Privacy policy
Last updated 22 August 2026 · Applies to the Stash iOS app and this website
Who is responsible for your data. The controller is Dmitrijs Sabelniks, a sole proprietorship (eenmanszaak) registered in the Netherlands, KvK number 70958416, VAT identification number NL002463368B81, registered address Gasthuisring 14-21, 5041 DS Tilburg, Netherlands. Write to privacy@stash.dmitrijs.dev about anything on this page.
Stash takes the TikTok videos you saved to your own Favourites and builds a searchable library out of them: recipes become recipe cards, music becomes a track list, how-to videos become summaries. Doing that means your data leaves your phone and is processed on servers we run and by two providers we use. This page says exactly what we hold, where it goes, how long it stays, and how to remove all of it.
What we collect
- Your Apple account identifier
- Signing in with Apple gives us a stable identifier that is unique to Stash. It is how we recognise you across devices and how everything below is keyed. Stash asks Apple for no name and no email address — we never receive them, not even a private relay address.
- Your quota counters
- Running counts of how many videos you have imported, so we can hold each account to its allowance.
- Your Favourites list
- For each saved video: the TikTok video ID and link, the date you saved it, the creator's handle, the caption, hashtags, thumbnail URL, and duration.
- The library Stash derives from it
- A category, title, summary and topic list per video, plus the structured recipe, track and code cards. To produce these, Stash transcribes the spoken audio and reads the text shown on screen, and it stores both the transcript and that on-screen text.
- Import bookkeeping
- Per-video processing state, retry counts, error codes and estimated processing cost, so a failed import can be resumed rather than restarted.
- Server logs
- Our servers log request times, paths, status codes and the IP address the request came from. We use these to keep the service up and to spot abuse.
Stash has no analytics SDK, no advertising SDK and no crash-reporting SDK. We do not track you across other companies' apps or websites, and we do not sell your data.
How your favourites reach Stash
Both live routes start with an action you take. Stash never reaches into your TikTok account by itself.
- Sharing a video into Stash (live)
- You tap Share on a TikTok and pick Stash. The extension records the link and nothing else — it sends no data anywhere. The next time you open Stash, that one video is fetched and analysed like any other.
- Your own TikTok data export (live)
- You request your data from TikTok, download the file yourself, and pick it in Stash. Stash reads the Favourite Videos entries out of it and ignores every other category in the file — messages, watch history, profile, wallet and the rest are never sent to our servers and never written to storage.
- TikTok Data Portability API (not available)
- Stash cannot connect to your TikTok account, cannot read it, and never asks for your TikTok password. We would like to offer this route so a library could stay in sync without you exporting anything. If it ever becomes available, connecting would be an explicit authorisation you give inside TikTok and revocable from TikTok's own settings at any time, and this page will be updated before the route is switched on.
Why we process it, and on what legal basis
- Running your account, importing your favourites, analysing them and counting your quota
- Article 6(1)(b) GDPR — necessary to perform the service you signed up for. Without this data there is no library.
- Keeping the service up, logging requests, preventing abuse, and enforcing the quota
- Article 6(1)(f) GDPR — our legitimate interest in running a small service on a fixed budget without it being scraped or overrun. We weighed this against your interests: the data involved is limited to logs and counters, it is not used to profile you, and it is deleted on the schedule below.
We do not rely on consent for any of the above, so there is no consent for you to withdraw — instead, deleting your account (below) ends the processing entirely. If we ever add something genuinely optional, we will ask for consent separately and it will be refusable without losing the rest.
Where it is processed
Stash runs on a single server we operate in Amazon Web Services' eu-north-1 region (Stockholm, Sweden). Your import queue and the database holding your library are in the same region. Text analysis runs on AWS Bedrock in eu-central-1 (Frankfurt, Germany), on an open-weights model hosted inside AWS — the captions and transcripts sent there are not passed to the model's original publisher. Speech-to-text runs at Groq, which is outside the EU; see international transfers below.
This is shared infrastructure. Your rows sit in the same database table and the same queue as other users', separated by your account identifier rather than by having a server of your own.
To transcribe a video and read its on-screen text, our server fetches the video from TikTok, extracts the audio and samples some frames, and deletes the downloaded file as soon as that is done. Stash does not keep copies of TikTok videos.
Who else processes it
These are our sub-processors. We do not share your data with anyone else, and we do not sell it.
- Amazon Web Services EMEA SARL
- Hosting, the import queue, and the database (eu-north-1, Stockholm); text analysis on Bedrock (eu-central-1, Frankfurt). Receives everything listed under "What we collect".
- Groq, Inc.
- Speech-to-text. Receives the audio track extracted from a saved video and returns the transcript. It does not receive your account identifier, your email, or your library.
International transfers
Groq, Inc. is established in the United States and we send audio to its API, so this is a transfer outside the EEA under Chapter V GDPR. It is made under the European Commission's Standard Contractual Clauses, together with the fact that the audio is transient — it is processed for the length of one request and is not retained by us afterwards.
AWS processes your data in the EU regions named above. AWS's parent company is American, so its Data Processing Addendum and the Standard Contractual Clauses cover any support access from outside the EEA. Stash does not use the AWS European Sovereign Cloud.
Videos made by other people
Your library is built out of other people's videos. Captions, creator handles, transcripts and on-screen text are personal data about TikTok creators who are not Stash users and never gave us anything directly. Contacting each of them would take effort out of all proportion to the processing, so we rely on the exemption in Article 14(5)(b) GDPR and set out here what we do instead: this content is only ever visible inside the private library of the user who saved the video, it is never published, never used to build creator profiles, and never used to train models.
