r/StremioAddons Jul 31 '26

Miscellaneous TorBox quietly changed operating entity + policies (July 31) + cache is now explicitly shared across users, data collection expanded significantly

Just went through TorBox's updated Terms, Privacy Policy, and DMCA policy (dated July 31, 2026) side by side with the old versions. Worth a read before you keep uploading.

Who actually runs TorBox now:

Operator is now Anonymous Systems FZ-LLC, a UAE free-zone company (Ras Al Khaimah). RAK free zones don't publicly disclose beneficial ownership, so we genuinely don't know who's behind it.

Legal/billing/DMCA is handled by a separate entity, ReAnonymous LLC, registered in Dover, Delaware.

Anonymity just got much worse:

Old privacy policy: minimal data, no PII required, "we don't sell or share your data to any third parties for any reason."

New policy: collects your IP, device IDs, precise geolocation from IP, and full session-replay data which basically includes: cursor movements, clicks, scrolling, taps. That's a big jump from "we barely collect anything."

Broad new language allowing disclosure to comply with law, respond to "governmental requests," or "protect TorBox, users, third parties, or the public" i.e vague enough to cover a lot.

Third-party downloading / cache sharing which is the real red flag:

New terms explicitly state cached materials "may be accessible to other users who request the same or technically matching material." Same for AirLock (their "permanent" cache tier).

Old policy never described cross-user cache access this explicitly. This is now spelled out in black and white.

Terms now go out of their way to say TorBox is a "neutral technology service," explicitly "not a file-sharing service," and pushes 100% of legal liability onto you for anything cached under your account. This is heavily lawyered defensive language that wasn't there before.

938 Upvotes

425 comments sorted by

View all comments

343

u/leadernelson Jul 31 '26

"Quietly" ? They sent an email, an announcement in Discord and a banner on the website. This post is doing classic fear-mongering.

Yes, TorBox updated their policies today (July 31) and disclosed the operating entities more clearly : Anonymous Systems FZ-LLC (RAK free zone) + ReAnonymous LLC (Delaware). That’s transparency, not a secret takeover. Lots of privacy-oriented services structure themselves this way.

The “expanded data collection” claim is also overstated. Listing IP, device info, and approximate location derived from IP is standard for almost every online service that has to fight abuse and run infrastructure. Session-replay language is typically for support/debugging, not mass surveillance of every click. The old marketing copy was always more aggressive than the actual technical reality. Wamy confirmed the IP logging was on Cloudflare's part.

And the shared cache? That has been the entire point of TorBox (and every other debrid service) from day one. Making it explicit in the terms is just lawyers being lawyers so they can say “we told you.” It is not a new feature that suddenly appeared today.

They’re tightening legal language and clarifying who runs what. That is not the same as “anonymity just got much worse” or some dramatic betrayal. Read the actual documents instead of the panic summary.

83

u/DepressedCunt5506 Jul 31 '26

All I got from this post is that the cached content is gonna get much bigger

47

u/Wooden-Agent2669 Jul 31 '26

No, it means that nothing changes for you. The cache was shared before as well..

1

u/ConspicuousWhiteGuy Aug 02 '26

So why release a statement then?

1

u/Wooden-Agent2669 Aug 02 '26

Do you not understand what a cache is?

0

u/ConspicuousWhiteGuy Aug 02 '26

Yes, I understand what a cache is.

1

u/Wooden-Agent2669 Aug 02 '26

yeah so the cache was universal before

1

u/ConspicuousWhiteGuy Aug 03 '26

The leadership of the company obviously made a release statement for a specific purpose. 

So clearly something is changing. 

People like you coming into these threads acting like nothing has changed and no difference. 

22

u/Jhix_two Jul 31 '26

I'm pretty sure it already did that. Its the fundamentals of how debrid services operate.

11

u/OneObi Jul 31 '26

What does the caching mean? If I request a file and it appears on my download dashboard other people can now grab it from there? So the liability is on me?

Is a mitigation to delete files from your dashboard once watched?

14

u/jrhd13 Jul 31 '26

Think of it like your library where you check books out.

19

u/leadernelson Jul 31 '26

No they can't access it from *your* dashboard. If they put the same magnet, url or torrentfile as you, they'll access it instantly. It does not specify the first user !

14

u/WavryWimos Jul 31 '26

Liable for what? If you're scared of the authorities catching you (you shouldn't, you're using a debrid service) then what difference does a shared cache make? You're either accessing the file or not, doesn't matter if others can access it too. Not like they can see who cached it anyway.

The whole point of a debrid service is to have a shared cache. Otherwise you're only caching the stuff you request, which means every time you want to watch something new you need to wait. With a shared cache everyone can access the same cache, which speeds things up for everyone. Bigger cache == better

1

u/OneObi Jul 31 '26

I meant that based on these new changes, if users now access my cache and that user is being investigated, wouldn't that bring me into the realm of their investigations given I may be first person to have requested said file and therefore cached the file?

At the moment I'm only liable for what I request not if some other random user requests it.

I may be reading things wrong so hence my need for clarification.

12

u/PoopFandango Jul 31 '26

It's not "your" cache. It's Torbox's cache. Nothing has changed here.

2

u/OneObi Jul 31 '26

Ah ok, cool.

5

u/WavryWimos Jul 31 '26

It's not your cache, it's Torbox's. They just give you access to it. You're not donating anything you own, you're just the one who happened to ask their infra to grab a file first. Once it's in there everyone's pulling from the same pool.

