Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- How can I start building on Lovable for free?
- What credit allowances does the free plan give me?
- Can I use AI features in my free apps?
- What happens to unused credits?
- What if I upgrade and later cancel my subscription?
- Do I retain ownership of my code on the free tier?
- How does the free plan compare to paid tiers?
- How do I monitor my credit usage?
- Is there any hidden cost in the free tier?
- Where can I find the official details?
- How can the free plan benefit from Decloak security scanning?
- How to run a Decloak free scan on a Lovable app
- Quick security checklist for free - plan apps
Key takeaways
- The free tier is fully functional: you can chat with the AI, build small apps, and host them using the monthly Cloud credit grant.
- All usage is measured in credits; the free tier supplies a limited but usable daily and monthly credit allowance.
- Credits that are not used within their grant period expire; there is no roll over or cash refund.
- Ownership of your projects remains with you even on the free plan.
How can I start building on Lovable for free?
You can start building on Lovable at no cost by creating a free workspace. The platform provides an AI - driven chat interface that lets you design web apps without paying upfront.
What credit allowances does the free plan give me?
The free plan grants two separate credit buckets: 5 build credits per day (up to 30 per month) and 20 Cloud credits per month for hosting. Both types of credits are automatically added and expire at the end of their respective period.
Can I use AI features in my free apps?
Yes, the free plan includes 4 trial AI - feature credits that you can spend on any AI functionality embedded in your apps. When you generate images, video, or invoke the "Plan" or "Build" actions, the normal credit rates apply.
What happens to unused credits?
Daily build credits disappear at day end and do not roll over. Monthly Cloud credits disappear at month end if they are not used. No cash refund is offered for expired credits.
What if I upgrade and later cancel my subscription?
If you cancel a paid subscription, your workspace reverts to the free plan at the start of the next billing cycle. Any paid - credit balance is lost after the current period, and you keep only the free - plan grants.
Do I retain ownership of my code on the free tier?
Yes, you own all code, projects and data created on Lovable, even on the free plan, subject only to third - party rights in the underlying AI models.
How does the free plan compare to paid tiers?
| Feature | Free plan | Paid plans |
|---|---|---|
| Daily build credits | 5 (max 30 per month) | Higher daily and monthly limits |
| Monthly Cloud credits | 20 | Larger hosting allowances |
| AI - feature trial credits | 4 | Unlimited or larger pools |
| Credit expiration | Daily build credits expire daily; Cloud credits expire monthly | Credits typically roll over within the subscription period |
| Project ownership | Retained by user | Retained by user |
| Access to advanced features (e.g., custom domains, team collaboration) | Not included | Included |
How do I monitor my credit usage?
The Lovable dashboard shows a real - time counter for both build credits and Cloud credits. When you approach the daily or monthly limits, the UI warns you so you can pause building or upgrade.
Is there any hidden cost in the free tier?
All actions that consume credits are covered by the granted allowances. If you exceed the daily or monthly caps, the platform will stop the action until the next reset; it does not automatically charge you.
Where can I find the official details?
The pricing page on Lovable’s website lists the free - plan credits, expiration rules and ownership terms. The blog announcement explains the daily free chat allowance and the credit model.
How can the free plan benefit from Decloak security scanning?
Decloak’s free scan can evaluate any Lovable app URL without requiring an account and returns a graded report in about 15 seconds. It checks HTTP/TLS posture, static HTML, rendered - page network behavior, JavaScript CVE patterns, tag manager configuration, third - party domains, vibe - coded platform security, and provides an AI - written executive summary. Run the scan from Decloak’s website, paste your app’s public URL, and review the findings to fix exposed headers, insecure TLS settings, or misconfigured Supabase tables before they become a risk.
How to run a Decloak free scan on a Lovable app
- Open https://decloak.com and click Free Scan.
- Enter the public URL of your Lovable app (e.g.,
https://myapp.lovable.dev). - Wait ~15 seconds for the report to generate.
- Review the eight core layers; any finding marked Critical or High should be addressed immediately.
- Implement the recommended remediation steps (e.g., enable HTTPS - only, add
Content - Security - Policy, lock down Supabase RLS) and re - scan to confirm the fix.
Quick security checklist for free - plan apps
- Ensure HTTPS is enforced and uses modern TLS ciphers.
- Add
X - Content - Type - Options: nosniffandReferrer-Policy: strict - origin - when - cross - originheaders. - Verify no public Supabase tables are exposed; enable Row Level Security.
- Remove
eval()or unsafeinnerHTMLassignments detected by the JavaScript CVE layer. - Limit third - party domains to only those you trust.
Following these steps keeps your free - tier Lovable app as secure as possible while you enjoy the credit allowances.
Related guides
How to Build Continuous Web - Security Scans with Scheduled Decloak Checks and Ticket Automation
Learn how to schedule Decloak scans via the REST API, compare results across runs, and push new or regressed findings to Jira or Linear automatically.
How can Decloak give auditor - ready proof for SOC 2 and ISO 27001 without weeks of manual work?
Decloak’s free and paid scans generate evidence packages and framework mappings that satisfy SOC 2 and ISO 27001 auditors quickly and automatically.
How can I quickly scan my single-page app for exposed secrets and vulnerable third - party scripts?
Use Decloak’s free 15 - second scan to detect hard - coded keys, outdated libraries, missing SRI and mixed content in a single - page app before a formal audit.