1. Acceptance and scope
This Usage Policy governs access to and use of the SupaTodo research prototype. By using it, you agree to follow this policy. Stop using the prototype if you do not agree.
SupaTodo is a personal educational and technical research environment. It is not an enterprise platform, production service, system of record, or approved location for business information.
2. Permitted use
You may use SupaTodo to evaluate basic authentication, account recovery, PostgreSQL row-level security, and user-scoped task operations. Reasonable manual testing is permitted.
You retain ownership of task content you submit. You grant the prototype operator and infrastructure providers only the limited rights needed to host, transmit, secure, and process that content to provide the service.
3. Prohibited use
You must not use SupaTodo to:
- Store confidential enterprise data, trade secrets, credentials, API keys, regulated records, financial account data, health information, government identifiers, or highly sensitive personal data.
- Upload or enter unlawful, abusive, threatening, defamatory, discriminatory, exploitative, or rights-infringing content.
- Impersonate another person, misrepresent authorization, or attempt to take over another account.
- Bypass authentication, row-level security, rate limits, access controls, or other safeguards.
- Probe, scan, exploit, disrupt, overload, scrape, or automate requests against the prototype, Supabase, or Cloudflare without explicit authorization.
- Trigger repeated authentication emails, create excessive anonymous accounts, or use the service for spam or denial-of-service activity.
- Distribute malware, malicious code, or instructions intended to compromise systems or users.
- Use the prototype for production, safety-critical, legal, medical, financial, employment, or other consequential decisions.
4. Accounts and access
- A guest account is tied to the browser session. Signing out or clearing storage before attaching and verifying an email can permanently remove access to its tasks.
- Email sign-in uses one-time links and is subject to Supabase email and authentication rate limits.
- You are responsible for controlling access to your email account, device, and active session.
- Do not share magic links or authentication tokens. Report suspected unauthorized access to the project owner.
5. Content and data handling
You are responsible for the content you enter and for having any rights or permissions required to process it. The operator may remove content or accounts that violate this policy, create legal or security risk, or interfere with the prototype.
The prototype is designed for short task titles, not document storage. Deleted content may remain temporarily in provider backups or operational logs according to provider retention and recovery processes.
6. Prototype availability
The prototype is provided on an experimental, best-effort basis. It may be changed, reset, paused, rate-limited, or discontinued without notice. There is no service-level agreement, durability commitment, backup promise, or guaranteed recovery.
Free-tier infrastructure may impose quotas, pause inactive projects, restrict email delivery, or change behavior. Do not rely on SupaTodo for important records.
7. Security research
Do not conduct penetration testing, vulnerability scanning, load testing, or automated security research without explicit authorization defining scope, time, tools, traffic limits, and disclosure procedures.
If you discover a potential vulnerability during ordinary use, stop testing and report the issue privately to the project owner through the access channel. Do not access, alter, retain, or disclose another user’s data.
8. Third-party services
SupaTodo depends on Supabase and Cloudflare. Your use is also subject to applicable provider terms, policies, technical limits, and acceptable-use requirements. The prototype operator does not control provider outages, policy changes, or data-processing practices.
9. Enforcement and termination
Access may be restricted or terminated when necessary to investigate abuse, protect users or infrastructure, comply with law, enforce this policy, or discontinue the experiment. The operator may delete accounts and data as part of a reset or shutdown, subject to applicable law.
10. Disclaimers and liability
SupaTodo is provided “as is” and “as available,” without warranties of availability, accuracy, fitness, non-infringement, security, or data preservation to the extent permitted by law. Use is at your own risk.
To the extent permitted by applicable law, the operator is not liable for lost data, lost access to a guest account, missed tasks, provider outages, indirect damages, or reliance on the prototype. Nothing in this policy excludes rights or liability that cannot lawfully be excluded.
11. Changes and contact
This policy may be updated as functionality or risk changes. The effective date and version identify the current policy. Continued use after an update indicates acceptance where permitted by law.
Questions, incident reports, or policy concerns should be sent to the project owner through the same channel used to provide access. A final production policy would require a verified legal operator, contact address, governing-law analysis, dispute terms, and counsel review.