Privacy
Sensitive practice data should be protected by default.
Anxiebuddy should not require a real name, public profile, GPS tracking, or sensitive-data-based marketing. Export and deletion flows are part of the MVP plan.
No real name requirement
The MVP should use email for account access and keep display name optional.
No sensitive marketing use
Exposure content must not be sent to MailerLite, ad platforms, analytics tools, or AI services.
Export and deletion
Users should be able to export their own data and delete exposure data or their account.
Access control from the start
All user-owned data tables should use Row Level Security once Supabase is added.