Skip to content
TodoTrail
How it worksLive demoPricingBlog
Sign inCreate my first route
Menu
How it worksLive demoPricingBlogSign in

Security

Security

TodoTrail uses account-based access and database policies intended to keep each user's route data private.

Account securityData accessAdministrative accessReporting concerns

Account security

TodoTrail uses Supabase Auth for email/password and Google sign-in. Authentication cookies are handled server-side in the Next.js application so that protected pages and APIs can verify the current user before returning private route data.

Data access

Saved routes, tasks, and feedback are associated with a user account. Database access policies are designed so normal users can write only their own TodoTrail data. Server APIs ignore client-supplied user identifiers and use the authenticated account from the session.

Administrative access

The administrative view is not linked from the public site. It requires a configured hidden route, a signed-in admin account, confirmed email, and a server-only Supabase service role key. The service role key must never be exposed in browser code.

Reporting concerns

If you notice a security concern, send a concise report through the feedback page. Include the affected URL, expected behavior, and observed behavior. Do not include passwords, tokens, or private data belonging to another person.

TodoTrail
Daily plannerTime blockingWeekly plannerOrganization appsVisual todo listTask routesComparePricingBlogFeedbackPrivacyTermsSecurity