---
title: "Lovable agency UK: take over, migrate or rebuild"
description: "UK Lovable agency. We read the code and the database, then fix, build on or rebuild your Lovable app on a stack you own. Fixed price from £10,000."
canonical: https://www.clientflow.ai/lovable-agency
verified: 2026-09-05
language: en-GB
---

# Lovable agency. Take over, migrate or rebuild.

A Lovable agency takes a build that started in Lovable and makes it a product you own. For teams whose build has stalled, or works and now has to hold other people’s data and money: we read the code and the database before we quote, fix what can be fixed, move the rest onto a stack in your name, and take Lovable out of the loop. One fixed price, set from a blueprint. Not a Lovable partner.

**Summary:** A Lovable agency takes a build that started in Lovable and makes it a product you own. Clientflow reads the repository, the schema and every policy before quoting, then fixes the build, builds on it or starts again with what it taught you, at a fixed price from a blueprint, from £10,000. The database moves into a Supabase project in your name, the policies are written and tested, the app runs on hosting and a domain of yours, and Lovable comes out of the loop. Clientflow is not a Lovable partner and is paid by nobody but you.

## Contents

1. [What a Lovable agency does](https://www.clientflow.ai/lovable-agency#what-it-is)
2. [The policies, before anything else](https://www.clientflow.ai/lovable-agency#security)
3. [Fix it, build on it, or start again](https://www.clientflow.ai/lovable-agency#outcomes)
4. [Moving off Lovable Cloud without losing the data](https://www.clientflow.ai/lovable-agency#migration)
5. [What you own on Lovable, and what you own after](https://www.clientflow.ai/lovable-agency#ownership)
6. [How much does it cost to take over a Lovable build?](https://www.clientflow.ai/lovable-agency#cost)
7. [Who pays for the attempts](https://www.clientflow.ai/lovable-agency#attempts)
8. [How long does a takeover take?](https://www.clientflow.ai/lovable-agency#how-long)
9. [When we will tell you to stay on Lovable](https://www.clientflow.ai/lovable-agency#when-to-stay)
10. [Questions people ask before handing over a Lovable build](https://www.clientflow.ai/lovable-agency#questions)

## 1. What a Lovable agency does

Clientflow’s takeover reads the code and the database, fixes what can be fixed, moves the data into a Supabase project in your name, locks down the permissions, and takes Lovable out of the loop, so the app runs on hosting and a domain of yours. The price is fixed from a blueprint.

| Aspect | Is | Is not |
| --- | --- | --- |
| **Shape** | A senior team reading the code and the schema before quoting | Another prompt, billed per attempt |
| **Where it ends up** | Your repository, your Supabase project, your hosting | A build that only runs while the credits last |
| **The decision** | Fix, build on, or start again, decided from the reading | A rebuild sold before anyone has looked |
| **Control** | The code was always yours; the rest becomes yours | One dependency swapped for another |

The good news comes from Lovable itself: you are never locked in, and a Lovable application is a standard Vite and React project with no proprietary frameworks[^1], synced to a repository you own[^2]. The half people miss is the database, the users and the server-side functions, which live wherever an early choice put them. That is the first thing we read.

## 2. The policies, before anything else

Lovable’s own guidance is that before going live every table needs Row Level Security policies, the rules that say who can read which rows, and that missing policies are the most common way app data gets exposed[^4]. In March 2025 a scan of 1,645 Lovable-built sites found endpoints on about one in ten that could be read or written without logging in[^7], recorded as CVE-2025-48757[^8]. So we do not run a scanner and call it done. We read the policies, and we test them as a logged-out user.

## 3. Fix it, build on it, or start again

We clone the repository, run it, read the schema and every policy, and list what is real: which features work end to end, which work only for the demo, and which are screens with nothing behind them. Then the decision is usually obvious. Each outcome is priced from that reading, and if what you need is an afternoon of fixes, we say so on the call and a good freelancer will do it for less than our floor.

## 4. Moving off Lovable Cloud without losing the data

Where the database lives decides how much of a migration there is. A Supabase project in your own account is already yours, and disconnecting Lovable changes nothing in it[^4]. Lovable Cloud runs on Supabase’s open-source foundation and your data can be exported, but the schema has to be rebuilt by hand in a project of your own[^3], and that is real work, priced as such.

- **Extraction**: The export from Lovable Cloud on day one, before anything is changed, because removing Cloud deletes the instance and cannot be undone[^3]. On your own Supabase project there is nothing to move.
- **The schema, rebuilt**: Cloud’s data can be exported, but the structure is rebuilt by hand in your project[^3]. This is where the three address fields become one and the status column stops meaning four things.
- **Parallel running**: The published Lovable app stays live while we work, because publishing is separate from the code[^5]. The new one runs alongside it on the same data until the comparison is observed rather than argued.
- **Cutover**: Hosting and the domain move to your name and Lovable comes out of the loop; the code does not notice. Nobody prompts in Lovable once we have cloned, because the sync works on one branch at a time[^2].