A transcript can incidentally contain sensitive material — someone talking about their health, their politics or their religion. We do not seek that out, do not index it as such, and do not use it for anything beyond producing your summary.
How long we keep it
- Your library and account
- Until you delete your account. If you stop using Stash entirely, we delete accounts that have had no activity for 24 months, after an email warning where we have an address to warn you at.
- Import bookkeeping
- 90 days after the import finishes.
- Server logs
- 30 days, then deleted.
- Queued work
- Messages carrying video links sit in the processing queue for at most 14 days before the queue drops them, whether or not they were handled.
- Backups
- The database has a rolling 35-day point-in-time backup window. Data you delete disappears from the live service immediately, but persists in that backup window until it rolls off. We do not restore backups to bring deleted accounts back.
Deleting your account and your data
Settings in the app has Delete account. It removes your account identifier, your library, your quota counters and your import bookkeeping from our servers, and it deletes the copy held on your phone. It also revokes the Sign in with Apple grant, so Stash disappears from the Apple ID list on your device. It is immediate and it is not reversible. The two lags above — the 14-day queue window and the 35-day backup window — are the only places anything survives, and neither is used to serve your data back to anyone.
Deleting in the app is all or nothing today: there is no button that removes a single video. If you want one video gone rather than the account, or would rather ask us than press the button, write to privacy@stash.dmitrijs.dev and we will remove it.
Your rights
Under the GDPR you have the following rights over your data. Exercise any of them by writing to privacy@stash.dmitrijs.dev; two of them you can also exercise yourself in the app.
- Access (Art. 15)
- Ask what we hold about you and get a copy.
- Portability (Art. 20)
- Settings has Export my data, which produces a machine-readable JSON file containing your library, your account record and your quota counters.
- Rectification (Art. 16)
- Ask us to correct anything wrong. Summaries and categories are generated by a model and are sometimes simply wrong — tell us and we will fix or remove them.
- Erasure (Art. 17)
- Delete your account in the app, or ask us to.
- Restriction (Art. 18)
- Ask us to stop processing while a dispute about accuracy or lawfulness is resolved.
- Objection (Art. 21)
- Object to the processing we base on legitimate interests. We will stop unless we can show compelling grounds that override your interests.
We answer without undue delay and within one month. If a request is genuinely complex we may take up to two months more, and we will tell you why within the first month.
Stash sorts your videos into categories using a language model. That is not automated decision-making with legal or similarly significant effects under Article 22 — nothing about you is decided, only how a video is filed, and you can change or delete any of it.
If you are in the United States
Stash is sold worldwide, so some of you are covered by California's CCPA as amended by the CPRA, or by a comparable state law in Virginia, Colorado, Connecticut, Utah, Texas, Oregon or Montana. The service works the same way for everyone; this section says the same things again in the vocabulary those laws use.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We never have. There is no advertising in Stash, no advertising SDK, no analytics SDK, and no data broker in the picture — which is why you will not find a "Do Not Sell or Share My Personal Information" link on this site. There is nothing for it to switch off.
In the twelve months covered by this policy we collect two of the statutory categories: identifiers (the app-specific Apple user identifier, and the IP address in our server logs) and internet or other electronic network activity (the videos you saved and everything we derive from them — captions, transcripts, on-screen text, summaries and categories). We collect no sensitive personal information as that term is defined, so the right to limit its use does not arise. Everything above is collected from you and from the TikTok data export you hand us, and it is used for one purpose: running the app you bought. Retention is set out under "How long we keep it".
You have the right to know what we hold and get a copy of it, to have it corrected, and to have it deleted. Two of those are buttons rather than requests: Settings has Export my data and Delete account, and neither asks us for permission. For anything else, or to have someone act as your authorised agent, write to privacy@stash.dmitrijs.dev. We verify a request by checking that it comes from the account it concerns, and we answer within 45 days.
We will not discriminate against you for exercising any of this — no price change, no degraded service. The app costs the same and works the same either way.
Security
Everything between the app and our server travels over HTTPS. The database and the processing queue are encrypted at rest. Administrative access to the server is by SSH key from a single operator address. Only the operator has access to production data, and only to run and repair the service.
Stash is a small operation on one server. We think that is the right size for what it does, but you should know that it is not a company with a security team, and this policy is not a promise that nothing can go wrong.
If there is a breach
If personal data is breached in a way that is likely to risk your rights and freedoms, we report it to the Autoriteit Persoonsgegevens within 72 hours of becoming aware, and we tell you directly when the risk to you is high.
Age
Stash is for people aged 16 and over. We do not knowingly create accounts for anyone younger. If you believe a child has an account, write to us and we will delete it.
Other services you touch through Stash
Watching a saved video inside Stash loads TikTok's own embedded player, which means TikTok sees that request and may set its own cookies — that is TikTok's processing, under TikTok's privacy policy, not ours. Tapping "Play on Spotify" opens Spotify with a search; from that point you are in Spotify's hands. Signing in uses Apple's own flow, and Apple sees that you use an app from our developer account.
Complaints
If you are unhappy with how we handle your data, tell us first — privacy@stash.dmitrijs.dev. You also have the right to complain to a supervisory authority. Ours is the Dutch one, the Autoriteit Persoonsgegevens in The Hague (autoriteitpersoonsgegevens.nl). You may equally complain to the authority in the EU country where you live or work.
We are not required to appoint a data protection officer, and we do not need an Article 27 representative because the controller is established in the EU.
Changes
We will post any change to this policy on this page with a new date at the top. If a change materially affects what we do with your data, we will tell you in the app before it takes effect.
Stash