Privacy notice · the playbakk app
What the app does with your data.
This notice is for the playbakk app at chat.playbakk.com: messages, calls, groups, AI assistants, solo clips, profiles, live and paid groups. Pay is not available in the pilot; section 4.12 applies when Pay is switched on. The playbakk website has its own notice at playbakk.com/privacy.
1. The short version
- Your chats and calls with people are end-to-end encrypted. playbakk's servers deliver them but cannot read them.
- Our servers still see some things they need to work: who is allowed to contact whom, when, your IP address, and the size of what you send. Section 5 lists them.
- Some features are not end-to-end encrypted: profiles, channels and posts (including paid group posts), public live streams, live chat, things you choose to put in a safety report, and the text an AI assistant asks to send for you. We say so in the app, and below.
- Recordings, call notes, translations and wellbeing data stay on your device.
- We do not sell your data. We do not use advertising or analytics trackers.
- You can delete your account in the app at any time. A few records are kept after that; section 9 says which and why.
2. Who we are
The controller of your personal data is:
UIE Ltd, trading as playbakk
Company number: 17334450 (registered in England and Wales)
Registered office: 66 Paul Street, London, England, EC2A 4NA
ICO registration: ZC210540
Privacy contact: privacy@playbakk.com
Data protection contact: contact@uieglobal.com (we have not appointed a statutory data protection officer; see below)
EU representative: not appointed, because the pilot is open only to people living in the UK. We will appoint one before people in the EU can join.
We do not receive what stays on your device (your Pay records, wellbeing data, recordings, call notes and translations). For that data you are in control, using the app's own controls (section 10). We are responsible for designing the app so it protects that data, and we are the controller for everything our servers receive.
3. Who this app is for
playbakk is for adults (18+). The pilot is only for invited adults living in the UK. During the pilot the app will not let anyone under 18 create an account, and an age we do not know is treated as under 18. Accounts for 14 to 17-year-olds come later, and we will update this notice before they do.
When you join, we ask for the year and month you were born, and your country. The app uses them once to work out your age band. Only that band is kept. Your date of birth is never stored or sent to us. We do not use other age checks during the pilot.
4. What we use, where it comes from, why, and our legal basis
"Legal basis" is the reason the law allows us to use your data. Under UK GDPR (and the EU GDPR for people in the EU) the main ones we use are:
- Contract: we need it to give you the service you asked for.
- Legitimate interests: we need it to keep the service safe and working, and this does not override your rights.
- Consent: you choose to switch something on, and you can switch it off at any time.
- Explicit consent: the stronger kind needed for health data.
- Legal obligation: the law requires it.
4.1 Your account and keys
| What | Where it comes from | Why | Legal basis |
|---|---|---|---|
| Your username, display name and account settings (including the age band) | You | To create your account and let people you choose reach you | Contract |
| Public keys for your identity and each device, device names and platforms, when a device was last online | Your devices | To encrypt messages to the right devices and let you manage them | Contract |
| A public, append-only key log (key ids, public keys, device-set versions, backup-commit hashes) | Our servers | So you and your contacts can check that nobody swapped your keys | Legitimate interests (security of everyone's messages) |
| Passkey records: credential public keys, counters, labels and encrypted vaults | Your device | Sign in on a new device, confirm sensitive actions, recover your identity | Contract |
| Encrypted backup (if you make one) and its size, version and dates | Your device | To restore your chats on a new device | Contract |
Your private keys are made on your device. The app cannot export them, with one exception: when you create your account and add a passkey, a copy sealed to that passkey is kept on our servers so you can sign in elsewhere. We cannot open it. We never receive a passkey's biometric data, your backup passphrase or your recovery code.
4.2 Finding people (optional)
| What | Where it comes from | Why | Legal basis |
|---|---|---|---|
| If you turn on Let people find you: a phone number or email address you add, checked with a 6-digit code | You | So people who already have your number or address can find your username | Consent (you switch it on and can switch it off) |
| If you use Find people you know: the contacts you pick, turned into scrambled values on your device | Your device | To tell you which of them are on playbakk | Legitimate interests (finding people you already know), including for people who are not on playbakk, whose numbers we only ever see scrambled and never store |
- We do not store your phone number or email address for this. We store a scrambled value that cannot be checked against a guessed number without our secret key, plus your username sealed so only someone who already has your number can open it.
- When you check your contacts, they are scrambled on your device first. Your address book is never uploaded. Names from your address book never leave your device.
- To send the code to an email address, it passes through our email provider, Resend. Codes by SMS are not available in the pilot.
- Anyone who receives a code they did not ask for can click "not me" in the email to stop it ever being used again.
