Privacy policy
What Stash keeps, and why.
Stash keeps the articles you choose to save, and the highlights and notes you make on them, so you can read them anywhere. That is all it collects, and that is all it uses them for.
Last updated 3 October 2026
- Collected
- Only what you save, and your account.
- Ads and tracking
- None. No analytics scripts either.
- The extension
- Runs only when you click it.
- Leaving
- Export or delete it all from Settings.
What Stash stores
Your account. Your email address. If you sign in with a password, it is handled by Supabase and stored only as a one-way hash, so nobody can read it back, including me. If you sign in with GitHub or Google, also the basic profile details they share with the sign-in, such as your name, username and profile picture.
What you save. For each article: its address, title, author, text and images, and when you saved it.
What you do with it. Your highlights and notes, your tags, and whether an article is archived, favourited, read or in the trash.
Your reading position and display settings (font, size, theme, list density) stay on your device and are not sent anywhere.
What the browser extension does
The extension does nothing until you click its button. It has no access to your browsing history and does not run in the background on the pages you visit.
When you open it, it sends the address of the current tab to Stash, to check whether you have saved that page already.
When you save, it sends that page’s content and the images already loaded on it to Stash, which turns it into a clean article in your library. That is whatever is on the page at the time, including anything personal shown on it, so save pages you would be happy to keep a copy of.
It signs in by using your existing Stash session in the same browser. It stores no password or token of its own.
Where it lives
Your data is stored with Supabase (database, file storage and sign-in), and the app runs on Vercel. Both keep standard technical logs, such as the addresses requests come from, as part of running their services. If you sign in with GitHub or Google, they handle that step.
So that Stash works offline, a copy of your library is also kept in your browser on each device you use it on. Signing out removes access to it.
When you save a link by pasting it, Stash’s server fetches that page to read it. After any save, pasted or from the extension, it also downloads the article’s images from the sites that host them and keeps a copy with the article, so it reads offline. Those sites see requests from Stash, not from you, along with the address of the article, as they would from a browser.
What Stash doesn’t do
It does not sell your data, show ads, use your data to target ads, or pass it to anyone except the services above, and only so they can run the app. It loads no third-party analytics or tracking scripts. The only cookies it sets are the ones that keep you signed in.
Taking your data, or deleting it
Export your data in Settings downloads every article and highlight in your library as a single file.
Delete account in Settings permanently deletes your account and everything in it, images included.
You can also delete any single article. It stays in the trash for 30 days and is then deleted permanently, along with its highlights and images. You can empty the trash sooner yourself.
If you can’t sign in to do any of this, email renjithravindran90@gmail.com from the address you signed up with, and I’ll delete your account by hand.
Changes and contact
If this policy changes, the date at the top changes with it. Questions go to renjithravindran90@gmail.com.