Lovable app QA testing: a person checks your flows before users do
Lovable changes your app fast, and one prompt can touch files you never mentioned. Nothing tells you when a flow that worked last week stops working. QA testing, the way I do it, means I use your app like one of your customers and write down what broke, so you can fix it before a real customer runs into it.
I've been testing software for 10+ years. Most of what I test now is built with Lovable and other AI builders, and I test it on the live product with accounts you set up for me. There's no call. It all runs by email, starting with the form below.
Send me your URL - I'll reply within 24 hours with 3 things I found by hand and a fixed price. Free, no call.
No newsletter - I use your email only to answer you.
What I test: the flows your customers use
I start with the paths that cost you users or money when they break:
- Sign-up with a real inbox, the confirmation email, the first login.
- Password reset, from the request to logging in with the new password. Here's why reset emails go missing in Lovable apps.
- The main job of your app, start to finish, as a brand-new user.
- Checkout in test mode: the price matches your pricing page, the plan unlocks, cancelling works.
- Two accounts side by side. Can one read or change the other's data? The part you can check alone is in the Supabase RLS guide.
- Forms fed with junk: empty fields, long text, HTML, double clicks, the Back button.
- Phones: Safari on a real iPhone, Android sizes in emulation.
Every problem goes into the report with steps to reproduce, what should have happened, what happened instead and how serious it is. Critical and high issues also get a screen recording, so whoever fixes the bug can watch it happen.
Regressions after the next AI edit
An audit tells you where the app stands on the day I test it. Then you keep prompting. A fix lands for one bug, and a form two screens away starts saving empty records. You find out when a user writes in, if they bother to.
That's what QA Partner is for. Before each release or bigger feature goes live, I test the new part and run the key flows again: sign-up, reset, payment, and whatever your app exists to do. You get priority turnaround, and re-tests of your fixes are included. It works like having a QA person on call without hiring one.
If you ship once and rarely touch the app after that, you don't need it. One audit, then a $290 re-test once your fixes are in, is enough.
How this differs from a free QA audit in two minutes
Some tools promise a QA audit of your app in two minutes, with no signup. They're worth running. Just keep in mind what two minutes without an account can reach: the logged-out pages, how fast they load, broken links, response headers, whatever the home page pulls in. My own free scan is that kind of tool, 17 checks against your live URL.
Lovable also scans your code on every publish, for free. It flags things like a table with RLS switched off or a secret key in the frontend. Run that too.
What no automated pass does is use the app as a customer: sign up with a real inbox and wait for the email, or log in as two people and compare what each one sees. Paying with a test card and checking that the plan unlocks is out of reach as well. That takes a person with accounts, and it's where the expensive bugs tend to sit. In the sample report below, the app kept telling users "Check your inbox" while no email was ever delivered.
When I scanned 190 live Lovable apps from the outside, 189 had at least one flagged issue. Most were configuration defaults, and none of those numbers say anything about what happens after login. Here's what the outside scan found, and what it couldn't see.
Price and turnaround
- Quick Check, $290. Report in 48 hours. The paths people hit first: sign-up email, password reset, one user against another user's data, the payment happy path.
- Pre-Launch Audit, $790. Report in 3-4 days. The full 48-point checklist, forms, mobile and security basics included. More on the scope in what a pre-launch audit of a Lovable app covers.
- QA Partner, $1,490/mo. Ongoing, monthly. Every release checked before it goes live, with the key flows run again each time.
I start when I get access. You get page 1 (the verdict) before paying. The invoice is a Payoneer link - card or bank transfer, no account needed. Full report the same day the payment lands.
What a report looks like
The sample report (PDF) is a real pre-launch pass on a study app built with Lovable, anonymized: 22 of 48 checks, 9 findings. Sign-up and file upload worked. Transactional email didn't, and the verdict on page 1 says to hold the launch until that one thing is fixed. The sample covers part of the checklist. Latest full audit: 36 findings across 44 of 48 checks, 4 critical.
Questions people ask first
Is this a security audit?
Partly. Access between users, keys in the frontend and HTTPS are on the checklist. Most of it is about whether the app works for a paying customer. If a client or an investor asks you for a penetration test report, that's a different service from a different kind of firm.
Can you test every release?
Yes, that's QA Partner. Tell me what changed and when it ships. I test the new part and the key flows before it goes live.
What do you need from me to start?
A test account, a second one so I can see what one user sees of another, and test-mode payments if the app takes money. I send the full list after you say yes.
Do you need my code, or a call?
Neither. I test the live app with the test accounts, and everything goes by email. Repo access is optional.
Want to see the outside first?
The free scan checks what anyone can see without logging in. About 20 seconds, no signup.
Run the free scan