## 5. What you own on Lovable, and what you own after

The code was always yours: Lovable says so, and the repository proves it[^1]. What a takeover adds is the rest: the database in a Supabase project in your name, hosting and the domain in yours too, the policies written and tested, and the intellectual property in everything we make for you assigned under the agreement. At handover you hold every account outright, including the ability to remove us.

That last part is worth checking with every supplier you speak to, because UK copyright law does not hand it over by default. The author of a work is its first owner[^9], the rule that gives an employer its staff’s work does not cover a contractor, and an assignment is only effective in writing, signed by the assignor[^10]. Paying the invoice is not what transfers the copyright.

## 6. How much does it cost to take over a Lovable build?

A rescue worth doing is a version one with a head start, so the floor is the same £10,000 as any build, and the price is fixed from the reading rather than from the demo. A fix keeps the repository and the database and works through the list of what is broken. A build-on keeps the front end and the parts of the schema that are right. A start-again is a normal build: the bands are on the [pricing page](https://www.clientflow.ai/pricing#bands) and what moves them is in the [cost guide](https://www.clientflow.ai/guides/bespoke-software-development-cost-uk).

The reading looks at five things: the data model, the permissions, what works, the integrations and what you need next. They decide the band, the way the five factors in the cost guide do for any build. Once it is live, a version one costs about £800 a year to run in your own accounts, itemised in the [running-costs guide](https://www.clientflow.ai/guides/running-costs), with nothing per seat and no credits.

## 7. Who pays for the attempts

Lovable bills per attempt, including the ones that broke something, and unused monthly credits expire two months after they are issued[^6]. The credit arithmetic is in the [guide](https://www.clientflow.ai/guides/stuck-with-a-lovable-build#who-pays-for-the-attempts).

| Question | The meter | The fixed price |
| --- | --- | --- |
| **A failed attempt costs** | You, per instruction | Us. It is inside the price |
| **What you pay for** | Each attempt | Working software, once |
| **Who holds the whole picture** | Nobody, a few prompts in | The engineer reading every change |
| **Unused money** | Credits expire two months after issue | There is none to expire |

We use the same models to build, with a senior engineer reading every change. The cost of every attempt we throw away is inside the fixed price, so you never see an AI bill from us.

## 8. How long does a takeover take?

A fix or a build-on usually takes weeks rather than months. The reading takes the first week, the blueprint turns it into one written price by the second, and a build-on runs from the second week to about the sixth. A start-again is a normal build: three to eight weeks after the blueprint. The published Lovable app stays up while we work[^5].

1. **Blueprint call** · Free · Day one

   Bring the Lovable link, the repository and the honest list of what does not work.

2. **Read** · Audit · Week 1

   The repository cloned and run, the schema and every policy read, the Cloud export taken.

3. **Blueprint** · Scoped · Weeks 1 to 2

   The outcome, what is kept, what is rebuilt, and one fixed price.

4. **Build on** · Built · Weeks 2 to 6

   The database into your own Supabase project, a policy on every table, tests around money and personal data, hosting in your name.

5. **Launch and handover** · Owned · Handover

   Every account in your name, your team trained, the same warranty as any build.


## 9. When we will tell you to stay on Lovable

Some calls end with us telling you to keep going, and we would rather that than take a project that does not need us. The moment to talk to someone is the moment the app starts holding other people’s data, taking their money, or standing between your team and their work. The cases in full are in the [guide](https://www.clientflow.ai/guides/stuck-with-a-lovable-build#when-to-stay-on-lovable).

1. It is a prototype and it is doing its job. If the point is to show an idea to customers, investors or your own team, a Lovable build is the fastest way to a thing people can click.
2. You are the only user, or it holds no personal data, so there is nobody to keep out.
3. It works and you enjoy it, and the prompting is not costing you sleep or customers.
4. The fix is an afternoon, or the budget is under £10,000. We will say so on the call, and a good freelancer will do it for less.

## 10. Questions people ask before handing over a Lovable build

### Can you take over my Lovable app?

Usually, and the call tells you how. If the code and the data model are sound and the list is bugs and gaps, it is a fix. If the screens are right and what is behind them is thin, we build on it. If the model itself is wrong, we say so and treat the prototype as the spec for a start-again. All three are priced from the blueprint after we have read the repository and the schema, never from the demo.

