10 Legal Traps in Vibe-Coded Apps: 170 Lovable Builds Found Leaking Data
alex_verem · x · 2026-10-08
AI tools ship features, not compliance. This thread breaks down 10 legal traps in vibe-coded apps:
- Exposed databases: RLS off or API keys in the frontend — 170 Lovable-built apps were found leaking user data, triggering breach-notice laws in every US state.
- No privacy policy: California requires one for apps collecting personal info, up to $2,500 per violation; app stores and Google sign-in will reject you without it.
- Kids on your app: COPPA requires parental consent (including cookies and device IDs) for users under 13, up to $53,088 per violation.
- Other issues include session replay capturing all clicks and keystrokes.
For anyone vibe-coding an app to monetize, these are real ways to get sued before you earn a dollar.
More from coding & agent
- 192 local runs show even good models shouldn't authorize their own tool calls — Slight_Analysis_5414 · 2026-10-08
- Jev 0.4.0 brings semantic ranking and routing to PowerShell pipelines — dfinke · 2026-10-08
- Five AI agents handle a mid-project requirement change in human-agent platform Teamily — cneuralnetwork · 2026-10-08
- Watching my AI agent do my job while I just say 'looks good' and 'continue' — tekbog · 2026-10-08
- Getting an LLM judge from garbage to 27/30 human agreement: an evals workshop writeup — tejaskumarlol · 2026-10-08
- AAA graphics in a browser tab: Opus 5.5 builds a custom three.js water and lighting engine — Daniel_Farinax · 2026-10-08