Getting Started » Security
November 9, 2025

Security

Work in Progress

This documentation is still being expanded and refined. Features, screenshots, and descriptions may change until Talescape's public release. If something is unclear or you need help, please ask on the official Talescape Discord. We're happy to clarify or update pages as needed.

Talescape was built to protect both your stories and your identity. Every Bard account includes strong authentication, encrypted connections, and tools to recover access safely.

Account Protection

All communication between the editor, player, and API is secured using HTTPS and modern encryption standards. Your personal data and story files are transmitted only through encrypted channels.

  • Password-based accounts are not supported to reduce the risk of leaks or phishing.
  • Talescape uses OAuth 2.0 for all logins. You can sign in with trusted providers like Google, Steam, Discord, or Twitch.
  • Each login is verified directly by the provider, Talescape never stores your password.

Two-Factor Authentication (2FA)

To further secure your account, Two-Factor Authentication is required for all Bards. 2FA helps protect against unauthorized access even if someone gains control of your OAuth account.

  • You can activate 2FA in your Account Settings.
  • Once enabled, Talescape will ask for a verification code (e.g., via app or email) in addition to your OAuth login.
  • 2FA must be enabled before you can publish stories or receive payouts.

Secondary Login Providers

If you lose access to your primary OAuth provider, you can link additional providers as backups.

  • Go to Account Settings → Linked Logins.
  • Add one or more secondary providers (e.g., Discord + Google).
  • Any linked provider can be used to access your account.
  • Removing a provider will immediately revoke its login access.

This makes it easy to recover your account without needing password resets or manual intervention.

Data Storage & Backups

Your stories, media, and metadata are stored securely on Talescape’s cloud infrastructure. All critical data is backed up automatically and replicated across multiple servers.

  • Story data and user information are stored in encrypted databases.
  • Media files are stored in secure object storage.
  • Regular integrity checks ensure that backups remain consistent and recoverable.

Lost Access

If you lose access to all linked providers and cannot recover through 2FA, you can request manual verification.

  1. Contact our support via Discord.
  2. Provide any verification details requested (e.g., proof of story ownership).
  3. Account recovery is handled manually for security reasons and may take several days.

Best Practices

  • Always link at least two login providers.
  • Keep your 2FA recovery codes in a secure place.
  • Never share your login access or story files outside the platform.
  • Use only the official Talescape website and app for authentication.
Next: Bard Tiers