Users can see each other’s data
One customer can open another customer’s records, or anyone can read your tables.
$390 · fixed price · 48-hour target · you pay once it works

Akshit Ahuja
senior engineer · no handoff
- previously
- engineer at Spinny, a $1B+ startup
- based
- Gurugram, India · US-morning overlap
- profile
- LinkedIn →
why it happens
In Supabase this is almost always row level security that is switched off, or policies that are too open. It is the most common serious issue in AI-built apps, and it is very fixable.
what I do
- ✓Check every table for who can read and write it
- ✓Turn on row level security with a policy per role
- ✓Test as two different users and as a logged-out visitor
- ✓Move any secret keys out of the browser
Every change lands on your GitHub, your features stay where they are, and you can keep building in your AI tool afterwards. If it turns out to be something you can fix yourself, I’ll tell you how.
what you hand over
- 01Your app. Add me to the Lovable, Bolt or Replit project, or connect it to GitHub and add me there.
- 02Your data. Invite me to Supabase or Firebase as a team member. Read-only first if your plan allows it.
- 03Payments, if needed. Invite me to Stripe as a Developer or View-only team member. Never send secret keys.
- 04Afterwards. Remove my access when we’re done. I delete any local copy of your code the same day.
how you pay
- You get an invoice in USD. Pay by card or bank transfer.
- Single fixes: invoiced after you’ve checked the fix on your live app.
What “works” means. Before I start, we agree one test in plain words, like “a test card payment unlocks the Pro plan”. When that passes on your live app, it works.
Send me the details. Fixed quote in one business day.
Rather talk first? Book a 20-minute call