EngineeringCodeCross Team
Harden a Bubble MVP before paid traffic (2026)
A 2026 wrap-in-place playbook for founders still on Bubble hosting: rank the blast (privacy rules vs hidden UI, API Connector secrets, exposed Workflow API, version-test vs custom domain, Workload Units, Deploy off switch), prove the doors before ads, then decide stay-harden vs leave.
Engineering
16 min
- Privacy
- Fail closed
- Secrets
- Private
- Ads
- After
Not a hidden page
Not option sets
Proof first
Citation-ready definition: Bubble apps can look launch-ready and still leak under ads. Privacy rules are the server gate — a hidden page is not. API Connector keys belong in collection Authentication or Private parameters, not option sets. Deploy from the editor is instant; Live and Development keep separate databases. A version-test or leftover bubbleapps.io URL is not the ad target. Workload Units burn on searches and recursive workflows. The off switch is a prior Live savepoint — not another editor pass.
This note is from CodeCross (Austin registration, Pakistan engineering on a US Central overlap). Cousin tools sit on vibe coding. Buying help is the Austin app development company page. If nobody can name a prior Live savepoint tonight, use book a conversation.
Money leaves when the campaign still lists a `version-test` URL, a leftover `bubbleapps.io` host, or an API key that lived in an option set. A stranger can find a row because the Everyone else rule still allows search. A Stripe or OpenAI key sat in a page state. Deploy is green, and the only undo is “we will edit the workflow again.” A calm run-mode is not a stranger test on the name you would put on a billboard.
This essay is the pre-ads wrap while the app still lives on Bubble hosting. It expands Harden a Bubble MVP before strangers hit the live app. It is not the first useful ship on Bubble to production, not the host exit on get off Bubble, not the extract on migrate from Bubble, not the overlap week on transition from Bubble. Framer, Softgen, Lovable, Replit, v0, and Bolt have cousin wraps — harden a Framer MVP before paid traffic, harden a Softgen MVP before paid traffic, harden a Lovable MVP before paid traffic, harden a Replit MVP before paid traffic, harden a v0 MVP before paid traffic, Bolt MVP hardening without a rewrite — and those pages are not this editor-hosting week. The question here is narrower: can you buy a click while Bubble Deploy is still the process? Soft CTA: when privacy rules, API Connector secrets, or the Deploy off switch is still red, book.
The punchy lists live on the landers. Bubble MVP hardening is the clipboard for this week. Bubble to production is hosting-is-not-a-ship-path. Get off Bubble is the host exit. Migrate from Bubble is extract. Transition from Bubble is the overlap week. The vibe coding hub maps cousins. This essay is the pre-ads proof on a live Bubble app.
Stay on Bubble hosting. Close the doors first.
The editor is paid to make workflows fire tonight. Paid traffic is paid to send strangers at the Live URL. Those jobs collide. A green Deploy badge can still leave an Everyone-can-find rule, a key in an option set, or a version-test host as the public origin.
Bubble’s own docs draw the line. Deploying your app is plain: Deploy copies Development to Live. It is instant once the Issue Checker is at zero. You can add a description. That text is saved with the savepoint so you can revert if the release is bad. Users who already have the tab open see a refresh banner. Users who do not have the app open get the new version next visit. That is closer to production than run-mode. It is still a lab until ads, mail, and Auth print the name you mean to keep.
Version control adds the quiet part. Development and Live exist in parallel. They have separate databases. Live is read-only. You push changes by Deploying. After a custom domain is connected you still have a Development URL with `version-test` on it. You do not need a new host this week. You do need to name who can Deploy, who holds admin, and which URL ads will hit.
Rank the blast. Ads make a small leak big.
Start with the blast, not a prettier repeating group. A stranger who dumps a data type, burns Workload Units on a recursive workflow, or posts into an exposed API workflow will cost more than a restyle. Rank those doors. Close the worst one tonight.
