Built in days. Owned for years.
We use Lovable to put a working app in front of real users in days, and Supabase to run it on a database you own. Already have one your team built? We audit it, harden it and grow it without starting over, and because we also run Supabase under Next.js, Webflow, WordPress and Shopify, graduating to a bigger stack never means losing your data.
public.orderssigned in as Ana
using (auth.uid() = user_id)
101ana€84✓
102bruno€129
103ana€42✓
104bruno€310
2 of 4 rows returned. Same publishable key, locked rows. See it live ↓
Lovable builds it. Supabase runs it.
Two tools, one job: turning an idea into software people log into and use, with a working version this week.
An AI app builder that writes real code
You describe what you need in plain language. Lovable writes the app in React and TypeScript, the code professional teams use, and shows it in minutes.
The code syncs to your own GitHub, so it is never trapped inside the tool.
The backend that remembers everything
A Postgres database, user logins, file storage, live updates and server functions, managed for you and built on open source.
It knows who your users are and what each may see. It works with Lovable and almost any other front end.
A real app in days, not months
Real logins, real data, a real URL. According to Lovable, its users sit in two thirds of the Fortune 500, and over 60% of new Supabase databases are now launched by an AI tool.
The catch: speed skips the parts nobody sees, like who can read which row. That is where we come in.
Not sure it fits your case? See when Lovable is the wrong tool, and which platform we would pick instead.
A new build, or the app you already have.
Many Lovable apps are started inside the company, which is the point of the tool. So we work both ways, to the same standards.
From idea to live app, fast and properly.
A working version in the first sprint, on production foundations before real data arrives.
- Web apps and portals with logins, roles and documents
- Internal tools that replace spreadsheets
- Landing pages and microsites, measured
- Interactive and gamified campaigns with live leaderboards
- Configurators and quote tools that write straight into your CRM
- MVPs and first SaaS versions, built to graduate
Your team proved the idea. We make it last.
A second pair of expert eyes, not a rescue. We keep what works and fix what is exposed.
- Audit first: security, keys, rendering, consent, speed, costs
- Hardening: policies, secrets, auth, backups
- Move to your own Supabase from Lovable Cloud, in a specific EU region
- Findability: server-side rendering, schema, AI search
- Tracking and consent that actually work in a single-page app
- Redesign and CRO without replatforming
Whichever path you take, you ownthe code in your GitHubthe data in your Supabaseevery decision, in writing
If people log in, play or buy through it, we build it.
Websites and web apps. Supabase sits under all of them.
Customer portals and member areas
Accounts, orders, bookings and documents, each customer seeing only their own.
Internal tools and dashboards
Admin panels, approvals and live reporting that replace the spreadsheet everyone fears.
Landing pages and microsites
Campaign pages shipped in days, server-rendered so search engines and AI answers can read them.
Gamified and interactive campaigns
Quizzes, challenges and live leaderboards on Supabase Realtime, with scores checked on the server.
Configurators and quote tools
A complex choice turned into a few clean steps, with the lead landing in your CRM.
Supabase behind your existing site
Logins, wishlists, loyalty and gated content for a Webflow, WordPress or Shopify front end.
Build what moves a business number.
A tool is only worth what it changes. We show the type of result, not a made-up percentage: your baseline decides the number, and we measure it with you.
Dealer or B2B customer portal
- Situation
- Partners email for prices, documents and order status.
- What we build
- Supabase Auth with row-level security per account, documents in Storage, orders synced from your ERP.
Quote tool on your existing site
- Situation
- Complex products, long back-and-forth before a price.
- What we build
- A configurator embedded in your Webflow or WordPress site; an Edge Function pushes qualified leads to your CRM.
Gamified campaign with a leaderboard
- Situation
- You want attention and first-party data, not just impressions.
- What we build
- A quiz on Supabase Realtime (Broadcast and Presence), scores validated server-side so nobody cheats the prize.
Two tracks. One database.
Start fast on Lovable. Grow into engineered code. Your database never moves.
