Security
Control at every step.
playbakk turns real calls into clips of just you. That means protecting your account, keeping your recordings on your device and making sure the other person is never included without their agreement. Here is how — and how to tell us if you find a problem.
Two checks before your workspace
Sign in with ChatGPT, then verify with a six-digit code from an authenticator app. Authenticator setup is required for every account and cannot be switched off. playbakk does not receive or store your ChatGPT password. A verified browser session lasts up to 12 hours.
Recovery and session controls
Eight single-use recovery codes are issued when you set up an authenticator. Store them privately. You can inspect and revoke verified browser sessions — one at a time or all at once — from your account. Revocation takes effect on the next server request; an already open local editor checks periodically. Media already downloaded cannot be recalled.
Account data is protected separately
- Authenticator secrets are encrypted with AES-256-GCM before storage, bound to your account.
- Recovery codes and session tokens are stored only as SHA-256 hashes.
- Repeated attempts are rate-limited and reused authenticator codes are rejected.
- Account changes are checked on the server; requests from other sites are blocked, and the verification cookie is HTTP-only, HTTPS-only and SameSite=Strict.
Your recordings stay local
The web app keeps a separate local workspace for each signed-in account, in your browser’s storage. This is not encryption of your media and does not protect against someone with access to your browser profile or computer. Use a private operating-system account, keep your device locked and download the originals you need. Local recordings do not sync between devices. Face detection for framing runs on your device; nothing is uploaded automatically.
Publication stays your decision
The other person is removed from your clips by default. Including them needs their explicit approval through a consent link, recorded as a signed receipt they can withdraw. Recording permission does not automatically mean publication permission: check the complete exported clip for private details in speech, captions and pictures. Automated checks are not a guarantee of anonymity.
Release boundaries
The desktop companion currently runs locally without the web account security layer and is distributed as a developer package. Signed desktop installers, mobile capture, cloud AI editing and subscriber publishing are not available. Security testing is ongoing; no independent audit or certification is claimed. More detail is in the trust centre.
Report a vulnerability
If you believe you have found a security vulnerability in playbakk, email security@playbakk.com. We aim to acknowledge reports acknowledged within 3 working days and to keep you updated until the issue is resolved. Our security.txt lists the same contact.
Please
- Give us enough detail to reproduce the issue, and a reasonable time to fix it before you disclose it publicly.
- Test only against your own account and data. Do not access, change or delete other people’s data, and stop as soon as you see data that is not yours.
- Do not run denial-of-service, spam, social-engineering or physical attacks, or automated scanning that degrades the service.
- Do not include real recordings of other people in your report.
In return
- We will not pursue or support legal action against good-faith research that follows these guidelines. [Requires counsel review: safe-harbour wording]
- We will credit you, if you wish, once the issue is fixed.
- We do not currently run a paid bug bounty.