Agent skill

Supabase Data Handling

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Implement GDPR/CCPA compliance with Supabase: RLS for data isolation, user deletion via auth.admin.deleteUser(), data export via SQL, PII column management, backup/restore workflows, and retention…

MITAuto-check passedLegal & Compliance

Install Supabase Data Handling

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-data-handling -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-data-handling --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/supabase-data-handling .claude/skills/supabase-data-handling && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
supabase-data-handling
GitHub stars
2.8k
Token cost
~1.9k tokens
SKILL.md length
650 words
Files
7 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Implement GDPR/CCPA compliance with Supabase: RLS for data isolation, user deletion via auth.admin.deleteUser(), data export via SQL, PII column management, backup/restore workflows, and retention…

  • Works in 3 steps: RLS for Data Isolation and PII Column… → User Deletion and Data Export → Retention Policies and Backup/Restore
  • Handling sensitive data
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 4 more sections
  • Needs SUPABASE_SERVICE_ROLE_KEY

What it does

Supabase Data Handling is an agent skill from jeremylongshore/tons-of-skills-marketplace. Implement GDPR/CCPA compliance with Supabase: RLS for data isolation, user deletion via auth.admin.deleteUser(), data export via SQL, PII column management, backup/restore workflows, and retention policies. Use when handling sensitive data, implementing right-to-deletion, configuring data retention, or auditing PII in Supabase database columns. Trigger with: "supabase GDPR", "supabase data handling", "supabase PII", "supabase compliance", "supabase data retention", "supabase delete user", "supabase data export".

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/deletion-and-export.md`, `references/errors.md` and `references/examples.md`). Compatibility notes: Designed for Claude Code

It sits in Legal & Compliance, covering Privacy and GDPR and SQL. It works with Supabase and SQL. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Handling sensitive data
  • Implementing right-to-deletion
  • Configuring data retention
  • Auditing PII in Supabase database columns

Example prompts

  • “supabase GDPR”
  • “supabase data handling”
  • “supabase PII”
  • “/supabase-data-handling”

Requirements

  • Node.js
  • A credential in SUPABASE_SERVICE_ROLE_KEY
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash(npx supabase:*), Bash(supabase:*), Bash(psql:*), Grep, Glob

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. RLS for Data Isolation and PII Column Management
  2. User Deletion and Data Export
  3. Retention Policies and Backup/Restore

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash(npx supabase:*)
    • Bash(supabase:*)
    • Bash(psql:*)
    • Grep
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript and sql).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • supabase.com
    • oag.ca.gov

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SUPABASE_SERVICE_ROLE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Supabase Data Handling loads about 1.9k tokens when it runs, and up to ~7.8k if it reads all its reference files. Until then it costs about 135 tokens; SKILL.md has 650 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~135
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 650 words, ~1,911 tokens.

Download SKILL.mdSave it as .claude/skills/supabase-data-handling/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
supabase-data-handling
description
Implement GDPR/CCPA compliance with Supabase: RLS for data isolation, user deletion via auth.admin.deleteUser(), data export via SQL, PII column management, backup/restore workflows, and retention policies. Use when handling sensitive data, implementing right-to-deletion, configuring data retention, or auditing PII in Supabase database columns. Trigger with: "supabase GDPR", "supabase data handling", "supabase PII", "supabase compliance", "supabase data retention", "supabase delete user", "supabase data export".
allowed-tools
Read, Write, Edit, Bash(npx supabase:*), Bash(supabase:*), Bash(psql:*), Grep, Glob
compatibility
Designed for Claude Code
version
1.54.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, supabase, gdpr, ccpa, compliance, data-handling, privacy

Supabase Data Handling

Overview

GDPR and CCPA compliance with Supabase uses a layered approach: Row Level Security (RLS) for tenant data isolation, supabase.auth.admin.deleteUser() for right-to-deletion, SQL-based exports for subject access requests, PII detection across columns, automated retention with pg_cron, and point-in-time recovery for backup/restore. Every requirement maps to a real Supabase SDK method or PostgreSQL feature.

When to use: Implement GDPR right-to-deletion, respond to data subject access requests (DSARs), audit PII in the database, configure automated retention, set up tenant isolation with RLS, or plan backup/restore procedures.

