Database
Supabase
Postgres here stores content and a copy of RevenueCat's entitlement verdict, never a subscription model of your own design. Because Better Auth replaces the bundled auth, that copy is read by your API rather than by row level security policies, so premium queries are filtered in server code against the cached entitlement. Keep the RevenueCat app user ID on the Better Auth user row and treat every write to the cache as webhook-only.