Blast rank — close the Bubble top layer first
Off switch and restore
A prior Live savepoint you can Deploy — not “we will edit the workflow.” Development History is not a Live rollback.
Workload Units
No WU alert. Overages disabled with no named owner. A search or recursive job that will eat the month on the first campaign.
version-test vs custom domain
Ads, mail, sitemap, and Auth redirects that still print bubbleapps.io, /version-test, or a leftover branch id.
Workflows and Workflow API
Expose as a public API workflow with None required. Ignore privacy rules checked. Recursive loops without a cap.
API Connector and plugin secrets
Keys in option sets, page states, or workflow inputs. Parameters not marked Private. Collection auth empty.
Privacy rules
Everyone else still can find or view. Hidden pages. Search privacy left Off. Data API on without Create/Modify/Delete locked.
Put six names on paper: who owns privacy rules, who proves API Connector on the advertised host, who can Deploy to Live, who watches WU, who owns the public origin, and who can restore a Live savepoint tonight. Two red names plus a campaign date means spend stays off. Soft CTA: if you cannot name a human for each layer, book.
Privacy rules: a hidden page is not a gate
Rows are the first thing ads will leak. Protecting data with privacy rules is the drawer. You open Data → Privacy. You set rules on each data type. A rule names who it applies to and what they can do. When more than one rule matches, any one grant wins. The automatically generated Everyone else rule is the floor. If that floor still allows Find this in searches or View all fields, a stranger with a private window can read the type.
Privacy is blunt about rank: privacy rules are the primary security measure. Hiding a group or sending a user to a different page does not stop a search. Security says the same in one line: database leaks are handled by privacy rules on every private type. A “Current user is logged in” condition on a button is a costume. The server still answers Do a search for.
Search privacy mode sits in Settings → General. Off lets any field be used as a constraint, even when the field is hidden from view. Automatic allows constraints already defined on your pages; constraints that are not — including Data API searches — need an explicit grant. Strict requires that grant on every constraint. Bubble’s own recommendation for private data is Strict. Turn it on before ads, then walk the Uses constraint field operator so the journeys you mean to keep still search.
Two more General checkboxes matter this week. Make new data types private by default so a type you add on Thursday does not ship public on Friday. Limit access to this app with a username and password is a kill switch for the Live URL — and it is not the same thing as a User in your database. Application rights (Private / Everyone can view / Everyone can edit) only covers the editor. Making the app Private does not hide Live from the web. Publishing your app says set the editor to Private before you go live, then remove leftover collaborators.
Run these four checks on the advertised Live host. Run-mode with your editor login does not count:
- Every type that holds personal data or money has an Everyone else rule with search and view off. A hidden repeating group is not that proof.
- Search privacy is Strict on the Live branch — or you can name every Off/Automatic exception.
- A stranger account cannot find another user’s row by changing an id in the URL or the debugger.
- Data API Create / Modify / Delete via API stay unchecked unless a named client needs them. Data API privacy rules warn that a Bubble API token skips privacy rules entirely.
API Connector: if it is not Private, it leaked
Keys are the second thing ads will leak. API Connector authentication is the vault Bubble actually ships. Collection Authentication stores tokens once, encrypted, on Bubble’s server. Calls route through that server by default. The browser sees the payload it needs to render — not the credential that fetched it. Private parameters stay on the server and are added to the request there.
The API Connector is the warning to keep: a description of the call still goes to the browser. Any secret that is not marked Private can be read by a savvy user. Do not store tokens in option sets, on-page elements, or workflow inputs. Those live in client source. API Connector security repeats the same split. Initializing a call with a default parameter writes that default into the app. If a key was ever a default, rotate it at the issuer.
Treat every plugin panel the same way. If a contractor with View and edit could copy the value, assume it leaked. If the value ever sat in an option set “so the page can read it,” assume it leaked. Rotate. Then search the published page source and the option-set list for the old value. Soft CTA: if the only place the key still lives is a panel you are afraid to open, book.
