Legal

Privacy Policy

Last updated August 25, 2026

Stow is a private archive: it exists to hold your content for you, not to monetize it. This policy explains exactly what we store, what our systems do with it, and the controls you have — in plain language.

Who we are

Stow is operated by Stow (operating entity to be announced) (“we”, “us”). We are the data controller for the personal data described here. You can reach us at support@stowapp.dev for any privacy question or request.

Data we store

We store only what the service needs to work:

  • Account data — your name, email address, and a hashed password (we never store the password itself).
  • Captured content — the notes, links, emails, and files you save to Stow, including attachments and text extracted from them. Your original content is immutable: AI output and your own edits are stored as separate layers and never overwrite what you captured.
  • Connected Google data — if you link Gmail or Google Drive, we read only the labels and folders you explicitly choose to watch, with read-only access. Matching messages and files are copied into your archive; we never modify or delete anything in your Google account.
  • Usage and audit records — an activity log of actions in your account (visible to you in the app) and the operational metadata needed to run capture and AI jobs.
  • Billing records — your plan and subscription status. Payments are processed by Stripe; card numbers never touch our servers (see Payments below).

We do not buy, sell, rent, or trade personal data. There is no advertising on Stow.

AI processing

Stow organizes what you capture using a large-language-model provider. To do that, the content of an item is sent to the AI provider to generate titles, summaries, tags, and filing suggestions. That output is stored as a separate suggestion layer you can review and override.

  • Content is sent for organization only — not for advertising or profiling.
  • We do not permit our hosted AI provider to use your content to train its models.
  • You may instead configure your own AI key and endpoint in Settings, in which case content is sent to the provider you chose, under your own agreement with them. Your key is stored encrypted.
  • If AI processing fails, your item stays safely in your Inbox flagged for review — content is never lost or discarded because of an AI error.

Google user data and Limited Use

Stow’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practice, for Gmail and Drive data that means:

  • It is used only to provide the archive features you see in Stow — capturing the messages and files from sources you chose to watch into your private archive.
  • It is never used for advertising, never sold, and never transferred to third parties except as needed to provide those features (for example, AI organization as described above), to comply with law, or as part of a merger with notice to you.
  • Humans do not read it, except with your explicit permission for support, where required for security or legal compliance, or when aggregated and anonymized.
  • Disconnecting a Google account in Settings stops all access; you can also revoke Stow’s access at any time from your Google Account security settings.

Payments

Paid plans are billed through Stripe. Your card details are entered on and stored by Stripe — we never see or store card numbers. We keep only what we need to know which plan you are on: a Stripe customer reference and subscription status. Stripe’s handling of your data is described in the Stripe Privacy Policy.

Service providers

We share data only with the processors needed to run Stow: our hosting and database infrastructure, file storage, the AI provider described above, and Stripe for payments. Each receives only what its function requires and is bound to process it solely on our instructions.

Your rights and controls

You do not need to email us to exercise the core rights — they are built into the app, on every plan including Free:

  • Access and portability — Settings → Account gives you a complete JSON export of your archive at any time. Export is never paywalled.
  • Erasure — Settings → Account lets you delete your account; deletion permanently removes your items, attachments, stored files, and account records.
  • Rectification and objection — you can edit or override any AI output in the app, and disconnect any source at any time.

If you are in the EEA, UK, or a jurisdiction with similar law, these correspond to your statutory rights of access, portability, rectification, erasure, restriction, and objection, and you also have the right to complain to your supervisory authority. For anything not covered in-app, email support@stowapp.dev and we will respond within 30 days.

Retention and security

We keep your content for as long as your account exists. Deleting an item removes it from your archive; deleting your account removes everything. Data is encrypted in transit, stored credentials and API keys are encrypted at rest, and API tokens are stored only as hashes.

Changes to this policy

If we make material changes we will update this page and its date, and notify you in the product or by email before the change takes effect.