PRIVACY POLICY Last updated May 20, 2026
This Privacy Notice for Stash AI ('we', 'us', or 'our') describes how and why we might access, collect, store, use, and/or share ('process') your personal information when you use our services ('Services'), including when you:
Download and use our mobile application (Stash AI) Engage with us in other related ways, including support or feedback Questions or concerns? Contact us at [email protected].
SUMMARY OF KEY POINTS What personal information do we process? We collect your email address, name, and the financial data you manually enter into the app — such as transactions, budgets, savings pots, and goals.
Do we process sensitive personal information? Yes — we process financial data that you voluntarily enter, plus (if you choose to link a bank account) read-only banking data we receive from your bank through TrueLayer, a UK FCA-regulated Open Banking provider. This includes balances, transactions, credit-card limits and statement information for accounts you explicitly authorise. We never see or store your online-banking credentials. All subscription payments to Stash AI are handled by RevenueCat and Apple In-App Purchases.
Do we collect information from third parties? Yes, with your explicit consent: if you link a bank account, we receive read-only account data from your bank via TrueLayer. We do not purchase or obtain data from marketing partners or data brokers. We receive crash and performance data via Sentry to keep the app stable.
How do we process your information? We use your data to provide the app's features, generate AI-powered insights, send notifications, and keep your account secure.
Who do we share your data with? We share data only with the essential service providers that power the app: Supabase (database and authentication), RevenueCat (subscription management), Apple (in-app purchases), Google Cloud AI / Gemini (AI insights), Groq and OpenAI (voice transcription and read-aloud speech), Sentry (crash reporting), and PostHog (analytics).
How do we keep your data safe? We use bank-grade encryption, biometric authentication (Face ID / Touch ID), and secure cloud infrastructure via Supabase.
What are your rights? Under UK GDPR, you have the right to access, correct, or delete your data at any time. Contact us at [email protected].
TABLE OF CONTENTS What Information Do We Collect? How Do We Process Your Information? What Legal Bases Do We Rely On? When and With Whom Do We Share Your Information? Do We Offer AI-Based Products? How Long Do We Keep Your Information? How Do We Keep Your Information Safe? What Are Your Privacy Rights? Children's Privacy Do We Make Updates to This Notice? How Can You Contact Us? How Can You Review, Update, or Delete Your Data?
We collect personal information that you voluntarily provide when you register for and use the app. This includes:
Email address Name Financial data you manually enter — including transactions, spending categories, budget limits, savings pots, and financial goals Subscription and bill information you add or that is detected from your own transaction history Payday and income details you configure Linked Bank Account Data (optional Pro feature):
If you choose to connect a bank account or credit card via TrueLayer (an FCA-regulated Open Banking provider), TrueLayer obtains your explicit consent through your bank's secure authentication flow, then provides Stash AI with read-only access to:
Institution and account / card identifiers and metadata Current and available balances, agreed overdraft, credit limit Transaction history (up to 90 days on initial connect, then ongoing) For credit cards: statement balance, last statement date, minimum payment, payment due date We store daily snapshots of your account balances so you can see your net worth and utilization change over time. We never receive or store your online-banking username, password, or PIN. The OAuth tokens that let our edge functions refresh your data are encrypted at rest (AES-GCM, key held only in Supabase Edge Function environment variables). You can disconnect any linked bank at any time from Profile → Connected Accounts; past transactions stay in the app for your records but no new ones will sync.
Payment Data: If you subscribe to Stash AI Premium, payment is processed through Apple In-App Purchases, managed by RevenueCat. We do not store your card number or bank details. All payment data is handled by Apple in accordance with their privacy policy: https://www.apple.com/legal/privacy/.
Device and App Permissions:
Calendar access — used to track your payday cycle and upcoming bills. You can revoke this in your device settings at any time. Push notifications — used to alert you about budget limits, upcoming bills, and payday reminders. You can turn these off in your device settings at any time. Face ID / Touch ID — used for biometric login to keep your account secure. Biometric data is processed entirely on your device and never sent to our servers. Microphone (optional) — used only when you tap the microphone button in the Atlas chat to dictate a message. Audio is streamed via our secure edge function to a speech-to-text provider, transcribed once, and discarded. We use Groq (Whisper large v3 Turbo) as the primary transcription provider and fall back to OpenAI (Whisper) if Groq is unavailable, so a given clip may be processed by either. Neither provider retains the audio after transcription or uses it to train models. You can revoke microphone access in your device settings at any time without losing any other functionality. Photo library (optional) — used only if you choose to set a profile picture. The image you pick is uploaded to our Supabase storage; the rest of your photo library is never read. Crash and Performance Data: We use Sentry to automatically collect anonymised crash reports and error logs to help us fix bugs and improve app stability. This data does not include your financial information.