Security
Account isolation
Private database queries are scoped to the authenticated user and should be enforced by Supabase RLS.
Secrets
Only the public Supabase URL and publishable/anon key belong in frontend configuration. Service-role and secret keys must never be shipped to browsers.
Reporting
Before launch, publish a real support/security contact and complete an independent review of RLS policies and database constraints.