Trust
Security and privacy by design
The system avoids browser-side secrets, keeps service-role keys server-only, hashes extension sessions, and keeps outreach manual.
Security posture
Supabase authentication, server-side admin access, row-level security, hashed extension sessions, and explicit user controls protect the product surface.
Responsible automation boundary
The extension can scan visible content and draft text, but it does not auto-send messages or bypass platform controls.
Security posture
Supabase authentication, server-side admin access, row-level security, hashed extension sessions, and explicit user controls protect the product surface.
No service-role key in browser
Hashed extension sessions
Admin-only routes
Manual outreach requirement
Responsible automation boundary
The extension can scan visible content and draft text, but it does not auto-send messages or bypass platform controls.
No DM blasting
No stealth behavior
No rate-limit evasion
No automatic comments
Next step
Read setup guide