Supabase
LiveSupabase Inc. · Infrastructure · Available now
Postgres database and authentication, with row-level security.
How it works
What happens when Supabase is connected
Postgres with row-level security enabled on every table holding workspace data. Policies scope reads to workspace members.
calendar_connections is the deliberate exception: it has no policy at all, so the anon and authenticated roles cannot read OAuth tokens even by accident. The service role, which only ever runs on the server, is the sole reader.
With no Supabase credentials configured the app reads the demo dataset instead and holds writes in memory for the life of the process, so an unconfigured deployment renders rather than crashes.
Data
What Setupp accesses
This is not something you connect. It is part of how Setupp runs, listed here because security reviewers are right to ask where the data goes.
No OAuth scopes. Setupp authenticates to this service with a server-side key that is never sent to a browser.
The full table, including what Setupp never does with any of it, is on the integrations overview.
Google Calendar, Google Meet, Outlook, Microsoft Teams, Zoom, Apple Calendar, Slack, HubSpot and Zapier are trademarks of their respective owners, and logos are used to identify the services Setupp connects to. Calendly is a trademark of Calendly, Inc., named only to identify the product being compared. Setupp is not affiliated with, endorsed by, or sponsored by any of them.