Short answer: you can put a Lovable app on your own domain in three ways: connect the domain directly in Lovable (paid plan), export the code to GitHub and deploy it on Vercel or Netlify, or move the project to your own server together with its database. Before you hit „Publish”, check database security and API keys - the most common problems in AI-built apps.
What is a Lovable app made of?
Lovable generates a React front end (Vite, TypeScript, Tailwind CSS), and features like login, database and file storage are usually handled through a Supabase integration. That matters for deployment: you are publishing two things - the front end and the Supabase backend.
3 ways to publish a Lovable app
| Option | Best for | Pros | Cons |
|---|---|---|---|
| Custom domain in Lovable | Prototypes, MVPs, idea tests | A few clicks, no setup | Paid plan, little control over infrastructure |
| GitHub + Vercel or Netlify | Projects you plan to keep developing | Automatic deployments, free start, global CDN | Costs grow with traffic, database still on Supabase |
| Your own server with a database | Commercial apps with steady traffic | Full control, fixed price, data in one place | Needs setup and technical care |
Step by step: GitHub and Vercel
1. Connect the project to GitHub
Enable GitHub sync in Lovable. The code lands in your repository, so you now own a full copy of the project outside the platform.
2. Import the repository into Vercel
Vercel detects the Vite project automatically. The key step is copying environment variables, such as the Supabase URL and public key. Without them the app builds but cannot reach the database.
3. Connect your domain
Add the domain in project settings and set the DNS records Vercel shows you at your registrar. The SSL certificate is issued automatically.
4. Update URLs in Supabase
Add the new domain as an allowed redirect URL in Supabase auth settings. This is a common reason why login works in preview but fails on your own domain.
What to check before going live
- Database security (RLS) - every Supabase table should have Row Level Security enabled with deliberate rules. Without it, user data can be readable by anyone who knows the API URL.
- API keys - the Supabase service role key and payment keys must never end up in front-end code.
- Backups - the free Supabase plan has no automatic backups, and inactive projects can be paused.
- Email - Supabase’s default email sending has low limits; production needs your own SMTP server.
- SEO - a client-rendered React app is less visible in Google. If search traffic matters, keep the marketing site separate or server-rendered.
When to hand deployment over to specialists
If the app takes payments, stores customer data or runs your business, „publish” alone is not enough. A security review, proper database setup and monitoring cost a fraction of a data leak or several days of downtime.
This is exactly the stage we handle: deployment and hosting of AI-built apps - on our own server or in the cloud, including the database and care after launch. Show us your project and we will tell you what needs fixing before you publish.
