Not every uploaded file should be publicly accessible. Supabase Storage allows you to design different access models depending on the application's requirements.
Public Files
Public storage is useful for files that anyone can view.
Examples might include:
Public blog images Product photos Marketing assets Public avatars
Private Files
Private storage is better for files that contain user-specific or sensitive information. Examples include: Private documents Invoices Internal reports User uploads Choose the Bucket Type
When creating your storage structure, decide whether the bucket should be public or private. Don't make private files public simply because it's easier.
Use Policies
For private files, create policies that determine who can access the files. For example, a user might only be allowed to access files belonging to their own account.
Test Access
Testing is important. Try opening a file while logged out and then while logged in as different users. The result should match your intended access policy.