Privacy Policy
Privacy Policy
Stash - Privacy Policy
INTERIM DOCUMENT - NOT YET REVIEWED BY COUNSEL
This is a provisional privacy policy written in-house so that Stash can describe honestly what it does with your information during alpha testing. It has not been reviewed or approved by a lawyer. It is not a substitute for legal advice, and it may be replaced in full once counsel reviews it. Every item in [SQUARE BRACKETS] is an open decision that the owner or counsel must settle before this policy is used in public release.
This document describes what the app actually does today, including the parts that are not ideal. Where a protection is planned but not yet built, it says so rather than implying it exists.
Version: 2026-08-31 Effective date: [EFFECTIVE DATE - SET WHEN PUBLISHED] (drafted 2026-08-22) Applies to: the Stash mobile app and the services behind it
1. The short version
Stash is a food journal. You photograph and describe what you eat, and we store it so you can look back at it and find it again.
- We collect what you type in, the photos you take, and where you were, because the app maps your meals.
- We use it to run the app for you, not to build an advertising profile.
- There is no ad tracking in Stash, no advertising networks, no session replay, no screen recording, and no automatic capture of your taps or the text you type.
- We remove the hidden metadata from your photos, including GPS coordinates, before storing them.
- Photos are stored on public web addresses, which is the one thing in this policy most likely to surprise you. Section 6 explains it.
- You can delete your account from the app, and you have 30 days to change your mind.
The rest of this document is the detail.
2. Who is responsible for your data
Bitter Melon Technologies LLC is responsible for the personal information described here. Contact details are in section 15.
[DATA CONTROLLER / REPRESENTATIVE - CONFIRM. If Stash is offered in the UK, EU, or certain US states, counsel should confirm the controller's registered identity and whether a representative or a data protection officer must be named.]
3. What we collect
Information you give us when you sign up
- Username. Public inside the app. Other users can search for it.
- Email address. Used to verify your account, to reset your password, and to tell you about your account. Not shown to other users.
- Password. Stored only as a one-way hash. We never store or log your actual password, and we cannot read it.
- Your confirmation that you are 13 or older, and your acceptance of the Terms. We record the time you accepted and the version you accepted.
Your taste profile
You are asked for these during onboarding, and you can change them later. They shape what the app shows you.
- Allergies.
- Dietary pattern, such as vegetarian, vegan, pescatarian, halal, kosher, or keto, and your own dietary restrictions.
- Spice tolerance and how adventurous you would like your suggestions to be.
- Favourite cuisines, ingredients you want to avoid, and free-form flavour notes.
- Typical spend, preferred currency, and what counts as cheap or expensive to you.
Some of this touches on health, because allergies and dietary needs can be medical. We treat it as information you have chosen to record about your food preferences, and we use it only to personalise what the app shows you. [HEALTH DATA CLASSIFICATION - OPEN. Allergy and dietary information is currently declared to Apple as "other user content" rather than "health data". Counsel must confirm this classification, because it drives the store privacy labels, this section, and whether the data needs special-category treatment under GDPR.]
What you record in the app
- Dishes and drinks. Names, descriptions, ratings, notes, cost, spice level, occasion, whether you would order it again, and similar fields.
- Deals. Promotions you post, including the venue, price, schedule, and description.
- Spots. Restaurants and places you log.
- Photos. The pictures you take or pick from your photo library.
- Trips, and the entries you group into them.
Location
Stash asks for your location while you are using the app. It is used to place your meals on the map, to tag where you ate, and to show nearby places and deals.
The coordinates we store are precise, not approximate, because a food journal that put your dinner on the wrong block would not work. When you search for a place by name, the text you search for is sent to our maps provider to turn it into coordinates.
You can refuse the location permission or turn it off in your device settings. The app still works, but map features and location tagging will not.
Diagnostics and analytics
These two are the only places where information about your usage is collected, and both are deliberately limited.
- Crash and error reports. When the app crashes or hits an error we collect the technical details of the failure so we can fix it. Before anything leaves your device, a filter removes personal details such as your email address and any access tokens. You are identified only by an internal account identifier.
- Product analytics. We record a small, fixed set of events, for example that you signed up, logged in, finished onboarding, saved a dish, or opened a screen. The details attached to them are counts, categories, and yes/no flags, never free text or the content of your entries. You are identified only by an internal account identifier, never by your email or username.
Both of these are switched off unless we have configured them. When they are not configured, the code does nothing at all. [OBSERVABILITY STATUS - CONFIRM before publishing whether crash reporting and analytics are actually enabled in the released build, and adjust the tense of this section to match.]
What your device tells us automatically
When the app talks to our servers, our servers see your IP address and basic request information, as any web service does. We use it to make the app work and to keep it secure against abuse.
4. What we deliberately do not collect or do
This list is exact, and it is meant to be held to.
- No advertising, and no ad networks or advertising identifiers. Stash contains none.
