Blog
Security & GDPR for AI-built apps
Practical guides from the team behind the scanner — what actually goes wrong in vibe-coded apps and how to fix it.
- Is your Bolt.new app GDPR compliant? What to check before taking EU users
Bolt apps ship fast — often with Supabase defaults, template trackers and no legal pages. What to check before your app meets EU users.
2026-08-06 - Do you need a cookie banner for your Lovable app?
Maybe not. When EU law actually requires consent, when it doesn't, and how to add a banner to a Lovable app without breaking the rules.
2026-08-06 - Is your Lovable app GDPR compliant? The 15-point checklist
The 15 things we check on every Lovable app before it takes EU users — what each one means, why it matters, and how to fix it.
2026-08-06 - Row Level Security in Lovable apps — why your database might be public
Lovable apps ship with Supabase. Without Row Level Security, your users table can be readable by anyone. How to check and how to lock it down.
2026-08-06 - Self-hosting Google Fonts — the 15-minute fix for a classic GDPR finding
Loading fonts from fonts.googleapis.com sends visitor IPs to Google. Why a German court cared, and how to self-host fonts in any AI-built app.
2026-08-06