Privacy Policy
Last updated: July 29, 2026
Stasher AI, Inc. ("Stasher", "we", "us") operates the Stasher document vault service. This policy explains what data we collect, how we use it, and your rights.
1. Data We Collect
1.1 Account Data
- Email address, display name, preferred language
- Apple Sign-In subject ID (if you sign in with Apple)
- Authentication tokens (JWT)
1.2 Documents You Add
When you scan, upload, or share a document into Stasher (via camera, file picker, WhatsApp, AirDrop, or other share sheet), we store:
- The document file itself (encrypted at rest)
- AI-generated metadata: document type, entity names, dates, amounts, tags, summary
- Search embeddings (mathematical vectors used for search - cannot be reversed to original text)
- The original OCR text is used to generate metadata and embeddings, then permanently deleted
1.3 Connected Email Accounts (Gmail, Outlook, Yahoo)
When you connect an email account, we collect:
- Email metadata: sender address, recipient addresses (to/cc/bcc), subject line, date/time, thread ID, message ID, labels/categories
- Email body text: processed in memory for embedding generation, then immediately discarded - never written to disk or database
- With your separate consent: a one-sentence AI summary and a PDF preview of the email body, stored for in-app access
- Attachment metadata: filename, MIME type, file size. Attachment files are stored as vault documents only if you consent
- OAuth tokens: access and refresh tokens, encrypted at rest
1.4 Connected File Storage (Google Drive, Dropbox)
When you connect a file storage account, we collect:
- File metadata: filename, MIME type, file ID, checksum, folder path, preview link
- File content: downloaded in memory for OCR, metadata extraction, and embedding generation, then immediately discarded - never stored on Stasher servers
- OAuth tokens: access and refresh tokens, encrypted at rest
1.5 Search & Usage Data
- Search queries (logged for quality improvement, auto-deleted after 90 days)
- Anonymous analytics events (no personally identifiable information)
- Device tokens for push notifications
1.6 Billing Data
- Stripe customer ID and subscription ID
- We do not store credit card numbers - all payment processing is handled by Stripe
2. How We Use Your Data
We never use your data to train AI models. All AI processing is inference-only.
We never sell your data. We share it only with the service providers listed in Section 4, solely to operate the Stasher service.
3. Legal Basis for Processing (GDPR Art. 13)
4. Service Providers (Sub-Processors)
We share data with the following providers solely to operate Stasher:
All providers operate under Data Processing Agreements (DPAs). Standard Contractual Clauses (SCCs) cover any processing outside the EU/EEA.
5. Third-Party Data Subjects (Email Contacts)
When you connect your email account, Stasher processes metadata about people who are not Stasher users - email senders, recipients, and CC'd parties.
We process this contact metadata solely to make your email searchable. Our legal basis is legitimate interest (GDPR Art. 6(1)(f)) - your interest in searching your own inbox, balanced against third parties' privacy interests.
We cannot realistically notify every email contact that their address appears in your indexed emails (GDPR Art. 14(5)(b) exemption - disproportionate effort). However, any individual who contacts us at privacy@stasher.app to request erasure of their contact data will have their request fulfilled within 30 days.
6. Connecting and Disconnecting Cloud Accounts
When you connect Gmail, Outlook, Google Drive, or Dropbox, you are asked for explicit consent before any content is accessed. You may disconnect at any time from Settings → Connected Accounts. Upon disconnection:
- All indexed metadata and search embeddings for that account are deleted within 30 days
- Your OAuth access tokens are revoked immediately
- No further data is retrieved from that account
You can also revoke Stasher's access directly from your Google, Microsoft, or Dropbox account security settings.
Email body text consent can be withdrawn independently. If you withdraw body-text consent, future emails are indexed by metadata only, and embeddings generated from body text are deleted within 30 days.
7. Data Retention
8. Your Rights
You have the right to:
- Access your data - export all your data from Settings → Export Data
- Delete your data - delete your account from Settings → Delete Account. All data is permanently removed after a 30-day grace period (you can cancel deletion during this period)
- Correct inaccurate data - edit your display name from your profile, and correct AI-generated document metadata from any document detail screen. For other corrections, contact privacy@stasher.app
- Withdraw consent - disconnect any cloud account, or withdraw body-text/attachment consent, at any time from Settings → Connected Accounts
- Object to processing - contact privacy@stasher.app
- Data portability - your exported data is in standard formats (JSON + original files)
9. Automated Processing
Stasher uses AI models to automatically classify your documents by type (e.g., invoice, contract, medical), extract metadata (dates, amounts, entities), and generate search embeddings. This processing is used solely to organize and make your documents searchable - it does not result in any legal or similarly significant decisions about you. You can review and correct any AI-generated metadata from the document detail screen.
10. Data Security
- All data encrypted in transit (TLS 1.2+)
- All data encrypted at rest (Google Cloud server-side encryption)
- OAuth tokens encrypted at rest
- No Stasher employee reads your documents or emails - all processing is automated
- We do not provide end-to-end encryption. Your data is encrypted on our servers but is decryptable by the service for processing
11. Children
Stasher is not intended for use by anyone under 16 years of age. We do not knowingly collect data from children under 16.
12. US State Privacy Law Disclosures (CCPA/CPRA)
Sale of personal information: Stasher does not sell, share, or rent your personal information to third parties. We do not use your data for targeted advertising.
Categories of personal information collected:
13. Changes to This Policy
We will notify you of material changes at least 30 days in advance via email and/or in-app notification. Continued use after the notice period constitutes acceptance. You may delete your account if you do not accept the changes.
14. Contact
For privacy questions, data requests, or complaints:
Email: privacy@stasher.app
Data Controller: Stasher AI, Inc.