Why Lovable apps ship without a privacy page
The launch checklist item is always the same: publish /privacy and name the vendors. On r/lovable that page is missing more often than login. People add Supabase, Stripe and a waitlist, then share a preview URL with no contact email and no policy.
Auth, payments and analytics are personal data even when the app has twelve users. A generic “we respect your privacy” block that does not name processors fails the first trust check — and it is the thing lawyers, Stripe, and picky customers look for.
What to name
List every processor that can see user data:
- Lovable if the app is still hosted there.
- Supabase for auth and the database.
- Stripe for checkout. Card numbers stay with Stripe; say that.
- Resend or Loops if you send mail.
- Fathom, Plausible, PostHog or Google Analytics if you measure usage.
If you add a vendor next week, regenerate the page. A stale list is worse than a short one.
How to add /privacy in Lovable
Generate the policy, copy the prompt, paste it in Build mode. The prompt creates /privacy and a footer link. Do not stack a cookie banner or /terms in the same message — that is how the chat restyles the whole app. The prompt library has the same “one screen, one change” pattern.
GDPR and CCPA in one paragraph
If most users are in the EU or UK, they can ask for a copy, a correction or a deletion. If they are in California, they can ask what you collected and tell you not to sell it. This generator writes those sentences. It does not pick a lawful basis, sign a DPA, or make Google Analytics legal in the EU. That last one usually needs a consent banner, in a separate prompt.
Frequently asked questions
Do I need a privacy policy for a Lovable app?
Yes if you collect emails, run login, take payments, or add analytics. A waitlist form is enough. Publish /privacy and link it in the footer before you share the link.
Is this privacy policy GDPR compliant?
No generator can promise that. This is a starter that names processors and states access and deletion rights. Have a lawyer review it if you take real EU money or store sensitive data.
What vendors should I list?
Lovable, Supabase, Stripe, your email provider, and your analytics tool. Name them. “Third parties” is not a list.
How do I add a /privacy page in Lovable?
Copy the generated prompt and paste it in Build mode. Then open /privacy yourself. Do not ask Lovable if the page exists.
Is this legal advice?
No. It is a starter template for indie Lovable apps. It is not affiliated with Lovable.
After you publish /privacy, walk the launch checklist and run the security checker on the production URL. If you still need a first prompt for the product itself, use the prompt generator.