This Privacy Policy explains how Lovax (“we”, “us”, or “our”) collects, uses, stores, shares, and protects personal information when you visit our website, sign in to your account dashboard, purchase a license, install and use the Lovable Unlimited browser extension, or contact our support team. We designed this document to comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), the requirements of the Chrome Web Store, Microsoft Edge Add-ons, and Firefox Add-ons, as well as major search-engine transparency guidelines. By using the website, dashboard, or extension you agree to the terms described below.
1. Who we are and how to reach us
Lovax operates a small SaaS product that helps builders get more out of the Lovable no-code / AI platform. Our service consists of three surfaces: the marketing website and Help Center, the authenticated dashboard where you manage licenses and billing, and the browser extension that runs on lovable.dev and related domains. You can contact us for any privacy question through the support channels listed in the footer of our site, or by opening a ticket from your dashboard. We aim to respond to every verified data-subject request within thirty (30) calendar days.
2. Data we collect
We only collect the minimum data required to deliver, secure, and improve the service.
2.1 Account data
When you register we store your email address, a hashed password (managed by our authentication provider, never stored in plain text), optional profile fields you choose to add (display name, avatar), and the timestamps of account events (creation, sign-in, password reset). If you sign in with Google we receive your email and public profile only.
2.2 Billing data
Payments are processed by third-party gateways (Paymob, Kashier, and Binance Pay). We never see your full card number, CVV, or bank credentials. We store the gateway transaction ID, the plan you purchased, the amount and currency, the payment status, and the billing country. This data is retained for the period required by applicable tax and accounting law (typically 5–7 years).
2.3 License and activation data
Every license issued by Lovax is bound to a set of anonymous device fingerprints. A fingerprint is a one-way hash derived from stable browser characteristics; it does not contain your name, IP address, browsing history, or the content of any Lovable project. We record the number of active devices, the first and last activation timestamps, and the extension version that last checked in. This lets us enforce the per-license device limit and protect you from credential theft.
2.4 Extension telemetry
The Lovable Unlimited extension sends a periodic “pulse” to our servers so we can display an accurate device list in your dashboard, deliver forced updates, and detect abuse. Each pulse contains the extension version, a random installation ID, the browser family (Chrome / Edge / Brave / Firefox), and a coarse online/offline status. The extension does not read, transmit, or store the source code of your Lovable projects, the prompts you send to the AI, or the pages you visit outside lovable.dev.
2.5 Support and communication data
When you contact support we retain the ticket contents, attachments you upload, and any follow-up messages. This lets us maintain a complete history of your requests and provide better assistance on subsequent issues.
2.6 Analytics
We use Google Analytics 4 with IP anonymisation enabled to understand aggregate usage of the website and Help Center. Analytics data is pseudonymous and cannot be used to identify you personally. We do not share this data with advertising networks, and we do not run remarketing pixels.
3. How we use your data
- Service delivery: creating your account, issuing and revoking licenses, syncing your subscription status, powering the dashboard and the extension.
- Billing and fraud prevention: processing payments, reconciling transactions, detecting stolen cards or abusive refund patterns.
- Security: rate-limiting sign-in attempts, detecting compromised sessions, enforcing the device-per-license limit, sending you a notification when a new device activates your key.
- Product improvement: analysing aggregate usage of Help Center articles, extension features, and AI tools to prioritise the roadmap.
- Legal compliance: responding to lawful requests from public authorities, keeping invoices for the period required by tax law, and enforcing our Terms of Use.
4. Legal bases (GDPR)
Where the GDPR applies we rely on the following legal bases: (a) performance of a contract for account, license, and billing data; (b) legitimate interest for security, fraud prevention, and aggregate analytics; (c) legal obligation for accounting and tax retention; and (d) consent, freely given and freely withdrawn, for optional marketing emails and non-essential cookies.
5. Sharing your data
We do not sell personal data. We share data with a small number of processors that are strictly bound by data-processing agreements: our hosting and database provider (Supabase), our payment gateways (Paymob, Kashier, Binance), our transactional email provider, and Google Analytics. Each processor accesses only the data required to perform its function. We may also disclose data when compelled to do so by law, in which case we will notify affected users unless legally prohibited.
6. International data transfers
Our infrastructure runs on servers located in the European Union and, for some regions, in the United States. When data is transferred outside your jurisdiction we rely on Standard Contractual Clauses approved by the European Commission and equivalent safeguards.
7. Data retention
Account data is retained for as long as your account is active. You can request deletion at any time; once verified we erase your profile within thirty (30) days, except for transactional records that we are legally required to keep for accounting purposes. License activation logs are retained for twenty-four (24) months to protect you from key theft. Support tickets are kept for thirty-six (36) months to help us serve you better.
8. Your rights
Depending on your jurisdiction you may have the right to access, rectify, delete, restrict, or port your personal data, to object to certain processing, and to lodge a complaint with your local supervisory authority. Californian residents have equivalent CCPA/CPRA rights, including the right to opt out of the “sale” or “sharing” of personal data — a right we honour by default, since we do neither.
9. Extension-specific disclosures
In line with the Chrome Web Store, Edge Add-ons, and Firefox Add-ons developer policies, we confirm that the Lovable Unlimited extension: (a) does not collect personally identifiable information beyond what is described in this Policy; (b) does not sell or transfer user data to third parties outside the approved use cases listed above; (c) does not use user data for purposes unrelated to the extension’s single purpose; and (d) does not use user data to determine creditworthiness or for lending purposes. Broad host permissions, where required, are used solely to inject the extension’s UI into Lovable and to communicate with our own backend.
10. Cookies and local storage
The website uses a small number of essential cookies to keep you signed in and to remember your language and theme preferences. Non-essential analytics cookies are only set after you interact with a page and can be disabled through your browser settings. The extension uses the browser’s local storage to cache your license status and preferences; nothing in that cache is transmitted to third parties.
11. Children
Our service is not directed to children under 16. If you believe that a child has provided us with personal data please contact support and we will delete it promptly.
12. Security
We enforce HTTPS everywhere, row-level security on every database table that contains user data, hardware-signed HMAC on every license verification request, and rotating signing keys for authentication tokens. Despite these measures, no system is perfectly secure. If you suspect a vulnerability please report it responsibly through our support channels.
13. Changes to this Policy
We will notify registered users by email or in-app notice before any material change takes effect. Continued use of the service after the change constitutes acceptance of the updated Policy. Historical versions are available on request.
