PRIVACY NOTICE
Privacy
This notice explains the information Hashnab handles to run search, accounts, security controls, connected-provider features, and the public API.
Effective August 26, 2026
1. Information Hashnab handles
The service can handle the following categories of information:
- Account data: name, email address, verification and recovery state, and timestamps associated with your account.
- Authentication and security data: session records and cookies, session expiry, and—when available—IP address and user-agent information. API keys are stored as one-way hashes; the full secret is returned when the key is created and is not available from the management list afterward.
- Connected-provider data: provider name, credential label and status, authorization state, limited provider metadata, and the credentials or tokens needed for supported provider calls. Credentials and tokens persisted through Hashnab's supported backend credential flows are encrypted at rest.
- Your activity and preferences: saved titles, filter preferences, search operations and cursors, API-key usage details, selected releases, debrid jobs, and provider-library metadata needed to provide requested features.
- Index and catalog records: title identifiers and metadata, release names, info hashes, file-manifest metadata, provenance, and observed provider availability. Some of this is shared index data rather than account-specific data.
- Operational data: request timing, rate-limit state, health information, errors, and security or abuse signals needed to operate and protect the service.
3. How information is used
Hashnab uses the information above to:
- authenticate users, maintain sessions, and deliver account security messages;
- search, rank, cache, and explain catalog and release results;
- remember preferences and saved titles;
- check debrid availability, submit requested provider actions, and synchronize library metadata;
- enforce scopes and rate limits, investigate failures, and protect the service; and
- maintain, debug, and improve service reliability.
4. Third-party services and disclosures
Hashnab sends data to metadata, index, debrid, authentication, email, or infrastructure services only as needed for the feature or operation involved. A provider request can reveal the requested identifier or release, your provider account, and ordinary network metadata to that provider. Those services apply their own terms and privacy practices.
Information may also be disclosed when reasonably necessary to protect users or the service, investigate abuse or security incidents, or comply with a valid legal obligation.
5. Retention and your controls
Retention depends on the record and why it exists. Some search operations, snapshots, observations, caches, authorization attempts, and completed mail records expire or are cleaned automatically. Account records, saved library items, preferences, provider connections, API-key records, and related history can remain while they are needed to run those features or meet operational, security, or legal needs.
Available controls let you remove saved titles, change preferences, revoke supported provider credentials, revoke API keys, and end sessions. Hashnab does not currently publish a self-service account-deletion mechanism. To ask about account data or deletion, use the Discord contact below to arrange a private support channel.
6. Security
Hashnab uses technical controls intended to limit access to account data and secrets. API keys are hashed at rest, and supported persisted provider credentials and tokens are encrypted at rest. Access checks, scoped keys, session controls, and request limits add further protection. No storage or transmission system can be guaranteed perfectly secure, so revoke exposed secrets promptly and report suspected account compromise.
7. Changes to this notice
This notice may be updated as Hashnab, its data handling, or its integrations change. The effective date at the top identifies the version currently published here.