The web apiKey in app.js is public client config (normal for Firebase web apps). Real protection is server-side rules.
Before production:
- In Firebase Console → Firestore → Rules, lock reads/writes to
request.auth.uid == userId(and only the fields you need). - Restrict Google sign-in to your OAuth client and authorized domains.
- Turn off any open collection writes; prefer custom claims / App Check if you scale.
Puff’s sw.js does not cache Firestore or identity traffic.
Open a GitHub issue for security concerns, or contact the maintainer via datafying.
- API keys and stats stay on-device unless the user enables cloud sync (GDPR consent).
- Microphone is requested only for the blow gesture and is not uploaded by this app.