- Honest limit: someone holding our secret key could work out which phone numbers are registered. We keep that key out of the database and backups.
4.3 Messages, calls and attachments
| What | Where it comes from | Why | Legal basis |
|---|---|---|---|
| The content of your 1:1 and group messages, voice and video calls, photos, files and voice notes | You | To deliver them | Contract. We cannot read this content. |
| Delivery information our servers see (section 5) | Our servers | To route messages, enforce who may contact you, stop spam and abuse | Contract; legitimate interests |
| Encrypted attachments, stored as scrambled data until the recipient downloads them | Your device | To deliver files too big for a message | Contract |
| Access: who you have allowed, for what and for how long; requests people send you, including the name and note they typed | You and the people who send requests | So only people you allow can reach you | Contract |
| Spam scores and reasons for requests sent to you | Our servers | To put likely spam in a separate Filtered folder | Legitimate interests |
- Messages are encrypted on the sender's device and decrypted only on the recipient's devices.
- Photos are stripped of location data on your device before they are sent.
- A group's name is encrypted so only members can read it. Our servers still see who is in a group.
- Calls are encrypted end to end. If the app cannot confirm that, it will not connect the call.
AI assistants are different. When an AI assistant you have connected asks to send a message for you, our servers see the text it wants to send so they can check it against what you allowed. Hosted AI assistants (run by our servers for a business that has no keys of its own) are encrypted to that business, not end to end.
4.4 Notifications
If you turn notifications on, we send a "wake-up" through your phone or browser maker's push service (Apple, Google, Mozilla or Microsoft). It says only "New message", "New request", "Incoming call" or "Request allowed". It never contains who it is from or what was said. The push service learns that your device was woken and when, and whether it was a call.
- What we keep: your device's push address and keys (web) or push tokens (iPhone and Android apps).
- Legal basis: consent for showing notifications (you turn them on); contract for delivering them.
4.5 Recording calls and clips (on your device)
- A solo clip records your own camera and microphone during a 1:1 call. It starts only after the other person has agreed, and their agreement is signed by their device.
- The other person's call audio and video are not recorded. But your microphone may pick up their voice if they are on a loudspeaker.
- Recordings, clips and call notes are kept on your device, encrypted. They are not uploaded unless you choose to export or post them.
- If you post a clip publicly, our servers check and store a record showing the other person agreed.
- In a live stream, only the host records, on their own device, and everyone is told first.
playbakk is not responsible for what you do with your own recordings. You are, and you must follow the law where you and the other person are (see the terms).
4.6 Call notes, captions and translation (on your device)
- Shared call notes and minutes are encrypted between the people on the call and kept on each person's device.
- Captions run only if everyone on the call agrees. Each device turns only its own microphone into text, on that device. Nothing is sent to a captioning service.
- Translation happens on your device or not at all. Translations are kept in memory only.
- To translate, your browser may download a language pack: either from your browser maker (who learns the language pair, not your text) or from our server after you tap Download (we see that your IP address fetched that language pair; we do not log it).
Legal basis: contract. Captions start only when everyone on the call has agreed, and each person's device turns only their own voice into text, so nothing more is needed.
4.7 AI assistants
playbakk's own Assistant is not available during the pilot. We will update this notice before it is switched on.
If you connect your own AI assistant (for example Claude, ChatGPT or Gemini), you give it signed permissions on your device saying what it may do. Our servers keep the permissions, the assistant's login tokens, requests waiting for your approval, and a receipt for each action in your own account's log.
- Requests from businesses' AI assistants are quiet by default: they do not ring or notify you unless a rule you set allows it, and you can turn every AI request off with one switch.
- Legal basis: contract (you switch these on).
- Automatic decisions: see section 12.
4.8 Wellbeing (health data, on your device)
Wellbeing is off until you turn on each type of data (sleep, steps, heart-rate summaries, mood and so on). Everything stays on your device, encrypted with a key that stays on that device. Our servers never receive it. If you share a summary with a contact, it travels end-to-end encrypted like any message.
- Legal basis: explicit consent for each type and each use (UK GDPR Articles 6(1)(a) and 9(2)(a)). Consent lasts up to a year, and you can withdraw it at any time; turning a type off deletes it.
- Wellbeing is for general wellness. It is not a medical device.
- We cannot get your wellbeing data back for you or delete it for you, because we never had it. Use Wellbeing → Data & privacy.
- Encrypted backups to our servers refuse wellbeing data; it can only go into a file you export.
- Teens: sleep, steps, activity and private check-ins only, and sharing only with one trusted contact.
