What I do: read your repo's database migrations (through Lovable's GitHub sync) and find every rule that lets the public key, or any signed-in user, read or change data, plus tables with row level security off. I fix it by scoping each rule to the row's owner, or by moving reads and writes into server functions. The change arrives as a pull request you review, and one click reverts it. Then I prove it with your consent: the same request with your app's public key, before and after (before: data; after: permission denied).