A security researcher disclosed that tl;dv, an AI meeting-notes platform used by more than two million people, left 181,874 meeting records exposed through a Firestore database missing tenant-isolation controls, allowing any authenticated user to query records belonging to other customers. Exposed data included meeting creators’ email addresses, conferencing provider, timestamps, and joinable conference IDs, with roughly 1,000 live calls queryable at any given time, including sessions hosted by government agencies and universities across 23 countries. The researcher reported the flaw on January 28, 2026, and said it remained unfixed for more than six months despite repeated follow-ups.