Privacy Policy
Who is responsible
Stash is operated by PEAK SALES DIJITAL PAZARLAMA SATIS VE DIS TICARET LIMITED SIRKETI (Necip Fazıl Mah. Mina Sok. No:1-2, Ümraniye, 34773 İstanbul, Türkiye). Contact: [email protected]. Last updated: 2026-09-15.
What we collect
Account: the app starts without an account, using a random device identifier. Email, name or an Apple/Google identity is added only if you link a second device or open household sharing.
Item data: the photos you take, the cut-out images, studio images and 3D models generated from them; per item a category, color, brand, estimated value, purchase/expiry/warranty dates, location (room, furniture, shelf), usage log, loans, lists and trips. Original photos are deleted after 30 days (unless you choose to keep them); cut-outs, studio images and 3D models stay until you delete them.
Sensitive categories: content in the documents and medicine/health categories is additionally encrypted with a key held on your device; the server only sees a type label. The medicine category counts as health data, is enabled with separate consent and is excluded from analytics.
Selfies/mirror photos are kept only with your explicit permission, as a single reference you can delete. Faces in pile and room photos are masked before processing.
Usage: screen durations, scan counts, app version, device type, event logs; subscription status and purchase events via the app stores (we never receive card details).
Ad measurement: install source (campaign), platform-permitted advertising identifiers and a random device identifier.
Permissions: camera (scanning), photo library (bulk scan; only the photos you pick), location (weather for outfits; approximate only), calendar (trip detection; optional), microphone (voice assistant). Each permission is requested when you use that feature; declining does not affect other features.
Why and on what basis
To build your inventory and provide services such as outfits, packing lists and reminders (performance of a contract); to improve the product and prevent abuse (legitimate interest); for ad measurement and the health category (consent); to meet legal obligations.
Who we share it with
AI providers: language/vision models for item detection, naming, outfit and report text (Anthropic and image-generation providers). Providers receive only the cropped item image and structured attributes, never the full room photo; no studio image is generated for documents. Data is not used to train models.
Image processing (cut-out, embedding, 3D) runs on our own servers or rented GPU providers; images are stored on Cloudflare R2. Weather via Open-Meteo, barcode lookups via open product databases (only the barcode number is sent).
Subscriptions: Apple App Store, Google Play and RevenueCat. Ad measurement: AppsFlyer, Meta, TikTok (install and purchase events). Error tracking: Sentry. Hosting: Hetzner (Germany) and Cloudflare.
Household sharing: only items you mark as shared are visible to household members; a member who leaves takes their own items. A public showcase is published only if you enable it, with the items you choose.
We do not sell data and do not share it with anyone else unless required by law.
How long we keep it
For as long as your account/device registration exists. You can export everything in one tap (ZIP: images + CSV + PDF) and delete everything (Settings → Your data). Deletion permanently erases images, 3D models, item records and personal details and destroys your encryption key; purchase records needed for accounting are anonymized and kept for the legally required period.
Your rights
You can access, correct, delete, export and object to the processing of your data (GDPR, CCPA and Turkish KVKK). Use the in-app export/deletion or write to [email protected]. EU residents may complain to their data protection authority.
Children
The app is not for children under 16. The kids category is used within an adult's account under parental supervision.
Security
Data is protected with TLS in transit; notes, serial numbers and people's names are encrypted per user (AES-256-GCM); document and medicine content is additionally encrypted with a device key. API keys never reach the device.
Changes
When this policy changes we notify you in the app and update the date.