Data & privacy
What playbakk keeps.
Last updated 8 October 2026. This notice is a working draft pending legal review; sections marked for counsel review are not yet final.
What this notice covers
This notice covers the playbakk website and the clip workspace: the earlier web app that records your own camera and microphone while you take a call in another app. The standalone playbakk app for messages, calls and agents is in an invite-only private beta. It is a separate service with different data flows, such as encrypted messages relayed between your devices, and it is not described here. Beta participants are given the notice that applies to it before they join. [Requires counsel review: privacy notice for the standalone app.]
Who is responsible
The controller of personal data processed by the playbakk service is:
[Operator legal entity — to be confirmed]
[Company number — to be confirmed] · [Registered address — to be confirmed]
Registered name, company number, registered address and, where required, EU/UK representative will appear here once confirmed.
Privacy contact: privacy@playbakk.com
If you sign in with Google, Apple, Microsoft or WeChat, that company is an independent controller for your account with them: it learns that you signed in to playbakk, and its own privacy terms apply. It is not our processor.
Your account
playbakk stores your account identifier, display name, the email address you gave or your sign-in provider shared, when and how the account was created, your sign-in methods (below), your encrypted authenticator configuration, hashed recovery codes, your active sessions and recent security actions. Security actions are kept for up to 30 days.
Each account has at least one strong second factor, a passkey or an authenticator app, plus recovery codes. Sign-in methods are never joined by email address: a new method is added only from inside your signed-in account.
Signing in
You choose how to sign in. What we receive depends on the method:
- Google — a stable account identifier for playbakk, your email address and whether Google has verified it, and your name.
- Apple — a stable identifier, an email address (your own or an Apple private relay address, as you choose) and, the first time only, your name.
- Microsoft — your organisation’s tenant identifier and your account’s object identifier, your email address and your name.
- WeChat (Tencent) — your WeChat union or open identifier and the nickname WeChat shares. WeChat does not give us an email address.
- Passkey — the passkey’s public key, its identifier, a name you can change, the type of authenticator, a signature counter and when it was created and last used. The private key never leaves your device or password manager, and your fingerprint or face never reaches us.
- Email code — your email address. We send a six-digit code and a one-time link through Resend, our email processor. The code is stored only as a hash and expires after 10 minutes.
We never receive your password for any of these services. Google, Apple, Microsoft and Tencent are independent controllers for the sign-in itself; we do not ask them for your contacts, files or anything else. For each method we record when you added it and when you last used it.
Accounts created earlier with ChatGPT keep their data and identifier. While such an account moves to one of the methods above, OpenAI confirms its identity one last time, as an independent controller; after that, playbakk no longer uses ChatGPT sign-in.
Your media
Recordings, edits and recovery chunks stay in browser storage or on your computer. They are not automatically uploaded. Browser data may be cleared or evicted. Account deletion removes server-side account information and attempts to delete this browser’s account workspace; it does not remove downloaded files or media on other devices. Close other playbakk tabs before deletion.
Recording other people
The clip workspace records your own camera and microphone by default. When you capture a call with it, playbakk works from the browser or operating-system window you choose to share and your own camera and microphone; it does not connect to, or read data from, the calling app itself.
The other person is excluded by default. Their face, window and speaking turns are removed from your clips unless they give explicit consent through a consent link you send them. They choose what is included and can withdraw consent later; withdrawal stops future exports but cannot recall copies already shared. If you send a consent request by email, we process their email address only to deliver that request and record their answer.
You are responsible for complying with recording laws where you and the other participants are, and with our acceptable use policy. Some US states and some countries require every participant’s consent before a conversation is recorded, not just yours. When in doubt, tell everyone and ask before you record. [Requires counsel review: jurisdiction-specific recording and publication rules.]
Contact form
When you use the contact form on the contact page or ask for a beta invite, we store the topic you chose, your name, the email address you gave, the subject and your message, when you sent it, a coarse description of your browser (such as “Safari on iPhone”), a keyed hash of your IP address that we cannot turn back into the address, and which mailbox it went to. If you were signed in, the message is linked to your account.
We use it to answer you and to keep the form free of abuse. The message is emailed, through Resend, to the playbakk mailbox for that topic and read only by the people who answer it; we email you a short acknowledgement that repeats nothing you wrote. Messages are deleted after 180 days. If the anti-spam check by Cloudflare Turnstile is switched on, Cloudflare processes your browser and request data to decide whether the request is automated.
Cloud processing
Cloud transcription and AI editing are currently disabled. If enabled later, these tools require a separate, explicit choice before sending selected content for processing. No automatic posting takes place.
Why we process data
Under UK and EU data-protection law we rely on:
- Contract — to create and secure your account, keep you signed in and provide the workspace you ask for.
- Legitimate interests — to answer messages you send us through the contact form and keep the form free of spam.
- Legitimate interests — to protect accounts and the service: security logs, abuse prevention, and security alerts such as a new sign-in or a change to your authenticator.
