hudr.net hudr.net

Privacy Policy

Last updated 7 August 2026

This is the plain-English version of what hudr.net knows about you, why we hold it, who else gets to see it, how long we keep it, and what you can do about it. It covers the website and the hudr.net mobile app, and it is the page the data we declare to app stores is written from. Where the honest answer is awkward — every page you load tells Google your IP address; deleting your account takes it off hudr.net but does not wipe our database — we say so here rather than bury it.

The short version

Six things worth knowing before the detail. Each one is explained in full further down.

  • You delete your own account, and you cannot undo it. It signs you out on every device and takes your profile, posts, comments and followers off hudr.net. What stays behind afterwards is listed in deleting your account, in full.
  • We keep a rolling device and location log. While you are signed in we write one row per device, IP address and day, with your city on it. Rows are deleted automatically after 30 days.
  • Google sees every visitor. Our typefaces load from Google's servers, so Google gets the IP address of everyone who opens a hudr.net page — signed in or not.
  • Direct messages are not end-to-end encrypted. There is an internal read-only tool that lets an administrator open them.
  • We do not sell personal information. There is no third-party ad network, no data broker and no advertising tracker on our pages, and the mobile app ships no analytics or crash-reporting SDK.
  • Most of your profile is public to anyone on the internet, including search engines. Your email address, phone number and birth date are not, unless you switch them on.

Who this covers

This policy applies to the hudr.net website and the hudr.net mobile app (“we”, “us”). It covers everyone who uses the service, not only members: some of what is described below happens for logged-out visitors, and some of it happens to people who have never been to hudr.net at all, because our review and post embeds run on other people's websites.

hudr.net is operated by Hudr.net, of India. That company is the one responsible for the data described here.

We have not appointed a data protection officer, we hold no privacy certification, and we are not going to claim either. If that ever changes, this page changes with it.

What we collect

In categories: account details, profile information you add, the content you create, messages, activity on the service, device, network and approximate location, payment records (never card numbers), and support and report messages. Each one is below, with why we have it. There is nothing collected that is not on this page.

When you sign up

Signing up asks for an email address and a password. We email you a 6-digit code, and once you enter it you choose a name and a username. That is the whole of it — no date of birth, no phone number, no address book.

Until you confirm your email, your details sit in a pending-confirmation record: the code and your password are both stored hashed (bcrypt), the code expires after 30 minutes, and the plaintext password is never written down anywhere. Once your account exists, the password stays hashed for its whole life. In plain terms: nobody at hudr.net can read your password, not even to help you.

What you choose to add later

Everything on your profile is added by you:

  • About you — name, username, profile and cover photos, headline and bio.
  • Where and who — country and city, gender, birth date, phone number, links, badges.
  • How the app looks — language and theme.
  • Professional sections — work history, education, skills, projects.
  • What you are interested in — the topics you pick, which the feed uses.

Setting up a profile on the web asks for a birth date. If you add a phone number we send a one-time code to it by SMS to check it is yours. Your email address, phone number and birth date are private by default; showing any of them on your profile is a switch you have to turn on.

What you create

Posts and the media in them — text, photos, video and reels, audio, documents, polls and GIFs; stories; comments and reactions; direct messages and their attachments; communities you run or join; job listings, and job applications including any CV or document you attach to one; reviews you write about other members; and ads or boosts you buy. We store what you upload and the technical details that come with it — file type, size, and for video the duration.

What we record while you use it

  • Activity — what you look at, like, follow, search for and bookmark, so the feed and search can be ranked and so counters work.
  • Reel watch time — for reels, how long you watched each one. Duration is measured server-side, not taken from your browser, and it feeds the distribution algorithm. These raw watch events are deleted after 30 days.
  • Ad and post measurement — that a sponsored item was shown or clicked, and that a post or story was viewed, so counters and advertiser totals work. Advertisers get numbers, never a list of who saw what.
  • Sessions and devices — your active sign-ins, so you can see them and sign them out.
  • Device and location records — continuous, and important enough to get its own section below, because it is the most identifying thing we hold.

Your signup IP address, kept permanently

The IP address you registered from is stamped onto your account record at the moment it is created. Unlike the 30-day log below, it is never refreshed and never pruned. It lives for as long as the account does. It exists so that abuse and mass-registration can be traced back after the fact.