Workflows: public endpoints and Ignore privacy rules
A backend workflow that “just emails the lead” is a write API the moment you expose it. API workflows run on the server. They keep running after the page closes. They can schedule themselves. They can override privacy rules. That is the power. It is also the blast.
Workflow API privacy rules draw the split. Privacy rules filter which rows a workflow can find. They do not stop the workflow from running. Checking Ignore privacy rules when running the workflow lets the job see everything, even with no authenticated user. Workflow API security is sharper: Expose as a public API workflow plus Authentication = None required plus Ignore privacy rules is the broadest door Bubble will let you open. Do not buy ads on that door.
Backend events add the jobs ads will poke: Schedule an API workflow, a database-change trigger, a recurring event, a recursive loop. Recursive API workflows can run away. New apps since 1 July 2024 default to a 10-iteration cap. Older apps may not. Name every recursive and recurring job that touches money or mail. Cap it. Prove a stranger cannot schedule a new chain from a public endpoint.
If a page workflow writes a thing for anyone who can click, treat that click as a mutating API. Conditions in Only when are the lock — not a hidden button. If the write must see rows the user cannot see, move it to a named backend workflow, not a public endpoint with Ignore privacy rules on.
version-test and leftover Bubble names leak into public links
Bubble gives you several addresses that look live. They are not the same job.
Three live URLs — only one is the ad target
01 · version-test
Lab
Development Main. Separate database. Preview button opens this. Branch ids replace version-test.
02 · app.bubbleapps.io
Default
Live on Bubble’s host. Still exists after you add a custom domain unless you redirect it.
03 · Custom domain
Ads
The name you mean to keep. This is the only public origin.
Previewing a web app is the lab URL: `https://yourapp.bubbleapps.io/version-test`. It is Development. It is not Live. The page prints the map: without a custom domain, Live is `https://appname.bubbleapps.io` and Development is that host plus `/version-test`. With a custom domain, Live is the name you own and Development is that name plus `/version-test`. Custom branches replace `version-test` with the branch id.
Custom domain and DNS is Settings → Domain & Email. One app, one domain or subdomain. Domain / email leaves the default host in place until you check Redirect all requests to the domain. Stay-harden is fine if ads, mail, sitemap, and Auth redirects print the name you mean to keep. It is not fine if the campaign still lists `version-test`, a branch id, or a leftover `bubbleapps.io` page. Search workflows for those hosts. Check signup redirects and “view app” links in mail.
Off switch: a prior Live savepoint is not “edit the workflow”
A bad Deploy needs an off switch you can name tonight. Deploying your app says the description you type is stored with the savepoint so you can revert. Version control is that switch: History → pick a savepoint → Restore to this savepoint. Deploy creates a savepoint automatically. You can also create one by hand. Version control and deployment adds Restore to a custom date and time, inside your retention window.
Restoring a Development branch is not the same as taking Live back. To undo a bad Live release you restore (or reset) a branch to the last good savepoint and Deploy that to Live — or you Deploy a hotfix branch. Version control is also plain that a hotfix Deploy leaves Development out of sync with Live; you sync after. “We will edit the workflow again” waits on a builder and another Issue Checker pass. It is repair. It is not an off switch.
Need the Live URL dark without a redesign? Settings → General has Limit access to this app with a username and password. That password is not a User in your database. Use it as a kill switch you can flip. Name the Deploy owner. Prove you can restore a prior Live savepoint. A feature flag on a page is extra. It does not replace a version you can Deploy in minutes.
Watching: WU, workflow errors, and a silent offline
Watching without an off switch is half a lock. Before ads, name the three signals you will actually see: Workload Unit burn, workflow errors after Deploy, and sign-in failures on the advertised host. Workload is Bubble’s single meter — database work, workflows, and web requests, counted in WU. Pricing FAQ is the quiet part: Live WU is end users; Development WU is editors and tests; both count. If you disable overages and hit the limit, Bubble emails that the app is offline. You bring it back by enabling overages, buying a workload tier, or waiting for the next billing period. You also get mail at 75% and 100%.
