Over 181,000 AI meeting recordings left wide open in note taking app
Source Entity
Hacker News

An AI meeting recording platform, tl;dv, has left over 181,000 recordings exposed due to an unsecured Firestore database. Despite being notified six months ago, the company has failed to address the vulnerability, risking sensitive corporate data.
The Security Oversight at tl;dv
In a significant lapse of data stewardship, the AI-driven meeting platform tl;dv has been identified as having left over 181,000 user meeting recordings accessible via an unsecured Firestore database. Despite an initial disclosure made on January 28, 2026, the vulnerability remains active as of July 2026. The continued exposure of this data, six months after the initial report, highlights a critical failure in internal security protocols and incident response management at the startup.
The Nature of the Exposed Data
tl;dv serves as an automated note-taking tool that integrates into platforms like Google Meet, Zoom, and Teams to transcribe and summarize professional interactions. With a user base exceeding 2 million, the platform processes highly sensitive information, including sales calls, job interviews, performance reviews, and internal strategy sessions. The exposure of these recordings creates a significant risk, as these sessions often contain proprietary trade secrets, confidential personnel evaluations, and private business strategies that were intended only for the participants.
The Failure of Disclosure and Remediation
The security researcher responsible for identifying the flaw noted a complete lack of response from the company’s CTO despite multiple attempts to communicate the severity of the situation. This lack of engagement suggests a breakdown in organizational communication or a disregard for security disclosures. In the cybersecurity landscape, the speed of remediation is paramount; leaving a database 'wide open' for half a year after notification is considered a severe departure from industry standard security practices.
Implications for AI Platforms
This incident raises broader questions regarding the security posture of AI-integrated productivity tools. As these platforms gain widespread adoption, often endorsed by professional influencers on networks like LinkedIn, they become attractive targets for data harvesting. The reliance on cloud-based databases like Firestore requires rigorous access control configurations; when these are mismanaged, the resulting data leaks can have long-lasting consequences for both the company and the individual users whose private conversations are exposed.
Future Trends in Data Governance
Moving forward, enterprises will likely demand more stringent security audits and transparency from AI vendors. The tl;dv incident serves as a cautionary tale for the industry, underscoring that the convenience offered by AI automation cannot come at the expense of privacy and data integrity. As regulatory scrutiny over AI and data protection intensifies, companies that fail to address known vulnerabilities risk not only their reputations but also significant legal and financial liabilities under global data protection frameworks.