Changes to your email or phone number

When you change your email address or phone number we keep a record of the old value and the new one, with the date. This is what an account-takeover dispute is settled from (“someone changed my email in March”). We keep it for 365 days, then it is deleted.

In the hudr.net mobile app

The app collects the same things the website does, plus two that are specific to a phone:

  • A push token. If you allow notifications, the operating system gives us a device token. We store the token, the platform (Android or iOS), the app version and when it was last used, so we can send you a notification. Signing out deletes it.
  • A device label — the phone model, shown to you in your list of signed-in devices so you can recognise a session and end it.

The app asks for photo and file access when you attach something, microphone access when you record audio, and notification permission for push. It does not ask for GPS location and does not read your contacts; the approximate location described below comes from your IP address, on the website and in the app alike. Your sign-in token is held in the phone's secure storage. There is no analytics SDK, no crash-reporting SDK and no advertising SDK in the app.

Money

Every account has a wallet. We store its balance and the transactions in and out of it.

  • Adding funds. Payment is taken by the payment provider we have enabled — this build supports Stripe, PayPal, YooKassa and RoboKassa, and the checkout page tells you which one you are on. Your card or payment-account details are entered on their page, not ours. We never see and never store a card number. We receive the result of the payment and the reference for it.
  • What the wallet pays for. Ads and boosts, a verification badge, and balance sent to another member. Joining a community is free. We keep the record of each purchase. What is charged, and what can and cannot be refunded, is on the payments and refunds page.
  • Getting paid out. Creator earnings accrue against your account and are credited to your wallet monthly. To withdraw, you fill in a cashout request with the payout method and the payout details you want to be paid into — an account number, a wallet address, whatever the method needs. You type that in yourself, it is stored on the request, and a hudr.net administrator reads it in order to make the payment.

If you apply for verification

A personal verification badge can be bought from your wallet balance, or applied for by submitting links to your profiles on other platforms plus an optional note, which our team reads. Company verification asks for an official company email address, optionally a registration number, and a supporting document you upload. See the verification rules for what actually happens to an application.

If you sign in with Google

Using the Google button means Google tells us your name, email address and profile picture, and tells Google that you signed in to hudr.net. We copy the picture once, to use as your avatar. We do not get your Google password or anything else in your Google account.

When you write to us, or report something

  • Support and contact messages — the name, email address, subject and message you send, the category you pick, and the IP address it came from. If you are signed in, it is linked to your account.
  • Reports — what you reported, the reason you chose and any comment you added, stored against your account so that the same item cannot be reported by you twice and so that abuse of the report button can be dealt with. The person you reported is not told who reported them.

If you tell us why you are leaving

The leave-a-message box on the account-deletion screen is optional, and if you use it we save the message together with a snapshot of your username, name, email address, phone number, signup IP address, browser User-Agent, join date and follower counts. That snapshot outlives the deletion. Leave the box empty and none of it is written.

The device and location log

This is the part most privacy policies describe as “we may collect device information”. Here is what it actually is.

While you are signed in, a browser or app that is simply open checks in with us at most once every five minutes. When it does, we write one record per account, device, IP address and calendar day, with a counter for the repeats. It holds:

  • Your IP address.
  • Your User-Agent — the full identification string your browser or app sends.
  • A device fingerprint hash derived from that User-Agent.
  • Your software — operating system and version, browser and version, and whether the device is a phone or a desktop.
  • Where the IP address is — by looking it up with ipinfo.io: country, region, city, time zone and network (ASN). This is an approximate location from an address, not GPS.

This is a history, not a login record. An account that signed in once months ago and has been left open still produces one row per day, per device, per address. If you are signed in on your phone on mobile data and on a laptop at the office, that is two rows a day, each with a city on it.

It is kept for 30 days and then deleted. A nightly job removes anything older, and the code that writes the log also prunes it occasionally, so the 30 days hold even if the scheduler stops running.

It is for looking at, never for acting automatically. Nothing in signing up, signing in or serving a request reads this log. It cannot rate-limit you, lock you out, or refuse a registration because other accounts share your address. Administrators read it to spot fake-account rings, and any action that follows is a human one you can appeal.