### Can you migrate our database from Lovable Cloud to Supabase?

Yes. The export is taken on day one, before anything is changed, the schema is rebuilt by hand in a Supabase project in your name, and the new app runs alongside the old one until the comparison is observed. If the database is already a Supabase project in your own account, there is nothing to move.

### Can you fix one thing without a full migration?

Yes, when the code and the data model are sound. A fix keeps the repository and the database and closes the list, and it is one of the three outcomes we quote for. What we will not do is fix one thing on top of tables without policies while the app holds other people’s data: the policies come first, whatever the outcome.

### Are you a Lovable partner?

No. Clientflow is not a partner, reseller or affiliate for Lovable or for any platform, and is paid by nobody but you. That is why the advice on the call can be to stay on Lovable, and sometimes is.

### Do you build with Lovable yourselves?

No. We build with the same underlying models, with a senior engineer reading every change and tests around anything that carries money or personal data. The difference is not the tool but who carries the cost of the attempts that do not work: with us, it is inside the fixed price.

### Is it safe to give you access to the project?

Yes. You add us to the repository and the Supabase project as collaborators, and you can revoke that at any time. A data processing agreement is part of every engagement, so any personal data in the database is handled in your name and under your instructions, and nothing is copied anywhere you have not agreed to.

### What do you need from us?

The Lovable link, the repository if there is one, the honest list of what does not work, and one person with the authority to decide. If the database is on Lovable Cloud, the export comes first and we take it with you on day one. During the build, nobody prompts in Lovable, and feedback comes in consolidated rounds within a couple of working days.

## Sources

Every claim about Lovable above was read from the page cited, on the date shown; they are the same sources the guide uses.

[^1]: [Lovable documentation, deployment, hosting and ownership options](https://docs.lovable.dev/tips-tricks/deployment-hosting-ownership). States that you are never locked in and that applications are standard Vite and React projects with no proprietary frameworks. Seen 4 September 2026.
[^2]: [Lovable documentation, GitHub integration](https://docs.lovable.dev/integrations/github). Two-way sync on one branch at a time; repositories private by default; clone locally and continue in your own editor. Seen 4 September 2026.
[^3]: [Lovable documentation, Lovable Cloud](https://docs.lovable.dev/features/cloud). Built on Supabase’s open-source foundation; data exports; moving to your own Supabase project means rebuilding the schema by hand; removing Cloud permanently deletes the instance. Seen 4 September 2026.
[^4]: [Lovable documentation, connect to Supabase](https://docs.lovable.dev/integrations/supabase). Your Supabase subscription is billed by Supabase; every table needs Row Level Security policies before going live; missing policies are the most common way app data gets exposed. Seen 4 September 2026.
[^5]: [Lovable documentation, publish your project](https://docs.lovable.dev/features/publish). A published app stays live after a downgrade; apps using Cloud or AI features need credits to keep serving requests. Seen 4 September 2026.
[^6]: [Lovable pricing page](https://lovable.dev/pricing). Worked examples of credits per instruction; Plan Mode at one credit a message; monthly credits expire two months after issuance. Seen 4 September 2026.
[^7]: [Matt Palmer, statement on CVE-2025-48757, 29 May 2025](https://mattpalmer.io/posts/statement-on-CVE-2025-48757/). 303 endpoints across 170 of 1,645 projects scanned on 21 March 2025; Lovable notified the same day. Seen 4 September 2026.
[^8]: [MITRE CVE record, CVE-2025-48757](https://www.cve.org/CVERecord?id=CVE-2025-48757). Published 30 May 2025; CVSS 9.3 critical; marked disputed, the supplier holding that customers are responsible for protecting their application data. Seen 4 September 2026.
[^9]: [Copyright, Designs and Patents Act 1988, section 11, legislation.gov.uk](https://www.legislation.gov.uk/ukpga/1988/48/section/11). Seen 5 September 2026.
[^10]: [Copyright, Designs and Patents Act 1988, section 90, legislation.gov.uk](https://www.legislation.gov.uk/ukpga/1988/48/section/90). Seen 5 September 2026.

## Go deeper

- [Stuck with a Lovable build? Here is what to do](https://www.clientflow.ai/guides/stuck-with-a-lovable-build): Fix it, build on it, or start again. What you own, and who has been paying for the attempts. Markdown: https://www.clientflow.ai/guides/stuck-with-a-lovable-build.md
- [What bespoke software actually costs in the UK](https://www.clientflow.ai/guides/bespoke-software-development-cost-uk): The bands, the five things that move the price, and when not to build. Markdown: https://www.clientflow.ai/guides/bespoke-software-development-cost-uk.md
