Stash Stash

Privacy Policy

Last updated: August 7, 2026  ยท  Effective: August 7, 2026

Stash is a mobile app that keeps track of the food in your kitchen. It is made and operated by CTF Designs LLC ("we", "us"), a California limited liability company. This policy explains exactly what Stash collects, why, who it is shared with, and how to get rid of it.

The short version. We collect the account you sign in with and the kitchen information you give us. We send your messages, receipt photos and voice recordings to AI providers so the app can understand them. We do not sell your data, we do not show you ads, and neither we nor our AI providers use your content to train AI models. You can have everything deleted at any time.

1. Information we collect

Account information

When you sign in with Google or Apple, we receive your email address and, if you allow it, your name. If you use Apple's "Hide My Email," we only ever see the private relay address Apple gives us. We store a user ID, your email, and your sign-in provider. We never receive or store your Google or Apple password.

Content you put into the app

Device permissions

PermissionWhy Stash asks
MicrophoneTo record a voice message when you press and hold to talk. Recording only happens while you are actively holding the button.
Camera and photosTo photograph or select a receipt to scan. Stash only accesses the specific image you choose.
LocationOptional. If you add a store and turn on arrival reminders, Stash sets a geofence around that store so your phone can remind you of your shopping list when you get there. Your location is used on your device by the operating system and is not sent to us or stored on our servers.
CalendarOptional. If you ask Stash to schedule a grocery run, it reads your calendar to find a free window and writes the event you confirm. Calendar contents stay on your device and are not sent to our servers.
NotificationsTo send reminders about food about to expire and about your shopping list. Notifications are scheduled on your device.

Every one of these is optional. Stash still works if you decline them, you just lose the feature that needs it.

What we do not collect

Stash contains no advertising SDKs, no analytics SDKs, and no third-party trackers. We do not collect advertising identifiers, we do not build advertising profiles, and we do not track you across other apps or websites.

2. How we use your information

We do not use your content for advertising, and we do not use it to train AI models.

3. Who we share it with

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We use a small number of service providers who process data on our behalf, under contract, and only for the purposes below.

ProviderWhat it receivesWhy
Supabase Your account, kitchen data, messages and notes Database, authentication and server functions. This is where your data lives.
Anthropic (Claude) Your messages, relevant kitchen context, and receipt photos Understanding what you said and reading receipts. Anthropic's commercial terms state that inputs and outputs from its API are not used to train its models.
Groq (Whisper) Voice recordings Turning speech into text. The audio is processed to produce a transcript.
Google / Apple Sign-in request only Letting you sign in without a separate password.

We may also disclose information if we are legally required to, or if it is necessary to protect the rights, safety or property of our users or of CTF Designs LLC. If our business is sold or merged, your data may transfer as part of it. We would tell you first, in the app or by email.

4. Where your data is stored

Stash's servers and databases are operated in the United States. If you use Stash from outside the United States, your information is transferred to and processed there.

5. How long we keep it

We keep your account and kitchen data for as long as your account exists. When you request deletion, your account is removed from our production database within 7 days, and from our backups within 30 days.

Receipt photos and voice recordings are processed to extract their content and are not stored as files on our servers; what we retain is the text result inside your account. Our AI providers may hold a copy briefly for abuse monitoring under their own policies, typically no more than 30 days.

6. Your choices and rights

If you are in California, the CCPA/CPRA gives you the right to know, delete, correct, and opt out of sale or sharing of your personal information, and to not be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of. If you are in the EEA or UK, the GDPR gives you rights of access, rectification, erasure, restriction, portability and objection. Our legal basis for processing is the performance of our contract with you, and your consent for optional device permissions. To exercise any right, email roman@ctfdesigns.com. We respond within 30 days and never charge for it.

7. Security

Data is encrypted in transit with TLS and encrypted at rest by our hosting provider. Access to production data is limited to the people who need it to operate Stash. Row-level security in our database restricts each account's data to that account. No system is perfectly secure, and we do not claim otherwise, but if a breach affects your data we will notify you as required by law.

8. Children

Stash is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us information, email us and we will delete it.

9. Changes to this policy

If we change this policy we will update the date at the top. For material changes we will notify you in the app or by email before they take effect. Continuing to use Stash after a change means you accept the updated policy.

10. Contact us

CTF Designs LLC
39525 Los Alamos Rd, Ste C #482
Murrieta, CA 92563, United States
roman@ctfdesigns.com