4.9 Safety reports
When you report someone, you choose what to include. We receive:
- the category you pick and any note you write (up to 500 characters);
- only if you tick the box, up to 20 recent messages as your device shows them, and up to 5 photos or voice notes they sent you;
- your key, your account and your age band; the reported person's display name, username and key;
- the network your report came from and the network your account was first set up from, as a shortened prefix (for example 203.0.113.0/24), never your full IP address. We use these only to tell apart reports from many separate people and reports from one group of accounts acting together;
- records our servers already had (a signed request they sent you, and times they contacted you).
We cannot check that the messages you send are real, and we label them that way. Reports may contain sensitive information. The reported person is never told who reported them.
- Legal basis: legitimate interests and legal obligation (the Online Safety Act 2023). Where a report contains sensitive information or allegations of crime, we rely on the Data Protection Act 2018, Schedule 1: preventing or detecting unlawful acts (paragraph 10) and, where a child or an adult at risk is involved, safeguarding (paragraph 18).
- The law requires us to report child sexual abuse content we become aware of to the National Crime Agency (Online Safety Act 2023, section 66), through the NCA's own reporting system. The law then requires us to keep the NCA's reference for 5 years, and the content, what we sent and related account information for 1 year.
- Where a report suggests a child is at risk, we may share information with the police, CEOP, the NCA or the Internet Watch Foundation.
- A copy of your report stays on your device, and you can download it to show a parent, teacher or the police.
4.10 Public posts, channels and live streams
- Profiles, channels, posts and comments, including paid group posts, are not end-to-end encrypted. Our servers store them and decide who may see them. Fields you mark "nobody" never leave your device.
- Public live streams are not encrypted end to end. Anyone with the link can watch. Our servers process the video, audio and chat, and see who is watching and their IP addresses. Contacts-only lives encrypt the video and audio, but live chat, questions, polls and reactions are never end-to-end encrypted.
- We do not store live chat, questions, votes, reactions or who watched. We store the live's record, who was on stage and their signed agreement, viewer reports and moderator actions.
Legal basis: contract; legitimate interests for moderation.
4.11 Connections to other apps
- If you connect your own Telegram or Discord bot, or post to Bluesky or Mastodon, we keep your token or app password encrypted, and use it only to do what you asked. Notifications to those apps never contain names or message text.
- If you forward a message to your own Telegram or Discord chat, that one message leaves end-to-end encryption and that company can read it. The app asks you to confirm first.
- Invites by email or SMS from playbakk are switched off in the pilot. You can share your invite link from your own apps instead; we do not see who you send it to.
4.12 Pay (in-chat money records)
Pay is not yet available in the pilot. This section applies when Pay is switched on.
Pay lets people in a chat keep track of who owes what, split costs and record who says they paid. playbakk doesn't move money. Section 4 of the Pay terms explains how it works.
| What | Where it is | Who can see it |
|---|---|---|
| Amounts, currency, titles, splits, balances, "says paid" and "confirmed by" records, reminders, saving goals, and the payout details you choose to share (for example a PayPal name or bank details) | Inside end-to-end encrypted messages, and on the devices of the people in that chat | The people in the chat. Not playbakk. |
| Whether a message is a Pay record (in 1:1 chats) | Hidden by padding | Not playbakk. In some group chats our servers can see the size of each message, which could hint that it is a Pay record. |
| Your device's face or fingerprint check before a hand-off | On your device only | Nobody. playbakk never sees your face or fingerprint. |
| Your country and age band, used to decide which Pay options to offer | On your device; our server may also read your country from the network | Our server sees one request asking which Pay options are switched on |
| AI assistant payment approvals (only if you let an AI assistant ask to pay someone) | Our servers | playbakk: the assistant's and payee's key ids, your limits, the currency, the purpose, and, for each approval, the amount. Kept 32 days. |
- When you pay, you leave playbakk. You pay in your own bank, PayPal, Monzo, Revolut or other app. That company is a separate controller with its own privacy notice. We do not tell it anything about you beyond the link or details you open.
- We never ask for, see or store card numbers, bank logins or one-time codes.
- If you choose "Share Pay history" with someone new in a group, you are sending them other people's Pay records. Think about whether those people would expect that.
- AI assistant payment approvals cannot actually be created, because no payment provider is connected. The data above applies if that changes.
Legal basis: contract (you switch Pay on per chat); legitimate interests for the AI assistant approval records (fraud and limit checks). Pay records describe money between the people in a chat, so they are about other people too: they stay inside that chat, and when someone shares the chat's Pay history with a new member, the app tells the chat.
