What Lovable does and doesn’t do
Lovable builds a React web app, usually with a Supabase backend, and publishes it to a URL. That’s it for distribution: no iOS project, no signed binary, no App Store Connect. Everything after the web app is on you.
Your three options
| Option | What it is | Good for | Watch out for |
|---|---|---|---|
| Capacitor | Wraps your built web app in a real Xcode project | Apps you’ll keep improving; adding native features | Needs a Mac/Xcode; you maintain the iOS project |
| Median (or similar) | Hosted service that wraps your site and builds it | Fastest path, little setup | Often loads the live URL, which is closest to what 4.2 rejects |
| Native rebuild | Rebuild the core screens in SwiftUI or React Native, keep the backend | Apps where the phone experience is the product | More work up front, but review is far easier |
Steps with Capacitor
- Connect Lovable to GitHub and clone the repo.
- Set production environment variables for the build: Supabase URL, anon key and any API base URLs.
npm run build, then add Capacitor (@capacitor/core,@capacitor/ios),npx cap initandnpx cap add ios.- Bundle the build: point Capacitor at your
distfolder, not at the live website URL. - Fix auth redirects for the app’s URL scheme so Supabase login returns to the app.
- Add native pieces that make it an app: native navigation, offline states, push, share sheet, Sign in with Apple if you offer Google.
- Open in Xcode, set the bundle ID, team, signing, icons and launch screen; archive and upload to App Store Connect.
- Create the listing: screenshots of real screens, privacy labels, age rating, support URL, demo account.
- Test the TestFlight build on a device, then submit for review.
The rejections Lovable apps hit most
- 4.2 Minimum Functionality: the wrapped site doesn’t feel like an app. By far the most common.
- 3.1.1 In-App Purchase: a Stripe “Upgrade” button for digital features.
- 4.8 Login Services: Google sign-in from the Supabase template with no Apple option.
- 5.1.1 Data Collection: no in-app account deletion.
- 2.1 App Completeness: missing env vars in the build, or a paused Supabase project.
Before you ship: check your keys
Lovable apps talk to Supabase from the browser. The anon key is meant to be public, but only if row-level security is on for every table. A service-role key in the client gives anyone full database access. Run our free key scanner on your published URL before you wrap it.
Or have us do it
Our App Store Launch takes your Lovable repo to an approved App Store listing: the wrap or native screens, signing, listing, review notes and any first-round rejections, for one flat fee.
Questions
Can Lovable publish to the App Store by itself?
Capacitor or Median?
Do I need a Mac?
Will my Supabase backend still work?
How much does it cost?
Last reviewed 2026-09-23. Guideline quotes are from Apple’s App Review Guidelines; Apple can change them at any time.

