It's a compelling option, but there are already a lot of sharp edges.
For example, PostgREST doesn't really highlight this, but for any non-trivial and sane application you have to create a separate schema ("api" or similar) to carefully pick what's exposed. PostgREST has a scary "allow by default" permission model which is nearly enough to turn me off of the whole project.
To help mitigate this, I'm evaluating only using PostgREST for reads in the "api" schema via access-restricted views, and having all writes go through supabase edge functions. This should simplify the RLS permissions (hopefully).
RLS has some pitfalls too, and it's the only mechanism you have to secure your data.
Serving assets from Postgres seems like a bad idea aside from some simple edge use cases. In general, you want to treat your DB as a precious resource and minimize the amount of work it has to do.
Nginx and similar are built and optimized for serving assets. Using your database to do this doesn't seem like a great idea if your application needs to scale.