← Osprey HashCat

Privacy Policy

Effective date: 20 September 2026

This Privacy Policy explains how Osprey Electronics ("we", "us"), operator of the Osprey HashCat platform, collects, uses, discloses, and protects personal data when you use our platform, website, and services (the "Service"). It should be read together with our Terms & Conditions.

1. Data We Collect

Account data

  • Email address, first and last name.
  • Password (stored only as a salted hash) or, for social sign-in, your provider identifier and the profile fields (name, email) shared by Google/Facebook.

Usage & job data

  • Sessions you create (algorithm, attack parameters, timestamps, status, token cost).
  • Hash targets you submit — processed to perform the requested recovery; not retained as target data after session completion beyond minimal audit/billing metadata.

Payment data

  • Token purchases and transaction records. Card payments are handled by Stripe; we do not store full card numbers.

Technical data

  • IP address, browser/user-agent, and timestamps (including for legal-acceptance and security audit logs).

2. How We Use Data

  • To provide, operate, and secure the Service and execute your cracking sessions;
  • To authenticate you and manage your account and token balance;
  • To process payments and prevent fraud;
  • To record your acceptance of legal terms (with timestamp, IP, and user-agent) for compliance;
  • To communicate service-related messages, including email verification codes;
  • To comply with legal obligations and enforce our Terms.

3. Legal Bases (GDPR)

Where the GDPR applies, we rely on: performance of a contract (providing the Service); your consent (e.g. social sign-in, marketing where applicable); legitimate interests (security, fraud prevention, service improvement); and compliance with legal obligations.

4. Sharing & Third Parties

We share personal data only as needed with:

  • Stripe — payment processing;
  • Google / Facebook — if you choose social sign-in (we receive your basic profile and email);
  • Infrastructure and hosting providers — to operate the Service;
  • Authorities — where required by law or to protect rights and safety.

We do not sell your personal data.

5. Data Retention

We retain account and transaction records for as long as your account is active and as required for legal, accounting, and audit purposes. Submitted hash targets are not retained as target data after session completion. You may request deletion of your account (see Your Rights).

6. Security

We use technical and organizational measures to protect personal data, including encrypted transport (HTTPS), hashed passwords, and access controls. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

7. Your Rights

Depending on your location (e.g. EEA/UK under GDPR, California under CCPA/CPRA, Texas under the Texas Data Privacy and Security Act), you may have rights to access, correct, delete, or port your data, to restrict or object to processing, and to withdraw consent. To exercise these rights, contact us at the address below. You may also lodge a complaint with your local data-protection authority.

8. Cookies

We use strictly necessary cookies/local storage to keep you signed in (authentication tokens). We do not use them to track you across other sites. If analytics or marketing cookies are added in the future, we will update this policy and, where required, request consent.

9. International Transfers

Your data may be processed in countries other than your own. Where required, we use appropriate safeguards (such as standard contractual clauses) for such transfers.

10. Children

The Service is not directed to individuals under 18, and we do not knowingly collect their data.

11. Changes

We may update this Policy from time to time. Material changes will be indicated by an updated effective date and, where appropriate, by requesting renewed acceptance.

12. Contact

Privacy questions or requests: [email protected].