How it works in plain English
When your app needs something from a Gateway-based connector — data, a document, a list, a file — it doesn't reach into the external provider itself. It asks Lovable's secure connection, which fetches that item live from your provider and hands it straight back to the app. Think of it as a locked, automated courier: it carries what you asked for and nothing more, keeps no copy, and lets no one ride along.
Your app
The app your team uses
Lovable's secure connection
- •Fetches your data live and streams it straight back — no data is cached or stored by Lovable unless you explicitly ask for data to be stored
- •OAuth tokens are encrypted and hosted in the EU
- •Automated and locked: by design, no Lovable staff are able to browse your files
- •Connectors' data, credentials and keys are never used to train AI
Your data
Your data, sites, documents and lists stay in your external provider. You choose the account it connects with — so it only sees what that account can see — and whether it can read only or also make changes.
What this means for you
Nothing of yours is kept.
Connectors' data is fetched fresh each time and shown, never stored on Lovable's side, and never used to train AI, unless you explicitly ask for data to be stored.
You decide what it can reach.
It can only see what the connector account you connect it with can see — connect a limited account and that's the ceiling. You also choose whether it can read only, or also make changes.
You stay in control.
You can disconnect at any time, and the app's access to connector stops immediately.
All connectors work the same way
The same secure pattern is shared by all of Lovable's 100+ connectors. Three of them (Firecrawl, Perplexity and ElevenLabs) use their own secure setup instead, and none of those touch your connectors. More information about how Lovable processes personal and company data using connectors can be found in our Privacy Policy.
