The original commenter is correct -- this is intended to run fully-client-side.
We provide a set of security rules and authentication that allow you to control access. Authentication tokens should always be generated on a trusted servers, either ours (in the case of Firebase Simple Login), or yours if you want to generate custom tokens, or a third party service like Singly.
Our billing structure is very similar to a CDN, where you are being charged for actual usage on a multi-tenant architecture.