Privacy Policy
Stash is built by Montedia ("we", "us"). Stash helps you keep an inventory of what's in your storage unit, garage, or home. This policy explains what we collect, why, where it goes, and how to delete it. The short version: we collect what the app needs to work, we don't sell it, and you can delete all of it from inside the app.
1. What we collect
Account
You can use Stash without an account — everything stays on your device. To sync across devices, share a location, or use AI scans, you sign in with Sign in with Apple. We receive a stable, app-specific Apple user identifier, the name you choose to share, and (optionally, possibly relayed through Apple's private relay) your email address. We never see your Apple ID password.
Inventory data
The locations, bins, items, weights, notes, metadata (like a book's ISBN or a shoe size), activity history (who put or took what, and when), and the members of each shared location. This is the product — it's stored so it can sync and be shared with the people you invite.
Photos
Photos you take of bins and items, and the optional background photo for a location. Photos are stored in encrypted object storage (Cloudflare R2) so they appear on your other devices and for members of a shared location. Photos are resized and re-encoded on your device before upload, which removes camera metadata such as GPS location.
Purchases
Stash Pro is sold through Apple's App Store. Apple processes the payment; we receive only the subscription status needed to unlock Pro features. We never see your card details.
Technical data
Standard server logs (IP address, request time, app version) kept for security and debugging for up to 30 days, and the count of AI scans per month to apply the free plan's limit of 10 scans. We do not use third-party analytics or advertising SDKs, and we don't track you across other apps or websites.
2. AI processing of photos
When you run an AI scan, the photos for that scan are sent to an AI model provider to identify the items shown. Today that provider is OpenAI (and, if configured, Google's Gemini models). Photos are sent under API terms that prohibit the provider from using them to train their models, and the model's output (item names, counts, estimated weights, attributes) is returned to your inventory for you to review. Nothing is saved until you tap Save. AI results can be wrong — always check them.
Barcode lookups (books and media) query the Open Library public catalog with the barcode number only — no photo or personal information is sent.
3. How we use your data
- To run the service: sync, sharing, labels, scanning, subscriptions.
- To enforce plan limits and prevent abuse.
- To answer support requests you send us.
- To keep the service secure and fix bugs.
We don't sell personal data, and we don't use your inventory or photos for advertising or to train AI models.
4. Sharing locations with other people
When you share a location, its members see its bins, items, photos, details, and the activity feed, including your display name next to your actions. Invite links work for 7 days and can be used once. The location's owner can remove members; members can leave at any time. If you delete your account, the location's history keeps working for the remaining members with your name replaced by "Former member".
5. Service providers
| Provider | Purpose | Data |
|---|---|---|
| Apple | Sign in, App Store purchases, push of app updates | Apple user ID, subscription status |
| Cloudflare | Photo storage (R2), website hosting | Photos, website traffic logs |
| OpenAI / Google | AI identification of items in photos | Scan photos (no account data) |
| Hosting provider for our API and database | Running the sync service | Account and inventory data |
| Open Library | Barcode lookups | Barcode number |
6. Retention and deletion
Your data is kept as long as your account exists. You can delete your account in the app: Settings → Delete account. This immediately removes your profile, sign-in tokens, and any location that only you belong to (including its photos). Locations you shared are handed to the next member so their inventory survives; your name on past activity becomes "Former member". Deleting a photo, item, bin, or location in the app removes it for everyone in that location. Backups roll off within 30 days.
You can also email privacy@stashstorage.pro to request deletion or a copy of your data.
7. Security
Data is encrypted in transit (TLS) and at rest. Photo uploads and downloads use short-lived signed URLs. Access to a location's data requires membership — there are no public inventories. Sign-in tokens are stored in the iOS Keychain on your device.
8. Children
Stash is not directed at children under 13 (or the equivalent age in your region), and we don't knowingly collect data from them. Family members who join a shared location need their own Apple ID.
9. Your rights
Depending on where you live (for example the EU/EEA, UK, or California) you may have rights to access, correct, export, delete, or restrict the processing of your personal data, and to complain to a supervisory authority. The in-app controls cover most of these; for the rest, email us. We don't discriminate against anyone for exercising their rights.
10. International transfers
Our servers and providers are located in the United States. If you use Stash from elsewhere, your data is transferred to and processed there under appropriate safeguards.
11. Changes
If we make material changes we'll post the new version here and note it in the app. Continued use after the effective date means you accept the update.
12. Contact
Privacy questions: privacy@stashstorage.pro
Everything else: support@stashstorage.pro