hasht

Privacy Policy

Effective October 7, 2026

The short version

Contents

  1. Who we are and what this covers
  2. Self-hosted servers
  3. Information we collect
  4. Voice and video calls
  5. Device permissions
  6. How we use information
  7. How we share information
  8. How long we keep it
  9. Security
  10. Your choices and rights
  11. Deleting your account
  12. Children
  13. International transfers
  14. Changes to this policy
  15. Contact us

1. Who we are and what this covers

hasht ("hasht", "we", "us") builds open-source chat software with messaging, file sharing, voice calls and video calls. This policy explains how we handle personal information when you use:

For Hasht Cloud, hasht is the controller of the personal information described here. Where we run a hosted server on behalf of an organization (for example, a company's workspace on a Business or Enterprise plan), that organization decides who can join and may set its own policies; we process the workspace's content on its behalf.

2. Self-hosted servers

hasht is open source, and anyone can run their own server. Our mobile and desktop apps are clients that connect to whichever server you choose — Hasht Cloud or a self-hosted one.

When you connect to a server someone else runs, your account, messages, files and call signaling are stored and handled by that server's operator, not by us. We have no access to that data, and this policy does not cover it. Ask the server's operator for their privacy policy.

The apps themselves store only the list of servers you've added and your preferences on your device. Sign-in sessions are kept in the app's local storage for each server and are never sent to us. The only hasht-operated services an app may contact while you use a self-hosted server are:

3. Information we collect

Account information

When you create a Hasht Cloud account we collect your username, email address and password (stored only as a salted hash). You may optionally add a display name, profile picture, status and other profile details. Profile information is visible to other people on the servers and in the channels you join.

Content you create

We store the content you send so we can deliver it and show you your history: messages, reactions, edits, files, images, voice messages and other attachments, along with the channels, servers and direct conversations you create or join. File metadata (name, size, type and upload time) is stored with each file. Content is visible to the people you share it with.

Contacts and social graph

We store the servers and channels you belong to, the people you message, your roles and permissions, and any users you block. We do not access or upload your phone's address book.

Billing information

If you buy a paid plan, payment is handled by our payment processor. We receive your billing name, email, billing address, plan and transaction history, and the last four digits and expiry of your card — never your full card number.

Usage and technical information

When you use Hasht Cloud our servers automatically record:

Diagnostics and crash reports

Hasht Cloud uses Sentry to detect and fix errors and performance problems. When something goes wrong, a diagnostic report may be sent containing the error and stack trace, the page or feature in use, timing information, device, OS and app or browser version, IP address, and an internal user ID so we can follow up on a problem affecting your account. Diagnostic reports are used only to keep the service working; they are not used for advertising or profiling.

Push notifications

If you allow notifications on mobile, your device receives a push token from Apple (APNs) or Google (Firebase Cloud Messaging). We store that token with your account so we can tell you about new messages and incoming calls. Notification contents are delivered through Apple's or Google's push service. When you sign out or turn notifications off, the token is unregistered.

If you use a self-hosted server, that server may deliver its notifications through a hasht relay, because mobile push can only be sent through the app publisher's credentials. The relay receives your device's push token and the notification in transit, forwards it to Apple or Google, and does not keep the notification after delivery.

Website

hasht.net uses no cookies, analytics or tracking. Our host keeps standard server logs (such as IP address and pages requested) for security and reliability. If you email us, we keep the email and your address so we can reply.

4. Voice and video calls

Calls use WebRTC. Audio and video are encrypted in transit between participants using DTLS-SRTP. On Hasht Cloud, calls are routed through our TURN relay so participants never see each other's IP addresses; the relay forwards encrypted media and cannot listen to or watch it.

We do not record calls. We keep call metadata — who took part, when the call started and ended, and its duration — so we can show call history and diagnose connection issues.

5. Device permissions

The apps ask for permissions only when a feature needs them, and you can revoke them at any time in your device settings.

PermissionWhy
MicrophoneTo speak in voice and video calls and record voice messages. On Android, a foreground notification is shown while a call keeps the microphone active in the background.
CameraTo turn on your video during a call, and to take photos to share if you choose to.
NotificationsTo alert you to new messages, mentions and incoming calls.
Photos and filesOnly the specific items you choose to attach or upload. The apps don't scan your library.
Screen sharing (desktop)Only when you start sharing your screen or a window during a call.

We never use the microphone or camera outside a call or a recording you start, and we do not collect precise location.

6. How we use information

We do not use your content for advertising, sell or rent personal information, or use your messages, files or calls to train AI models — ours or anyone else's. Optional AI features, where offered, act only on the content you or your workspace choose to give them.

If you are in the EEA, UK or Switzerland, our legal bases are: performing our contract with you (providing the service), our legitimate interests (security, abuse prevention and diagnostics), your consent (such as push notifications and marketing emails, which you can withdraw), and legal obligations.

7. How we share information

We share personal information only in these cases:

8. How long we keep it

9. Security

All traffic between the apps and Hasht Cloud is encrypted in transit with TLS, and call media is encrypted with DTLS-SRTP. Passwords are stored as salted hashes. Access to production systems is restricted to the people who need it to run the service. Because hasht is open source, anyone can inspect the code that handles their data.

No system is perfectly secure. If we learn of a breach affecting your personal information, we will notify you and the relevant authorities as the law requires. To report a vulnerability, email [email protected].

10. Your choices and rights

Wherever you live, you can:

Depending on where you live (for example under the GDPR, UK GDPR or California's CCPA/CPRA), you may have further rights, including data portability and the right to complain to your local data protection authority. We don't sell or "share" personal information for cross-context behavioral advertising as those terms are defined under California law, and we won't discriminate against you for exercising your rights.

To make a request, email [email protected] from the address on your account. We'll respond within 30 days. For content in an organization's workspace, we may refer you to that organization.

11. Deleting your account

You can delete your Hasht Cloud account at any time:

Deleting your account removes your profile, push tokens, direct messages and files you uploaded from our live systems, and from backups within 30 days. Messages you posted in shared channels are deleted, except where a workspace's administrator has a retention policy that requires keeping them. We keep billing records as required by law and may keep minimal records needed to prevent abuse (for example, of banned accounts).

Uninstalling an app does not delete your account. For an account on a self-hosted server, contact that server's operator.

12. Children

Hasht Cloud is not directed at children under 13, and you must be at least 13 years old (or the minimum age of digital consent in your country, if higher) to create an account. We don't knowingly collect personal information from children under that age. If you believe a child has given us personal information, contact [email protected] and we will delete it.

13. International transfers

We and our service providers may process information in countries other than your own, including the United States. Where we transfer personal information out of the EEA, UK or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

14. Changes to this policy

We'll update this page when our practices change and revise the effective date above. If a change is significant, we'll notify you in the app or by email before it takes effect. Past versions are available in this site's public history on GitHub.

15. Contact us

Questions or requests about privacy: [email protected]
General: [email protected]