Every app sits on a prototype track (move fast, validate with real users) or a production track (engineered to last), as on our Web Apps page. Lovable drives the prototype track. Supabase runs under both, for websites and web apps alike, so users, data and permissions carry straight across when you graduate.
Front end still open? See our Websites and E-commerce Shops or the tech pages for Webflow, WordPress and Shopify.
A build team inside a martech team.
An app that works is not yet legal, found and measured. Those three are usually bolted on after launch, by someone else. Ours sit next to the builders from the first sprint.
Build team
20 people who design and build websites, shops and apps.
- UX and interface design
- Supabase schema, policies and Edge Functions
- Hand-off to engineered code when it is time
Legal by design
Reads schemas, not only contracts.
- EU region picked before creation (Lovable Cloud cannot move later)
- Processor list naming Lovable, Supabase and the AI model provider; notice, terms and cookies
- European Accessibility Act checks
- AI Act transparency notice when the app uses Lovable's AI gateway
Found in search and AI answers
An invisible app is a private app.
- Server-side rendering on TanStack Start, or pre-rendering for older builds
- Public pages with Organization and FAQ schema, stable entity names and llms.txt, so AI assistants can cite them
- Private app screens kept out of the index by design
Measured from day one
- CMP loads first
- Consent state setConsent Mode v2 defaults
- GA4 configvia server-side tagging
- page_view on every routenot just the first load
- Server-side conversionsent from an Edge Function
It is what Wise Pirates means by the best of a great team, frameworks, technology and proprietary data, aimed at your business results. On launch day of a campaign microsite, that means the consent flow above, schema and llms.txt shipped with the pages, and a privacy notice that names every processor.
Audit. Build. Optimise. Repeat.
We are strong at all three, and the value is in the loop: every audit feeds the backlog, every build ships measured.
Audit
A scoped look at what you have, or at the data the idea will hold.
- Supabase Security Advisor, RLS and key review
- Rendering, metadata and AI-search readiness
- Consent, tracking, speed, accessibility and running costs
Build
Short sprints, a working version at the end of each.
- Lovable for speed, code review for safety
- Preview branches so nothing breaks live
- Hardening gates before any real data
Optimise
After launch, the app becomes a growth asset.
- Conversion tests on real funnels, and Postgres cost tuning
- SEO and GEO content on top of fast pages
- New features ranked by measured impact
Illustrative rhythm. Each marker is a demo with you; the real plan comes out of the audit.
Proof, without the padding.
No invented percentages. Just what we can stand behind.
Two years on Lovable: what each release taught us.
Two years is not a decade. On a platform this young it covers most of what matters.
- 2025CVE-2025-48757 goes public170+ Lovable-built apps found leaking user data through missing or weak row-level security.What we do sinceNo table goes live without a policy and a test run as a real signed-in user. Lovable's own scanners are our first gate, never the last.
- Feb to Apr 2026Public-project exposure incidentA regression exposed chats and code of public projects; Lovable fixed it and published a post-mortem.What we do sincePrivate projects only, no secrets in prompts, rotate anything that was ever public.
- May 2026TanStack Start becomes the defaultNew projects render on the server; older ones can upgrade.What we do sinceSEO audits now start with how the app renders, then move to content.
- Jun 2026One credit balance for everythingBuilding, hosting and in-app AI share one pool.What we do sinceBudgets separate build credits from running costs.
- By end 2026Supabase retires legacy API keysThe old
anonandservice_rolekeys give way to publishable and secret keys.What we do sinceKey migration is now a standard line in every audit of an older project.
From prompt to production, with an exit door.
The prompt is the easy part. Production needs a backend you control and gates nothing skips: a failed gate sends the change back to be fixed. And there is always a way out: code in your GitHub, data in standard Postgres you own.
Prompt: describe the app in plain words.
The publishable key, and the locked rows.
Every Lovable app talks to Supabase with a key that ships inside the browser. That is by design, and it is safe only if row-level security (RLS) protects every table. Without a policy, anyone holding that publishable key can read everything.
