Your data may not be protected
Problem: profiles can be read more broadly than expected.
Explanation: row-level security is off, so your API may expose data paths you did not mean to leave open.
Fix: review the security change first, then turn protection on with a preview of the SQL.