AI app builders are genuinely good now. Ask for a booking page on a Saturday and you can have people signing up by Sunday. The catch is that "it works" and "it's safe" are two different tests, and only one of them shows up on screen.
On September 25, 2026, TechCrunch reported that many apps built on Supabase, a popular database service, are exposing their users' personal data to anyone who looks. Plenty of them were built with AI tools, the style people now call vibe coding.
To be clear about what this is: Supabase was not hacked, and the AI tools are not broken. The databases behind these apps were simply never locked. That is good news, because a lock is something you can add yourself this afternoon.
Picture a coach who asks an AI app builder for a booking page: a form, a button, a thank-you screen. The page needs to save each booking somewhere, so it talks to a database using a key that sits right inside the page. Anyone who opens the page's code can find that key. That part is normal and by design.
What keeps strangers out is a lock on each table, called row level security. With it on, the database checks every request and only hands back the rows that person is allowed to see. With it off, anyone holding that public key can ask for the whole table, and get it: every name, email and phone number your customers trusted you with.
Why it gets skipped: when you ask AI to make it work, it makes it work. The form saves and the list fills up. A missing lock is invisible when everything works, so it's easy for the AI, and for you, to never notice it.
1. Look at every table. Open your Supabase dashboard and go through each table your app uses, not just the one you remember making.
2. Run the security check. Supabase has built-in advisors that flag problems. Read every warning about a table anyone can read.
3. Ask your AI builder to lock it. Something like: "Turn on row level security for every table, so each person only sees their own data." Supabase explains the feature in its row level security guide if you want to see what it's doing.
4. Test it like a stranger. Log out, or open a private window, and try to see the list. If you can see other people's details without logging in, it isn't locked yet.
Lock first, launch second. No real names go into the app until every table is locked. Test with obviously fake data until then.
Only collect what you need. If a booking only needs an email, don't ask for a phone number. Data you never collect can't leak.
AI can build the house in a weekend. You still have to lock the door.
The first thing most small businesses build with AI is something that collects information: a booking form, a signup list, an intake page. That makes the database the most valuable thing you own online, and the easiest to forget, because it never shows up on the page.
The fix is not to stop building. It is to make a short safety check part of how you build, the same way you'd lock up the shop at night. That kind of habit is what setting AI up around your own work and rules is really about.
Sources: TechCrunch's report (September 25, 2026) and Supabase's documentation on row level security and advisors.
The free quiz takes 2 minutes and gives you a starting list for your business. No call, no card.
Take the free 2-minute quiz