howsafeismyapp

Research · 2026-08-13

The state of GDPR & security in Lovable apps

We passively scanned 55 publicly reachable apps built with Lovable — the same GET-only check any visitor's browser performs — and aggregated what we found. No app is named; every number below is anonymous.

100%

of the 55 apps had at least one GDPR or security finding — on average 4.3 per app.

01

How common is each finding?

No Content-Security-Policy Security header98%
No clickjacking protection Security header98%
Third-party tracking service embedded Art. 6 GDPR94%
Tracking loads before anyone could consent § 25 TDDDG94%
Google Fonts loaded directly from Google Art. 44 GDPR46%

Each finding links to what it means and how to fix it.

03

Method

The check is passive: each app was loaded once over HTTPS with GET requests, exactly like a normal visitor, and we recorded what the page sends out and which security headers it returns. No login attempts, no active testing, no guessing of hidden paths. Apps that were unreachable at scan time are excluded. Results are reported only in aggregate — no individual app is identified, which is the whole point of how we work.

This is a convenience sample of 55 publicly discoverable apps, not a random draw — read the percentages as directional, not exact. We also exclude findings that are public by design (a Supabase anon key belongs in the frontend) and count only documented security and GDPR checks.

Snapshot from 2026-08-13. Practical guidance, not legal advice.

Curious where your app stands? The same free passive check runs on your URL in about a minute — no login, nothing stored.

Check your app free