Privacy & Security
Every piece of your writing is protected at the database level, not just hidden by the interface.
1 min read · Updated 1 October 2026
How access control works#
Inkora enforces access with database-level row security — meaning a private book's chapters, characters, locations, and notes are unreachable even through a direct request, not merely unlinked in the app. Visibility settings (see "Stories & Visibility") are the real, enforced boundary, not a cosmetic one.
Your account#
Authentication is handled by Supabase Auth. Your password is never stored in plain text or visible to anyone, including Inkora's own team.
What's never exposed#
Private books, chapters, characters, notes, and worldbuilding stay private regardless of any Community feature — nothing in Discover, Stories, or a public profile can surface content from a book you haven't explicitly made Community or Public.