It is the most common failure in AI-built apps. Try the three states.
RLS off: the publishable key reads every row, including Bruno's. This is the CVE-2025-48757 pattern.
user_id matches their own signed-in id.Three things every audit checks first.
It passes every scanner that only asks "is RLS enabled?". We rewrite it per role and test it signed in as Ana and as Bruno, because the dashboard runs as a privileged role and proves nothing.
A service_role or third-party API key pasted into client code. We move it into an Edge Function, rotate it, and migrate the project to publishable and secret keys.
In a single-page app GA4 often fires once. We send a page view on every route change and make sure consent loads before any tag.
Context: CVE-2025-48757 documented 170+ Lovable-built apps exposing data through missing or weak RLS (statement); a later Escape study of 5,600+ vibe-coded apps reported 2,000+ vulnerabilities (methodology). Skipped reviews, not the stack.
Lovable Cloud or your own Supabase? Decide early.
Since Lovable Cloud launched in September 2025, Lovable offers two backend modes, both on Supabase technology. They are not equal once real customers arrive, and today there is no automatic migration between them.
Lovable Cloud
- Fastest start, for prototypes and internal tools
- No Supabase dashboard, no secret key, no direct database URL
- No external connections for BI tools, n8n or Postgres clients
- Region (EU, US or APAC) chosen once, fixed forever
Your own Supabase
- Full dashboard, SQL, logs, backups and point-in-time recovery
- Connects to your CRM, BI, warehouse and automation tools
- A specific EU region you pick, such as Frankfurt, Paris or Stockholm
- A separate bill, which we size with you
Our default path
- Prototype wherever it is fastest, with no real personal data
- Decide before the first real customer record lands
- Production on a Supabase project owned by you, not by us
- Our access is scoped, logged and revoked at the end
Moving off Cloud later means exporting and rebuilding schema, auth, storage and functions. It can be done, and we do it. It is just cheaper to decide on day one.
The whole stack, with nothing hidden.
If your CTO reads one section, make it this one: ten questions to ask any Lovable and Supabase partner, and our answers.
What changes as the app grows.
- Step 1PrototypeLovable Cloud or a development Supabase project.Trigger: an idea to validate, no real personal data.
- Step 2Your own Supabase, with branchingClient-owned, EU region, preview and staging branches.Trigger: the first real customer record, an integration, or a second developer.
- Step 3Scale the databaseCompute add-on, read replicas, pooling. Sharding is still alpha.Trigger: sustained load, slow queries, many concurrent connections.
- Step 4Engineered code, same SupabaseNext.js-style engineering with AI-assisted development.Trigger: prompts stop steering the codebase reliably, or the team grows.
Architecture
Generated code you can read, on a backend you can query.
- React, TypeScript and Tailwind; server-side rendering with TanStack Start for new projects since May 2026
- Supabase: Postgres, auto-generated API, Auth, Storage, Realtime and Edge Functions
Under the hood: PostgREST and pg_graphql APIs, Supavisor pooling, Deno Edge Functions. Anything touching money, scores or permissions runs server-side.
Security
Defence in depth, starting at the database row.
- RLS on every exposed table, policies per role, tested as real signed-in users
- Security Advisor at zero criticals, Lovable deep scan, external penetration test for high-stakes apps
Plus publishable and secret keys, MFA, rate limits, SSO, CSP and HSTS.
Environments and CI/CD
Nobody edits production by prompt.
- Two-way GitHub sync, so every change is reviewable as a diff
- Supabase branching: a preview branch per pull request, a persistent staging branch, migrations deployed on merge
GitHub Enterprise, GitLab and Bitbucket options depend on the Lovable plan.
Performance
Fast first paint, fast queries, measured in the field.
- Server-side rendering, compressed images, code splitting; Core Web Vitals tracked on real users
- Indexes and query plans reviewed; compute and read replicas sized to real load
Integrations and APIs
An app that talks to the rest of the business.
