Privacy Policy
Effective October 7, 2026
The short version
- We collect what we need to run your chats, calls and file sharing — and nothing for advertising.
- We don't sell your data, share it for advertising, or train AI models on your messages.
- The hasht apps contain no ads, ad SDKs or third-party analytics.
- If you connect an app to a self-hosted server, that server's operator controls your data there, not us.
- You can export or delete your data, and delete your account, at any time.
Contents
- Who we are and what this covers
- Self-hosted servers
- Information we collect
- Voice and video calls
- Device permissions
- How we use information
- How we share information
- How long we keep it
- Security
- Your choices and rights
- Deleting your account
- Children
- International transfers
- Changes to this policy
- Contact us
1. Who we are and what this covers
hasht ("hasht", "we", "us") builds open-source chat software with messaging, file sharing, voice calls and video calls. This policy explains how we handle personal information when you use:
- Hasht Cloud — our hosted chat service at chat.hasht.net and hosted plans we run for teams and communities;
- hasht for iOS and Android (the "hasht-app" mobile apps);
- hasht for macOS, Windows and Linux (the "hasht-desktop" apps); and
- our website at hasht.net.
For Hasht Cloud, hasht is the controller of the personal information described here. Where we run a hosted server on behalf of an organization (for example, a company's workspace on a Business or Enterprise plan), that organization decides who can join and may set its own policies; we process the workspace's content on its behalf.
2. Self-hosted servers
hasht is open source, and anyone can run their own server. Our mobile and desktop apps are clients that connect to whichever server you choose — Hasht Cloud or a self-hosted one.
When you connect to a server someone else runs, your account, messages, files and call signaling are stored and handled by that server's operator, not by us. We have no access to that data, and this policy does not cover it. Ask the server's operator for their privacy policy.
The apps themselves store only the list of servers you've added and your preferences on your device. Sign-in sessions are kept in the app's local storage for each server and are never sent to us. The only hasht-operated services an app may contact while you use a self-hosted server are:
- Push notifications (mobile) — see Push notifications below.
- Update checks (desktop) — the desktop app checks our public GitHub releases for new versions. This request goes to GitHub and includes your IP address and app version; it contains no account information.
3. Information we collect
Account information
When you create a Hasht Cloud account we collect your username, email address and password (stored only as a salted hash). You may optionally add a display name, profile picture, status and other profile details. Profile information is visible to other people on the servers and in the channels you join.
Content you create
We store the content you send so we can deliver it and show you your history: messages, reactions, edits, files, images, voice messages and other attachments, along with the channels, servers and direct conversations you create or join. File metadata (name, size, type and upload time) is stored with each file. Content is visible to the people you share it with.
Contacts and social graph
We store the servers and channels you belong to, the people you message, your roles and permissions, and any users you block. We do not access or upload your phone's address book.
Billing information
If you buy a paid plan, payment is handled by our payment processor. We receive your billing name, email, billing address, plan and transaction history, and the last four digits and expiry of your card — never your full card number.
Usage and technical information
When you use Hasht Cloud our servers automatically record:
- IP address, approximate location derived from it (country/region), and connection times;
- device type, operating system, app or browser version and language;
- security and service logs, such as sign-ins, failed sign-in attempts, API requests and errors.
Diagnostics and crash reports
Hasht Cloud uses Sentry to detect and fix errors and performance problems. When something goes wrong, a diagnostic report may be sent containing the error and stack trace, the page or feature in use, timing information, device, OS and app or browser version, IP address, and an internal user ID so we can follow up on a problem affecting your account. Diagnostic reports are used only to keep the service working; they are not used for advertising or profiling.
Push notifications
If you allow notifications on mobile, your device receives a push token from Apple (APNs) or Google (Firebase Cloud Messaging). We store that token with your account so we can tell you about new messages and incoming calls. Notification contents are delivered through Apple's or Google's push service. When you sign out or turn notifications off, the token is unregistered.
If you use a self-hosted server, that server may deliver its notifications through a hasht relay, because mobile push can only be sent through the app publisher's credentials. The relay receives your device's push token and the notification in transit, forwards it to Apple or Google, and does not keep the notification after delivery.
Website
hasht.net uses no cookies, analytics or tracking. Our host keeps standard server logs (such as IP address and pages requested) for security and reliability. If you email us, we keep the email and your address so we can reply.
4. Voice and video calls
Calls use WebRTC. Audio and video are encrypted in transit between participants using DTLS-SRTP. On Hasht Cloud, calls are routed through our TURN relay so participants never see each other's IP addresses; the relay forwards encrypted media and cannot listen to or watch it.
We do not record calls. We keep call metadata — who took part, when the call started and ended, and its duration — so we can show call history and diagnose connection issues.