4.13 Paid access
Charging for access (a price to send someone a request or call them) is not available yet. We will update this notice before it is switched on.
4.14 Paid groups (Stripe)
If you sell or buy a membership of a paid group:
- The creator sells the membership and is paid straight into their own Stripe account. playbakk never holds members' money and never sees card details: they go directly to Stripe.
- Members' billing details (name, email, billing address and card) are held by Stripe in the creator's Stripe account. The creator and Stripe are each responsible for that information; the paid group terms say how creators may use it.
- What playbakk keeps: which paid group you are a member of, the membership's state and dates, the price and currency, the Stripe reference numbers (customer, subscription and payment ids), the billing country Stripe reports, refunds and why a membership ended, and the record of what you agreed to at checkout (time and terms version). For creators: your membership Stripe account id, its status and country, your fee rate, and when you confirmed you are 18 or over and accepted the terms.
- We send Stripe only reference numbers. Your messages and what you post are never sent to Stripe.
- Posts in a paid group are not end-to-end encrypted (section 4.10); group chats are.
Legal basis: contract; legal obligation for accounting records. Stripe acts as the creator's payment provider and as a separate controller for its own fraud prevention, identity checks and legal duties.
5. What our servers can see, even with encryption
End-to-end encryption hides what you say. It does not hide everything about how you use playbakk.
| Our servers see | Notes |
|---|---|
| Who may contact whom (access, blocks, who is in which group) | Our servers enforce these, so they must see them |
| Your IP address | Logs keep only the first part of it (for example 203.0.113.x). We store the network prefix (for example 203.0.113.0/24, or /48 for IPv6) your account was first set up from, to spot groups of accounts acting together, until you delete your account. To limit how fast anyone can send requests, the full address is held in memory for 60 seconds. |
| When messages and calls happen | Timing is exact |
| Roughly how big messages and files are | Sizes are rounded into a few fixed sizes where both devices support it |
| For most 1:1 messages between up-to-date devices: not who sent each message | "Sealed sender" hides the sender from our servers |
| Group membership, roles and when a group is renamed | Not the group's name |
| That a call happened | The call server sees encrypted traffic sizes and timing |
| What AI assistants ask to send for you, and their permissions | Section 4.7 |
| Public posts and public live streams | Section 4.10 |
6. Where we get data from other people
Some data about you may come from other users: a request someone sends you, a report about you, a group you are added to, or your phone number in someone's contacts when they check who is on playbakk (which we receive only in scrambled form, never store, and cannot link to a person without guessing numbers). This notice is how we tell people who are not on playbakk about that; we cannot contact them individually because we do not know who they are.
8. Sending data outside the UK
Our servers are in the UK. Stripe processes some data in the United States and India, and Resend in the United States. For both we rely on the UK Extension to the EU–US Data Privacy Framework for transfers to the United States, and on the UK Addendum to the EU Standard Contractual Clauses in their data processing terms (which also covers India for Stripe). Apple, Google, Microsoft and Mozilla receive only a device address and an encrypted wake-up; where they are in the United States we rely on their UK Extension certification or, if they have none, their own transfer terms. You can ask us for a copy of the safeguards.
9. How long we keep things
| Data | How long | Then |
|---|---|---|
| Your account, keys, access, rules, devices | Until you delete your account | Erased at once |
| Messages waiting for an offline device | Up to 7 days, or until 1,000 are waiting | Deleted |
| Encrypted attachments | 30 days | Deleted |
| Encrypted backups | The newest 2 versions | Older ones deleted; all deleted with your account |
| Requests: pending | Until answered; they expire quietly after 7 days | — |
| Requests: closed | 30 days after the request arrived | Deleted |
| Requests in the Filtered folder | 7 days (1 day if dropped as spam), then 30 more days | Deleted |
| Safety reports | 90 days from the report | Deleted; longer if referred to the authorities (legal hold) |
| Reports of child sexual abuse content to the NCA | The NCA's reference: 5 years. The content, what we sent and related account information (including from the two weeks before): 1 year from the report | Deleted |
| Network prefixes stored with your account or a report | Until you delete your account, or until the report is deleted | Deleted |
| Safety reports after the reporter or reported person deletes their account | Reduced to a record with no names, text or evidence | Deleted at 90 days |
| AI assistant permissions and their login tokens | Until revoked, expired (at most 90 days) or account deletion | Deleted |
| Hosted AI assistant tasks | 7 days; their keys 30 days | Deleted |
| Rate-limit counters | Up to 24 hours | Deleted |
| Server logs | Limited by size, set to hold about 14 days at pilot volume. Our app server shortens IP addresses before logging them. Our call-connection (TURN) server logs full IP addresses and connection names; its logs are capped at 30 MB | Overwritten oldest first |
| Database backups (encrypted) | Up to 15 days on our server | Deleted |
| Paid group memberships (members and creators) | While the membership runs, then until you delete your account | Deleted, except payment records |
| Paid group payment and fee records (Stripe reference numbers, amounts, refunds) | 6 years from the end of our financial year in which the payment was made, with your key replaced by a scrambled value | Deleted |
| Your account's own log of who sent requests, who you allowed and what your AI assistants did | Until you delete your account | Erased |
| Your username, after deletion | Kept as a scrambled value forever | So nobody can take your username and pretend to be you |
| The public key log | Forever | It cannot be changed without breaking everyone's security checks. It holds key ids and public keys, not your name or messages |
| Your records in other people's account logs and group histories | As long as they keep them | Key id only, no name |
| Anything on your devices (chats, recordings, notes, wellbeing) | Until you delete it, or delete your account on that device | Erased by the app |
10. Your rights
You have the right to: ask for a copy of your data; correct it; delete it; restrict or object to how we use it; take it to another service; and withdraw consent at any time.
