Privacy Policy — Stash

Last updated: August 22, 2026

Stash (“the app”, “we”, “us”) is a personal budgeting app. We designed it to be private by default. This policy explains what data the app handles.

Data stored on your device

Your saved financial information — including transactions, wallets, budgets, payday plan, and recurring items — is stored locally on your device. Stash does not connect to or read your bank account. If you import a bank statement, you choose the file yourself. Backups are created or restored only when you ask.

Optional AI-assisted features

Stash offers optional features powered by Claude from Anthropic. Before using each feature, Stash explains what will be sent and asks for your permission. These features include:

Requests pass through our Supabase backend to Anthropic. Stash uses anonymous authentication to protect and rate-limit requests. Original receipt images and bank files are processed for the request and are not retained by our backend. We may retain limited user-scoped job status, structured review results, usage counts, and technical error information to operate and protect the service. Claude does not calculate your balances, save transactions, move money, or change your plan. AI suggestions are validated by Stash and, where applicable, must be confirmed by you.

You can use Stash without these AI-assisted features. Smart heads-ups remain off unless you explicitly enable them. See Anthropic’s privacy policy and Supabase’s privacy policy.

Purchases

In-app purchases (Stash Pro) are processed by Apple and by our payments provider, RevenueCat. To manage your purchase and restore it across your devices, RevenueCat receives a non-identifying, randomly generated app user ID and your subscription/purchase status. We do not receive your name, email, or payment card details. See RevenueCat’s privacy policy and Apple’s privacy policy.

Information we do NOT collect

Analytics & diagnostics

Stash uses limited product analytics and diagnostics to understand whether features work and to improve the app. This may include app events, device and app information, crash details, and an automatically generated identifier. We do not intentionally include transaction descriptions, receipt contents, bank-file contents, or account credentials in analytics. Providers may include Apple, PostHog, RevenueCat, and Meta. Meta access to tracking-related identifiers is subject to Apple’s App Tracking Transparency permission.

Retention and deletion

You can remove locally stored financial data by deleting it in Stash or deleting the app. To request deletion of backend records associated with optional AI features, contact us at the address below. We retain operational records only for as long as reasonably necessary to provide, secure, and troubleshoot the service or meet legal requirements.

Children’s privacy

Stash is not directed at children under 13 and does not knowingly collect personal information from them.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above.

Contact

Questions about this policy? Email contact@majorgen.com.