5. Device permissions
The apps ask for permissions only when a feature needs them, and you can revoke them at any time in your device settings.
| Permission | Why |
|---|---|
| Microphone | To speak in voice and video calls and record voice messages. On Android, a foreground notification is shown while a call keeps the microphone active in the background. |
| Camera | To turn on your video during a call, and to take photos to share if you choose to. |
| Notifications | To alert you to new messages, mentions and incoming calls. |
| Photos and files | Only the specific items you choose to attach or upload. The apps don't scan your library. |
| Screen sharing (desktop) | Only when you start sharing your screen or a window during a call. |
We never use the microphone or camera outside a call or a recording you start, and we do not collect precise location.
6. How we use information
- To provide the service — delivering messages, files and calls, syncing across your devices, and sending notifications.
- To keep it safe — preventing spam, abuse and fraud, enforcing our terms, and responding to reports.
- To keep it working — diagnosing errors, monitoring performance and capacity, and fixing bugs.
- To communicate with you — account, security, billing and important service notices. We'll send product news only if you opt in, and you can opt out at any time.
- To meet legal obligations — tax and accounting records, and lawful requests.
We do not use your content for advertising, sell or rent personal information, or use your messages, files or calls to train AI models — ours or anyone else's. Optional AI features, where offered, act only on the content you or your workspace choose to give them.
If you are in the EEA, UK or Switzerland, our legal bases are: performing our contract with you (providing the service), our legitimate interests (security, abuse prevention and diagnostics), your consent (such as push notifications and marketing emails, which you can withdraw), and legal obligations.
7. How we share information
We share personal information only in these cases:
- With the people you communicate with. Messages, files, profile details and call participation are shared with the members of the conversations, channels and servers you join.
- With service providers who process data for us under contract and only on our instructions:
- cloud hosting and storage providers, for running Hasht Cloud and storing messages and files;
- Apple and Google, for push notifications;
- Sentry (Functional Software, Inc.), for error and performance diagnostics;
- our payment processor, for paid plans;
- our email provider, for account and service emails.
- With your organization. If you use a workspace run by an organization, its administrators may be able to access, export or delete content in that workspace.
- For legal reasons. When we believe in good faith that the law requires it, or to protect the safety, rights or property of our users, the public or hasht. Where permitted, we will notify you before disclosing your data.
- In a business transfer. If hasht is involved in a merger, acquisition or sale of assets, personal information may transfer as part of it, subject to this policy. We will notify you before that happens.
8. How long we keep it
- Messages and files are kept until you delete them, a server or channel admin deletes them, or your account is deleted. Workspaces on paid plans may set their own retention periods.
- Deleted content is removed from our live systems promptly and purged from backups within 30 days.
- Server and security logs are kept for up to 90 days.
- Diagnostic reports are kept for up to 90 days.
- Billing records are kept for as long as tax and accounting law requires.
9. Security
All traffic between the apps and Hasht Cloud is encrypted in transit with TLS, and call media is encrypted with DTLS-SRTP. Passwords are stored as salted hashes. Access to production systems is restricted to the people who need it to run the service. Because hasht is open source, anyone can inspect the code that handles their data.
No system is perfectly secure. If we learn of a breach affecting your personal information, we will notify you and the relevant authorities as the law requires. To report a vulnerability, email [email protected].
10. Your choices and rights
Wherever you live, you can:
- Access and export your account information and content;
- Correct your profile and account details in settings;
- Delete individual messages and files, or your whole account;
- Turn off notifications and revoke device permissions at any time;
- Object to or restrict certain processing, and withdraw consent you've given.
Depending on where you live (for example under the GDPR, UK GDPR or California's CCPA/CPRA), you may have further rights, including data portability and the right to complain to your local data protection authority. We don't sell or "share" personal information for cross-context behavioral advertising as those terms are defined under California law, and we won't discriminate against you for exercising your rights.
To make a request, email [email protected] from the address on your account. We'll respond within 30 days. For content in an organization's workspace, we may refer you to that organization.
11. Deleting your account
You can delete your Hasht Cloud account at any time:
- In the app or on the web: open Settings → Account → Delete account and confirm.
- By email: write to [email protected] from the address on your account and ask us to delete it.
Deleting your account removes your profile, push tokens, direct messages and files you uploaded from our live systems, and from backups within 30 days. Messages you posted in shared channels are deleted, except where a workspace's administrator has a retention policy that requires keeping them. We keep billing records as required by law and may keep minimal records needed to prevent abuse (for example, of banned accounts).
Uninstalling an app does not delete your account. For an account on a self-hosted server, contact that server's operator.
12. Children
Hasht Cloud is not directed at children under 13, and you must be at least 13 years old (or the minimum age of digital consent in your country, if higher) to create an account. We don't knowingly collect personal information from children under that age. If you believe a child has given us personal information, contact [email protected] and we will delete it.
13. International transfers
We and our service providers may process information in countries other than your own, including the United States. Where we transfer personal information out of the EEA, UK or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
14. Changes to this policy
We'll update this page when our practices change and revise the effective date above. If a change is significant, we'll notify you in the app or by email before it takes effect. Past versions are available in this site's public history on GitHub.
15. Contact us
Questions or requests about privacy: [email protected]
General: [email protected]