- No tracking of you across other apps or websites. We do not do it and we do not let anyone else do it through Stash.
- No response to a "Do Not Track" signal is needed, because Stash does not track you across other apps or websites in the first place.
- No selling your personal information, and no sharing it for anyone else's advertising.
- No session replay and no screenshots of your screen. The analytics tool supports these features and they are switched off.
- No autocapture. Your taps, gestures, and the text you type are not automatically recorded. Every analytics event is one we wrote deliberately.
- No GPS or camera metadata kept inside your stored photos. See section 6.
- No reading of your contacts, your calendar, your messages, or your photo library beyond the pictures you choose to add.
- No microphone or audio recording.
- No selling or sharing of your allergy or dietary information with anyone.
5. Why we use your information
We use it only for these purposes.
- To give you the app: storing your entries and photos, showing your journal, your map, and your history.
- To personalise what you see: using your taste profile and your past entries to decide what to show you.
- To run your account: verifying your email, resetting your password, and telling you about important account events such as a scheduled deletion.
- To let you share: showing what you have chosen to share to the people you shared it with, and showing deals you post to other users.
- To keep Stash safe: handling reports and blocks, removing content that breaks the rules, and preventing abuse.
- To fix and improve the app: diagnosing crashes and understanding which features are used.
- To meet legal obligations.
We do not make any decision about you that has a legal or similarly significant effect using automated processing alone.
6. Photos, and an important limitation
What we do to a photo
When you add a photo, we remove the embedded metadata before storing it, including GPS coordinates, camera details, and timestamps. We keep the picture itself as you framed it, and we do not crop it unless you chose a crop.
Please note one gap. There is a fallback upload path in the app where a photo can reach storage without passing through that removal step, and a photo taking that path can keep its original metadata. We are closing it. [EXIF FALLBACK PATH - engineering must close the direct-upload path that bypasses the metadata strip, or route it through the strip, before public release. Until then this paragraph must stay in the policy, because removing it would make the policy inaccurate.]
Where photos are stored, and who can reach them
Photos are stored with our cloud storage provider.
The stored photos are served from public web addresses. Anyone who has the address of a photo can open it without logging in to Stash. The addresses are not listed anywhere public and they contain a random identifier, but they are not secret, and the path includes your account number.
This means a photo's address, if it is shared or leaks, gives access to that photo. Photos are not currently protected by a login check.
We consider this a weakness rather than a design goal, and moving photo delivery behind signed, expiring links is planned. [PHOTO ACCESS MODEL - OPEN AND IMPORTANT. The storage bucket is currently readable by anyone with the address. Counsel and the owner should treat this as a disclosure requirement for the store privacy labels, and engineering should schedule the move to a private bucket with signed URLs. This paragraph must not be softened while the bucket stays public.]
7. What other people can see
- Your username is visible to other users and can be found by search.
- Your email address is not shown to other users.
- Your journal entries are private to you by default.
- Dishes you share go to the specific friends you send them to. They keep their copy.
- Deals you post are visible to all Stash users on the Discover map. Do not post anything in a deal you would not want public.
- Your username is shown as the contributor on deals you post, so that the person who found a deal gets the credit for it. This is controlled by your Socialize setting, which is in Settings and is on by default. Turning Socialize off removes your name from deals you have already posted, everywhere and immediately. The deal itself stays on the map either way, with or without your name. A deal also carries no contributor name when you have scheduled your account for deletion, or when you and the person reading it have blocked each other, and deals that came from the data we loaded to start the map have no contributor at all.
- Spots you log feed a shared pool of places used across the app.
- Your taste profile is used to personalise what you see and is not published to other users.
If you block someone, you and they stop seeing each other's shared content.
8. Who we share your information with
We do not sell your information. We share it only with the companies that run parts of Stash for us, and only so they can do that job. We require each of them to protect your information to at least the standard this policy sets, and to use it only for the work they do for us.
| Who | What they do for Stash | What reaches them |
|---|---|---|
| Cloud storage provider | Stores your photos | Your photos, and the account number in the storage path |
| Maps provider | Maps, and turning place names into coordinates | Map and search requests, including coordinates and the place text you search for |
| Hosting provider | Hosts our servers and database | Everything the app stores, as our hosting provider |
| Email delivery provider | Sends account emails | Your email address and the contents of the email |
| Crash and error reporting provider | Crash and error reporting | Technical error details, with personal details filtered out, and an internal account identifier |
| Product analytics provider | Product analytics | The limited set of events described in section 3, and an internal account identifier |
[SUBPROCESSOR TERMS - CONFIRM that a data processing agreement is in place with each of these, and that the transfer mechanism for any data leaving the user's region is documented. Also CONFIRM the storage and hosting regions to name them here.]
We may also disclose information if the law requires it, if we need to enforce our Terms, or if it is necessary to protect someone's safety. If our business is transferred to another company, information would transfer with it, and we would tell you.