Prerequisites

  • @supabase/supabase-js v2+ with service role key for admin operations
  • Supabase project on Pro plan (for pg_cron and point-in-time recovery)
  • Understanding of GDPR Articles 15-17 (access, rectification, erasure)
  • Database access via SQL Editor or psql for schema changes

Instructions

Step 1: RLS for Data Isolation and PII Column Management

Enable RLS on every table holding user data, then classify PII columns so later deletion and export steps know what to touch. The RLS skeleton is one USING (auth.uid() = ...) policy per access pattern:

sql
ALTER TABLE public.profiles ENABLE ROW LEVEL SECURITY;

CREATE POLICY "users_read_own_profile" ON public.profiles
  FOR SELECT USING (auth.uid() = id);

Pair the policies with a PII audit — an information_schema.columns scan by naming pattern, COMMENT ON COLUMN tags, a pii_registry view, and an SDK-side regex scanner for emails, phones, SSNs, and IPs.

See RLS and PII reference for the full multi-tenant policy set, the PII audit SQL, the pii_registry view, and the scanTableForPII() SDK scanner.

Step 2: User Deletion and Data Export

Implement GDPR Article 17 (erasure) and Article 15 (access). Deletion runs in cascade order — application tables, then storage files, then the auth user, then an immutable audit-log entry that must survive the erasure:

typescript
// Cascade order matters: children before parents, auth user last
const tablesToPurge = ['comments', 'orders', 'documents', 'profiles'];
// ...delete rows, remove storage files, then:
await supabase.auth.admin.deleteUser(userId);
await supabase.from('gdpr_audit_log').insert({ action: 'USER_DELETION', subject_id: userId });

Export is the inverse: read every user-scoped table plus storage listings into one JSON payload and log a DATA_EXPORT audit row.

See deletion and export reference for the full deleteUserData() pipeline (with the gdpr_audit_log migration and locked-down RLS policy) and the exportUserData() DSAR builder.

Step 3: Retention Policies and Backup/Restore

See retention policies and backup/restore for pg_cron automated retention schedules (30/90/730-day tiers), SDK-based retention monitoring, pg_dump/pg_restore commands, and point-in-time recovery configuration.

Output

Completing this skill produces:

  • RLS tenant isolation — row-level policies ensuring users access only their own data
  • PII column registry — documented and classified PII columns across all tables
  • PII scanner — SDK-based pattern detection for emails, phones, SSNs, and IPs in text columns
  • User deletion pipeline — complete auth.admin.deleteUser() flow with cascade table deletion, storage cleanup, and audit logging
  • Data export — DSAR-compliant export of all user data from tables and storage
  • GDPR audit log — immutable log of all deletion and export operations with legal basis
  • Automated retention — pg_cron jobs for 30/90/730-day retention tiers
  • Backup/restore — pg_dump/pg_restore commands and PITR configuration
Show full SKILL.md (219 more words)Show less

Error Handling

ErrorCauseSolution
auth.admin.deleteUser() returns 404User already deleted or wrong IDCheck auth.users table; may have been deleted by another process
violates foreign key constraint during deletionChild rows reference userDelete in cascade order (comments → orders → profiles) or use ON DELETE CASCADE
permission denied for function cron.schedulepg_cron not enabled or wrong planEnable pg_cron extension; requires Supabase Pro plan
pg_dump: connection refusedUsing wrong port or pooler URLUse direct connection (port 5432), not pooler (port 6543) for pg_dump
RLS policy blocks admin operationsService role key not usedUse createClient with SUPABASE_SERVICE_ROLE_KEY to bypass RLS
Audit log entries missingTable has RLS blocking insertsUse SECURITY DEFINER function or service role for audit writes
Retention job not runningpg_cron job disabled or erroredCheck cron.job_run_details for error messages

Examples

Each example uses the functions defined in the reference files above. See deletion and export reference for deleteUserData().

Example 1 — Handle a GDPR deletion request:

typescript
// Wraps deleteUserData() behind an API endpoint; GDPR requires completion within 30 days
async function handleDeletionRequest(userId: string) {
  const result = await deleteUserData(userId);
  return { status: 'completed', auditId: result.auditLogId };
}

Example 2 — Quick PII audit:

sql
-- Count rows with email-like patterns in unexpected columns
SELECT 'profiles' AS table_name, 'bio' AS column_name, count(*) AS rows_with_email
FROM public.profiles
WHERE bio ~ '[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}';

Example 3 — Verify retention job execution:

typescript
async function checkRetentionJobs() {
  const { data, error } = await supabase.rpc('get_cron_status');
  if (error) throw error;
  for (const job of data ?? []) {
    console.log(`Job "${job.jobname}": last_run=${job.last_run}, status=${job.status}`);
  }
}

Resources

Next Steps

  • For enterprise role-based access control, see supabase-enterprise-rbac
  • For security hardening and API key scoping, see supabase-security-basics
  • For observability and audit trail monitoring, see supabase-observability

