Privacy Policy
Last updated: 5 September 2026
Stash is a self-hosted “read it later” app. This instance is run by an individual for personal use and for a small number of personally invited testers. There is no company behind it and no commercial use of your data. This policy covers the Stash web app and its Google sign-in; the browser extensions are covered by a separate policy.
Signing in
When you choose Continue with Google, Google shares your name, email address, and profile picture with this Stash instance. That information is used only to create and identify your account so your saved articles stay private to you. Email/password sign-in is available as a fallback and stores only your email address and a hashed password (handled by Supabase Auth).
Sign-up is invite-only: an address that has not been added to this instance's allow-list cannot create an account.
What is stored, and where
| Data | Where it goes | Why |
|---|---|---|
| Articles you save — URL, title, and extracted text — plus folders, tags, and reading progress | This instance's Supabase (Postgres) database | This is the core feature. Rows are private to your account, enforced by Postgres Row Level Security. |
| Your account (name, email, profile picture, session) | Supabase Auth | Identifies your account and keeps you signed in. |
| Anonymous usage events (e.g. “save succeeded”, “search used”) | PostHog, if configured for this instance | Understanding which features are used and diagnosing failures. No article URLs or content are included. |
| Error reports (stack traces) | Sentry, if configured for this instance | Diagnosing crashes in the app. |
What is never done
- Your data is never sold, rented, or shared for advertising or any unrelated purpose.
- Your data is never transferred to third parties except the infrastructure providers listed above (Supabase, and optionally PostHog and Sentry), acting solely to provide the service.
- Your browsing history is not tracked. Nothing is recorded until you explicitly save a page.
Google user data
Stash's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. The only Google data Stash requests is your basic profile (name, email address, profile picture), and it is used only for the account sign-in described above — it is not transferred to others, and not used for advertising.
Retention and deletion
Your saves live in this instance's database for as long as your account exists. Deleting a save in the app removes it from the database immediately. To delete your account and all associated data, contact the maintainer (see below) and it will be removed.
Contact
This is an open-source project. Questions, issues, and data-deletion requests can be filed at the project's GitHub repository: github.com/JordanTranchina/stash, or sent to the support email shown on the Google sign-in screen.