Stashit Back to the site
Privacy policy · Android app

We don’t have your data

Not as a promise about how carefully we look after it — as a description of how the app is built. There is no account, no server holding your records, and nothing for anyone to look at even if they wanted to.

This page is about the Android app. The web version of Stash it works differently in two places that matter, and it has a policy of its own. Where they differ, the differences are named below.

The short version

What is stored, and where

Everything you put in is written to a database on the device you are holding. It is not uploaded, synced or mirrored. Uninstall the app and it is gone — which is why the app keeps asking you to make a backup.

That includes:

Scans of documents, and the lock they require

You can photograph a document — a passport page, an insurance certificate — and the app keeps it. Because a scan in an unlocked backup would be a plain file anyone who opens that folder can read, the app asks you to set a backup passphrase before the first one, and will not let you remove it while any scan remains. Delete the scans and the choice comes back.

Sharing a document with somebody is the other way a scan could leave the phone, and it takes its own switch. Ticking “include photos and receipts” does not send a passport page; there is a second switch, worded for what it is, and both start off every single time. With it off the scan is never read out of the database at all, so it cannot travel by mistake.

Document numbers are still not a field

There is nowhere to type a passport or licence number, on purpose. A number next to a name is a better identity-theft package than the scan is, it is not needed to remind you of a date, and anything the app never holds cannot leak.

Encryption, and what it does not cover

The database is encrypted with SQLCipher, using a key kept in the phone’s hardware-backed Keystore. The key never leaves the handset, which is also why a lost phone means lost data: nobody can open the file, including us.

The backup file you export is not encrypted. It has to be readable by a future version of the app and by you, so treat it like any other file holding your records.

The web version stores its data in the browser and says plainly that it is not encrypted. This is one of the two places the two versions genuinely differ.

Reminders

Reminders are worked out on the phone and handed to Android, which wakes the app on the day. Nothing is sent anywhere, because there is nowhere to send it — no account, no sender, no keys.

This is the other real difference. A browser cannot wake itself, so the web version needs a server that knows which phone to ping and when. That whole arrangement is absent here, and it is the single biggest reason this policy is shorter than the other one.

What a notification says is composed on the phone and shown by the phone. It deliberately names things rather than describing them — “Passport — Nuno” and not “passport expires 11 February” — because a lock screen is readable by anyone holding the phone.

Backups you choose to send

“Back up now” makes one file with everything in it and hands it to the phone’s share sheet. Where it goes — a cloud drive, an email to yourself — is your choice and happens outside Stash it. It is never received by anyone here.

Locking a backup with a passphrase

You can set a passphrase, and from then on every backup the app writes is encrypted with it — AES-256, with the key stretched from your passphrase so that guessing it is slow.

Nobody can reset it and nobody has a copy: not us, not Google, and not anyone who finds the file. That is the point of it, and it is also the risk — a backup whose passphrase is forgotten is gone, and so is everything in it. Write it down somewhere that is not this phone.

The format is written down in the app’s own source so that a person with the passphrase can open a backup with ordinary tools and no copy of Stash it. Encryption should not be the reason you cannot reach your own data.

The folder you choose for automatic backups

You can pick a folder and let the app write a backup into it on the same interval it would otherwise remind you on. Android asks you which folder and grants the app permission to that one only — it cannot see anything else on your device, and you can take the permission back in Android’s own settings or by pressing Stop in the app.

Where that folder lives is entirely your choice. If it is one your cloud app syncs, your backups go wherever that account is; Stash it writes a file and knows nothing about what happens to it afterwards. The app still has no network permission and still sends nothing anywhere.

The file is not encrypted, for the reason given above. Anyone who can open that folder can read it, so choose one only you can reach. The app keeps the five most recent backups and deletes older ones — only files it wrote itself, matched by name. Nothing else in the folder is ever touched.

The permissions the app asks for

PermissionWhat it is for
Notifications Reminders before a warranty or a renewal runs out. Optional.
Camera Photographing an item or a receipt. Photos are written straight into the app’s own storage. Optional — you can pick existing files instead.
Fingerprint / face The optional lock on the app. Off unless you turn it on.
Run at startup So scheduled reminders survive a restart. It does nothing else.

The internet permission is the one worth explaining. It is there because Google Play's billing library needs it to sell the one-time unlock, and for no other reason: no part of this app opens a connection, and there is no server of ours for it to open one to. Tapping a link — this policy, an email to the developer — hands off to your browser or mail app, which is a different app reaching out.

Home screen widgets

Android draws widgets from your launcher's own process. It cannot open this app's database and it cannot ask the phone for the key, so a widget that shows anything at all needs a copy of that something kept where the launcher can read it: ordinary app storage, unencrypted.

What gets copied is only what the widget you chose displays — the names and dates on its face, and nothing else. No prices, no serial numbers, no photographs, no notes. Remove the widget and the copy is removed with it.

There is a second thing worth saying plainly. Notifications from this app redact themselves on a locked phone. A widget cannot. Android offers no equivalent, so whatever it shows is simply visible, to you and to anyone who picks up your phone. If you track something you would not want read over your shoulder, use the widget that shows counts rather than names, or do not add one.

The biometric lock

It guards the app, not the data. The database key is released whether or not you have just used the sensor, so the lock stops somebody picking up your phone; it does not stop somebody with your phone and a laptop.

Payment

Stash it holds twenty things for free. Lifting that limit is a single payment, handled entirely by Google Play — no card details ever pass through Stash it, and we see only what Play shows any developer: that a purchase happened, not who made it or how they paid.

It is not a subscription, and there is nothing else to buy.

Children

Stash it is not directed at children and collects nothing from anyone, including them.

Your rights over your data

Because we hold nothing, there is nothing for us to hand over, correct or erase on your behalf, and no request you need to make of us. Your copy is yours: export it from Settings at any time, and delete it by uninstalling the app.

Changes

The full policy also ships inside the app, under Settings → Privacy, so it always describes exactly the version you are holding. This page is kept in step with it.

Contact

Questions about any of this: FLuXappStudios@gmail.com.

Last updated 3 September 2026.