9. Where your information is held
Our servers and storage are hosted in [HOSTING REGION - CONFIRM] and [STORAGE REGION - CONFIRM]. If you use Stash from somewhere else, your information is transferred to those places.
[INTERNATIONAL TRANSFERS - CONFIRM the lawful transfer mechanism if Stash is offered in the UK or EU.]
10. How long we keep things
- Your account and your entries are kept until you delete them or delete your account.
- Photos are kept until you delete the entry they belong to, or your account is permanently deleted.
- Email verification and password reset links are stored only as a hash, are single use, and expire after a short time.
- Crash reports and analytics events are kept according to our providers' retention settings. [RETENTION PERIODS - CONFIRM and state the actual configured retention for the crash reporting and analytics providers.]
- Server logs are kept for a short operational period. [LOG RETENTION - CONFIRM the actual period.]
- Moderation reports are kept after they are resolved, so that repeat problems can be seen. [MODERATION RETENTION - CONFIRM a defined period.]
11. Deleting your account, and what survives
You can delete your account in the app.
We schedule the deletion 30 days out and email you. During those 30 days you can recover the account: sign back in and choose to keep it. Signing in alone does not cancel the deletion, you have to choose. We email you again shortly before the deadline.
After 30 days the deletion runs and is permanent.
What is removed: your account record, your dishes and entries, your trips, your friendships and shares you sent, your taste profile, your blocks and the reports you filed, your recommendation data, and your photos in storage.
What is not removed, and you should know this before you delete:
- Deals you posted stay on the Discover map. They are unlinked from you, so they no longer show who posted them, but the deal itself remains, because other users rely on it.
- Spots and restaurants you added stay in the shared pool of places, unlinked from you, for the same reason.
- Dishes you shared with a friend stay in that friend's collection, because it is their copy of something they were given. Your username currently remains attached to it so that they can still see who sent it. [SHARED-DISH ATTRIBUTION AFTER DELETION - OPEN OWNER DECISION. This is a deliberate product choice, not an oversight, and it means a deleted user's username persists in other users' data. Counsel must confirm it is defensible against erasure rights, and the owner must confirm it is what they want. If it is not, the alternative is to blank the name on deletion.]
- Anything we are required to keep by law, and routine backups, until they age out.
If you want your account removed without using the app, email us at the address in section 15. [WEB DELETION PAGE - a publicly reachable account deletion request page is required by Google Play and does not exist yet. It must be built and linked here.]
12. Your choices and your rights
Inside the app you can:
- Edit or delete any entry, photo, deal, or spot you created.
- Change your taste profile at any time.
- Block and unblock other users, and report content.
- Turn off the location permission in your device settings.
- Delete your account.
Depending on where you live, you may also have the right to ask for a copy of your information, to correct it, to have it deleted, to object to or restrict how we use it, and to complain to your data protection regulator.
To exercise any of these, email us at the address in section 15 and we will respond. We will need to be satisfied that the request is really from you.
Please be aware there is no self-service export in the app yet. A request for a copy of your data is handled by hand today. [DATA EXPORT - a self-service export does not exist. Counsel should advise on the required response deadline, and engineering should build an export path.]
[US STATE PRIVACY RIGHTS - CONFIRM whether Stash meets the thresholds for California, Colorado, and similar state laws, and add the specific notices and the "do not sell or share" statement if so. Stash does not sell or share personal information for advertising, which should make this straightforward.]
13. How we protect your information
- Traffic between the app and our servers uses HTTPS.
- Passwords are stored only as a one-way hash that we cannot reverse, and are never logged.
- Email verification and password reset links are stored only as a hash, are single use, and expire after a short time.
- Every request for your data is checked against the account making it, so you can only reach your own entries.
- Sign-in attempts are protected against automated guessing and abuse, and sign-in errors are deliberately vague so they cannot be used to discover whether an account exists.
- Analytics and crash data pass through a filter that removes personal details before leaving your device.
No service is perfectly secure, and we cannot promise your information will never be accessed improperly. Note the photo storage limitation in section 6, which is a real and current exception to the protections above.
[BREACH NOTIFICATION - CONFIRM the notification obligations and timescales that apply, and whether they should be stated here.]
14. Children
Stash is not for children under 13, and we do not knowingly collect information from them. The app asks you to confirm you are 13 or older when you sign up.
If you believe a child under 13 has an account, contact us and we will remove it.
[CHILDREN - CONFIRM the minimum age with counsel, including whether any market Stash ships to requires a higher age or parental consent, and whether the alcohol-related deals in the app affect the age rating.]
15. Contact us
- Email: [email protected]
- Post: [BUSINESS ADDRESS - CONFIRM]
We aim to answer privacy questions promptly.
16. Changes to this policy
We will update this policy as the app changes, and certainly once counsel has reviewed it.
When we make a material change we will raise the version number and show you the new policy in the app before you carry on using Stash. For smaller corrections we will update the version and the effective date here. The version and effective date at the top always tell you which policy is current.