The archive · Developer & Business Tools · Technical decision · 2020–2026
tl;dv's meeting-AI bet: 2M users, then 181,874 calls exposed
Cologne's tl;dv bet teams would let an AI bot record every call; by 2026 it had 2M users - and a Firestore hole exposing 181,874 meetings.
tl;dv
What the business is
Cologne-based AI meeting assistant (founded 2020) whose bot joins Google Meet, Zoom and Teams calls to record, transcribe and summarize them, syncing searchable clips to Slack, Notion and CRMs.
Starting capital:€4.3M seed round, June 2022, led by Madrid-based K Fund with Seedcamp, Mustard Seed Maze and others (per Tech.eu).
How it started
Raphael Allstadt co-founded tl;dv in Cologne in April 2020, at the moment work went remote. His bet, as he told Tech.eu, was 'asynchronous collaboration at scale': recordings of meetings that people who were not there could consume later. The June 2022 seed led by K Fund backed that thesis, funding deeper meeting-provider integrations and the search-and-share layer.
What happened
The company grew on integrations: Zoom support followed Google Meet, clips synced to Slack, Notion, HubSpot and Pipedrive, and by 2026 marketing claimed more than 2 million users including Salesforce, Forbes and Cloudflare. In late January 2026, security researcher BobDaHacker found the catch: the Firestore 'meetings' collection had no tenant isolation, so any signed-in tl;dv user could list every meeting's metadata - creator email, provider, recording status, and a conference ID that could reach the live call. Roughly 1,000 calls were actively recording at any moment. He reported it on Jan 28, 2026 and followed up through July; Dark Reading (Aug 4, 2026) confirmed the exposure was still live and that tl;dv did not reply to its requests either.
How it ended up
Still live as of Sept 2, 2026, but the disclosure was unresolved: six months after the first report the Firestore collection remained open per Dark Reading, while the researcher documented entering a Malaysian education-ministry call with 157 participants and a university product session. The HN front-page post (Aug 10, 2026, 633 points) turned the episode into a public trust crisis for a product whose entire value proposition is recording sensitive conversations.
Background
tl;dv is a Cologne-based AI meeting assistant founded in April 2020 by Raphael Allstadt on a simple bet: after remote work began, teams would want every call recorded, transcribed and searchable so people who missed it could catch up - 'asynchronous collaboration at scale'. The June 2022 seed round of €4.3M, led by K Fund with Seedcamp and others, funded integrations with Google Meet, Zoom, Slack, Notion and CRMs.
Growth followed the wedge: a bot users invite into calls they already host, no behavior change required. By 2026 the company claimed more than 2 million users worldwide, including Salesforce, Forbes and Cloudflare, while staying on seed funding and revenue.
In late January 2026, security researcher BobDaHacker found that the product's Firestore 'meetings' collection had no tenant isolation: any signed-in user could list every meeting across all accounts - creator email, recording status and the conference ID of live calls. He reported it on January 28 and followed up repeatedly through July, with no response from the CTO. Dark Reading independently confirmed on August 4, 2026 that the exposure was still active and that the company had not replied to its queries either.
The case became public through the researcher's own write-up and Dark Reading's coverage; on August 10, 2026 the HN thread reached the front page with 633 points and 208 comments. As of September 2, 2026 tl;dv is still operating, but the episode stands as the unresolved trust failure of a product whose business is listening to people's most confidential conversations.
What has to be true
- The pandemic created a real wedge - teams already in Meet/Zoom/Teams adopted a bot that needed no change in meeting behavior.
- Integrations did the compounding: recordings pushed into Slack, Notion and CRMs made the tool feel essential rather than optional.
- The single missing Firestore rule shows how one data path can invalidate an otherwise tenant-isolated product.
- Silence broke the deal: six months without a fix or reply converted a technical bug into a public trust crisis on HN.
What can be applied
A product that records the most sensitive conversations sells a trust contract: one unsecured collection plus six months of silence can outrank 2M users and every integration win.
Aftermath
As of Sept 2, 2026, tl;dv continues to run with its claimed 2M+ users, but the January-reported Firestore tenant-isolation flaw was still open when Dark Reading published on Aug 4, 2026, and the company had not responded to the researcher or to Dark Reading. The Aug 10 HN front-page thread (633 points, 208 comments) spread the story across the developer community. No public fix, remediation notice or comment from tl;dv had been confirmed by the asOf date, leaving the product's central promise - safe recording of confidential calls - publicly in question.
Sources
- AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls
- tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
- Inside the tl;dv Flaw That Exposed Live Government and Corporate Meetings
- Catch up on meetings in minutes? tl;dv picks up €4.3 million to show how
spotted an error? The archive wants to know.
Your turn
You just read one. Describe what you are building, and see who is betting on the same thing.
Free account · 3 free questions · no card