Workload notifications are the alert you must prove. Bubble already mails on spikes (2× or 3× the last seven days, or a large share of the monthly allowance in an hour). You can add your own alert from Settings → Notifications or the Logs page — an amount of WU over an hour, day, week, or month. Admins get the mail. Tracking workload is the Logs chart and the server log. Point a human at the first 24 hours of spend. If you cannot say who would notice a WU spike at 11 p.m., spend stays off.
Wrap score — mark costume vs proof
Privacy
Costume
Hidden page
Wrap
Rules listed
Proof
Stranger cannot find rows
Secrets
Costume
Key in option set
Wrap
Moved to Connector
Proof
Private + rotated
Workflows
Costume
Public + Ignore rules
Wrap
Auth named
Proof
Stranger cannot schedule
Public name
Costume
Ads list version-test
Wrap
Custom name, old links live
Proof
Sitemap + Auth match
WU watch
Costume
No alert, overages off
Wrap
Chart opened once
Proof
Named alert + owner
Off / watch
Costume
“We will edit workflow”
Wrap
Savepoint known, no drill
Proof
Prior Live Deployed once
Score each row against the advertised Live host, not run-mode. One red cell — an Everyone-can-find rule, a key in an option set, a public Ignore-privacy-rules workflow, a `version-test` in ads, a WU alert nobody owns, or a rollback you have never hit — is enough to hold the spend. Move that cell. Do not greenwash the matrix.
The pre-ads week
Treat the next seven days as operator time on the Bubble app, not a slogan. Inventory who can Deploy, who holds admin, and which URL ads will hit. Then seal. Then prove. Leave the host-exit pages closed until that list is honest.
Harden on Bubble — seven operator steps
01 →
Inventory the public path
Who can Deploy. Who is admin. Which URL ads will hit. Which types hold personal data. Where API Connector secrets live.
02 →
Seal privacy rules
Everyone else fail closed. Strict search privacy. New types private by default. Stranger cannot find another user’s row.
03 →
Seal API Connector
Collection Authentication or Private parameters. Rotate anything that appeared in option sets or page states.
04 →
Lock workflows
No public None-required Ignore-privacy-rules jobs. Cap recursive and recurring chains. Only when on mutating page workflows.
05 →
Fix the URL map
Redirects, Auth callbacks, sitemap origin. No version-test, branch id, or leftover bubbleapps.io in ads.
06 →
Name WU watch
Custom alert on Logs or Settings → Notifications. Know whether overages are on. Who gets the 75% mail.
07
Rollback + watch, then buy
Prior Live savepoint Deployed once. Who watches WU and workflow errors. Then spend.
Day 0 is inventory. Write five facts. The public URL. The person who can Deploy. Whether Every data type that holds personal data has an Everyone else fail-closed rule. Whether API Connector still holds a live key in a non-Private field. Whether a stranger can hit an exposed API workflow. If the public origin is already taking leads and you cannot name those five, stop. You do not need a new page. You need this list.
Seal privacy first. Then secrets. Then workflows. Bots do not wait for DNS. If a Workflow API exists, prove Authentication is not None required on any job that writes money or personal data. Then strip version-test hosts. Then Deploy a prior savepoint once so you know the off switch works. Then spend. The Bubble MVP hardening clipboard is the short list. This page is the week you run it.
Illustrative operator days before a Bubble ad buy
daysUnpriced Ads on a red list
3–5 wks
Campaign live. Doors still open. Cleanup later.
Illustrative operator days — not measured traffic, not a Source: Admin analytics series. Unpriced feature sprints on a public Bubble app often cost more than the wrap when the first leak hits.
