Skip to main content

EngineeringCodeCross Team

What a stranger can still open on your preview app link (2026)

You are about to send a customer a Lovable, Bolt, Bubble, Framer, Base44, Softgen, or v0 preview or default host. Here is what anyone else in the US can still open on that same link.

Engineering

11 min

Link
Public door

Anyone with the URL

Host
Default name

Not your domain

Test
Private window

Before you paste

Citation-ready answer: A preview or default host link is already a public door. Anyone who gets the URL — from mail, chat, a screenshot, or search — can open the same pages you just sent a customer. That can include leftover admin screens, other people's rows, and forms that write. Close those doors on a name you own before you paste the link.

This note is from CodeCross (Austin registration, Pakistan engineering on a US Central overlap). Studio evidence lives on proof. If the link you are about to paste still prints a vendor host, book a conversation.

You are not buying ads. You are not hiring a team. You are about to drop a URL into a customer email. The customer is in the US. The link still says `lovable.app`, `bolt.host`, `bubbleapps.io`, `framer.app`, `base44.app`, a Softgen preview, or a `vercel.app` working-branch host. That name is the first fact. A stranger who finds the same string can open the same door.

This page is that one moment. It is not the pre-ads wrap on Lovable MVP hardening. It is not a hire list. It does not ask who owns the repo or whether a second person can ship. It asks a smaller thing: if you send this link today, what can a person you did not invite still open?

You are about to paste the lab

A customer link should be the name you mean to keep. A preview or default host is the name the builder printed while you were still building. Those jobs are not the same. The customer thinks they received the product. A stranger who later finds the same URL gets the product too.

Vendors are honest about this. They call these hosts preview, development, or a free built-in URL. They do not call them a private room. Anyone with the link is the usual default. That is fine for you and a teammate. It is a different fact once the URL leaves your laptop.

The host name is the first fact

Read the host before you write the email. If the name still belongs to the builder, you are sending the lab. A custom domain can sit next to that lab name. The old host does not vanish just because you also have a nicer one.

BuilderWhat the lab host looks likeWhat the vendor says
Lovable`your-app.lovable.app`, or a share previewHosting puts a published snapshot on `lovable.app`. Share preview is a view-only in-progress URL. Anyone with the link can open it without a Lovable account. Free and Pro links expire after 7 days.
Bolta `bolt.host` addressPublish gives a free `bolt.host` URL. Default visibility is public. On the Free plan every published site is public. Search engines can list a public site.
Bubble`yourapp.bubbleapps.io/version-test`Previewing a web app always opens Development. The page maps Live to `https://appname.bubbleapps.io` and Development to that host plus `/version-test`.
Framera `.framer.app` previewHosting infrastructure (updated 30 Sep 2026) says preview links on `.framer.app` let you test without touching the live domain. Password protection is supported.
Base44`myapp.base44.app`Connecting a domain says every app is live on a free built-in URL from the moment you create it. Managing access sets Public as anyone on the internet, with sign-in not required.
Softgenthe in-builder preview, then a Vercel URLThe FAQ says production hosting is not included. You get a preview while you build. Deploy with Vercel is the later live URL.
v0a working-branch preview, often `*.vercel.app`Deployments give working branches unique preview URLs. First publish confirms a `vercel.app` domain. That preview is not the stable production URL.

None of those hosts are “your company” just because HTTPS works. HTTPS means the padlock. It does not mean only your customer can open the page.

What anyone with the URL can still open

A stranger does not need your builder login. They need the string you pasted. That string is enough for a lot of leftover doors.

What you meant to send vs what the URL still is

You thought

  1. One customer

    A private review before the real launch.

  2. The happy path

    Sign up, click around, say yes.

  3. My demo data

    Fake names you typed last night.

The URL still is

  1. Anyone with the string

    Mail forwards, chat logs, screenshots, search.

  2. Every route that loads

    Admin, exports, other people’s records.

  3. Live writes

    Forms, sign-up, and rows the builder already stored.

The customer got one link. The host does not know they were the only person you had in mind.

Start with the published default, not the editor. Lovable’s hosting page is plain: by default, anyone with the link can visit the published app, on every plan. Publishing never exposes the editor or the chat. It does expose the running app. Share preview is even wider in one way: share a project says anyone with the link can open it without a Lovable account. A password, when your plan allows one, does not name the person. Anyone with both the URL and the password can open it while the link is live.

Bolt’s publish page is the same class of fact. Public means anyone on the web can view the site. Search engines can list it. Private visibility exists on paid plans. The Free plan has no private published site. If you are on Free and you send `something.bolt.host`, you sent a public site.

Bubble’s preview is not Live. Previewing a web app loads Development at `/version-test`. The page also says all pages are public once they exist. Hiding a page in the editor does not hide the URL. A customer who gets `https://yourapp.bubbleapps.io/version-test` can try `/version-test/admin` the same way you can. Privacy rules in the database are the lock. A page redirect is not.

Framer’s hosting guide treats `.framer.app` as staging. Password protection is a real gate. Google is not indexing my site says a password-protected page returns 401 and cannot be indexed. If you skip that gate, the preview is just another public URL. A branch preview is a second copy. The customer and a stranger can both land on it.

Base44 does not wait for a publish click to exist on the internet. Connecting a domain says the built-in `myapp.base44.app` URL is live from the moment you create the app. Managing access starts many site-like apps as Public without login. Anyone on the internet can open that link. Private visibility is a paid-plan switch, and it still needs invites. A custom domain is a different string. The built-in `base44.app` name is still the easy one to leak if you keep pasting it.

