Know what happens to your client work.
SEOryx separates account access, billing, reviews, and installer access. The public site explains the controls; each deployment still needs its own configuration review before launch.
Your client work deserves a clear boundary.
Project context stays attached to the account and project that supplied it.
Google, GitHub, and SEO connections use the permissions you grant them.
Project history helps you continue the work. It is not published as customer proof.
You should review retention, deletion, and connected-account settings before rollout.
The important checks happen before access is granted.
Sign in before checkout
Supabase checks the signed-in account before the site creates a checkout session or a download request.
Your rows belong to your account
Subscription rows are readable only by their owner. Reviews become public only after approval.
Downloads are checked
Installers live in a private Storage bucket. An active subscription receives a short-lived link instead of a permanent public URL.
Payment status comes from Stripe
Only a signature-verified Stripe webhook records subscription state. The browser cannot mark a payment as complete.
