Account boundary
Firebase Authentication owns Google and verified-email access. Recent authentication is required for purchases, export, deletion, session changes, and other sensitive actions.
SECURITY
Identity, household records, story work, media, billing, privacy jobs, and operations sit behind separate authorization and least-privilege boundaries.
Firebase Authentication owns Google and verified-email access. Recent authentication is required for purchases, export, deletion, session changes, and other sensitive actions.
The Android app does not directly read business data from Firestore or private Storage. The API rechecks account state, household role, object ownership, and entitlement.
Offline packages are encrypted with non-exportable Android Keystore-backed keys. The local device gate is a convenience control, never a replacement for server identity.
Support sees masked references and minimal state. Story content is closed by default; future break-glass access must be reason-bound, audited, and security reviewed.