Private and reserved IP addresses are never sent for a location lookup, and results are cached, so ipinfo.io is asked about an address once rather than on every check-in.

Why we use it

  • To run your account — signing you in, keeping you signed in, showing your profile, sending the emails and SMS codes the service depends on.
  • To deliver the features you use — feed, reels, stories, messages, communities, jobs, reviews, wallet and payouts.
  • To notify you — sending the push notifications you allowed, to the device token you gave us.
  • To rank and recommend — what appears in your feed, which reels travel further, who is suggested to you. Reel watch time, your interests and your own country are inputs to this.
  • To keep the place usable — checking reels, and other new posts while post review is switched on, before they reach the public feed; reviewing what is reported; finding spam and fake-account networks; enforcing our rules; and defending against attacks.
  • To handle money — taking payment, crediting earnings, paying out, and keeping the records those require.
  • To answer you — support requests, appeals and verification applications.
  • To sell advertising — see below; this is first-party only.

Advertising on hudr.net is bought from us directly. Advertisers get counts — impressions, clicks, spend — not your identity and not a list of who saw what. There is no third-party ad network, no data broker, and no advertising tracker embedded in our pages. We do not sell personal information, and we do not use it to build profiles for anyone else.

If you live somewhere whose law works this way, these are the grounds we rely on:

  • Running your account and delivering the features you asked for — performance of our contract with you.
  • Ranking, recommendations and product measurement — our legitimate interest in a service that works.
  • The device and location log, the permanent signup IP address, content review and anti-abuse work — our legitimate interest in keeping the platform free of illegal content, fraud and fake-account networks.
  • Phone verification, push notifications and marketing email you have opted into — your consent, which you can withdraw.
  • Payment and payout records, and responding to lawful requests — legal obligation.

In plain terms: most of it is “the service does not work without it”, some of it is “we think it is fair, and you may object”, a little is “you said yes and can say no again”, and the rest is “the law requires it”. Where we rely on a legitimate interest, you can object — use the contact page and tell us which processing and why.

What is public by default

hudr.net is a public network. Unless you have restricted it, the following is visible to anyone on the internet, signed in or not, and can be indexed by search engines:

  • Your profile — name, username, photos, headline, bio, badges, the professional sections you filled in, and your follower and following counts.
  • What you post — posts, reels, comments and reactions, and the communities you post in.
  • What you list — job posts.
  • Reviewsreviews written about you, and reviews you write about other people, along with your rating.
  • Stories — for the 24 hours they exist.

Your email address, phone number, birth date and exact location are private unless you switch them on. You can also limit who may message you, who sees your online status, and whether you appear in search. Deleting a post takes it off hudr.net immediately — it stops being visible to anyone, everywhere, at once. We can put one back if you deleted it by mistake, or if it is the subject of a report we are still working on.

Anything public can be screenshotted, copied or archived by other people. We cannot undo that, and neither can you.

Embeds on other people's websites

Two hudr.net features are designed to run inside somebody else's web page:

  • The reviews widget. A member can put their hudr.net rating on their own website. It shows only published reviews, it never touches your session, it sets nothing and it counts nothing. It loads no fonts and no external files at all — at most one image, the profile's avatar, from us. It is the one surface here built to be worthless to the site hosting it.
  • Post embeds. A single post can be embedded on another site. This one does load our web fonts from Google (below), so viewing a page with an embedded post tells Google your IP address and browser, even if you have never used hudr.net.

The site hosting an embed also gets its own server logs of your visit, under its own privacy policy, not ours.

Direct messages

Messages are stored on our servers and are not end-to-end encrypted. In plain terms: hudr.net administrators can read them. There is an internal tool that shows an administrator a member's conversations and full message threads. It is read-only, it is limited to administrator accounts, and it is used for abuse and safety investigations — but it exists, and you should know that before you type something sensitive.

If someone you are not connected to messages you, it arrives as a message request rather than in your inbox, and they cannot reach you again unless you accept. Attachments you send are stored the same way any other media is. You can mute or block the other account, and you can report the conversation or the person.

