Automate Basics
At work · TechCrunch

UpGuard finds personal data exposed in Supabase databases

By Automate Basics, written with AI from TechCrunch's original

· 2 min read

Hand covers part of a printed grid beside a meeting room folder
Image: AI-generated illustration.

UpGuard found personal data publicly accessible in databases hosted by Supabase, according to TechCrunch. The findings give teams using AI-built apps a reason to check whether their database settings protect the information they collect.

What UpGuard found

TechCrunch reports that security firm UpGuard found around 16,000 databases hosted by Supabase with some personal data accessible on the public web. UpGuard found names, addresses and phone numbers, along with a smaller number of passwords and authentication tokens. The exposed databases were connected to a range of projects, including services handling private conversations and contact details.

The report connects the risk to apps built with AI assistance. An AI tool may help someone create an app, but the resulting code can have security flaws, and the person building it may not know which database settings need attention. Supabase told TechCrunch that its projects are secure by default and that customers control how their projects are configured. The company said it notifies affected customers when it discovers security issues.

Who needs to check a Supabase project?

Teams that use Supabase to store information for an app or website have a reason to review their projects, especially if an AI tool helped build them. The finding does not mean every Supabase database is exposed. It does show that storing data on the platform does not remove the need to check how a particular project is configured.

A work team collecting names, contact details or private messages should pay particular attention to who can retrieve those records. The source does not identify affected subscription plans or say that exposure depends on a paid feature. It also gives no pricing information. Supabase describes security as a responsibility shared with customers: the company provides defaults and tools, while customers decide how their projects are configured.

How do I check an AI-built app at work?

A useful first task is to review an AI-built app that collects personal information and stores it in Supabase. Ask the person responsible for the project to check which records someone without permission could access. Focus on actual stored data, not just what the app displays to an ordinary user. Check whether contact details, private conversations or credentials are reachable by people who should not have them.

TechCrunch does not provide a testing procedure or identify a Supabase setting to change, so the report is not a substitute for a security review. If the team cannot establish who can access its records, treat that uncertainty as something to resolve before collecting more sensitive information. For staff who build or commission apps, AI data privacy training can help make that check part of the work rather than an afterthought.

Frequently asked questions

Did UpGuard say every Supabase database is exposed?

No. TechCrunch reports that UpGuard found around 16,000 Supabase-hosted databases with some personal data publicly accessible. The report does not say that every Supabase project has this problem. Supabase told TechCrunch its projects are secure by default and customers control their own project configurations.

Why does this matter for apps built with AI?

AI tools can help people build apps without ensuring the resulting code or database configuration protects stored information. TechCrunch says the findings illustrate how configuration mistakes and security flaws can expose personal data. Teams should check access to the records their own apps store, not assume an app is safe because it works.

Written with AI from TechCrunch's original and published after automatic checks: every figure here appears in the original, and no sentence is copied from it. The picture is AI-generated. The original is the authority.

Source: Some Supabase customers are publicly exposing reams of people’s data to the web, TechCrunch, 25 Sept 2026.