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in skills/.curated/supabase-data-handling of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/deletion-and-export.md
  • references/errors.md
  • references/examples.md
  • references/implementation.md
  • references/retention-and-backup.md
  • references/rls-and-pii.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Supabase Data Handling next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Supabase Data Handling compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Supabase Data Handling this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.9kAutomated safety check: PassMIT
Safe SQL Executionsupabase/supabase111k—~4.2kAutomated safety check: PassApache-2.0
Replica ArchitectJakeschincariol/replica-skill1.4k—~1.1kAutomated safety check: PassMIT
Srtd CLIt1mmen/srtd105—~360Automated safety check: PassMIT
Databasegridaco/grida2.7k—~3.2kAutomated safety check: PassApache-2.0
Test The Docssupabase/supabase111k—~1.3kAutomated safety check: PassApache-2.0

Similar skills

  • Safe SQL Execution

    supabase/supabase

    Official

    A skill your agent uses whenever code will build, return, fetch, or execute SQL that runs against a user's real Postgres database — even when the request reads like an ordinary feature or bug fix…

    111k GitHub stars~4.2k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Replica Architect

    Jakeschincariol/replica-skill

    Plans the stack, database schema and API for an app clone, from the recon map replica-recon wrote.

    1.4k GitHub stars~1.1k tokensUpdated 7 days ago
    DatabasesAuto-check passed
  • Srtd CLI

    t1mmen/srtd

    This skill should be used when the user mentions "srtd", "sql templates", "migrations-templates", "live reload sql", "supabase functions", when working with files in supabase/migrations-templates/…

    105 GitHub stars~360 tokensUpdated 1 mo ago
    DatabasesAuto-check passed
  • Database

    gridaco/grida

    Use BEFORE editing any file in supabase/migrations/ or supabase/schemas/, OR when the user runs a /database subcommand (compact local migration, rls scenarios, align).

    2.7k GitHub stars~3.2k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Test The Docs

    supabase/supabase

    Official

    Execute runnable docs snippets and examples inside a disposable Docker Compose sandbox (runner container + local Supabase stack via supabase start).

    111k GitHub stars~1.3k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Expert Database

    ReJeCtAll/ExpertTeam-Codex

    数据库优化专家入口。用于 Codex CLI 的 $expert-database 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex.

    113 GitHub stars~692 tokensUpdated 3 mo ago
    DatabasesAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Supabase Data Handling

What does Supabase Data Handling do?

Implement GDPR/CCPA compliance with Supabase: RLS for data isolation, user deletion via auth.admin.deleteUser(), data export via SQL, PII column management, backup/restore workflows, and retention…. Supabase Data Handling is an agent skill from jeremylongshore/tons-of-skills-marketplace.deleteUser(), data export via SQL, PII column management, backup/restore workflows, and retention policies.

When should I use Supabase Data Handling?

Supabase Data Handling fits situations like: handling sensitive data; implementing right-to-deletion; configuring data retention; auditing PII in Supabase database columns.

How do I install Supabase Data Handling in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-data-handling -a claude-code`. Or copy the skill folder (skills/.curated/supabase-data-handling in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/supabase-data-handling in your project. Claude Code loads it when a task matches its description.

How do I install Supabase Data Handling in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-data-handling -a codex`. Or copy the skill folder (skills/.curated/supabase-data-handling in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/supabase-data-handling in your project. Codex loads it when a task matches its description.

Can I use Supabase Data Handling in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-data-handling -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supabase-data-handling, .gemini/skills/supabase-data-handling, .github/skills/supabase-data-handling and .opencode/skills/supabase-data-handling in your project.

What does Supabase Data Handling need to run?

Going by SKILL.md and its folder, Supabase Data Handling needs credentials named SUPABASE_SERVICE_ROLE_KEY. Our summary lists: Node.js; A credential in SUPABASE_SERVICE_ROLE_KEY. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(npx supabase:*), Bash(supabase:*), Bash(psql:*), Grep, Glob. Compatibility (from SKILL.md): Designed for Claude Code.

Does Supabase Data Handling access the network?

SKILL.md names 2 domains. As links in the text: supabase.com and oag.ca.gov. This is read from the text; nothing was executed.

Is Supabase Data Handling safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Supabase Data Handling use?

Supabase Data Handling is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Supabase Data Handling use?

About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.9k tokens, read only when the agent opens those files.

What are the alternatives to Supabase Data Handling?

Skills that share tags, products or a category with Supabase Data Handling: Safe SQL Execution (supabase/supabase, 111k stars), Replica Architect (Jakeschincariol/replica-skill, 1.4k stars), Srtd CLI (t1mmen/srtd, 105 stars) and Database (gridaco/grida, 2.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Supabase Data Handling?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.