Many of these you can do in the app:
| What | Where |
|---|---|
| Delete your account | Account → Delete account |
| Remove a device, sign out everywhere else | Account → Devices & passkeys |
| See, narrow or remove AI assistants | Account → AI assistants & permissions |
| Turn off "Let people find you" | Account → Let people find you |
| Download or delete wellbeing data | Wellbeing → Data & privacy |
| Export call notes | Calls → Call notes |
| Download a report you made | From the report |
| Turn notifications off | Account → Notifications & quiet hours |
| Cancel a paid group membership | Memberships → Manage |
For anything else, email privacy@playbakk.com. We answer within one month. Because your messages are end-to-end encrypted and much of your data stays on your device, we may not be able to give you a copy of things we never had; we will tell you what we hold. If you ask what we hold about a report made about you, we will not tell you who made it. If information about you was recorded because of an allegation made by a malicious person and no further action was taken, you can ask us to erase it (UK GDPR Article 17(1)(g)).
11. Under-18s
playbakk is not open to anyone under 18 during the pilot. If we learn that an account belongs to someone under 18, we close it. Before accounts for 14 to 17-year-olds open, we will update this notice with the extra protections they get.
12. Automated decisions
- Spam filtering. Requests from people you have not allowed are scored by fixed rules (for example, a brand-new account writing to many people). Likely spam goes to a Filtered folder instead of your Requests. You can see the reasons and release any request. The sender is not told.
- Paid groups. If Stripe reports a billing address outside the countries paid groups are sold in, the membership is cancelled and refunded in full automatically.
- AI assistants act only within the permissions you gave. Anything outside it, or anything a message tries to make them do, needs your approval.
If an automatic decision affects you, you can tell us why you disagree, ask for a person to review it, and challenge it: email hello@playbakk.com (appeals, Terms section 9) or privacy@playbakk.com. Spam filtering does not stop anyone reaching you: you can see and release every filtered request.
13. Keeping data secure
We use end-to-end encryption, sealed sender, padding, signed records, a public key log, rate limits and strict separation of what our servers can see. Our security work has been tested by automated tools and internal reviews. It has not yet been independently audited, and has not been tested on real phones. No system is perfectly secure. If we have a data breach that puts you at risk, we will tell you and the ICO as the law requires.
14. Storage on your device
The app does not use advertising or analytics cookies. It stores what it needs on your device:
| What | Technology | Why |
|---|---|---|
| Your keys, chats, settings, block list, call notes, Pay records, wellbeing data | IndexedDB, encrypted with a key that cannot leave the device | So the app works and stays private |
| Small settings (for example wind-down hours, first-run progress, caption language) | localStorage (pb.*) | Remember your choices |
| Language packs for translation (only if you download one) | Origin Private File System or Cache Storage | On-device translation |
| Offline page and notifications | Service worker | Show notifications and work when offline |
| Keys in the iPhone and Android apps | Keychain / Keystore, this device only | Keep keys outside web storage |
Each of these is strictly necessary for the service you asked for, so we do not ask for cookie consent (Privacy and Electronic Communications Regulations 2003, regulation 6 and Schedule A1, paragraph 4). Our servers set no cookies.
15. Complaints
If you are unhappy with how we use your data, please contact privacy@playbakk.com first. You can also complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113). If you live in the EU, you can complain to your local data protection authority.
16. Changes to this notice
We will update this notice before we start using data in a new way, and tell you in the app if the change is important. The date at the top shows the latest version.