Legal · Stash AI Ltd

Privacy Policy

Last updated August 29, 2026Company no. 17428170England & Wales

This Privacy Notice for Stash AI Ltd ('we', 'us', or 'our') describes how and why we might access, collect, store, use, and/or share ('process') your personal information when you use our services ('Services'), including when you:

  • Download and use our mobile application (Stash AI)
  • Engage with us in other related ways, including support or feedback

Who we are. Stash AI Ltd is the data controller for the personal information described in this notice. We are a private limited company registered in England and Wales under company number 17428170.

Questions or concerns? Contact us at support@stashai.co.uk.

Summary of key points

What personal information do we process? We collect your email address, name, and the financial data you manually enter into the app — such as transactions, budgets, savings pots, and goals.

Do we process sensitive personal information? Yes — we process financial data that you voluntarily enter, plus (if you choose to link a bank account) read-only banking data we receive from your bank through TrueLayer, a UK FCA-regulated Open Banking provider. This includes balances, transactions, credit-card limits and statement information for accounts you explicitly authorise. We never see or store your online-banking credentials. All subscription payments to Stash AI are handled by RevenueCat and Apple In-App Purchases.

Do we collect information from third parties? Yes, with your explicit consent: if you link a bank account, we receive read-only account data from your bank via TrueLayer. We do not purchase or obtain data from marketing partners or data brokers. We receive crash and performance data via Sentry to keep the app stable.

How do we process your information? We use your data to provide the app's features, generate AI-powered insights, send notifications, and keep your account secure.

Who do we share your data with? We share data only with the essential service providers that power the app: Supabase (database and authentication), RevenueCat (subscription management), Apple (in-app purchases), Google Cloud AI / Gemini (AI insights), Groq and OpenAI (voice transcription and read-aloud speech), Sentry (crash reporting), and PostHog (analytics).

How do we keep your data safe? We use bank-grade encryption, biometric authentication (Face ID / Touch ID), and secure cloud infrastructure via Supabase.

What are your rights? Under UK GDPR, you have the right to access, correct, or delete your data at any time. Contact us at support@stashai.co.uk.

Table of contents

  1. What information do we collect?
  2. How do we process your information?
  3. What legal bases do we rely on?
  4. When and with whom do we share your information?
  5. Do we offer AI-based products?
  6. How long do we keep your information?
  7. How do we keep your information safe?
  8. What are your privacy rights?
  9. Children's privacy
  10. Do we make updates to this notice?
  11. How can you contact us?
  12. How can you review, update, or delete your data?

1. What information do we collect?

Personal information you provide to us:

We collect personal information that you voluntarily provide when you register for and use the app. This includes:

  • Email address
  • Name
  • Financial data you manually enter — including transactions, spending categories, budget limits, savings pots, and financial goals
  • Subscription and bill information you add or that is detected from your own transaction history
  • Payday and income details you configure

Linked Bank Account Data (optional Pro feature):

If you choose to connect a bank account or credit card via TrueLayer (an FCA-regulated Open Banking provider), TrueLayer obtains your explicit consent through your bank's secure authentication flow, then provides Stash AI with read-only access to:

  • Institution and account / card identifiers and metadata
  • Current and available balances, agreed overdraft, credit limit
  • Transaction history (up to 90 days on initial connect, then ongoing)
  • For credit cards: statement balance, last statement date, minimum payment, payment due date

We store daily snapshots of your account balances so you can see your net worth and utilization change over time. We never receive or store your online-banking username, password, or PIN. The OAuth tokens that let our edge functions refresh your data are encrypted at rest (AES-GCM, key held only in Supabase Edge Function environment variables). You can disconnect any linked bank at any time from Profile → Connected Accounts; past transactions stay in the app for your records but no new ones will sync.

Payment Data: If you subscribe to Stash AI Premium, payment is processed through Apple In-App Purchases, managed by RevenueCat. We do not store your card number or bank details. All payment data is handled by Apple in accordance with their privacy policy: https://www.apple.com/legal/privacy/.

Device and App Permissions:

  • Calendar access — used to track your payday cycle and upcoming bills. You can revoke this in your device settings at any time.
  • Push notifications — used to alert you about budget limits, upcoming bills, and payday reminders. You can turn these off in your device settings at any time.
  • Face ID / Touch ID — used for biometric login to keep your account secure. Biometric data is processed entirely on your device and never sent to our servers.
  • Microphone (optional) — used only when you tap the microphone button in the Atlas chat to dictate a message. Audio is streamed via our secure edge function to a speech-to-text provider, transcribed once, and discarded. We use Groq (Whisper large v3 Turbo) as the primary transcription provider and fall back to OpenAI (Whisper) if Groq is unavailable, so a given clip may be processed by either. Neither provider retains the audio after transcription or uses it to train models. You can revoke microphone access in your device settings at any time without losing any other functionality.
  • Photo library (optional) — used only if you choose to set a profile picture. The image you pick is uploaded to our Supabase storage; the rest of your photo library is never read.

Crash and Performance Data: We use Sentry to automatically collect anonymised crash reports and error logs to help us fix bugs and improve app stability. This data does not include your financial information.

