Menu

Privacy Policy

Last updated: 2026-06-29

This Privacy Policy explains how HashtagPLUS (“we,” “us,” or “our”) collects, uses, and shares information when you use HashtagPLUS (the “Service”) at hashtagplus.com. HashtagPLUS is currently operated by an individual and is not yet incorporated. The Service is intended only for individuals 18 and older (see Section 8).

1. Information We Collect

Information you provide when you register an account:

  • Email address — for sign-in, email verification, and account notifications.
  • Username — your public identifier on the Service.
  • Date of birth — collected to enforce our 18+ age requirement. We store your full date of birth.
  • Password — stored only as a salted bcrypt hash; we never store your plaintext password. (Passwordless magic-link sign-in is also supported, in which case no password is set.)
  • Invite information — if you register through an invite, we record the inviting account and invite code.
  • Optional profile information — display name, bio, headline, website, and similar fields you choose to add.

Information generated by your use of the Service:

  • User-generated content — links you submit, captions, comments, votes, follows, bookmarks, and topic preferences.
  • Derived content — for links you submit, we fetch the page and store an extracted title, excerpt, and metadata, and we generate hashtags (see Section 3 on AI providers).

Information we collect automatically:

  • IP address — used for security, rate limiting, and abuse/spam prevention (including for anonymous posting). Our infrastructure reaches the origin through Cloudflare, and we use the Cloudflare-provided client-IP value rather than the spoofable X-Forwarded-For header by default.
  • Session cookies — set by our authentication layer (NextAuth) to keep you signed in. A theme-preference cookie may also be set.
  • Server logs — standard request logs for operating and securing the Service.

Anonymous users. You can post without an account. We still process IP address and apply abuse-prevention controls to anonymous activity, and we may store a local anonymous identifier in your browser to remember preferences.


2. How We Use Information

We use information to:

  • Operate, maintain, and provide the Service and its features (feeds, posting, voting, following, bookmarks).
  • Verify your email and confirm your eligibility (18+).
  • Send transactional messages (verification emails, password resets, magic-link sign-in, account and security notices).
  • Generate hashtags and extract article metadata for submitted links.
  • Protect the Service: rate limiting, spam/abuse detection, ban enforcement, and security investigations.
  • Comply with law and enforce our Terms of Service and Community Guidelines.

We do not sell your personal information.


3. Third-Party Service Providers (Processors)

We share information with vendors that process it on our behalf, only as needed to provide the Service:

  • Hosting / application platform — processes all application data and logs.
  • Database — stores account and content data.
  • CDN / DNS / network — Cloudflare. Processes request metadata, including IP addresses, at the network edge.
  • Email delivery — Resend, a third-party transactional email API. Transactional mail (email verification and magic-link sign-in messages) is sent via Resend, with an SMTP fallback. Resend processes recipient email addresses and message content for verification and transactional mail.
  • AI providers (hashtag generation) — when hashtags are generated via a hosted AI provider, the extracted article text is sent to that provider to produce hashtags. A local model and a statistical (TF-IDF) fallback may be used instead, in which case no data leaves our infrastructure.

Each provider has its own privacy practices.


4. Legal Bases for Processing

Where required (e.g., under the EU/UK GDPR), our legal bases are: performance of a contract (operating your account and the Service), legitimate interests (security, abuse prevention, and improving the Service), consent (where required, e.g., optional emails), and legal obligation. If you are in a U.S. state with a privacy law (e.g., California/CCPA-CPRA), see Section 7 for your rights; we do not sell or “share” personal information for cross-context behavioral advertising.


5. Cookies and Similar Technologies

  • Essential session cookies — set by NextAuth to authenticate you and keep you signed in. The Service cannot function as intended without them.
  • Preference cookies — e.g., a theme (light/dark) preference.

We do not use third-party advertising or analytics cookies. You can block or delete cookies in your browser, but essential cookies are required to sign in and use account features.


6. Data Retention

  • Account data is retained while your account is active.
  • Account deletion — when you delete your account (or we delete it), we remove or de-identify your personal information within 30 days, except where retention is required by law, needed to resolve disputes, or necessary to enforce our agreements or prevent abuse.
  • Public content you posted may remain visible (and may be retained in de-identified or aggregated form) after account deletion.
  • Security logs and IP data are retained only as long as needed for security and abuse prevention.
  • Email verification, password-reset, and magic-link tokens are short-lived and single-use.

7. Your Rights and Choices (GDPR and CCPA/CPRA)

Depending on where you live, you have rights over your personal information. We honor the rights below for all users regardless of location, to the extent they apply.

For residents of the EU/UK and similar jurisdictions (GDPR-style rights):

  • Access — request a copy of the personal information we hold about you.
  • Correction — request that we fix inaccurate or incomplete information.
  • Deletion (“right to be forgotten”) — request that we delete your personal information.
  • Portability — request an export of your information in a portable format.
  • Objection and restriction — object to or restrict certain processing (e.g., processing based on legitimate interests).
  • Withdraw consent — where processing relies on consent, withdraw it at any time.

For residents of California and other U.S. states with privacy laws (CCPA/CPRA-style rights):

  • Right to know — what personal information we collect, the sources, the purposes, and the categories of third parties with whom we share it.
  • Right to access — a copy of the specific pieces of personal information we have collected about you.
  • Right to correct — request correction of inaccurate personal information.
  • Right to delete — request deletion of your personal information, subject to legal exceptions.
  • Right to opt out of sale/sharing — we do not sell your personal information and we do not “share” it for cross-context behavioral advertising, so there is nothing to opt out of.
  • Right to non-discrimination — you will not be discriminated against for exercising any of these rights.

To exercise any of these rights, contact [email protected]. We will verify your request and respond within the time required by applicable law. You may also unsubscribe from non-essential emails using the link in those emails. An authorized agent may submit a request on your behalf where the law permits.


8. Children / Age (18+)

The Service is not intended for anyone under 18, and we do not knowingly collect personal information from anyone under 18. We enforce an 18+ age gate at registration using your date of birth. If you believe someone under 18 has provided us information, contact [email protected] and we will delete it.


9. Security

We use technical and organizational measures to protect your information, including: salted bcrypt password hashing; transport encryption (HTTPS) in production; single-use, time-limited tokens for verification and password reset; IP-trust hardening (we rely on the Cloudflare edge-provided client IP rather than the spoofable X-Forwarded-For header by default); and rate limiting and abuse controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.


10. International Data Transfers

Your information may be processed in countries other than where you live, including by the providers listed in Section 3. Where required, we rely on appropriate safeguards for cross-border transfers (such as Standard Contractual Clauses).


11. Changes to This Policy

We may update this Privacy Policy. If we make material changes, we will update the effective date above and may provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance.


12. Contact

Privacy questions or data requests: [email protected].