[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-privacy-rules::en":3,"gloss-cluster-privacy-rules::en":26,"gloss-next-privacy-rules::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"privacy-rules","no-code","Privacy Rules (Row-Level Security)","Privacy rules control which users can see or change which rows of data in a no-code app, enforced on the server rather than just hidden in the interface. In tools like Bubble they are conditions attached to a data type — for example, a user can read an Order only if its Creator is the logged-in user. Why it matters: the single most common security failure in no-code apps is data that looks hidden in the UI but is still returned by the underlying API. Anyone who opens the browser network tab, or calls your app's data endpoint directly, can pull every record unless a privacy rule blocks it at the source. Practical note: set rules per data type before you build screens, default to denying everything, then grant the minimum each role needs. Test them while logged in as a real non-admin account, not as the app owner, whose view often bypasses restrictions.","Privacy rules decide which users can read or change which rows in a no-code app — and they must be enforced server-side, not merely hidden in the interface.",null,[11,14,17,20,23],{"slug":12,"name":13},"backend-as-a-service","Backend-as-a-Service (BaaS)",{"slug":15,"name":16},"bubble","Bubble",{"slug":18,"name":19},"database-app","Database App",{"slug":21,"name":22},"internal-tool","Internal Tool",{"slug":24,"name":25},"no-code-app-builder","No-Code App Builder",[27,31,35,38,41,44,47,50,53,54,57,58],{"slug":28,"category":5,"name":29,"updated_at":30},"action","Action","2026-08-24T02:46:36+00:00",{"slug":32,"category":5,"name":33,"updated_at":34},"aggregator","Aggregator","2026-08-24T02:46:37+00:00",{"slug":36,"category":5,"name":37,"updated_at":30},"airtable","Airtable",{"slug":39,"category":5,"name":40,"updated_at":30},"api","API",{"slug":42,"category":5,"name":43,"updated_at":30},"api-key","API Key",{"slug":45,"category":5,"name":46,"updated_at":34},"approval-workflow","Approval Workflow",{"slug":48,"category":5,"name":49,"updated_at":30},"automation-platform","Automation Platform",{"slug":51,"category":5,"name":52,"updated_at":30},"automation-recipe","Automation Recipe",{"slug":12,"category":5,"name":13,"updated_at":30},{"slug":55,"category":5,"name":56,"updated_at":34},"backfill","Backfill",{"slug":15,"category":5,"name":16,"updated_at":30},{"slug":59,"category":5,"name":60,"updated_at":30},"business-logic","Business Logic"]