What the Stash app collects, why, where it is stored, and how you can delete it. It covers both roles: the owner who catalogs and lends, and the borrower who requests an item from a web link.
The short version
No tracking. No advertising identifier (IDFA). No App Tracking Transparency prompt, because there is nothing to track. No third-party analytics or advertising SDKs. We do not sell your data. Infrastructure and AI service providers process data only so Stash can provide the features you choose.
Everything below is collected only to provide app functionality. Each item is linked to your use of the app, and none of it is used to track you across other apps or websites.
The app data categories are collected for App Functionality and none are used for tracking. The owner iOS app's PrivacyInfo.xcprivacy declaration covers the app-side categories; Android and the web public-content report flow also use the report data described above for moderation.
What we do not do
Stash does not track you. There is no advertising identifier (IDFA), no App Tracking Transparency prompt, no third-party analytics or advertising SDKs, and no cross-app or cross-site profiling. We do not build advertising profiles and we do not sell data.
Location is used for one thing: when you take a photo of an item, the app can stamp the item with where it was last seen, so it is easier to find later.
Stash can identify an item from a photo. On Android, the default identification method uses OpenRouter cloud identification through Rejog infrastructure. Android users can opt out in the app and use on-device MobileCLIP identification instead. When cloud identification is used, the app sends the captured image bytes to the Rejog Worker using the owner's authenticated connection.
The Worker holds the server-side caller key, encodes the image, and relays it through Rejog infrastructure to an AI provider. The AI provider returns suggested item details such as a name, note, and category. The purpose is only to help catalog your item; it is not advertising, tracking, or cross-app profiling.
The photo bytes are handled as a relay request for the identification result. Rejog may keep internal request metadata such as tenant, timing, response status, and monthly usage counters so we can operate the feature, enforce limits, and investigate errors. Binary image bodies are not stored in Rejog's verbose trace logs; those logs record a placeholder for image requests and are short-lived.
Stash uses two systems, each for a specific job:
Apple, Cloudflare, and AI service providers act as processors or service providers for the features above. We do not sell your data, and we do not share it with any third party for their own purposes.
When someone borrows through a web link, their contact information is handled carefully:
The rule
A borrower's name and contact are given to the owner only once a loan is confirmed and active - not on a pending request, and never to any other borrower. For approval-mode items the owner sees the request without the contact details until they approve. A request the owner declines never reveals the borrower's contact.
The borrower's own device may keep a local list of their borrows in the browser (the holding list). That list lives in the browser only and is never sent to any server; clearing browser data clears it.
Owners: on iOS, your catalog lives in your private CloudKit database - you can erase all of your data from within the app, on-device, and because the catalog is in your own iCloud database it is under your Apple account's control. Deleting the app removes the local copy of your data from that device. On Android, the catalog stays on-device, so deleting the Android app deletes that data.
Borrowers: a borrow record is keyed to the share it came from and is kept only as long as it is needed to track that loan; it expires and is pruned when the share ends or the record ages out. A waitlist ("notify when free") entry stores only your email and the item reference, and is cleared once the notification is sent.
Android launch email: if you leave your email on the marketing pages for Android availability updates, we store only that address and the page you signed up from. It is used for one Android availability email, then the list is deleted.
Public-content reports: reports are moderation evidence. They do not automatically disappear when a stash, item, or tenant is removed, because operators may need the evidence to review abuse, enforce the terms, or explain an action. There is no automatic deletion schedule for these report rows today.
If you want data associated with a borrow, waitlist, Android launch email signup, or public-content report removed, contact us using the address below.
Stash is a general-audience app for lending and borrowing personal belongings. It is not directed to children, and we do not knowingly collect personal information from children under 13.
If this policy changes, we will update this page and revise the "Last updated" date above.
Privacy questions
Email help@rejog.net with any privacy question or a request to delete your data.