v1.11.0 is live. It changes nothing about how your Bunny reads or answers. It is about three quieter things: who can open your data, whether a deleted file is really gone, and a dashboard that stops leaving you behind a spinner.

These are the fixes that matter since the last deployment, in the middle of September. The small ones are left out.
Private means private
A private record now opens for two kinds of people only: the person who uploaded it, and the people it was shared with. Being an admin of the project is no longer enough, and a public record no longer opens the private records attached to it. The project owner still sees that a private record exists, with its contents withheld.
Files got the same treatment:
- Reading a file's text, or a spreadsheet's rows, requires being signed in.
- Stored files are served through signed links only. The plain storage address refuses them.
- An upload link is good for one upload. It is pinned to the size you declared, it expires within an hour, and the record it belongs to is checked again on every request. A file that arrives at a different size is deleted.
- A file follows its record. It goes private when the record does, and it is removed when the record is.
A deleted file is deleted all the way
Deleting a large indexed spreadsheet used to leave rows behind. Every row of a sheet is its own record, and the clean-up removed them 200 at a time, handing each page on to a fresh run. After about fifteen hand-offs the chain was mistaken for a runaway loop and cut off, so the rows past roughly the first 3,000 stayed in your project, taking up database room, where your Bunny could still find them.
The clean-up now works through its pages in a single run and only hands off when it is about to run out of time, and a hand-off is no longer mistaken for a loop. The same repair went into the seven other background jobs that page through their work the same way.
Two smaller leaks closed with it:
- A retried step no longer queues its successor twice, which used to make the rest of a clean-up run twice.
- A deleted record leaves its subscribers' feeds together with the record, instead of lingering there.
Big records moved out of the database
A record whose data is larger than 32 KB is now kept in file storage instead of the database, where the same bytes cost a fraction as much. Records you already had were moved during this deployment, so your database usage may have dropped without you doing anything. Nothing changes in how you or your Bunny read them.
Saving a large record also gets 28 seconds instead of 15 before it gives up.
Signing in and managing projects
- Google sign-in can no longer trap you behind a loader. If the sign-in was declined, or could not be matched to your account, you were left on a full-screen loader with nothing to click. Every path now ends on the form, with a message.
- A project that fails to create says so. The dialog used to hang on its spinner, or stay open on top of the project it had just created.
- Deleting a project takes more than a click. One checkbox and a button used to be all that stood between you and an empty project. You now type
delete my projectto confirm. - Billing is in the profile menu, and a billing page that fails to open tells you, instead of covering the screen with a loader.
- The widget version check gives up after 8 seconds instead of sitting on "Checking..." forever, and it no longer reports an old cached template as the current one.
Over your plan, and able to fix it
The new plan limits suspend a project that holds more than its plan allows. The way back is to delete something, and the dashboard was standing in the way.
- The files page opens on a suspended project without asking for an AI platform or a key, so you can list, download and delete. Uploads stay locked until you are back under the limit.
- The Plan card names the limits you are over, and where to delete to get under them.
- Downloads from a suspended project work. They could answer "not found", because a finished link was being rewritten.
- The project list tells the truth. No more "Deletes undefined", and a cancelled plan keeps showing which plan it is.
Small things you will still notice
- The theme follows your device until you pick one yourself, and the hint text in dark mode is easier to read.
- Refreshing a table no longer covers it with a loader. A small indicator inside the table does the job.
- Searching users lets you choose the condition for every field, and a range is sent as a range.
- Projects in Paris and São Paulo can sign in to the MCP server.
- Articles have an RSS feed at bunnyquery.com/feed.xml.
More news coming up!
Subscribe to the newsletter from your account profile page so you do not miss anything, and past articles are always at bunnyquery.com/articles.
That is it for this round. Enjoy your Bunny!
Baksa, Creator of BunnyQuery