- Consent — to include another participant in your clips, and for any optional cloud processing you switch on. Consent can be withdrawn at any time.
- Legal obligation — to keep billing and tax records, if paid plans are introduced.
[Requires counsel review: lawful-basis mapping and any special-category data in recordings.]
Service providers
We use these processors to run playbakk. Each receives only what it needs for its task. The sub-processor list shows purpose, location and whether each is enabled yet; business customers can request our Data Processing Addendum.
- Cloudflare — hosts the web workspace and the account database; processes request data such as IP address and browser details.
- Vercel — hosts the public website; processes request data for delivery and security.
- Resend — sends transactional email (sign-in codes, security alerts, consent requests, contact-form messages and acknowledgements) when email is enabled, and marketing email only to people who opted in. Open and click tracking are off.
- Cloudflare Turnstile — an optional anti-spam check on the contact form, only if we switch it on.
- Stripe — payments and subscription records, only when paid plans are enabled. Card details go directly to Stripe and are never stored by playbakk.
- Supabase — account database, only if and when the account store moves there.
- jsDelivr and Google Cloud Storage — deliver the face-detection component that runs on your device for auto-framing and call imports. They receive request data such as your IP address, never your media.
Some providers process data outside the UK and EEA, including in the United States, under appropriate safeguards such as standard contractual clauses or the UK International Data Transfer Agreement. [Requires counsel review: transfer mechanisms and processor agreements.]
Marketing email
We only send marketing email if you ask for it. You choose the topics (product updates, tips and guides, offers); every box starts unticked, and nothing is sent until you confirm your address from the link we email you. We keep a record of what you chose, where and when you signed up, and when you confirmed, so we can show that you agreed. Every marketing email has a one-click unsubscribe link and a link to your email preferences, and you can withdraw at any time. Account, security, consent-request and billing emails are not marketing and are not affected. If you unsubscribe, or if email to your address bounces or is reported as spam, we keep only your address and the reason so that we never email it again. Deleting your playbakk account deletes your marketing choices too. [Requires counsel review: lawful basis and retention wording for marketing consent records.]
How long we keep it
- Account profile, authenticator configuration and hashed recovery codes — until you delete your account.
- Sign-in sessions — end after 7 days without use and at most 30 days after sign-in, or when you sign out or revoke them. A sign-in that still needs its second step lasts 15 minutes. Authenticator-check sessions expire after 12 hours.
- Sign-in in progress (the provider round trip and email codes) — 10 minutes.
- Sign-in methods and passkeys — until you remove them or delete your account.
- Contact-form messages — 180 days.
- Security activity — up to 30 days.
- Consent records — while the consent is active, and afterwards only as long as needed to show that a clip was made with permission. [Retention period to be confirmed by counsel.]
- Email delivery logs — held by Resend for its standard log period.
- Billing records — for the period tax law requires, if paid plans are introduced.
- Media — never held on our servers; it stays on your device until you or your browser remove it.
Cookies and local storage
Signing in uses strictly necessary, first-party cookies only: __Host-playbakk-session keeps you signed in (an HTTP-only random token; we store only its hash), and __Host-playbakk-flow holds the state of a sign-in for 10 minutes while you are with Google, Apple, Microsoft or WeChat. A verification cookie for the authenticator check expires after 12 hours. Local storage is used for device preferences and your local media workspace. The website does not include advertising or analytics trackers. The cookie policy lists everything stored on your device.
How to get a copy of your data
Signed in, open Account › Data and choose Download my data. You get a JSON file (a versioned, documented format) of everything our servers hold about your account: profile, sign-in methods with when each was added and last used, passkey details, active sessions, 30 days of security activity, subscription status, consent requests and signed receipts, email preferences and contact-form messages sent while signed in. It never contains your authenticator secret, recovery codes or session tokens.
Some of your data is not on our servers, so it is not in that file:
- Recordings and the studio workspace are kept in your browser on your device. Export them as a
.playbakkarchive from Your recordings. - The messenger keeps your messages encrypted on your devices and has its own export in its settings.
- Your sign-in provider (Google, Apple, Microsoft or WeChat) holds its own records; ask it for a copy.
For anything else, such as contact messages sent while signed out or email delivery logs, email privacy@playbakk.com.
Your rights
You can ask to access, correct, delete, restrict or object to processing of your personal data, to receive a copy in a portable format, and to withdraw consent at any time. Many of these are self-service: download your data, change your display name, add or remove sign-in methods and passkeys, replace your authenticator, revoke sessions or delete your playbakk account in account settings. For anything else, email privacy@playbakk.com; other addresses are on the contact page. You can also complain to your data-protection authority; in the UK, that is the Information Commissioner’s Office.
Changes to this notice
- — New sign-in methods (Google, Apple, Microsoft, WeChat, passkeys and email codes) replace ChatGPT sign-in; new sign-in cookies; the contact form and what it stores; how to download a copy of your data.
- — First published.