GIFs are the one thing in a message that is not hosted by us: they are loaded straight from Giphy's servers. That means Giphy sees the IP address of everyone who views a GIF, including inside a private conversation. Searching for a GIF is different — the search runs through our server, so your search terms go from us to Giphy, not from your browser.

Who else receives your data

We use a small number of outside services. This is the complete list, what each one actually gets, and why:

  • Google Fonts — gets the IP address, browser User-Agent and referring page of every visitor to a hudr.net web page: signed in, signed out, or just looking at a post embed on a stranger's website. Why: our typefaces are loaded from Google's servers on every page.
  • Giphy — gets the IP address and browser of anyone who views a GIF, including in a private message. Separately, our server sends Giphy the words you type into the GIF search; your browser does not talk to Giphy for searches. Why: GIFs are shown from Giphy's own network rather than copied to ours.
  • Amazon S3 — gets the files you upload (photos, videos, documents, avatars) and the requests to fetch them. Why: media storage and delivery.
  • Firebase Cloud Messaging (Google) and Apple Push Notification service — get your device push token and the notification we are asking them to deliver, which includes the text you see on the lock screen. Why: there is no other way to push a notification to a phone.
  • Amazon SNS — gets your phone number and the one-time code, when you verify a number or use phone sign-in. Why: sending the SMS.
  • Our email provider (ElasticEmail, over SMTP) — gets your email address and the contents of the emails we send you: confirmation codes, notifications, security alerts. Why: delivering email.
  • ipinfo.io — gets IP addresses, sent one at a time to be looked up. It is not told which account the address belongs to. Why: turning an IP address into a country, region, city, time zone and network for the security log.
  • Google (sign-in) — only if you use the Google button: it is told that you are signing in to hudr.net. In return it gives us your name, email address and profile picture. Why: signing you in without a separate password.
  • The payment provider on your checkout page (Stripe, PayPal, YooKassa or RoboKassa) — gets whatever you enter on their payment page, including card details. We do not see it. Why: taking payment and telling us whether it succeeded.

We also disclose information when the law requires it, when we need to establish or defend a legal claim, or when there is a genuine risk to someone's life or safety — which includes reporting child sexual abuse material to the authorities. If a business transfer ever moves the service to another owner, your data moves with it and this page will say so before it happens.

These providers operate internationally, so your data is processed outside your country — for most of them, in the United States. By using hudr.net you accept that your data is handled in those countries, whose data protection laws may differ from the ones where you live.

How long we keep it

  • Your account, profile and everything you posted — for as long as the account exists. What happens to it when you delete the account is in the next section.
  • Device and location log (IP, User-Agent, device hash, city, network) — 30 days, then deleted automatically overnight.
  • Reel watch events30 days, then deleted.
  • Email and phone change history (old and new values) — 365 days, then deleted.
  • Stories24 hours.
  • Push device token — until you sign out on that device, turn notifications off, or the token stops working.
  • The IP address you signed up from — as long as the account exists; it is never pruned.
  • Unconfirmed signup records (hashed code and password) — the code expires in 30 minutes.
  • Reports, and support and contact messages — kept after they are dealt with, so that a repeat offender or a repeat complaint can be recognised.
  • Payment, earning and payout records — as long as we need them for accounting, tax and to answer a dispute or chargeback. These are not deleted when an account is.

Your choices

  • Correct anything. Every field on your profile is editable in Settings, at any time, on the web and in the app.
  • Control what is visible. Privacy settings cover your email address, phone number, birth date, country, city, gender, online status, last-seen time and whether you appear in search. Separate settings control who can follow you, who can send you a direct message, who can reply to your stories, who can add you to a group, who can @mention you, who can send you money, and whether other people see that you are online. There is no site-wide “who can comment” setting — comments are controlled per post, by the author, from the post itself.
  • Block, mute and report. You can block or mute an account, mute a conversation, turn comments off on your own post, and report a post, reel, photo, video, poll, story, person, community, group chat or review from the menu on it. What is and is not allowed, and what happens to a report, is in the community guidelines.
  • End sessions. Settings lists the devices signed in to your account and lets you sign them out. That takes effect on their next request, not five minutes later, and it revokes app tokens and “remember me” cookies too.
  • Turn off notifications. Notification settings control which emails and pushes we send. Security and account emails cannot be switched off. Turning push off in your phone's settings stops them regardless.
  • Delete individual content. Posts, comments, messages, listings and stories can be removed one by one.
  • Get a copy of your data. There is no self-service export button today. Ask us through the contact page from your account's email address and we will put a copy together for you.
  • Object, restrict, or complain. Same route. If your country has a data protection authority, you are entitled to complain to it, and you do not need our permission to do so.

