Are vibe coded apps safe to sign up for?

Most apps built with AI are harmless. Some leak everything typed into them. A few checks before you sign up tell you which kind you are looking at.

Are vibe coded apps safe? Usually, yes, in the sense that most are made by ordinary people who mean no harm. The risk is different: an app built in an afternoon by someone who never read its code may not protect what you type into it. This guide explains what tends to go wrong, the real incidents behind the concern, and what to check before you create an account.

What actually goes wrong

AI app builders generate a front end and often wire it to a hosted database, frequently Supabase, plus a sign-in system. The database's safety then depends on access rules: who may read and change which rows. In Supabase these are called row-level security policies.

If the rules are missing or too loose, anyone who knows where to look can read the whole database through the same public key the app uses in the browser. That can include every user's email, messages, uploads or payment records. The person who built the app may never notice, because the app works perfectly in normal use.

This has happened at scale

In 2025 a security researcher disclosed CVE-2025-48757, describing apps generated with Lovable whose Supabase databases lacked row-level security, leaving user data readable by anyone. The researcher's own scan of 1,645 Lovable projects found 170 with inadequate access rules, about 10%. The CVE record notes that Lovable disputes it, because each customer is responsible for protecting their own app's data. Lovable has since added security scanning that warns builders about this class of problem. Similar misconfigurations have been reported across other builders and in hand-written apps too: the issue is skipped security review, not one tool.

Other common problems in quickly built apps:

  • Secret API keys placed in the page, where any visitor can copy them
  • Admin pages that only hide a button rather than checking who you are
  • File uploads stored in public buckets
  • No way to delete your account or data

Six checks before you sign up

  1. Who runs it? Look for a real person or company name and a way to contact them. An app with no owner can't be held to anything.
  2. Is there a privacy policy? It should say what is stored, why, for how long and how to delete it. A template policy with [Company Name] still in it is a warning.
  3. What does it ask for? Be wary of apps that want ID documents, health details, financial records or lots of personal information for a simple task.
  4. How was it built? An address on lovable.app, bolt.host, base44.app or replit.app, or a builder badge, tells you it was likely made quickly with AI. That's not bad in itself, but it should raise the bar for what you share. See which AI builder made this website?
  5. Does it look finished? Placeholder text, a default tab title or broken links suggest nobody did a final review, which likely includes the security settings.
  6. Can you avoid making an account? If you only need to try it, see whether it works without signing up, or use a separate email address.

How to protect yourself anyway

  • Use a unique password, ideally from a password manager. If the app leaks, nothing else is exposed.
  • Prefer "Sign in with Google" or "Sign in with Apple" where offered, so the app never sees a password at all.
  • Share the minimum. Skip optional fields. Don't upload documents you wouldn't want made public.
  • Don't store payment details in the app itself. Reputable apps hand payments to a processor like Stripe, whose checkout opens on its own domain.

If you build with AI

Turn on row-level security for every table and write a policy for each, run your builder's security scan, keep secret keys on the server, and test your app while signed out and signed in as a second user. Then add a real privacy policy and contact details. Your users can't see your code; these are the signals they have.

Where Kitsuvo fits

Kitsuvo, our no-AI web browser, can't see an app's database, so it can't tell you whether one is secure. What it does show is how a site was made, on every page you open: the builder, the score and the evidence. That's the context that tells you when to apply the checks above. And if an app is pretending to be a brand to collect your password, Kitsuvo stops you with a warning.

For a broader checklist, read how to check if a website is legit.

Questions people ask

Are apps built with Lovable or Bolt safe?

Many are, but safety depends on how the person who built the app set it up, not on the builder. The most common problem is database access rules left open. Check who runs the app and what it asks for, and use a unique password.

What is row-level security?

Row-level security is a database feature, used by Supabase and PostgreSQL, that controls which rows each user can read or change. Without it, an app's public key can expose every user's data.

How do I delete my data from an app I no longer trust?

Look for an account deletion option or contact details in the privacy policy, and ask for deletion in writing. Change any password you reused there. If the app has no owner you can reach, assume the data may persist and act accordingly.