Security & GDPR for AI-built apps with EU users
One URL, one passive look from the outside — backend access, exposed secrets, tracking, US data transfers, legal pages. Nothing on your systems is touched.
18,642+ websites checked
The builder ships the app — not the obligations. As the operator, you’re the one liable.
18,642
apps checked
100 %
send visitor data to third parties
78 %
without any visible consent
From the inside, nothing looks wrong — it only shows up when someone checks from the outside.
Website-check total updates continuously · percentages from our passive July 2026 sample, n = 41
We load your app like a normal visitor and log everything it sends out — nothing on your systems is touched.
The five areas · what most apps get wrong
Check all 5 areas on your app — free
one scan covers all five · report in under a minute
Every finding in plain language, with the rule it touches. We say what passed, what didn’t, and when we’re not sure — no invented urgency, no lawyer letters.
61/100
3 of 5 areas need attention
Passed · Backend
Well done: your database backend is protected (no open access found).
Critical · Tracking § 25 TDDDG
Scripts load before anyone could consent. No consent banner found.
Finding · Legal pages § 5 DDG · please verify
We couldn’t find a page recognizable as an imprint — we checked the usual paths and the footer.
Start with the free scan; pay only if you want the full fix list. For higher assurance, book a call about an active deep scan plus a manual penetration test.
First report
€0
every scan starts here
Full report
€4.99 €149
one-time · launch offer
All findings with step-by-step fixes and legal context, PDF for your lawyer/DPO, 1 re-test.
Deep scan & pentest
Beyond the passive scan: an active deep scan plus a manual penetration test by our team — commissioned by you as the operator, scoped to your app, priced by scope after a short call.
Scan your whole Lovable portfolio in one run — and give every client a clear, shareable technical report under your name.
If people in the EU use your app, the GDPR applies to you regardless of where you’re based (Art. 3(2) GDPR). The security checks — open databases, exposed keys, missing headers — matter everywhere. A few findings are specific to the German market and are labeled as such.
The free report only loads publicly reachable pages, like a normal visitor. No login attempts or active testing. We retain a limited result digest, not page contents. The deeper scan only runs after you commission it as the operator.
No — the opposite. You check your own app and get an action list. howsafeismyapp sends no legal threats and demands nothing.
As soon as there’s a contact form, a login or a booking, you’re processing personal data — and the obligations apply.
If there is one, yes — such as a database readable without a login. The most common finding in practice, though, is tracking without consent.
Free, passive, no login.
Start your free reportpassiveno loginfull report €4.99 €149