Skip to content
Glossary

What is Supabase?

The backend under a large share of AI-built apps, Lovable's included. Here is what it is and where its defaults stop.

Plutonapps Engineering1 min read

In short

Supabase is an open-source backend platform built on PostgreSQL. It gives an app a Postgres database with an instant API, user sign-in, file storage, realtime updates and server-side functions, managed as one project. Lovable Cloud, Lovable's built-in backend, is built on Supabase's open-source foundation, so many AI-built apps already run on it.

Why it matters when your prototype goes to production

Supabase exposes your database through an API the browser can call directly. That is what makes it fast to build on, and it is why one setting matters more than any other: row-level security. Supabase's own documentation says to enable it on every table in an exposed schema, because once it is on, no data is reachable with the public key until you write policies.

The rest of production readiness is the usual list, applied to Supabase: keep the secret key on the server, make schema changes through versioned migrations, confirm backups and point-in-time recovery match what you can afford to lose, and watch the logs.

Supabase or Lovable Cloud?

Lovable Cloud is the managed route inside Lovable. A Supabase project of your own gives you direct control of settings, billing and access. Either way, the database underneath is PostgreSQL, which keeps your data portable.

Common questions

Is Supabase secure?

The platform gives you the tools; the app decides whether they are used. The most common gap is a table exposed without row-level security policies.

More on this: Production architecture & security · All glossary terms

Built something in Lovable you want people to rely on?

We are the engineers who take it the rest of the way — secured, tested, released and supported.