HashMyWordsOpen app

Legal

Privacy Policy

How HashMyWords handles proof data, optional accounts, security information, support messages and public Hedera records.

Last updated: 11 September 2026

1. What HashMyWords handles

HashMyWords is designed to minimise the amount of original material it receives. The information handled depends on which feature you use.

  • Protect: the source PDF and rebuilt protected PDF are processed locally in your browser. Neither PDF nor either filename is uploaded to HashMyWords. The browser calculates the standard SHA-256 of the exact protected PDF and submits that SHA-256 with proof metadata so it can be recorded publicly on Hedera. Protect references, filenames and sizes shown in locally generated receipts or certificates remain browser-side unless you choose to share those files yourself.
  • File proofs: your browser calculates the standard file SHA-256 locally. The original file and filename are not uploaded to HashMyWords. The standard SHA-256 is submitted with proof metadata and is intentionally recorded publicly on Hedera so it can be reproduced and checked with ordinary SHA-256 tools.
  • Historical file proofs created before the raw-SHA format used a domain-separated derived proof hash rather than publishing the standard file SHA-256. Those earlier proofs remain verifiable under their original format.
  • Public text proofs: the name you provide, the public text, its digital fingerprint, timestamp and Hedera transaction details may be stored and displayed in public search.
  • Private text proofs: the plaintext and a random private salt remain in your browser. HashMyWords receives only the resulting salted SHA-256 hash and proof metadata; the receipt contains the salt needed to reproduce the same hash later.
  • Secret codes: HashMyWords stores only a one-way check value. The original secret code is not stored in recoverable form.
  • Optional accounts: we handle the email address you provide, a salted one-way password hash, account sessions, proof associations, private labels, Collections, Version Chains and share-link settings you choose to create. Verification and password-reset tokens are stored only as protected one-way values.
  • Security and abuse-prevention data: we may process protected browser and network identifiers, rate-limit information and anti-bot verification results needed to protect the service.
  • Contact and report forms: we handle the email address, message, report reason and other information you choose to submit so that we can receive and respond to the request.

2. Why we use this information

We use information to protect and timestamp documents, create and verify proofs, provide optional account features, operate owner-created read-only sharing, display public records, respond to support requests, moderate public content, prevent abuse, maintain security and diagnose service problems.

We do not use private files, protected PDFs or private text for advertising. The files and private plaintext are not uploaded to HashMyWords. Standard SHA-256 values used by current File Proof and Protect workflows are public proof identifiers, not the underlying file contents.

3. Browser-local Protect, file and private-text processing

Protect rebuilds supported PDFs locally in your browser before hashing the exact protected output. The source PDF and rebuilt PDF stay on your device. The standard SHA-256 of the rebuilt PDF and proof metadata are submitted for public timestamping on Hedera. Protect can flatten ordinary form fields and remove interactive or active PDF structures from the rebuilt copy; that transformation occurs locally.

For a current File Proof, the original file stays on your device while its standard SHA-256 is submitted and recorded publicly on Hedera. For Private text, the plaintext and random private salt stay in your browser and only the resulting salted SHA-256 hash is submitted. Historical H1 file proofs continue to use their original derived-hash format.

JSON receipts and PDF proof certificates are generated locally from proof information available in your browser. A JSON receipt can contain a private secret code and should be stored securely. A shareable PDF certificate deliberately excludes the secret code but can contain filenames, standard SHA-256 values and, for Protect, a Protect reference and local source-file metadata, so sharing a certificate discloses those details to the recipient.

4. Hedera records are public and persistent

Hedera is a public distributed ledger. Current H2 File Proof and Protect records intentionally publish the standard SHA-256 of the exact file together with the HashMyWords proof framing and public transaction metadata. Historical H1 proofs publish their earlier derived proof hash. Once a transaction is confirmed, HashMyWords cannot simply rewrite or delete that ledger history.

A public SHA-256 is a fingerprint, not the file itself, but anyone who has a candidate file can calculate its SHA-256 and compare it with the public Hedera value. Publishing the SHA-256 may therefore allow correlation if the same exact file is known elsewhere.