Deleting your account

You do this yourself. You do not have to ask us, and we do not have to approve it.

Where: SettingsAccount actionsDelete account. It is the same account whether you signed up on the web or in the app, so deleting it there deletes it everywhere, including on your phone. If you are on the app, open https://hudr.net/data-deletion in a browser and sign in with the same account. You confirm with your password; the message box is optional.

What it does: you are signed out on every device, your app tokens and sessions are revoked, and your profile, posts, reels, comments, stories, communities and follower list stop being visible to anyone — on hudr.net, to logged-out visitors and to search engines. You cannot undo this yourself.

What is still held after you delete

Deleting takes the account off hudr.net; it is not an instant wipe of every row in our database, and we are not going to pretend otherwise. Afterwards:

  • The account record and the content attached to it are retained in a closed state, not visible to anyone using hudr.net. They are retained so that a deleted account cannot be used to escape a ban, a report, a chargeback or a payout dispute.
  • Payment, earning, payout and tax records are kept, as accounting and dispute rules require.
  • The optional leaving message, and the snapshot of your details saved with it, is kept. Leave that box empty and it is never written.
  • Reports you filed about other people stay in the report queue, so cases are not lost when a reporter leaves.
  • The 30-day device log and the 365-day contact-change history age out on their own schedule and are then gone.
  • Messages you sent remain in the other person's conversation, in the same way an email you sent stays in the recipient's inbox.

Copies that other people made while your content was public — screenshots, reposts, search engine caches — are outside our control, and outside yours.

Cookies and browser storage

We use cookies to sign you in and protect forms, and browser storage to remember things like your theme and language. There is also a setting that lets a site-wide measurement snippet be added to every page; if one is ever in use, it can set its own cookies and see your visit, and it will be named on the Cookies Policy, which is where the full detail lives. The mobile app does not use cookies for any of this; it holds a sign-in token in the phone's secure storage instead.

Children

You must be at least 13 years old to use hudr.net. If the law where you live sets a higher age for using a service like this without a parent's permission, that higher age applies to you.

We do not ask your date of birth when you sign up, so we cannot verify age at the door — we rely on reports. If we find out that an account belongs to someone below the minimum age, we remove it and delete what we hold.

Child sexual abuse and exploitation material is forbidden on hudr.net, without exception. Posts, reels, photos, videos, polls, stories, people and communities all carry a report option with a child-safety reason on it. Content of that kind is removed, the account is terminated, and it is reported to the authorities. Our child safety standards set this out in full. If you believe a child has given us information, or you have seen something of this kind and cannot report it in the app, tell us through the contact page or at [email protected].

Security

Traffic is encrypted in transit. Passwords are stored hashed with bcrypt and cannot be read back, by us or by anyone who obtained the database. Two-factor authentication is available in Settings, and sign-in notifications can be turned on. Password checks, account deletion and other sensitive endpoints are rate-limited, and administrator access is restricted to administrator accounts.

Card details never reach us. Payment happens on the payment provider's own page; we receive the outcome and a reference, and we do not see, store or transmit card numbers.

What we do not claim: messages are not end-to-end encrypted, uploaded files are not encrypted with a key only you hold, and no system is perfectly secure. If a breach ever affects you, we will tell you and any regulator we are required to tell.

Changes to this policy

When we change this page we update the date at the top. If a change materially affects what we collect or who receives it, we will say so in the product rather than relying on you to re-read the page. Continuing to use hudr.net after a change takes effect means the updated policy applies to you.

Contact us

Questions about this policy, or a request for a copy of your data: use the contact page, or email [email protected] . Please write from the email address on the account, so we can tell it is you. Deleting your account is not one of the things you need us for — that is in Settings.

The company responsible is Hudr.net, India. Any dispute about this policy is governed by the law of India.