> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vaudiolink.eu/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and privacy

> Understand accounts, temporary credentials, relay behavior, logs, and safe support practices.

## Security boundaries

* The host signs in through browser device authorization.
* Guests join with temporary, role-specific credentials rather than the host's account.
* Hosted relay access is authorized by short-lived server-issued tokens.
* Relays forward media for the authorized stream identity without transcoding it.
* The OBS plugin is not trusted with hosted service secrets or billing enforcement.

## Media handling

Hosted relays forward product media and do not normalize, gate, downmix, transcode, or store the media payload.

Scene Share keeps its H.264 video and AAC audio muxed. Music Collab transfers the prepared backing asset required for the shared session. Consult the [Privacy Policy](https://vaudiolink.eu/legal/privacy) for the service's complete legal data-handling terms.

## Secrets users may encounter

Never publish:

* Guest keys.
* Receiver SRT URLs.
* Account or device tokens.
* OBS stream keys.
* API keys or private keys.
* Payment information.

<Warning>
  OBS logs and screenshots can include URLs, status text, source names, or environment details. Review and redact them before sharing.
</Warning>

## Device authorization

The dock opens a browser authorization and may show a short device code. Complete authorization only on the intended vAudioLink domain. If the browser cannot open, use the dock's copied URL rather than manually searching for a sign-in page.

You can deauthorize or revoke plugin devices from the account panel. Revoke a device you no longer control.

## Safe support bundle

Include:

* Product and plugin version.
* OBS version.
* Host, guest, sender, or receiver role.
* Exact error text.
* Approximate time and time zone.
* A reviewed OBS log.

Remove:

* Complete credentials and URLs.
* Account tokens.
* Private IP or hostname details that are unnecessary.
* Personal information unrelated to the incident.

## Report a suspected exposure

1. End or rotate the affected session.
2. Revoke the device if account authorization may be affected.
3. Preserve a redacted timeline and relevant logs.
4. Contact [vAudioLink support](https://panel.vaudiolink.eu/app/support).
