Security
Control at every step.
playbakk turns real calls into clips of just you. That means protecting your account, keeping your recordings on your device and making sure the other person is never included without their agreement. Here is how — and how to tell us if you find a problem.
The standalone app
The standalone playbakk app is in an invite-only private beta. Keys are made on your device, messages are end-to-end encrypted and calls are encrypted frame by frame, so the service passes on content it cannot read. To deliver it, the service still sees network details such as your IP address, when something was sent and who it is for. The app has not yet had an independent security audit. See the product page for what is in the beta.
The rest of this page describes the website and the earlier clip workspace.
Two checks before your workspace
Sign in with a passkey, which counts as both steps, or with email (or Google, Apple, Microsoft or WeChat where offered) and then a passkey or a six-digit code from an authenticator app. Authenticator setup is required for every account and cannot be switched off: each account keeps a passkey or an authenticator, plus one-time recovery codes. playbakk does not receive or store a password for any sign-in provider. A signed-in browser stays signed in for up to 30 days, ending after 7 days without use.
Recovery and session controls
Eight single-use recovery codes are issued when you set up an authenticator. Store them privately. You can inspect and revoke verified browser sessions — one at a time or all at once — from your account. Revocation takes effect on the next server request; an already open local editor checks periodically. Media already downloaded cannot be recalled.
Account data is protected separately
- Authenticator secrets are encrypted with AES-256-GCM before storage, bound to your account.
- Recovery codes and session tokens are stored only as SHA-256 hashes.
- Repeated attempts are rate-limited and reused authenticator codes are rejected.
- Account changes are checked on the server; requests from other sites are blocked, and the verification cookie is HTTP-only, HTTPS-only and SameSite=Strict.
Your recordings stay local
The web app keeps a separate local workspace for each signed-in account, in your browser’s storage. This is not encryption of your media and does not protect against someone with access to your browser profile or computer. Use a private operating-system account, keep your device locked and download the originals you need. Local recordings do not sync between devices. Face detection for framing runs on your device; nothing is uploaded automatically.
Publication stays your decision
The other person is removed from your clips by default. Including them needs their explicit approval through a consent link, recorded as a signed receipt they can withdraw. Recording permission does not automatically mean publication permission: check the complete exported clip for private details in speech, captions and pictures. Automated checks are not a guarantee of anonymity.
Release boundaries
The desktop companion currently runs locally without the web account security layer and is distributed as a developer package. Signed desktop installers, mobile capture, cloud AI editing and subscriber publishing are not available. Security testing is ongoing; no independent audit or certification is claimed. More detail is in the trust centre.
Report a vulnerability
If you believe you have found a security vulnerability in playbakk, email security@playbakk.com. We aim to acknowledge reports acknowledged within 3 working days and to keep you updated until the issue is resolved. Our security.txt lists the same contact.
Please
- Give us enough detail to reproduce the issue, and a reasonable time to fix it before you disclose it publicly.
- Test only against your own account and data. Do not access, change or delete other people’s data, and stop as soon as you see data that is not yours.
- Do not run denial-of-service, spam, social-engineering or physical attacks, or automated scanning that degrades the service.
- Do not include real recordings of other people in your report.
In return
- We will not pursue or support legal action against good-faith research that follows these guidelines. [Requires counsel review: safe-harbour wording]
- We will credit you, if you wish, once the issue is fixed.
- We do not currently run a paid bug bounty.