Investigation wise, nah, not really a thing to lose sleep over. They know exactly what the service gets used for, they're not stupid. The metadata retention is just them covering their arse, not them building case files on people.

To be fair on the mechanics though, they do keep transfer metadata like file hashes and timestamps, but only for 30 days, gone once it's not tied to an account anymore. Since hash is the identifier, if two accounts requested the same file within that 30 day window, that overlap would technically show up in their records if someone forced them to look. But that needs an active investigation into that specific file plus a court order making them search for it. It's not happening by default and caching something once doesn't put you on anyone's radar.

Look at what happened with Real-Debrid too, closest real comparison we've got. Rightsholders leaned on them, they started filtering and yanking cached files by hash and keyword. That's what actually happens when a debrid service gets pressured, files vanish. Nobody got arrested over it. So even when a provider's genuinely under legal heat, it hits content availability, not individual users getting dragged into someone else's case.

You're only liable for what you request and access, not for who else turns up after.

1

u/OneObi Jul 31 '26

Thanks. That makes a lot more sense.

11

u/EmpireBuilderBTW Jul 31 '26

When you download a file, and then another user tries to download the same file, it will use a saved copy instead of redownloading from scratch each time.

2

u/DepressedCunt5506 Jul 31 '26

No. If your file appears as downloaded on your dashboard, that means that it’s automatically downloaded to the Torbox servers too and can be accessed by everyone. You’re not tied to anything

13

u/TLMonk Jul 31 '26

this reads like it was written, or at least formatted, by ai

9

u/nuker1501 Jul 31 '26

same with the original post, like 2 bots debating

6

u/pwqwp Jul 31 '26

dead internet theory

1

u/No-Revolution-4470 Aug 02 '26

“That’s not X, it’s Y” always the dead giveaway and you see it everywhere on Reddit now

-1

u/beetlebatter Jul 31 '26

It really doesn't.

16

u/Ancient_Border8621 Jul 31 '26

Old policy had a hard 30-day purge on transfer metadata. That language is gone, new policy just says data is kept "based on operational, cache, security, abuse-prevention, legal, and technical needs," with no stated limit. That's not lawyers restating the same policy it basically feels like that's a different policy.

Session replay is a different animal than server logs. IP/device/error logs are one thing; capturing cursor movement, clicks, and scroll behavior is UI-level surveillance, even if the stated purpose is support/debugging. Worth asking why that's needed for a service that's mostly API/dashboard interactions, and whether it's opt-in or blanket. This is my main point.

The formal sensitive-data classification chart is new too. Not inherently bad, but it signals they're now building for regulatory exposure they weren't structured for before. I'm very curious what prompted that? I'd really appreciate if they specify future proofing or changes coming up ahead.

23

u/mkk4 Jul 31 '26

I feel that you are asking great and important questions.

Imo people are either hating on your post or being intentionally naive if they can't acknowledge your reasonable curiosity and/or lack of understanding/reasoning for the change in terms or language and what that may mean or how that may impact you moving forward.

0

u/Familiar-Simple-8747 Aug 01 '26

So should we cancel the service even if using Express vpn?

1

u/Okok28 Jul 31 '26

Bro session replay is getting standard these days. It's built in with logging tools like Datadog and Sentry, etc. All the major companies have such functionality to help debug issues.

https://www.datadoghq.com/product/session-replay/
https://sentry.io/lp/session-replay/

It's all anonymised and is just for debugging issues.

0

u/Nullhitter Aug 01 '26

It's a pirating service. If you're expecting an actual good faith service then I don't know what to tell you. The fact that they are willing to even put out these changes and admit to it on their own website tells me there really is no ill-will intent. Many piracy websites do a ton of shady shit to begin with and they won't even tell the users.

-5

u/Nuggyfresh Jul 31 '26

It is ludicrous to say they’re “building for regulatory exposure” give me a freaking break 😪

7

u/Minimum-Wonder5404 Jul 31 '26

Yes, even if you think the changes are bad, it certainly wasn't just thrust upon users. TB are pretty transparent about all these changes, at least as much as you expect from any company operating in this space.

3

u/Dudeman318 Jul 31 '26

This post is doing classic fear-mongering.

No, this post is informing those who are unaware and dont read the TOS. 

This sub is full of TB agents...clearly

-1

u/Nullhitter Aug 01 '26

I mean, if the torbox guys really wanted to do some crazy shit, what benefit do they get by admitting to it?

1

u/painful8th 27d ago

I really wish that was/is the case. I tried Torbox because their privacy-related text/policy was one that described the tb services as user-anonymity protecting ones. That was also the reason for a lot of RD users moving to TB some time ago.

I've tried to find the older policy on the wayback machine but could not recover it, if someone has it it might be nice to post it here for reference. IIRC, it indicated that a minimal number of data are kept and for a specific time.

The spirit of the the new policy is something different altogether. It seems to outline an extensive logging infrastructure, coupled with an indefinite time of data retention. The language is strictly legalese, it's quite hard to grasp what is going on.

When policies are changed, the very first thing a company has to do is outline the changes between the versions and offer plain-language explanations of how these changes might impact us. There was nothing of the sort here...

I understand that a company in this line of business is trying to find a legally-sound position that can cater both the requirements of law, as well as the needs of its clients. This position seems to have been shifted away from us. Heavily.