Bolt.new?
Scan the deployed URL for exposed keys in your JavaScript, missing headers, open files and TLS issues. No signup needed to see your first results.