I see Scott started this thread earlier, but no response. My limited observation from the US is few companies are willing to guarantee absolute GDPR compliance as it is interpreted by lawyers, but if it matters the users data is stored encrypted when not in use:
https://github.com/supabase/supabase/discussions/3656
Supabase does not use the database data for other purposes per their terms.
Nothing in the software/service prevents you from deleting customer data on demand.
FWI...