Softgen’s FAQ splits the week in two. During development you have a preview. Production hosting is not included. Deploy with Vercel later prints a live URL. If you send the preview, you send the lab. If you send the first Vercel URL and never set Deployment Protection, you may have sent a public preview deployment. Vercel’s own page says Standard Protection covers deployments except production domains. A working-branch URL is the thing that page is for.

v0 follows that Vercel split. Deployments give each working branch a unique preview URL. Publish updates the stable production URL. The first-publish flow asks who can access the deployed app. That choice depends on the team plan and Deployment Protection. A canvas preview inside the chat is not the customer link. The `vercel.app` preview you copied out of the branch menu is.

A private-window walk before you send

Do this on a phone or in a private window. Stay signed out of the builder. Use the exact string you were about to paste. Do not use your editor session. Your editor already knows you.

Five clicks before the customer email

  1. 01 →

    Read the host

    If the name still belongs to the builder, you are sending the lab.

  2. 02 →

    Open it signed out

    A private window. No builder cookie. No saved demo login.

  3. 03 →

    Try leftover paths

    /admin, /dashboard, /users, /api. Guess what the chat named.

  4. 04 →

    Make a second account

    See if that account can read the first account’s rows or files.

  5. 05

    Submit a form

    If a stranger can write, the customer link is already a write API.

If any step is still open, do not send the link. Fix the door, or send a later host.

Lovable’s share-preview docs are useful here even if you are on another builder. Share a project says opening a password-protected preview is not a login. Lovable does not identify who opened the link. Treat every other “anyone with the link” host the same way. A password on the gate is not a named guest list.

If the walk fails, stop. Do not send “just this once.” The customer will forward the mail. A screenshot will show the full URL. A US coworker will open it on another laptop. The stranger you should worry about is often one extra person, not a movie hacker.

When the default host cannot be the customer door

Sometimes the builder host can stay for a short review if you lock it. Lovable Business can password a share preview. Bolt paid plans can publish private. Framer can password `.framer.app`. Vercel can put Authentication in front of a preview. Those are gates on the lab. They are not a new product.

Sometimes the lab cannot be the door. The customer needs a name you own. The leftover `lovable.app` or `bolt.host` still loads. Sign-up is open. A second account can see the first account’s rows. Then the job is not “word the email more carefully.” The job is to close the door, or to move the running app.

If you still want to stay on the builder and only close doors, use Lovable MVP hardening as the short wrap list — even when the app is not Lovable, that page is the shape of “preview is not the customer host.” If the default host itself is the product and you need the rows and the name to leave, open the matching extract page: migrate from Lovable, migrate from Bolt, migrate from Bubble, migrate from Framer, migrate from Base44, migrate from Softgen, or migrate from v0.

Those migrate pages are extract, not this walk. This page only decides whether you may paste the current string. Company-level evidence for how CodeCross works lives on proof.

Next steps

Copy the exact URL you were going to send. Open it signed out. Read the host. Walk leftover paths. Make a second account. Submit one form. If a stranger can still read or write, do not send the link. Put a vendor gate on the lab, move the customer to a name you own, or open the matching migrate page. When you want a second pair of eyes on that URL before the customer sees it, book a conversation.

CodeCross LLC is an Austin-registered product studio (1606 Headway Cir STE 9212, Austin, TX). The week we run here is simple: name the host, open it like a stranger, and refuse to paste a lab URL that still writes. Proof is the studio record. Book if the link is still the vendor’s name and a customer is waiting.

FAQ

Yes. Lovable’s share preview and hosting pages both treat “anyone with the link” as the default. Bolt’s publish page says a public `bolt.host` site can be viewed by anyone on the web. Mail forwards. Chat logs keep the string. A screenshot shows the address bar. One inbox is not a lock.

No. A password is a gate in front of the app. Lovable says a protected preview is not a login and does not identify who opened it. Framer’s indexing guide says a password-protected page returns 401 before the page. After a person is through that gate, row rules and roles decide what they can read. If those rules are open, the password only slowed the first click.

No. The host does not become private because the first reader is in the US. Lovable hosting serves the published site from locations around the world. Framer’s hosting guide uses anycast. The stranger can be in the same city as your customer. Geography is not the lock. The URL is.

A crop that hides the address bar is a picture, not a door. A full-window shot often prints the host. People also type what they can read. If you need the customer to click, send a host you have already walked in a private window. If you only need them to see a layout, send the crop and keep the URL off the image.

Does turning off search make a lovable.app or bolt.host URL safe to send?

No. Bolt says search engines can list a public site. That is one way a stranger finds it. It is not the only way. Lovable share previews are not a search listing. They still open for anyone who has the string. Hiding from Google does not hide the link you already put in mail.

Unpublish stops new visits to that snapshot. Lovable’s hosting page says you can unpublish and publish again later. Bolt’s publish page has the same off switch. People who already loaded the app may still hold data they copied. Deleting a Lovable share preview can take up to a minute to apply everywhere. Do not treat unpublish as an erase of what they saw.

Should I send the editor preview or the published default host?

Send neither if you have not walked it signed out. Lovable is sharp here: the editor preview can differ from the published site, and a share preview is the in-progress version. Bubble Preview is always Development. v0’s canvas is not the working-branch URL. The customer should get one host you have already opened like a stranger. If that host still belongs to the builder, say so in the mail — or wait.

Book a call

Thirty minutes with a senior teammate — honest next steps.

Ready to price an Austin build?

Bring the problem, the users, and a budget ceiling. We’ll tell you whether an app is the right next spend — and what the first year actually costs.

Prefer writing? Send project details on the contact page.