howsafeismyapp

Security & GDPR for AI-built apps with EU users

Check your AI‑built app before it becomes a liability.

One URL, one passive look from the outside — backend access, exposed secrets, tracking, US data transfers, legal pages. Nothing on your systems is touched.

18,642+ websites checked

Built fast doesn’t mean run safe.

The builder ships the app — not the obligations. As the operator, you’re the one liable.

18,642

apps checked

100 %

send visitor data to third parties

78 %

without any visible consent

From the inside, nothing looks wrong — it only shows up when someone checks from the outside.

Website-check total updates continuously · percentages from our passive July 2026 sample, n = 41

One passive look, five areas, under a minute.

We load your app like a normal visitor and log everything it sends out — nothing on your systems is touched.

The five areas · what most apps get wrong

Five questions that decide whether your app is safe to run in the EU.

Backend access
Is your database readable without a login? usually ok
Secrets
Is an API key exposed in your frontend? usually ok
Tracking
Who receives visitor data — and is there consent? most fail
Legal pages
Privacy policy in place — plus imprint for the German market? often missing
Transport
Security headers set, connection clean? often gaps

Check all 5 areas on your app — free

one scan covers all five · report in under a minute

This is what comes back.

Every finding in plain language, with the rule it touches. We say what passed, what didn’t, and when we’re not sure — no invented urgency, no lawyer letters.

First report scheduler-example.lovable.app 🇩🇪

61/100

3 of 5 areas need attention

Passed · Backend

Well done: your database backend is protected (no open access found).

Critical · Tracking § 25 TDDDG

Scripts load before anyone could consent. No consent banner found.

Finding · Legal pages § 5 DDG · please verify

We couldn’t find a page recognizable as an imprint — we checked the usual paths and the footer.

+ further items in the full report passive · no login

Free shows what. Paid shows how.

Start with the free scan; pay only if you want the full fix list. For higher assurance, book a call about an active deep scan plus a manual penetration test.

First report

€0

every scan starts here

Your score out of 100 The most important findings PDF by email — no login

Full report

€4.99 €149

one-time · launch offer

All findings with step-by-step fixes and legal context, PDF for your lawyer/DPO, 1 re-test.

Start with the free scan

Monitor

€19 / month

We keep checking and alert you to new issues. Start monitoring →

Deep scan & pentest

Higher assurance, on request

Beyond the passive scan: an active deep scan plus a manual penetration test by our team — commissioned by you as the operator, scoped to your app, priced by scope after a short call.

Book a call →

Running client apps? Check them all at once.

Scan your whole Lovable portfolio in one run — and give every client a clear, shareable technical report under your name.

Check your portfolio →

Common questions

I’m not in the EU — is this relevant for me?

If people in the EU use your app, the GDPR applies to you regardless of where you’re based (Art. 3(2) GDPR). The security checks — open databases, exposed keys, missing headers — matter everywhere. A few findings are specific to the German market and are labeled as such.

Is this legal — are you scanning my site?

The free report only loads publicly reachable pages, like a normal visitor. No login attempts or active testing. We retain a limited result digest, not page contents. The deeper scan only runs after you commission it as the operator.

Is this one of those legal-threat schemes?

No — the opposite. You check your own app and get an action list. howsafeismyapp sends no legal threats and demands nothing.

I “only” have a small landing page.

As soon as there’s a contact form, a login or a booking, you’re processing personal data — and the obligations apply.

Do you find data leaks too?

If there is one, yes — such as a database readable without a login. The most common finding in practice, though, is tracking without consent.

Check your app in under a minute.

Free, passive, no login.

Start your free report

passiveno loginfull report €4.99 €149