Lovable denies data breach, says public settings are ‘intentional’

Lovable denies data breach, says public settings are ‘intentional’



Stockholm-based AI app-building platform Lovable said it did not suffer a data breach after concerns surfaced over the visibility of chat messages and code in projects set to public.

The startup acknowledged that its documentation around what “public” meant had been unclear.

In a statement posted on X on Monday, the company said it had been “made aware of concerns regarding the visibility of chat messages and code on Lovable projects with public visibility settings.” It added that the issue stemmed from unclear documentation rather than a security breach.

The statement follows disclosures by a researcher posting under the handle “impulsive” (@weezerOSINT), who went public with the issue after reporting it to the company more than six weeks ago.

In a series of posts on X, the researcher said he was able to access another developer’s active project, including its full source code, database credentials, customer records, AI chat histories and related data.