Treat those bars as calendar you reserve, not a vendor promise. If you cannot name the advertised host, who can Deploy, and who can restore a Live savepoint, the later days will thrash. The long bar is the expensive miss: a “small” test while Everyone can find or a version-test host is still the company. Ranges are studio-observed operator days — not a bid and not a Bubble SLA.
Stay-harden vs leave. Do not mix the seats.
Pick one seat for this week. Stay-harden keeps Bubble hosting as the host, with privacy rules fail closed, secrets out of option sets, workflows sealed, and a Live savepoint rollback already proved. Leave opens get-off Bubble and stops buying clicks that need that Deploy tab. Running both seats at once is how teams rebuild pages they already had.
Stay-harden vs exit — pick one seat
Stay-harden (this page)
Process still in Bubble
Hosting plus Deploy. You accept the bill and the vendor.
Doors closed on that path
Privacy, secrets, workflows, URL map, WU watch, rollback.
Ads wait for green
A red layer pauses spend, not the product.
If the public origin must leave Bubble hosting, stop this wrap and open the exit. If ads are close and the origin can stay, finish the wrap first. ↓If the public origin must leave Bubble hosting, stop this wrap and open the exit. If ads are close and the origin can stay, finish the wrap first.
Leave (other pages)
Process leaves Bubble hosting
Rebuild you run. See get-off and migrate.
A custom domain is not the exit
DNS on Bubble is still Bubble. Rows and secrets stay until you move them.
Kill the Bubble Deploy tab
App still answers when the editor is closed.
If you only need a leave date, use when to leave an AI builder. A door that will not close on this Bubble app belongs on rewrite vs harden. A personal Git remote belongs on GitHub handoff. A Deploy-only ship path belongs on CI/CD after an AI builder. Framer, Softgen, Lovable, Replit, and v0 have their own wrap essays — harden a Framer MVP before paid traffic, harden a Softgen MVP before paid traffic, harden a Lovable MVP before paid traffic, harden a Replit MVP before paid traffic, harden a v0 MVP before paid traffic. The Bolt cousin is Bolt MVP hardening without a rewrite. Those cousins are not this editor-hosting week.
Wrap loop — prove, then decide
01
Prove the door
One layer. One test on the advertised Live URL.
02
Close it
Tighten the rule, rotate, un-expose, redirect, or Deploy a prior savepoint.
03
Re-check ads list
If a layer is still red, spend stays off.
04 · loops
Stay or leave
Green wrap can stay. Red host row opens the exit.
When the list turns red
Leave the product up. Kill the campaign if any of these are still true:
- A live key still exists only in an option set, a page state, a workflow input, or an API Connector field that is not Private.
- A data type that holds personal data or money still lets Everyone else find or view rows.
- A Workflow API job is still None required, or Ignore privacy rules is on without a named owner.
- Ads, mail, or the sitemap still list `version-test`, a branch id, or a leftover `bubbleapps.io` host.
- Overages are disabled and nobody owns the 75% WU mail — or a recursive job has no cap.
- The off switch is “we will edit the workflow,” or you have never restored a Live savepoint.
- Two people disagree about who can Deploy or who holds admin.
A single red door is a miss, even if Deploy is green. Stop adding pages until privacy rules, API Connector, workflows, and the savepoint rollback are honest. Finish that wrap. Then spend — or open get-off Bubble if editor hosting is still the company.
Bring a second pair of hands when the founder cannot rotate a key without pasting it back into an option set, when a stranger can still find another user’s row and the campaign is close, or when nobody has restored a Live savepoint before the date. Hire for privacy rules, Connector secrets, workflow seats, and the URL map — not for a prettier repeating group. Austin app development company is the studio brief. Austin mobile app development if the next door is a store binary that still points at this Bubble URL.
