Yeah the emails are a concern - I’m planning to encrypt the emails themselves using KMS, so Bubble would only ever handle encrypted values or non-sensitive data. All the encryption and decryption would happen on the backend (Xano).
I hope that might solve the PII issue… I will consult a lawyer to be sure about it
thanks again for the inputs!
I would appreciate any other tip you might have on the matter 