This policy explains how Stowspace handles information in the Windows desktop app, Android app, Chrome and Edge extension, website, account services, sync service, and hosted AI features. The free local app works without an account. Account and cloud processing described below applies when you create an account or use connected features.
Stowspace has no ads, does not resell personal data, and does not track what you save for advertising. Content leaves your device only when you use a connected feature such as paid sync or request a hosted AI action.
Scope
Stowspace lets you save articles, snippets, notes, and videos into a local library. Local libraries and local search remain on each device unless you enable a connected feature. Paid sync, cloud archive, and hosted AI require an account.
Who operates Stowspace
Stowspace is operated by Alexandru Grecu, doing business as Stowspace, in Romania. For the personal data described in this policy, the operator acts as the data controller unless a provider's own terms identify that provider as an independent controller for a particular activity, such as payment processing.
Data Stowspace handles
Account and security data
Supabase provides authentication and database services. Supabase Auth handles your email address, password credential or Google identity, account identifier, confirmation state, and session data. Stowspace stores a profile containing your name and account or entitlement state. Stowspace does not receive your plaintext password.
When you accept the legal documents, Stowspace records the accepted terms and privacy versions, timestamp, signup method, and hashed IP address and user-agent values. Security-sensitive authentication activity may be recorded with the event type, time, outcome, account identifier, provider, and limited request metadata needed to investigate abuse and account problems.
Library and sync data
If you use paid sync or cloud archive, Supabase stores user-scoped library metadata, sync events, collections, tags, notes, snippets, search metadata, and references to private stored objects. Cloudflare R2 stores private article HTML, thumbnails, video blobs, and related synced file content. These cloud copies are associated with your account and are not public.
Billing data
Polar is the merchant of record and handles checkout, payment details, taxes, invoices, refunds, and subscription administration. Stowspace does not store full payment-card details. Stowspace stores the Polar customer reference and entitlement state needed to enable paid features and AI credit purchases.
Hosted AI data
Hosted AI runs only when you initiate a specific action such as a summary, key-points extraction, or tag suggestion. That request can carry the relevant item text and the instructions needed for the selected action to OpenRouter and the model provider selected through OpenRouter. AI usage and metering records may include the action, model, token counts, cost, credit use, and success or failure.
Stowspace does not use your saved content to train models and does not permit OpenRouter or the selected model provider to train on Stowspace user content. Do not submit information to an AI action that you do not want processed by those providers for that request.
Error diagnostics and support
The Windows app keeps size-limited diagnostic logs locally for up to seven days. These logs are designed to exclude saved content, credentials, email addresses, full file paths, and raw URLs. You can inspect, export, or clear them from About & support.
The website sends account-unlinked, sanitized operational errors to Sentry. Error reporting in the desktop app, mobile app, and browser extension is off by default and starts only after you explicitly enable it. Reports can include the app release, platform and runtime versions, error category, sanitized stack information, and an incident reference. They do not include a Stowspace user identity, session replay, saved content, page URLs, or attached log files. Turning optional reporting off stops future reports from that client.
If you submit the support form, Stowspace stores the report fields, contact email, version context, and any diagnostics text file you deliberately attach. The confirmation includes a one-time deletion code that can remove the report without an account.
Abuse-prevention data
Cloudflare Turnstile processes browser and network signals when it verifies selected authentication forms. Upstash stores short-lived rate-limit keys, counters, and expiry information used to protect public and authenticated endpoints. These controls are not used to profile saved content.
How Stowspace uses data
Stowspace uses this information to:
- create, authenticate, secure, and support accounts;
- provide sync, archive, billing, and requested AI features;
- meter paid AI credits and maintain entitlement state;
- detect abuse, enforce rate limits, and diagnose failures;
- process account deletion and notify connected devices; and
- comply with legal obligations and enforce the Terms.
Depending on the activity, processing is necessary to provide the service you request, to protect the service and users, to comply with legal obligations, or is based on consent where applicable. Stowspace does not sell or rent personal data, run advertising profiles, or disclose the subjects of your saved items to advertisers.
