Security
Work in Progress
This documentation is still being expanded and refined. Features, screenshots, and descriptions may change until Talescape's public release. If something is unclear or you need help, please ask on the official Talescape Discord. We're happy to clarify or update pages as needed.
Talescape protects account access with passwordless sign-in, encrypted connections and recovery options.
Account Protection
All communication between the editor, player and API is secured using HTTPS and modern encryption standards. Your personal data and story files are transmitted only through encrypted channels.
- Talescape does not use or store account passwords.
- You can sign in with a verification code sent to your email address.
- You can also sign in through connected external providers such as Google, Steam, Discord or Twitch.
- External providers verify their own logins directly.
Email login provides Dreamer access. A connected external account is required to use the authoring tools for Bards.
Two-Factor Authentication (2FA)
To further secure your account, Two-Factor Authentication is required for Bard verification. 2FA helps protect against unauthorized access even if someone gains control of your OAuth account.
- You can activate 2FA in your Settings.
- Once enabled, Talescape will ask for a verification code (e.g., via app or email) in addition to your OAuth login.
- 2FA must be enabled before you can publish paid stories and receive payouts (including contest prizes).
Secondary Login Providers
You can link additional external providers as alternative sign-in methods.
- Go to Settings → Connections.
- Add one or more secondary providers (e.g., Discord + Google).
- Any linked provider can be used to sign in.
- Removing a provider immediately revokes its login access.
- The final external login provider cannot be removed while the account has authoring access.
Email login can also be used when an external provider is unavailable.
Data Storage & Backups
Your stories, media and metadata are stored securely on Talescape’s cloud infrastructure. All critical data is backed up automatically and replicated across multiple servers.
- Sensitive data and user information are stored encrypted.
- Media files are stored in secure object storage.
- Regular integrity checks ensure that backups remain consistent and recoverable.
Lost Access
If you cannot access a connected provider, try email login or another connected provider first. If none of these methods is available, request manual verification.
- Contact our support via Discord.
- Provide any verification details requested (e.g., proof of story ownership).
- Account recovery is handled manually for security reasons and may take several days. Keep your Account Settings current to reduce recovery friction.
Best Practices
- Keep your email address current.
- Link a second external provider if you want another sign-in method.
- Keep your 2FA recovery codes in a secure place.
- Never share your login access or story files outside the platform.
- Use only the official Talescape app for authentication.