Sensitive data scanning
Sensitive data scanning helps you find and manage personal information like names, addresses, or credit card numbers in your Lovable project. It can check new messages as they are sent and scan existing project data like chat history or your built-in database.
Anyone working with private, regulated, or customer information needs this to ensure sensitive data is handled correctly.
Do this, in order
- 1
Make sure you have an Enterprise plan for your Lovable workspace.
This feature is only available on the Enterprise plan.
- 2
Ask your workspace owner or admin to enable 'Sensitive data scanning' in your workspace settings under 'Privacy & security'.
This turns on the core feature and makes other related settings and the 'Sensitive data' tab visible.
- 3
Decide how Lovable should handle new chat messages with sensitive data by choosing a 'Chat send protection' mode in the workspace settings.
This controls whether sensitive data is logged, paused for review, or blocked when users send new messages or files.
- 4
Consider enabling 'Block publishing with PII' in workspace settings if you want to prevent projects from being published or updated with unresolved sensitive data.
This ensures that all sensitive data issues are addressed before a project goes live or is updated.
- 5
Go to 'Project' -> 'More' -> 'Sensitive data' in your project and click 'Run scan' to check existing chat history, built-in database, and storage for sensitive information.
This helps you find sensitive data that is already stored in your project.
- 6
Review the findings in the 'Sensitive data' tab, prioritizing 'High' sensitivity items, and take action by marking them as 'Not PII', 'Redacting' chat messages, or 'Deleting' files.
This allows you to manage and resolve detected sensitive information according to your needs.
Paste this into your project
Please enable 'Sensitive data scanning' for our workspace and set 'Chat send protection' to 'Ask before sending'. Also, enable 'Block publishing with PII'. Once enabled, I will run an on-demand scan on my project to review existing sensitive data.
Words decoded
- PII
- Personally Identifiable Information, which is any data that could potentially identify a specific individual, like a name, email address, or phone number.
- DLP
- Data Loss Prevention, which refers to strategies and tools designed to prevent sensitive information from leaving an organization's control.
- Redact
- To remove or obscure sensitive information from a document or message, often by replacing it with a placeholder like '[REDACTED:TYPE]'.
- False positive
- When the system incorrectly identifies something as sensitive data when it is not.
- On-demand scan
- A scan that you start manually to check existing data, rather than one that runs automatically as new data comes in.
Where people get stuck
- Not having an Enterprise plan, as this feature is exclusive to it.
- Forgetting to enable 'Sensitive data scanning' in workspace settings, which prevents any detection from happening.
- Not understanding that scans are read-only and do not automatically change, move, redact, or delete data; you must take action on findings.
- Assuming that 'Log only' mode will prevent sensitive data from being sent; it only records the finding.
- Not realizing that 'Block original' mode for chat messages and files means the original content cannot be sent at all if PII is detected.
- Forgetting that disabling 'PII detection warning' for a project still records findings, it just doesn't show the user a warning.
- Expecting external or self-hosted databases and storage to be scanned; only Lovable's built-in resources are covered.
- Not manually removing database rows after a finding, as Lovable cannot directly fix them, only mark them as 'Not PII'.
- Relying on scans for unsupported file types or files beyond the sampled limits, as they will be skipped.
- Not re-running on-demand scans after major data changes, which could leave new sensitive data undetected.
- Expecting to export the findings log, as this feature is not currently available.
The short version, steps, decoder and prompt on this page are written automatically from Lovable's own documentation and can lag or misread it. The official page is always the authority.