Authentication & access
Accounts sign in with email + password or Google. Passwords are hashed by our auth provider — we never see them in plaintext. Each account can only view and edit its own profile, links, subscribers, inquiries, broadcasts, and billing; Row-Level Security policies enforce these boundaries at the database layer, not just in the app UI.
Admin actions (moderation, SSL queue, team roles) are gated by a separate server-checked role. Session tokens live in the browser and can be revoked by signing out or changing your password.