Security & Privacy

Private by default. Honest by design.

We describe only what's actually built. If a capability isn't implemented, you won't find it promised here.

Your data, scoped

Access to messages, media, and profiles is enforced server-side with row-level security — membership and roles decide what you can see.

Moderation with accountability

Reporting, audit logs, and role-based moderator tools keep actions transparent inside each community.

Desktop hardening

The desktop app follows Electron security best practices: sandboxed renderers, strict IPC boundaries, and a locked-down content security policy.

Audio Privacy

How audio respects your privacy.

These rules apply to voice rooms today, and to Community Radio and Podcasts when they launch.

Microphone, only on your action

Microphone permission is requested only when you join a voice room or host a radio broadcast — never in the background.

Capture starts explicitly

Screen and audio capture begin only with your explicit action. There is no silent recording.

Broadcasting is permission-gated

Starting a radio broadcast or publishing a podcast episode is governed by community-level permissions.

Host & moderator controls

Hosts and moderators can end broadcasts and manage listeners at any time.

Diagnostics contain no raw audio

Diagnostic data never includes raw audio content.

Storage follows community permissions

Podcast upload and storage access follow the same community permission model as everything else.

Transcripts: privacy review first

The future transcript feature will go through an explicit privacy review before it launches.

Permissions

One permission model for everything.

Chat, voice, screen sharing, broadcasting, and publishing are all governed by the same role-based, community-level permission system — set once, enforced everywhere.

Role-based access

Owners define roles; roles decide who can post, speak, share, broadcast, and publish.

Community-level control

Each community sets its own rules. Nothing is granted globally by default.

Enforced server-side

Permissions are checked on the server, not just hidden in the interface.

Consent, in practice

Terms you actually review.

When policies change, Picom asks again — with the exact version named and both documents one click away. Acceptance records the version and server timestamp.

Picom's policy update screen asking the user to review the updated Terms of Service and Privacy Notice before continuing
Security architecture

How Picom protects communities today.

These sections describe shipped controls and planned work. Planned items are labeled — never presented as available.

Identity & accounts

Planned

Email authentication and session restore ship in beta. User MFA / 2FA is Planned. Trusted-device and recovery workflows expand as those controls land.

MFA Coming later — not available yet

Safety & moderation

Planned

Human moderation tools, reporting, and role-based controls ship today. AI-assisted moderation and automated fairness systems are Planned — not marketed as live product features.

AI safety Planned

Privacy approach

Available

Profile privacy controls, consent prompts for policy updates, and privacy-request channels support GDPR/KVKK-oriented practice. This is not a certification claim.

Controls available — not a compliance certificate

Operations

Beta

Public status communication and incident contact paths exist on the website. Deeper monitoring and disaster-recovery detail expands with production maturity.

Operational honesty in beta

Media & uploads

Available

Image attachments in chat follow community membership and permissions. Malware scanning and advanced media protection remain post-V1 exclusions.

Attachments available; advanced scanning Planned

What we don't claim

You will not see claims like "end-to-end encrypted audio" or descriptions of recording and transcription features on this site unless those capabilities are actually implemented and verified. Honest labeling is a design rule, not a slogan.

Questions about security?

We're happy to walk through how Picom handles your community's data.