Service providers
Stowspace sends information to service providers only as needed for their stated function:
- Hetzner: website and server-side application hosting, including the request traffic needed to deliver those services.
- Supabase: authentication, profiles, consent and audit records, sync metadata, and application database records.
- Google: identity authentication when you choose to sign in with Google.
- Cloudflare R2: private article HTML, thumbnails, video blobs, and other synced file content.
- Polar: checkout and merchant-of-record billing.
- OpenRouter and the selected model provider: the text and instructions for an AI action you initiate.
- Cloudflare Turnstile: bot and abuse checks on selected authentication forms.
- Upstash: rate-limit keys and counters.
- Sentry: account-unlinked, sanitized website errors and optional desktop, mobile, and extension error events when you opt in on those clients.
- GitHub: public signed desktop release metadata and installer downloads when the app checks for updates.
See the Subprocessors page for the current provider list and purpose of each service.
Your choices and rights
Depending on where you live and the circumstances, you may have rights to access, correct, delete, restrict, or object to processing of personal data, and to receive portable data. You may also withdraw consent where processing is based on consent. These rights are not absolute and may be limited by applicable law.
You can update profile information and delete your account through the Account page. You can export the local library from the app. For another privacy request, email [email protected]. Stowspace may need to verify your identity before completing a request. You may also complain to the data-protection authority in your country of residence or work, or where you believe an infringement occurred.
Browser extension and local bridge
The Chrome and Edge extension requests the permissions needed to capture a page, link, or selection when you ask it to save. Capture is user-initiated. The extension passes the requested material through a native-messaging bridge on the local computer to the Stowspace Windows app. The bridge is not a remote web service.
Material received by the desktop app remains local unless you have enabled paid sync or explicitly run a hosted AI action. Extension permissions are not used to build a browsing history or monitor pages you do not ask Stowspace to capture.
Retention and deletion
Items moved to trash are retained for 30 days so that you can restore them, then become eligible for permanent deletion. Local application data remains on a device until you delete it, uninstall or reset the app, or an account-deletion receipt instructs that device to erase its library.
You can delete your cloud account from the Account page. The account-deletion flow removes cloud database records, Supabase Auth identity, and your R2 blobs. Before that cleanup, Stowspace creates minimal per-device deletion receipts. A connected device receives the receipt the next time it contacts the service, wipes its local library, and can acknowledge completion. Receipts and operational cleanup records are retained only as long as needed to complete, verify, retry, and protect the deletion process.
Deletion from active systems can take time when a provider is temporarily unavailable. Provider backups, financial records, and security logs may persist for their normal or legally required retention periods before being overwritten or deleted.
Support reports expire no later than 90 days after submission. Reports marked resolved or closed expire after 30 days if that is sooner. Their private diagnostic attachment is deleted with the report. You can delete a report earlier with its reference and one-time deletion code. Sentry events are not linked to a Stowspace account; their retention follows the configured Sentry project plan.
Security
Stowspace uses user-scoped access controls, private object storage, encrypted network connections, hashed security identifiers, rate limits, and restricted server credentials. No system can guarantee absolute security. Please report suspected account or data-security issues using the contact information below.
Children's use
Stowspace is intended only for people who are at least 18 years old and must not be used by anyone under 18. If you believe someone under 18 has created an account or supplied personal information, contact Stowspace so the account can be reviewed and removed.
Changes to this policy
This policy may change as Stowspace develops. The publication date and document version at the top will be updated when the policy changes. If a change materially affects existing account data, Stowspace will provide an appropriate notice or request renewed consent before the change takes effect where necessary.
Contact
Questions, deletion requests, and privacy concerns can be sent to [email protected] or by post to:
Alexandru Grecu, doing business as Stowspace
Street Elena Farago nr. 35 bl. 170I
Craiova 200704
Romania
Read the Terms of Service, the Cookie Policy, or the privacy and data guide.