Next steps
Walk the gates in order. Inventory the public URL, the person who can Deploy, and who holds admin. Fail-close privacy rules on every type that holds personal data. Set search privacy to Strict. Drain option-set and page-state secrets into API Connector Authentication or Private parameters. Un-expose Workflow API jobs that strangers can hit. Cap recursive chains. Strip `version-test`, branch ids, and leftover `bubbleapps.io` hosts from ads, mail, sitemap, and Auth redirects. Name a WU alert. Restore a prior Live savepoint once. Then buy the click — or open the exit if the process itself must leave Bubble hosting. Pause any editor pass that only ships from Deploy while a gate is red.
CodeCross LLC is an Austin-registered product studio (1606 Headway Cir STE 9212, Austin, TX). The Bubble week we run is privacy rules, API Connector secrets, Workflow API locks, version-test cleanup, then a Live savepoint rollback. The Austin app development company page is the studio brief. Austin mobile app development is the store-binary engagement if the next door is a signed build that still points at this Bubble URL. Company-level evidence lives on proof. When the off switch, privacy gates, or the advertised host is still red and the campaign is close, book a conversation.
Bubble hosting is allowed to stay the host. Ads are not allowed to treat a run-mode pass, a custom domain, or a Deploy badge as that proof. Show a prior savepoint you can Deploy, privacy rules that fail closed for strangers, and keys that never lived in an option set. Most teams never need a second codebase once those three exist.
FAQ
When Deploy succeeds, did Development and Live receive the same data?
No. Version control says Development and Live have separate databases. Deploy copies the app — pages, workflows, privacy rules — not the Live rows. A run-mode pass that only wrote Development data is a lab. Prove the money path on the advertised Live host with stranger-like accounts. Previewing a web app is sharper: Preview always opens `version-test`, which is Development.
Does connecting a custom domain finish the wrap?
No. Custom domain and DNS still sits on Bubble hosting. Domain / email leaves `appname.bubbleapps.io` reachable until you check Redirect all requests to the domain. Development is still `/version-test` on the custom name. Stay-harden is fine if ads, mail, sitemap, and Auth redirects print the name you mean to keep. It is not fine if the campaign still lists a lab host. Leaving Bubble hosting is the get-off job, not this page.
If run-mode can find a row, does that search exist on Live for a stranger?
Not as proof. Protecting data with privacy rules applies to the current user. Your editor login is not a stranger. Privacy rules that look closed in run-mode can still grant Everyone else Find this in searches. Privacy is the primary lock. Prove a private-window account on the advertised Live URL cannot find another user’s row.
Can I paste keys into option sets and buy ads?
No. The API Connector and authentication say tokens belong in collection Authentication or Private parameters — not option sets, page elements, or workflow inputs. Those are client source. Rotate anything that appeared there. If a View-only collaborator can open the Connector, sharing is still red. Do not buy ads on a red drawer.
Can strangers write rows if I hid the admin page?
Hiding a link is not a lock. Privacy rules govern Find, View, and auto-binding. A page workflow with no Only when condition is a write API. A Workflow API job set to None required plus Ignore privacy rules is a write API with the lights off. Workflow API security is the seat list. Collaboration is the editor seat list — View and edit plus database View and edit is a write path. A shared admin login is a miss.
Is “we will edit the workflow” an off switch?
No. Version control restores a savepoint, then you Deploy that to Live. Deploying your app stores the description with the savepoint for that revert. Editing a workflow and hoping the Issue Checker stays at zero waits on a builder. The password gate in General can take the URL dark. Name the Deploy owner. Hit the savepoint rollback once before ads.
Why are Workload Units a paid-traffic risk?
Workload meters every search, workflow, and request. Ads multiply those. Pricing FAQ says disabling overages takes the app offline at the limit. Workload notifications are the mail you must own. A recursive workflow without a cap is how a “small test” spends the month. Name the alert. Name who gets it. Do not buy ads on a silent meter.
Thirty minutes with a senior teammate — honest next steps.
Ready to price an Austin build?
Bring the problem, the users, and a budget ceiling. We’ll tell you whether an app is the right next spend — and what the first year actually costs.
Prefer writing? Send project details on the contact page.