Rejog stash
Legal

Privacy Policy

What the Stash app collects, why, where it is stored, and how you can delete it. It covers both roles: the owner who catalogs and lends, and the borrower who requests an item from a web link.

Last updated: July 31, 2026

The short version

We collect only what the app needs to work - nothing for tracking or advertising.

No tracking. No advertising identifier (IDFA). No App Tracking Transparency prompt, because there is nothing to track. No third-party analytics or advertising SDKs. We do not sell your data. Infrastructure and AI service providers process data only so Stash can provide the features you choose.


What we collect and why

Everything below is collected only to provide app functionality. Each item is linked to your use of the app, and none of it is used to track you across other apps or websites.

Data
Why we collect it
Photos and videos
Item photos you take or choose, so you can recognize your things. If you publish an item or lend by link, selected item photos are uploaded to Rejog photo storage so borrowers can see the public catalog or lend link. When cloud photo identification is used, including Android's default OpenRouter identification unless you opt out and use on-device MobileCLIP, the captured photo bytes are relayed through Rejog infrastructure to an AI provider to suggest item details.
Precise location
Read only at the moment you capture a photo, to stamp where an item was last seen so you can find it later. Never read in the background, never used to follow your movements.
Email / contact info
A borrower's name and email or phone number, given when they request an item from a web borrow link. Stored so the owner can arrange the loan - and shared with that owner only.
User content
Item names, notes, categories, rooms, descriptions, lend-mode choices, and similar text you enter to describe, publish, organize, and lend your things.
Public-content reports
If someone reports public stash content, the report stores the target stash handle, optional item identifier, selected reason, optional detail text, and contract version for moderation review. The report does not collect reporter contact information, advertising identifiers, location, or raw reporter IP in the report record.

The app data categories are collected for App Functionality and none are used for tracking. The owner iOS app's PrivacyInfo.xcprivacy declaration covers the app-side categories; Android and the web public-content report flow also use the report data described above for moderation.


No tracking, no ads, no analytics

What we do not do

Stash does not track you. There is no advertising identifier (IDFA), no App Tracking Transparency prompt, no third-party analytics or advertising SDKs, and no cross-app or cross-site profiling. We do not build advertising profiles and we do not sell data.


About location

Location is used for one thing: when you take a photo of an item, the app can stamp the item with where it was last seen, so it is easier to find later.

  • It is read only in the foreground, at the moment of capture - never in the background.
  • It is attached to that item for your own reference.
  • It is never used to track your movements or shared for advertising.

Cloud photo identification

Stash can identify an item from a photo. On Android, the default identification method uses OpenRouter cloud identification through Rejog infrastructure. Android users can opt out in the app and use on-device MobileCLIP identification instead. When cloud identification is used, the app sends the captured image bytes to the Rejog Worker using the owner's authenticated connection.

The Worker holds the server-side caller key, encodes the image, and relays it through Rejog infrastructure to an AI provider. The AI provider returns suggested item details such as a name, note, and category. The purpose is only to help catalog your item; it is not advertising, tracking, or cross-app profiling.

The photo bytes are handled as a relay request for the identification result. Rejog may keep internal request metadata such as tenant, timing, response status, and monthly usage counters so we can operate the feature, enforce limits, and investigate errors. Binary image bodies are not stored in Rejog's verbose trace logs; those logs record a placeholder for image requests and are short-lived.


Where your data is stored

Stash uses two systems, each for a specific job:

  • Your owner catalog - the items, photos, notes, and location stamps you create. On iOS it lives in your own private iCloud (CloudKit) database, hosted by Apple, tied to your Apple account, and not a shared, public database. On Android, the catalog lives in a private database on the device itself.
  • The share and borrow flow - a public catalog link, a borrow request, and the borrower's contact and loan status - is served by the Rejog backend (a Cloudflare Worker with a Cloudflare D1 database and photo storage). This is what lets a borrower use a link in any browser without an account, on every platform.
  • Cloud identification - when cloud identification is used, including Android's default unless you opt out and use on-device MobileCLIP, captured photo bytes pass through the Rejog Worker and Rejog's API routing infrastructure to an AI provider so the provider can return the suggested item details.
  • Public-content reports - reports are stored in Rejog's moderation database with the target identifiers, reason, optional detail, and a snapshot of the reported target available at submission time.

Apple, Cloudflare, and AI service providers act as processors or service providers for the features above. We do not sell your data, and we do not share it with any third party for their own purposes.


Borrower contact is private until a loan is real

When someone borrows through a web link, their contact information is handled carefully:

The rule

A borrower's name and contact are given to the owner only once a loan is confirmed and active - not on a pending request, and never to any other borrower. For approval-mode items the owner sees the request without the contact details until they approve. A request the owner declines never reveals the borrower's contact.

The borrower's own device may keep a local list of their borrows in the browser (the holding list). That list lives in the browser only and is never sent to any server; clearing browser data clears it.


How long we keep data, and deleting it

Owners: on iOS, your catalog lives in your private CloudKit database - you can erase all of your data from within the app, on-device, and because the catalog is in your own iCloud database it is under your Apple account's control. Deleting the app removes the local copy of your data from that device. On Android, the catalog stays on-device, so deleting the Android app deletes that data.

Borrowers: a borrow record is keyed to the share it came from and is kept only as long as it is needed to track that loan; it expires and is pruned when the share ends or the record ages out. A waitlist ("notify when free") entry stores only your email and the item reference, and is cleared once the notification is sent.

Android launch email: if you leave your email on the marketing pages for Android availability updates, we store only that address and the page you signed up from. It is used for one Android availability email, then the list is deleted.

Public-content reports: reports are moderation evidence. They do not automatically disappear when a stash, item, or tenant is removed, because operators may need the evidence to review abuse, enforce the terms, or explain an action. There is no automatic deletion schedule for these report rows today.

If you want data associated with a borrow, waitlist, Android launch email signup, or public-content report removed, contact us using the address below.


Children

Stash is a general-audience app for lending and borrowing personal belongings. It is not directed to children, and we do not knowingly collect personal information from children under 13.


Changes to this policy

If this policy changes, we will update this page and revise the "Last updated" date above.


Contact us

Privacy questions

Email help@rejog.net with any privacy question or a request to delete your data.