Deleting or changing data in the HashMyWords application cannot necessarily remove or alter a corresponding Hedera transaction or HCS message.

5. Accounts, Collections, Version Chains and sharing

Accounts are optional. New accounts are activated only after email verification. Passwords are stored as salted one-way hashes. Verification links expire after 24 hours; password-reset links expire after 30 minutes, and a completed password reset revokes existing account sessions.

Private labels, Collection names and descriptions, Collection membership, Version Chain names and descriptions, Version Chain membership and share-link settings are HashMyWords account metadata. They are not separate Hedera assertions. Each underlying proof remains independently anchored on Hedera.

Collections and Version Chains are private by default. If you create a read-only share link, a recipient can see the grouping information and included confirmed proof metadata until the link expires or is revoked. Account email addresses, secret codes and original files are not included in shared views. Current H2 file SHA-256 values are public Hedera evidence and may be represented in proof metadata. Private proof labels are excluded unless you deliberately enable them.

6. Cookies, browser storage and anti-bot checks

HashMyWords uses essential browser storage and opaque cookies where needed for account sessions, security and service operation. We do not currently use advertising cookies.

Cloudflare Turnstile is used for human verification on proof-creation workflows and may also be enabled on other public write forms, such as Contact. Cloudflare may process browser, device and network information needed to provide that anti-abuse service under its own privacy terms.

7. Service providers

HashMyWords relies on infrastructure and specialist providers to operate the service. These include hosting and network providers, Hedera network and Mirror Node infrastructure, Cloudflare for security and Turnstile, and Resend for transactional email, including account verification, password recovery and contact-form delivery.

Those providers receive only the information needed for the relevant function. For account email, Resend receives the destination address and the verification or recovery message. For a Contact submission, Resend receives the HashMyWords contact inbox destination, the email address you supplied as the reply-to address and the message you submitted. Current File Proof and Protect workflows publish the standard SHA-256 as part of the Hedera proof; public Mirror Node infrastructure can therefore return that SHA-256, while the original file and protected PDF themselves are not included in the request.

If you choose to upload a protected PDF to an AI service or any other third party after downloading it from HashMyWords Protect, that sharing occurs between you and that third party and is governed by the third party’s own privacy, retention and data-use terms.

8. Retention

We keep information only for as long as reasonably needed for the service, verification, account history, sharing, moderation, security and legal obligations. Unverified pending sign-ups expire after 24 hours and password-reset links after 30 minutes. Used or expired verification and recovery records, expired sessions and security identifiers can be removed under configured retention processes.

Contact messages may remain in the destination support mailbox for as long as reasonably needed to handle the request, maintain service records or meet legal obligations. Public messages may remain available unless moderated or deleted from the HashMyWords application. A confirmed Hedera transaction or HCS message is outside the ordinary application retention cycle and may remain permanently available on the public network.

9. Your choices and rights

You can use the core proof tools without creating an account, choose whether to use Protect before sharing a PDF, choose Public or Private text, decide whether to create share links, revoke active share links and choose whether private proof labels are included in a shared view.

Current File Proof and Protect workflows intentionally publish the file SHA-256 on Hedera. If you do not want an exact file fingerprint to become public and persistent, do not create that proof. Private text uses a separate salted-hash workflow that keeps the plaintext and private salt in your browser.

Depending on where you live, privacy law may give you rights to access, correct, delete, restrict or object to certain processing of personal data. Those rights can be subject to legal exceptions and cannot necessarily alter a public Hedera transaction or HCS message. Use the Contact page for privacy requests.

10. International processing

HashMyWords and its service providers may process information in more than one country. Where applicable privacy law requires safeguards for international transfers, the relevant provider arrangements and legal mechanisms apply to that processing.

11. Security

We use safeguards including one-way password and token hashing, opaque account sessions, rate limits, anti-bot controls, browser security headers and restricted service credentials. Public forms can also use honeypot and rate-limit controls to reduce automated abuse. No internet service can guarantee absolute security, so keep original material, protected PDFs, receipts and secret codes securely.

12. Changes and contact

We may update this policy as HashMyWords changes. The current version and its last-updated date will be published on this page. Questions or privacy requests can be sent through the Contact page.