congratulations on the launch!
are there any checks done on the backend to guarantee that the website using the "init(appId)" call is the right one?
The attack vector here is a fake website - say "userbose dot com" - where the login would be validated by the backend and can now access all data for that user.