Connect Lovable
Turn on GitHub sync in Lovable, then connect that repository. Poliogo reads what your generated app actually calls.
How the connection works
- Turn on syncPoint your builder at a GitHub repository so it pushes your generated code there.
- Connect that repoPick it in Poliogo — the scanner reads what the generated code really calls.
- Detection stays onRegenerate in your builder and the next scan picks up what changed.
What it looks like once connected
An illustration of this connection inside your Poliogo dashboard — not live data.
Detected in this project
- Stripestripe in package.json
- SupabaseSUPABASE_URL in .env.example
- OpenAIfetch to api.openai.com — no SDK
- PostHognew since your last scan
Exact permissions requested
Every permission this connection asks for, named as Lovable names it on its own consent screen — so you can compare this table to what you are shown.
| Permission | Grant | What it is used for |
|---|---|---|
| Contents | Read | Read manifests, source text and .env.example in the repositories you select. |
| Metadata | Read | List your repositories and their default branch so you can pick one. |
| Email addresses | Read | Identify your account when you sign in with GitHub. |
| Contents — branch + pull request | Write | Create a poliogo/* branch and open a pull request on it. Changes reach your default branch only through a pull request you approve. |
Setting it up
What you do, and what you will be looking at while you do it.
Turn on GitHub sync in Lovable
Open your Lovable project, find the GitHub option, and connect it to a repository. Lovable then pushes your generated code there every time you build.
Let it push once
Make any small change so Lovable commits. Poliogo reads the code in the repository, so there has to be some there before the first scan.
Connect that repository to Poliogo
Press Connect below, install the GitHub App on that repository, and pick it.
Check what it found
You get a plain-English list of every service your app uses — including ones called over plain HTTP with no package installed, which is the normal shape of generated code. Correct anything, then generate.
Keep building
Every time you regenerate in Lovable, the next scan sees what changed and prepares the policy update for you to approve.
Choose how to scan your app
Pick one. We scan your code and settings to find the services your app uses — the scan keeps that list, not your files.
In Lovable: ⋯ menu → GitHub → Connect, then pick that repository below.
Authorise on GitHub
Granted on GitHub's own screen — this panel can show it, never widen it.
Connect GitHubSelect repositories
What Poliogo detects from Lovable
The right-hand column is the part worth reading: it is what this connection cannot reach even if we wanted it to.
What it reads
- Dependency manifests — package.json, requirements.txt, Cargo.toml, go.mod, composer.json, pubspec.yaml and the rest.
- The endpoints your code actually calls. A raw fetch to api.openai.com is found even with no SDK installed.
- Environment variable names in .env.example — STRIPE_SECRET_KEY proves Stripe without reading any secret.
- Your framework and where its routes live, so generated policy pages land in the right folder.
- Cookies and tracking scripts referenced anywhere in the source.
What it never reads
- Repositories you did not select.
- The value of any secret or environment variable.
- Your default branch, except through a pull request you approve — updates arrive on a poliogo/* branch.
Ready to connect Lovable?
The free plan covers one project with no credit card. You approve everything before a single document is written.
Poliogo is a compliance management platform, not a law firm. What it produces is not legal advice. See exactly what each connection reads.