What the Stash app collects, why, where it is stored, and how you can delete it. It covers both roles: the owner who catalogs and lends, and the borrower who requests an item from a web link.
The short version
No tracking. No advertising identifier (IDFA). No App Tracking Transparency prompt, because there is nothing to track. No third-party analytics or advertising SDKs. We do not sell your data, and we do not share it with third parties for their own purposes.
Everything below is collected only to provide app functionality. Each item is linked to your use of the app, and none of it is used to track you across other apps or websites.
That is the complete list. It matches the iOS app's PrivacyInfo.xcprivacy declaration and the App Store's App Privacy labels: all four categories are collected for App Functionality, all are linked to you, and none are used for tracking. The Android app will declare the same categories in its Play Store data-safety form when it ships.
What we do not do
Stash does not track you. There is no advertising identifier (IDFA), no App Tracking Transparency prompt, no third-party analytics or advertising SDKs, and no cross-app or cross-site profiling. We do not build advertising profiles and we do not sell data.
Location is used for one thing: when you take a photo of an item, the app can stamp the item with where it was last seen, so it is easier to find later.
Stash uses two systems, each for a specific job:
Apple and Cloudflare act as infrastructure providers that process this data on our behalf so the app can function. We do not sell your data, and we do not share it with any third party for their own purposes.
When someone borrows through a web link, their contact information is handled carefully:
The rule
A borrower's name and contact are given to the owner only once a loan is confirmed and active - not on a pending request, and never to any other borrower. For approval-mode items the owner sees the request without the contact details until they approve. A request the owner declines never reveals the borrower's contact.
The borrower's own device may keep a local list of their borrows in the browser (the holding list). That list lives in the browser only and is never sent to any server; clearing browser data clears it.
Owners: on iOS, your catalog lives in your private CloudKit database - you can erase all of your data from within the app, on-device, and because the catalog is in your own iCloud database it is under your Apple account's control. Deleting the app removes the local copy of your data from that device. (The Android app, when it ships, keeps its catalog on-device, so deleting the app deletes the data.)
Borrowers: a borrow record is keyed to the share it came from and is kept only as long as it is needed to track that loan; it expires and is pruned when the share ends or the record ages out. A waitlist ("notify when free") entry stores only your email and the item reference, and is cleared once the notification is sent.
Launch list: if you leave your email on the marketing pages to hear when the apps ship, we store only that address and the page you signed up from. It is used for a single launch announcement and the list is deleted after it goes out.
If you want data associated with a borrow, waitlist, or launch-list signup removed, contact us using the address below.
Stash is a general-audience app for lending and borrowing personal belongings. It is not directed to children, and we do not knowingly collect personal information from children under 13.
If this policy changes, we will update this page and revise the "Last updated" date above.
Privacy questions
Email help@rejog.net with any privacy question or a request to delete your data.