Legal
Privacy Policy
Last updated: April 15, 2025
StashSync.app ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and the choices you have when you use our website at stashsync.app and our web application at web.stashsync.app (collectively, the "Service").
1. Information We Collect
1.1 Account Information
When you create an account, we collect your email address, name, and any profile information you provide. Account registration and authentication is handled by Clerk (clerk.com). Clerk processes your credentials securely on our behalf. Please review Clerk's Privacy Policy for more details on how they handle authentication data.
1.2 Content You Create
StashSync.app stores the notes, bookmarks, and files you create or upload ("Content"). Your Content is stored locally on your device using browser IndexedDB and synced to Cloudflare's global edge network when you are online. We do not read, analyze, or sell your Content.
1.3 Usage and Analytics Data
We use the following analytics services to understand how the Service is used and to improve it:
- Google Analytics — collects anonymized data about page views, session duration, device type, browser, and general geographic location. Google Analytics uses cookies and similar tracking technologies. You can opt out via the Google Analytics opt-out browser add-on.
- Cloudflare Analytics — collects aggregate, privacy-preserving metrics about traffic (page views, request counts) without cookies or cross-site tracking. See Cloudflare's Privacy Policy.
1.4 Error and Performance Monitoring
We use Sentry to capture application errors and performance issues. Sentry may collect your IP address, browser type, operating system, and the actions you were taking when an error occurred. This data is used solely to diagnose and fix bugs. See Sentry's Privacy Policy.
1.5 Payment Information
If you subscribe to StashSync.app Pro, payments are processed by Lemon Squeezy. We do not store your payment card details. Lemon Squeezy handles all billing data in accordance with PCI-DSS standards. See Lemon Squeezy's Privacy Policy.
1.6 Log Data
Our infrastructure (hosted on Cloudflare Workers) may automatically record standard server log data such as your IP address, request timestamps, and HTTP response codes. This data is used for security and operational purposes and is not linked to your account.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Authenticate your account and keep it secure
- Sync your Content across your devices
- Process subscription payments and manage billing
- Diagnose bugs, errors, and performance issues
- Understand how the Service is used (in aggregate) to improve it
- Send transactional emails (e.g., password resets, billing receipts) via Clerk or Lemon Squeezy
- Comply with applicable legal obligations
We do not sell your personal data to third parties. We do not use your data for advertising targeting.
3. Cookies and Tracking
StashSync.app uses cookies and similar technologies for authentication (session management via Clerk) and analytics (Google Analytics). We do not use advertising or third-party tracking cookies.
Cloudflare Analytics is cookieless and does not track users across websites.
You can control cookie preferences through your browser settings. Disabling cookies may affect authentication and your ability to use the Service.
4. Data Storage and Security
Your Content is stored on Cloudflare's global edge network. Data is encrypted in transit using TLS. We apply industry-standard security measures to protect your information from unauthorized access, disclosure, or destruction.
Offline data is stored in your browser's IndexedDB on your local device. This data is subject to your device's own security controls.
While we take reasonable precautions, no system is 100% secure. We encourage you to use a strong, unique password for your account.
5. Data Sharing
We share your data only with the following categories of third parties:
- Clerk — for account authentication and user management
- Cloudflare — for hosting, edge delivery, and analytics
- Sentry — for error monitoring
- Google — for website analytics (Google Analytics)
- Lemon Squeezy — for payment processing
We may also disclose your information if required by law, legal process, or to protect the rights, safety, or property of StashSync.app or others.
6. File Sharing
StashSync.app Pro includes a file-sharing feature. When you generate a public share link for a file, that file becomes publicly accessible to anyone with the link. You are responsible for the content you share publicly. You can revoke access by deleting the share link or setting an expiration date.
7. Data Retention
We retain your account data and Content for as long as your account is active. If you delete your account, we will delete your data within 30 days, except where retention is required by law (e.g., billing records retained for tax purposes).
Analytics data collected by Google Analytics and Cloudflare Analytics is retained per those services' default policies. Error data in Sentry is retained for 90 days.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you
- Correction — request that inaccurate data be corrected
- Deletion — request that your account and data be deleted
- Portability — export your notes as Markdown at any time from the app
- Objection — object to certain processing of your data
- Opt-out of analytics — use the Google Analytics opt-out add-on, or a browser-level do-not-track/ad-blocker setting
To exercise any of these rights, contact us at support@stashsync.app. We will respond within 30 days.
9. Children's Privacy
StashSync.app is not directed to children under 13 (or 16 in the EU/UK). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
10. International Transfers
StashSync.app operates globally via Cloudflare's edge network. Your data may be processed in countries outside your own, including the United States. Where required, we rely on appropriate safeguards (such as those provided by our third-party service providers) for international data transfers.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For significant changes, we may notify you via email or an in-app notice. Continued use of the Service after changes take effect constitutes your acceptance of the revised policy.
12. Contact Us
If you have questions or concerns about this Privacy Policy or how we handle your data, please contact us at: