Identity & accounts
PlannedEmail authentication and session restore ship in beta. User MFA / 2FA is Planned. Trusted-device and recovery workflows expand as those controls land.
MFA Coming later — not available yet
We describe only what's actually built. If a capability isn't implemented, you won't find it promised here.
Access to messages, media, and profiles is enforced server-side with row-level security — membership and roles decide what you can see.
Reporting, audit logs, and role-based moderator tools keep actions transparent inside each community.
The desktop app follows Electron security best practices: sandboxed renderers, strict IPC boundaries, and a locked-down content security policy.
These rules apply to voice rooms today, and to Community Radio and Podcasts when they launch.
Microphone permission is requested only when you join a voice room or host a radio broadcast — never in the background.
Screen and audio capture begin only with your explicit action. There is no silent recording.
Starting a radio broadcast or publishing a podcast episode is governed by community-level permissions.
Hosts and moderators can end broadcasts and manage listeners at any time.
Diagnostic data never includes raw audio content.
Podcast upload and storage access follow the same community permission model as everything else.
The future transcript feature will go through an explicit privacy review before it launches.
Chat, voice, screen sharing, broadcasting, and publishing are all governed by the same role-based, community-level permission system — set once, enforced everywhere.
Owners define roles; roles decide who can post, speak, share, broadcast, and publish.
Each community sets its own rules. Nothing is granted globally by default.
Permissions are checked on the server, not just hidden in the interface.
When policies change, Picom asks again — with the exact version named and both documents one click away. Acceptance records the version and server timestamp.

These sections describe shipped controls and planned work. Planned items are labeled — never presented as available.
Email authentication and session restore ship in beta. User MFA / 2FA is Planned. Trusted-device and recovery workflows expand as those controls land.
MFA Coming later — not available yet
Human moderation tools, reporting, and role-based controls ship today. AI-assisted moderation and automated fairness systems are Planned — not marketed as live product features.
AI safety Planned
Profile privacy controls, consent prompts for policy updates, and privacy-request channels support GDPR/KVKK-oriented practice. This is not a certification claim.
Controls available — not a compliance certificate
Public status communication and incident contact paths exist on the website. Deeper monitoring and disaster-recovery detail expands with production maturity.
Operational honesty in beta
Image attachments in chat follow community membership and permissions. Malware scanning and advanced media protection remain post-V1 exclusions.
Attachments available; advanced scanning Planned
You will not see claims like "end-to-end encrypted audio" or descriptions of recording and transcription features on this site unless those capabilities are actually implemented and verified. Honest labeling is a design rule, not a slogan.
We're happy to walk through how Picom handles your community's data.