Privacy Policy

Last updated 30 September 2026

This page says what Stash, run by Hive Asset Group, LLC ("we", "us") collects when you use Stash, what we do with it, and what you can do about it. The short version: we keep what you give us so we can organise it for you, we send it only to the services that do parts of that work, and we do not sell it, advertise with it, or train AI on it.

What we collect

  • Your account: your email address and a name taken from it. Your password is stored only as a scrypt hash, which cannot be turned back into the password.
  • What you stash: files, photos, notes, links, voice memos, and email you forward to Stash, including its sender and subject.
  • What Stash works out from them: text read out of images and scans, titles, summaries, tags, dates and the facts it finds, and where each thing was filed.
  • What you do in Stash: your spaces and folders, the corrections you make to its filing, your questions in Ask and its answers, and a log of changes so they can be undone.
  • Billing: your plan, and the customer and subscription identifiers Stripe gives us. Stripe holds your card details. We never see them.
  • Technical: our host keeps standard server logs (IP address, browser, the page asked for, the time). We do not add any analytics or tracking of our own.

What we do with it

Run Stash for you: store your things, read them, name them, sort them, make them searchable, answer your questions about them, and take payment if you choose a paid plan. We email you about your account (a password reset, a change to these policies or to your price), and never for marketing unless you have asked us to.

We do not sell your data, we do not use it for advertising, and we do not use it to train AI models.

Who else handles it

These services each do part of the work. Each gets only what it needs for its part.

  • Netlify. Hosts the site and stores your library and files. Also keeps standard server logs (IP address, browser, the page asked for).
  • Stripe. Takes payments. Your card details go to Stripe and never to us.
  • OpenAI. Reads photos, scans and voice memos so they can be searched, and answers questions in Ask. We ask it not to store requests; under its API terms it may keep them for up to 30 days to detect abuse, and it does not train on them.
  • TypeSafe. Decides which space and folder something belongs in, and which name to give it. It receives the item's text (up to about 20,000 characters), its file name, and for forwarded mail the sender and subject.
  • Postmark. Receives the email you forward to your own Stash address, and sends password-reset emails.

These providers are based in the United States, so your data is processed there. We will update this list before adding anyone new.

We will disclose data if the law genuinely requires us to, and will tell you first unless we are legally prevented from doing so.

Cookies

Stash sets only the cookies it needs to work, so there is no cookie banner:

  • stash_session. Keeps you signed in, for up to 30 days.
  • stash_unlock. Used only by the owner of this copy of Stash, who signs in with a passcode instead of an account.

Your choice of light or dark theme is remembered in your own browser and is never sent to us.

How long we keep it

  • Your things stay for as long as your account exists, or until you delete them.
  • Deleting an item moves it to Trash, where you can restore it. Emptying the Trash, or deleting from the Trash, removes it and its files for good.
  • Deleting your account removes your library, every file in it, and your account record from our storage straight away, and cancels any subscription.
  • We keep a nightly backup of each library's database (the text, names and organisation, not the files themselves) for 7 days, so we can recover from a fault. Anything you delete is gone from those backups within 7 days.
  • We keep a record of payment events (which subscription, which plan, when) after an account is deleted, because tax and accounting law requires it. It contains nothing you stashed. Stripe keeps its own payment records under its own policy.
  • Server logs are kept by our host for a limited period under its own policy.

Your rights

Wherever you live, you can:

  • Get a copy of everything: Settings, then Export everything as a zip. It includes every original file and all the data about them.
  • Correct anything: rename, move, edit or delete any item at any time.
  • Delete everything: Settings, then Delete account.
  • Ask us anything about your data, or object to how we use it. Write to support@getstash.cloud. We will answer within 30 days.

If you are in the UK or the European Economic Area you also have the right to complain to your data protection authority, and if you are in California you have the rights the CCPA gives you. We do not sell or share personal information as the CCPA defines those words.

Keeping it safe

Everything travels over encrypted connections. Each account's library is its own database, so one person's queries cannot reach another's. Files are held in private storage and are only served to the account they belong to. Passwords are hashed, and sessions are signed so they cannot be forged.

No system is perfectly secure. If we ever find that your data has been exposed, we will tell you promptly and say what happened.

Children

Stash is not for anyone under 16, and we do not knowingly collect data from them. If you think a child has made an account, tell us and we will delete it.

Changes to this policy

If we change this policy in a way that matters, we will tell you by email or in Stash before the change applies. The date at the top says when it last changed.

Talking to us

Anything about your privacy. Write to support@getstash.cloud.

Stash is run by Hive Asset Group, LLC. Contact: support@getstash.cloud