I asked which “hash” they used and whether passwords were salted. I have not heard back yet.
—
On August 3, an attacker gained unauthorized access to Metabase, the analytics service we use to see how Tally is used. Through that they reached your email address, and your password as a cryptographic hash. A hash is one-way, so it can't be turned back into your password. They didn't reach your forms, or the answers people submitted to them. Those are stored separately.
colesantiago•56m ago
What other data did the attackers get other than the email?