match /path/to/{file} { // Deny reads allow read: if false; // Or, allow reads by authenticated users allow read: if request.auth != null; }