/incidents · incident · April 27, 2026

Lovable: chat histories of public projects readable

Source: Halborn, April 27, 2026. Written by Lior Aharonov, updated October 3, 2026.

What happened.

Halborn reports that in December 2025 Lovable made projects on its entry tier private by default and patched the related API.

In February 2026 an update to Lovable’s permission management backend re-enabled access to the chats of public projects.

Per Halborn, those chats could contain API keys, credentials, business logic and personal data.

Halborn says the patch first covered new projects and not existing ones, which stayed exposed until after public disclosure in April 2026.

Why it happens.

A builder’s chat is part of the project: it holds the keys you pasted, the logic you explained and sometimes real customer records. When a project is public, people tend to think of the app, not the conversation that built it. A permission change on the platform side can move that line without anyone touching the project.

How to check yours in five minutes.

  1. Check whether each of your projects is public or private.
  2. Search your project chats for anything you pasted: keys, passwords, customer data.
  3. Rotate any key that ever appeared in a chat, and store the new one in Secrets.
  4. Move real customer data out of prompts; describe its shape instead.
  5. Run the public scan on the published app.

Check the public side now.

Ten seconds. We read only what any visitor’s browser already sees, and store nothing.

Opens the app security check on this site with your address filled in.

Source

Halborn ↗

Published April 27, 2026. Read it in full; this page summarizes only what it reports.