- Auto-generated REST and GraphQL from the schema, webhooks and database triggers
- Stripe payments; CRM sync such as HubSpot through Edge Functions
Foreign Data Wrappers reach legacy systems; change-data capture to BigQuery was in public alpha in mid 2026.
AI and agentic readiness
AI features and agents get the same permissions as people, never more.
- pgvector and Vector Buckets for retrieval over your content, with RLS deciding what each user's assistant can see
- Supabase MCP server for coding agents with read-only, project-scoped access, pointed at development branches
Lovable adds agent integrations for published apps and, in September 2026, announced Lovable apps inside Salesforce and Slack. AI Act transparency applies where users talk to AI.
Data residency and compliance
Where the data lives is a legal decision, not a default.
- A specific Supabase EU region (Ireland, London, Paris, Frankfurt, Zurich, Stockholm), never the generic "Central EU" option
- DPAs with both vendors; Supabase is a US company and both run on US-headquartered cloud providers, even in EU regions
As published: Lovable SOC 2 Type II and ISO 27001:2022; Supabase SOC 2 Type II and ISO 27001 reports on Team plans.
Observability and operations
You see problems before your users do.
- Supabase logs kept 1, 7, 28 or 90 days depending on plan, plus Health Check Advisors (September 2026)
- Logs queried by AI-assisted debugging through the Supabase MCP
query_logstool, on scoped access
Alerts before the Lovable credit pool runs dry, an incident runbook, and restore tests on a schedule.
Governance for citizen builders
Let your teams build, without letting them ship risk.
- Business or Enterprise workspace: SSO, roles, publishing controls
- Private projects, a scan before every publish, expert review before customer data, credit budgets watched
Ownership and exit
You can leave us, and you can leave the tools.
- Code and content are yours, in your GitHub, hosted on Lovable or on your own infrastructure
- Supabase is standard Postgres: pg_dump out, or self-host with Docker
Self-hosting loses managed branching and point-in-time recovery. Lovable Cloud is the main lock-in point.
Our go-live checklist, in short
Nothing handles real customer data until every line is ticked. It is also what we check first when a project starts on an existing app.
- Private project, no secrets in prompts, code or the browser
- Production on a client-owned Supabase, in a specific EU region
- RLS on every table, tested per role; Security Advisor clean
- Auth hardened; backups verified with a restore test
- Consent before tags, GA4 on every route; schema and legal texts live
- Logs, alerts, runbook; access reviewed with a revocation date
Infrastructure beyond Supabase runs through our Cloud Services practice and our Google Cloud partnership. Agents and AI features go deeper with AI Enablement and Data Science.
When Lovable is the wrong tool.
We would rather lose a Lovable project than win the wrong one.
Pick the platform that fits. Not the one that pays us.
Build it, then put it to work.
The app is where the work starts. Traffic, data and growth come from the rest of the agency.
On a new project, the first step is usually an audit.
Auditing is one of our specialties. We review what you have before we build or change anything, so every decision rests on what is really there. Talk to our specialists to see how this applies to your case.
Lovable and Supabase, answered.
Is Lovable good enough for production apps?
Is Lovable secure?
Should we use Lovable Cloud or our own Supabase project?
Do we own the code and the data built with Lovable?
Is the Supabase publishable key safe to expose in the browser?
Can you take over and fix a Lovable app our team already built?
Do you use Supabase without Lovable, for websites and other stacks?
Can Supabase power games, quizzes and live interactive campaigns?
Do you work with companies in Portugal and Spain?
Can our data stay in the EU?
Are Lovable sites good for SEO and AI search?
How much does a Lovable and Supabase project cost?
How long does it take to go from prompt to production?
What happens if we want to leave Lovable, Supabase or Wise Pirates?
How can our own teams build on Lovable safely?
Ship it fast. Keep the keys.
On an app you have, the first step is usually an audit; on a new one, a scoped first sprint. Either way you get a working version early, decisions in writing, and a backend you own.
Lovable and Supabase are trademarks of their respective owners. Logos are shown for identification only. Wise Pirates is an independent agency; no official partner status is implied.