# Is it safe to use Firebase api keys while I'm evaluating Free account?

**URL:** <https://community.thunkable.com/t/is-it-safe-to-use-firebase-api-keys-while-im-evaluating-free-account/297690>\
**Category:** Questions about Thunkable X\
**Created:** [October 31, 2019, 5:29pm UTC](https://community.thunkable.com/t/is-it-safe-to-use-firebase-api-keys-while-im-evaluating-free-account/297690 "2019-10-31T17:29:44Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![MartinP](https://avatars.discourse-cdn.com/v4/letter/m/ea666f/32.png) [@MartinP](https://community.thunkable.com/u/MartinP)\
**Post date:** [October 31, 2019, 5:29pm UTC](https://community.thunkable.com/t/is-it-safe-to-use-firebase-api-keys-while-im-evaluating-free-account/297690/1 "2019-10-31T17:29:44Z")

</div>

Hello,

Is it safe to use Firebase api keys while I’m evaluating Free account?  
I mean do people see credentials as project is Public?

---

<div class="post-metadata">

**Author:** ![actech](https://avatars.discourse-cdn.com/v4/letter/a/3d9bf3/32.png) [@actech](https://community.thunkable.com/u/actech)\
**Post date:** [October 31, 2019, 7:17pm UTC](https://community.thunkable.com/t/is-it-safe-to-use-firebase-api-keys-while-im-evaluating-free-account/297690/2 "2019-10-31T19:17:55Z")

</div>

hello,

It’s not safe, but nothing prevents you from making a temporary account.

When copying project, to Firebase and Airtable access field is clear. Therefore, public projects, users can not gain access to your accounts. Try my app - [https://x.thunkable.com/projects/5d70f93f8a62b4079eedaff2/project/properties/designer/](https://x.thunkable.com/projects/5d70f93f8a62b4079eedaff2/project/properties/designer/) and try to log in to my account on Firebase and AirTable.

If your data contains a state secret, it is best not to use them on your computer and any other electronic device that is connected to the Internet.

---

<div class="post-metadata">

**Author:** ![MartinP](https://avatars.discourse-cdn.com/v4/letter/m/ea666f/32.png) [@MartinP](https://community.thunkable.com/u/MartinP)\
**Post date:** [October 31, 2019, 7:21pm UTC](https://community.thunkable.com/t/is-it-safe-to-use-firebase-api-keys-while-im-evaluating-free-account/297690/3 "2019-10-31T19:21:16Z")

</div>

@actech

Not a good idea to reveal API keys even for a temp account. You can’t login, but you can post data to a database when API key is present.

---

<div class="post-metadata">

**Author:** ![actech](https://avatars.discourse-cdn.com/v4/letter/a/3d9bf3/32.png) [@actech](https://community.thunkable.com/u/actech)\
**Post date:** [October 31, 2019, 7:31pm UTC](https://community.thunkable.com/t/is-it-safe-to-use-firebase-api-keys-while-im-evaluating-free-account/297690/4 "2019-10-31T19:31:07Z")

</div>

What do you think, Apple and Microsoft will have a good data protection? These companies spend millions of dollars on defense, but why, then, there are pirate copies?

Do you think that private-account guarantees you 100% data protection? Tell me, what prevents Windows developers, Firebase, Thunkable X, developers of mobile devices to view your information on the sly? Call me at 100% reliable system for storing information. Bank? And the banks, you know sometimes rob.

I use Thunkable X more than 2 years and not once give users the keys to my account. Problems still was not. Why? Because I do not keep them secret information, and my data are not wanted, and for 10$.

---

<div class="post-metadata">

**Author:** ![MartinP](https://avatars.discourse-cdn.com/v4/letter/m/ea666f/32.png) [@MartinP](https://community.thunkable.com/u/MartinP)\
**Post date:** [November 1, 2019, 5:41am UTC](https://community.thunkable.com/t/is-it-safe-to-use-firebase-api-keys-while-im-evaluating-free-account/297690/5 "2019-11-01T05:41:39Z")

</div>

> [@actech](#):
>
> What do you think, Apple and Microsoft will have a good data protection?

Have you heard about GDPR? I think that I don’t want my test users emails to be exposed due the fact that Firebase keys are open to the public. Doing this is 100% violation of GDPR.

---

<div class="post-metadata">

**Author:** ![actech](https://avatars.discourse-cdn.com/v4/letter/a/3d9bf3/32.png) [@actech](https://community.thunkable.com/u/actech)\
**Post date:** [November 1, 2019, 7:53am UTC](https://community.thunkable.com/t/is-it-safe-to-use-firebase-api-keys-while-im-evaluating-free-account/297690/6 "2019-11-01T07:53:21Z")

</div>

As for GDRP that is an interesting site [https://breachlevelindex.com/](https://breachlevelindex.com/)

I gave you a link to my public project. Look at it carefully and write to me, you can go to my Account in Firebase or AirTable? If you can, then I ask you to put on this forum data that you could without my permission to add into my database.

It is enough for the answer to your question?

[https://x.thunkable.com/projects/5d70f93f8a62b4079eedaff2/project/properties/designer/](https://x.thunkable.com/projects/5d70f93f8a62b4079eedaff2/project/properties/designer/)

---

<div class="post-metadata">

**Author:** ![actech](https://avatars.discourse-cdn.com/v4/letter/a/3d9bf3/32.png) [@actech](https://community.thunkable.com/u/actech)\
**Post date:** [November 1, 2019, 8:05am UTC](https://community.thunkable.com/t/is-it-safe-to-use-firebase-api-keys-while-im-evaluating-free-account/297690/7 "2019-11-01T08:05:06Z")

</div>

I also recommend that you consider the information from the developers at this links

 ![%D0%B8%D0%B7%D0%BE%D0%B1%D1%80%D0%B0%D0%B6%D0%B5%D0%BD%D0%B8%D0%B5](https://us1.discourse-cdn.com/flex015/uploads/thunkable/original/3X/9/2/923f058ee4e5af757e84c07b09b896f465419170.png)

---

<div class="post-metadata">

**Author:** ![actech](https://avatars.discourse-cdn.com/v4/letter/a/3d9bf3/32.png) [@actech](https://community.thunkable.com/u/actech)\
**Post date:** [November 1, 2019, 8:38am UTC](https://community.thunkable.com/t/is-it-safe-to-use-firebase-api-keys-while-im-evaluating-free-account/297690/8 "2019-11-01T08:38:20Z")

</div>

In official documents also have the necessary information:

[https://docs.thunkable.com/app-data-privacy](https://docs.thunkable.com/app-data-privacy)

---

<div class="post-metadata">

**Author:** ![ioannis](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/ioannis/32/146956_2.png) [@ioannis](https://community.thunkable.com/u/ioannis)\
**Post date:** [November 8, 2024, 12:08pm UTC](https://community.thunkable.com/t/is-it-safe-to-use-firebase-api-keys-while-im-evaluating-free-account/297690/9 "2024-11-08T12:08:28Z")

</div>


