Security & Breach Notification
Reporting a vulnerability, and what we do if there is a breach.
The operator has not yet published: legal entity name, registered address, governing law / jurisdiction, legal contact address, privacy contact address. Each missing item is marked in the text below. Until they are published this service should not be taking money from the public.
Reporting a vulnerability
[not yet published: security contact address]. Tell us what you found and how to reproduce it. We will acknowledge within 5 working days and keep you informed until it is fixed.
We will not pursue legal action against anyone who reports a vulnerability in good faith, who does not access, modify or delete other people's data, who does not degrade the service, and who gives us a reasonable chance to fix it before publishing. Testing that involves other users' accounts, denial of service, or physical or social-engineering attacks on people is outside that protection.
What we do to protect data
- Passwords are stored hashed, never in a form we could read.
- Ordinary chats are not end-to-end encrypted: we can read message text, and Privacy says so in full. A private chat is, and the server refuses to store anything readable in one. Messages sent before 26 July 2026 also remain ciphertext we cannot open, and calls are encrypted between the people on them — except large meetings, where the audio and video are encrypted to LiveKit's servers, which forward them to everyone in it.
- Transport is HTTPS; the app refuses to use the camera or microphone on an insecure page rather than falling back.
- Two-factor authentication is available and recommended.
- Access to production data is limited to those who need it, and is logged.
- Rate limits and input caps on the paths that would otherwise be worth attacking.
If there is a breach
Our commitment, and the timetable the law holds us to:
- Contain. Cut off the access, rotate what needs rotating, preserve the evidence.
- Assess. What data, whose, and what could follow from it.
- Notify the regulator within 72 hours of becoming aware, where the breach is likely to risk people's rights and freedoms (GDPR Art. 33), and as US state breach laws require.
- Notify you without undue delay where the risk to you is high (Art. 34): what happened, what data, what we are doing, and what you should do.
- Publish a post-incident account once the immediate risk has passed.
We will not delay telling you in order to have a better story to tell.
What has changed
24 September 2026 · version 4
- Calls: a large meeting is encrypted to LiveKit's servers, not end to end.
20 September 2026 · version 3
- Private chats added: the server refuses to store readable text in one.
20 September 2026 · version 2
- CORRECTION. This document said direct messages were end-to-end encrypted. They have not been since 26 July 2026: we can read message text sent on or after that date. Messages sent before it remain ciphertext we cannot open, and calls are still encrypted between the people on them.
12 July 2026 · version 1
- First published.