Legal
Security
How we protect your account, content, and payments — and how to report a vulnerability.
Updated: 26 July 2026
Accounts and access
- Passwords are stored as bcrypt hashes, never in plain text.
- Sessions use short-lived access tokens with rotating refresh tokens.
- Google sign-in is available as an alternative to passwords.
- Sign-in and sign-up forms are protected against automation by an anti-bot challenge.
Data isolation
All content is scoped to a workspace. Voices, generations, and koin balances are accessible only to members of that workspace, with roles governing what each member can do.
Payments
We never store card details or payment credentials. Transactions are handled by our payment provider, and we always re-verify payment status with the provider before crediting koin.
Reporting a vulnerability
If you find a security issue, please report it to us via the Contact page before disclosing it publicly. Include the steps to reproduce. We will keep you posted on how it is handled.