
tl;dv left its Firestore database open for six months: 181,874 meeting records
A security researcher says tl;dv's Firestore database had no tenant isolation, letting any authenticated user read meeting records belonging to every customer on the platform.
A security researcher writing under the name BobDaHacker has published a detailed report on tl;dv, an AI meeting-recording platform with more than two million users: the company's Firestore database was left without tenant isolation, and the flaw went unfixed for over six months.
What was exposed
tl;dv drops a bot into Google Meet, Zoom and Teams calls, records them, and produces transcripts and AI summaries. After signing up, users receive a JWT that is exchanged for a Firebase token at gw.tldv.io/v1/users/firebase/token; that token grants access to the Firestore database in the lmi-store project.
According to the researcher, the meetings collection had no tenant isolation, so any authenticated user could read the meeting records of every account on the platform. Each record exposed the organiser's email address, the conference ID — a joinable Google Meet or Teams room — the recording status and timestamps. Meetings in recording status pointed at live calls; roughly 1,000 such meetings were available at any moment.
The researcher says he verified the flaw in practice, joining a live Google Meet for the Malaysian Ministry of Education with more than 157 participants, and a call where students at a major US university were building a startup app.
The scale
The open collection contained 181,874 meeting records belonging to 84,312 unique users across 35,003 email domains. It included government meetings from 23 countries, among them Brazil, Ukraine, the Philippines, Mexico, Malaysia and Israel; university meetings from Berkeley and the University of Tokyo; and corporate records from companies such as HubSpot, Confluent and Mitsui-Soko.
The busiest month was July 2025 with 43,209 meetings, and the busiest time slot was Wednesdays at 2pm UTC with 7,804 meetings. The researcher also checked 27,334 meeting IDs and found that more than 1,000 were public; those records exposed 715 invitee email addresses across 228 domains.
Disclosure
The researcher reported the issue on 28 January 2026, first through a company contact on LinkedIn and then by email to the CTO. He says he followed up repeatedly in February and March without a reply, and that in late July the database was still open. tl;dv's security page advertises SOC 2, GDPR and EU AI Act compliance and promises a response to security reports within 24 hours.
According to the report, other collections — users, chats, transcripts and recordings — correctly return 403. The researcher calls on tl;dv to apply the same rules to the meetings collection, to secure or take down an internal World Cup prediction app, and to respond to security researchers.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.