Menu icon
Developers
Start hereDocumentationChangelog
HIPAAPricing
Resources
BlogCustomers
Jobs
we're hiring!
Log inSign up for free
DevelopersHIPAAPricingCustomersBlogLog inSign up for free
Security & Compliance
Data Processing Addendum
Secure Infrastructure
Security Controls
Secure Calls
Data Protection
GDPR Compliance
Related links
  • HIPAA compliance
  • Privacy Shield
  • Our privacy policy
Back to security

Data Protection

Audio, video, and screen-sharing media

We never store any audio, video, or screen-sharing data from any call other than through our documented recording APIs, which are entirely under the control of developers.

A Daily.co call can be recorded only when:

  • The enable_recording property is set for the Daily.co room for the call. Recording is disabled by default for rooms created with the Daily.co REST API.

If recording is enabled for a room, a recording will only start if:

  • The Daily.co pre-built user interface is used and a user who has recording privileges for the room clicks on the recording button in the UI, or
  • The daily-js front-end library startRecording() method is called

Application-level messages

We do not log or store any data passed through our infrastructure via the sendAppMessage() API call.

The Daily.co prebuilt user interface includes a text chat feature. Text chat data is encrypted and stored in encrypted form for approximately 15 minutes following a call, then text chat data is deleted.

Access logs and personally identifying information

The only personally identifying information we store is:

  • The client IP address, in front-end server HTTPS access and error logs
  • The client user_name only if a developer supplies this via the daily-js front-end library
  • The client user_id only if a developer supplies this via the daily-js front-end library

Logs are stored in the AWS cloud. No log data is stored longer than necessary to perform analytics to improve Daily.co service quality.

Access controls

Your information is stored only in the Daily.co production environment. Since your information is private and confidential, we have strict controls that limit access to the production environment to individuals that need to perform tasks to keep Daily.co up and running. All access requires 2FA and is logged using AWS IAM.

Read more about our security controls.

Product
Video chat APIHIPAASecurity & CompliancePricingFeaturesDeveloper hub
Resources
Getting startedReference docsTutorialsChangelogHelp centerZapier appIntercom app
Customers
Meet our customersTandem case studyTeamflow case studyFocusmate case study
Company
About usPrivacy policyTerms of service
Jobs
we're hiring!
Contact us

Built worldwide