Privacy Policy · Last updated: September 1, 2026
Privacy Policy
HashZyn (“we”, “us”) operates hashzyn.com, a malware scanning service and developer API. This policy explains what we collect, how we use it, and your choices.
Who we are
HashZyn provides hash-first malware scanning for files, URLs, and code snippets, plus a REST API for developers and security teams. Official website: hashzyn.com. Privacy and data requests: support@hashzyn.com.
Information we collect
Account data: email address, authentication identifiers, subscription plan, credit balance, and API key metadata (hashed secrets; we never store full API keys after creation). Scan inputs: SHA-256 hashes, filenames, URLs, short code snippets, and file bytes submitted for scanning (size limits apply). Usage data: scan counts, rate-limit counters, and coarse IP-based quotas for abuse prevention. Support data: messages you send via our contact form or email. Analytics (optional): with your consent, anonymous usage metrics via Google Analytics and optional session analytics.
Scan data and sample handling
We hash files in the browser when possible so known digests can be checked without re-uploading. When you submit an unknown file, it is transmitted to our API and may be analyzed by third-party commercial malware engines and threat intelligence feeds for the duration of the request only. We do not operate a public malware sample archive. File bytes are not retained after the scan completes. We may store non-sensitive scan metadata (verdict, hash, timestamp, engine summaries) to power your account history and public hash reputation pages where applicable.
How we use information
We use collected data to provide and improve the service, authenticate users, enforce plan limits, prevent abuse, respond to support requests, process billing when enabled, and comply with legal obligations. We do not sell personal information.
Third-party processors
We use trusted providers to run HashZyn, including: Supabase (authentication and account storage), commercial malware scanning engines (ephemeral file analysis), threat intelligence feeds, Vercel (website hosting), Render (API hosting), Resend (transactional email), and payment processors when online billing is enabled. These providers process data only as needed to deliver the service.
Cookies and analytics
Essential cookies support sign-in and account sessions. Analytics cookies are optional. You can accept or reject analytics in the cookie banner. Rejecting analytics does not block access to the scanner or API.
Retention
Account data is kept while your account is active. Scan metadata may be retained for service operation and reputation lookup. Uploaded file content is not kept after scanning. You may request account deletion by contacting support@hashzyn.com.
Security
We use industry-standard measures including encrypted transport (HTTPS), hashed API key storage, and access controls on backend systems. No method of transmission or storage is 100% secure; use HashZyn as one layer in your security workflow, not as a sole guarantee.
Your rights
Depending on your location, you may have rights to access, correct, delete, or export personal data, and to object to certain processing. Contact support@hashzyn.com and we will respond within a reasonable time.
Children
HashZyn is a B2B and developer-focused service not directed at children under 16. We do not knowingly collect data from children.
Changes
We may update this policy. Material changes will be posted on this page with an updated date. Continued use after changes constitutes acceptance of the revised policy.
Questions: support@hashzyn.comTerms of ServiceContact us