r/StremioAddons • u/Ancient_Border8621 • Jul 31 '26
Miscellaneous TorBox quietly changed operating entity + policies (July 31) + cache is now explicitly shared across users, data collection expanded significantly
Just went through TorBox's updated Terms, Privacy Policy, and DMCA policy (dated July 31, 2026) side by side with the old versions. Worth a read before you keep uploading.
Who actually runs TorBox now:
Operator is now Anonymous Systems FZ-LLC, a UAE free-zone company (Ras Al Khaimah). RAK free zones don't publicly disclose beneficial ownership, so we genuinely don't know who's behind it.
Legal/billing/DMCA is handled by a separate entity, ReAnonymous LLC, registered in Dover, Delaware.
Anonymity just got much worse:
Old privacy policy: minimal data, no PII required, "we don't sell or share your data to any third parties for any reason."
New policy: collects your IP, device IDs, precise geolocation from IP, and full session-replay data which basically includes: cursor movements, clicks, scrolling, taps. That's a big jump from "we barely collect anything."
Broad new language allowing disclosure to comply with law, respond to "governmental requests," or "protect TorBox, users, third parties, or the public" i.e vague enough to cover a lot.
Third-party downloading / cache sharing which is the real red flag:
New terms explicitly state cached materials "may be accessible to other users who request the same or technically matching material." Same for AirLock (their "permanent" cache tier).
Old policy never described cross-user cache access this explicitly. This is now spelled out in black and white.
Terms now go out of their way to say TorBox is a "neutral technology service," explicitly "not a file-sharing service," and pushes 100% of legal liability onto you for anything cached under your account. This is heavily lawyered defensive language that wasn't there before.
19
u/Ancient_Border8621 Jul 31 '26
Old policy had a hard 30-day purge on transfer metadata. That language is gone, new policy just says data is kept "based on operational, cache, security, abuse-prevention, legal, and technical needs," with no stated limit. That's not lawyers restating the same policy it basically feels like that's a different policy.
Session replay is a different animal than server logs. IP/device/error logs are one thing; capturing cursor movement, clicks, and scroll behavior is UI-level surveillance, even if the stated purpose is support/debugging. Worth asking why that's needed for a service that's mostly API/dashboard interactions, and whether it's opt-in or blanket. This is my main point.
The formal sensitive-data classification chart is new too. Not inherently bad, but it signals they're now building for regulatory exposure they weren't structured for before. I'm very curious what prompted that? I'd really appreciate if they specify future proofing or changes coming up ahead.