2. How do we process your information?

We process your personal information for the following reasons:

  • Account management — to create and maintain your account and keep it secure
  • App functionality — to power your dashboard, budgets, transactions, savings pots, goals, subscription tracker, and payday calendar
  • AI insights — to analyse your spending patterns and generate personalised financial insights via our AI assistant, Atlas
  • Notifications — to send you relevant alerts about your finances (budget alerts, payday reminders, upcoming bills)
  • Payments — to process your subscription via Apple In-App Purchases and RevenueCat
  • Crash reporting — to identify and fix bugs using anonymised diagnostic data via Sentry
  • Legal compliance — to meet our obligations under applicable law

Under UK GDPR, we rely on the following legal bases:

  • Performance of a Contract — processing your data is necessary to provide the app's features as agreed when you create an account
  • Consent — for push notifications and optional features; you may withdraw consent at any time
  • Legitimate Interests — for crash reporting and app improvement, where our interests do not override your rights
  • Legal Obligations — where required by applicable law

4. When and with whom do we share your information?

We do not sell your personal data. We share data only with the following essential service providers:

ProviderPurposePrivacy Policy
SupabaseDatabase, authentication, and secure data storagehttps://supabase.com/privacy
TrueLayerUK FCA-regulated Open Banking — read-only access to balances, transactions and credit-card data from accounts you explicitly link, plus payment initiation for Split Bill / shared-goal payoutshttps://truelayer.com/privacy/
RevenueCatSubscription management and entitlement verificationhttps://www.revenuecat.com/privacy
AppleIn-app purchase payment processinghttps://www.apple.com/legal/privacy/
Google Cloud AI (Gemini)Powers the Atlas AI assistant and spending insightshttps://policies.google.com/privacy
Groq (Whisper API)Primary speech-to-text for the Atlas voice-input button and Solon voice calls (audio sent only when you speak, then discarded — never used for model training)https://groq.com/privacy-policy/
OpenAI (Whisper API + Text-to-Speech API)Fallback speech-to-text when Groq is unavailable, and the text-to-speech voice used for Atlas read-aloud and Solon voice replies (the reply text Stash generates is sent to produce the audio)https://openai.com/policies/privacy-policy
SentryAnonymised crash reporting and error trackinghttps://sentry.io/privacy/
Expo / EASPush notification delivery and OTA update infrastructurehttps://expo.dev/privacy
PostHogProduct analytics and feature usage trackinghttps://posthog.com/privacy

We may also share your information if required by law or in connection with a business transfer (e.g. merger or acquisition), in which case we will notify you in advance where possible.

5. Do we offer AI-based products?

Yes. Stash AI includes Atlas, an AI-powered financial assistant. Atlas uses Google Cloud AI (Gemini) to analyse your spending patterns and generate personalised insights and recommendations.

When you use Atlas, your financial data is sent to Google Cloud AI for processing. So that Atlas can answer questions about your actual money, this includes:

  • your first name, so Atlas can address you naturally;
  • merchant names and categories from your transactions, and your typical spend at places you visit repeatedly;
  • account, card and goal names, the card network (Visa, Mastercard, Amex), and the name of the bank or institution holding each account;
  • balances, credit limits, utilisation, statement and due dates, budgets, income and savings figures.

We deliberately do not send: your surname, email address, postal address, phone number, date of birth, bank account numbers, sort codes, full card numbers, or card and account last-four digits. We do not send your Stash account identifier or any advertising identifier.

This is done securely and in accordance with our agreement with Google. We do not use your data to train AI models, and per our agreements with Google (Gemini), Groq and OpenAI, none of these providers uses API content to train their models. You must not input sensitive personal information unrelated to your finances (such as health or identity data) into the Atlas chat.

If you choose to use the voice input button in the Atlas chat, or speak to Solon on a voice call, the audio clip is streamed via our secure edge function for transcription only — to Groq (our primary provider), or to OpenAI if Groq is unavailable. We do not store the audio, and neither provider retains it after transcription.

If you use read-aloud or a Solon voice call, the reply text that Stash has generated for you is sent to OpenAI's text-to-speech API to synthesise the spoken audio. That text can include your first name and figures drawn from your finances, because it is the same answer shown on screen. You can use Atlas entirely in text by typing your message and not using read-aloud — denying the microphone permission has no other effect on the app.

6. How long do we keep your information?

We retain your personal information for as long as your account is active. If you delete your account, we will delete or anonymise your data within 30 days, except where we are required by law to retain it longer (for example, for tax or fraud prevention purposes).

7. How do we keep your information safe?

We protect your data using:

  • End-to-end encryption for data in transit (TLS)
  • Encrypted data storage via Supabase
  • Biometric authentication (Face ID / Touch ID) on your device
  • Row-level security policies ensuring users can only access their own data
  • Automated crash monitoring via Sentry to quickly identify and resolve vulnerabilities

Where your data is stored. Your account and financial data are stored on Supabase infrastructure in the European Union — specifically the eu-north-1 region (Stockholm, Sweden). Product analytics events are sent to PostHog's EU cloud (eu.i.posthog.com). TrueLayer processes Open Banking data in the UK / EU. A small number of subprocessors (Sentry crash reports, RevenueCat subscription metadata, Google Gemini, Groq, OpenAI) may process data in the United States; in each case the transfer is covered by the provider's Standard Contractual Clauses (SCCs) under UK GDPR Article 46. We minimise what is sent to those US providers: no Stash account identifier, email address or device identifier is sent to Gemini, Groq or OpenAI, and no user identifier is set in Sentry. Gemini does receive your first name and the merchant, account, card and institution names needed to answer questions about your own money — see "Does the app use AI?" above for the full list of what is and is not sent.

No system is 100% secure. While we take every reasonable precaution, we cannot guarantee absolute security against all threats.

8. What are your privacy rights?

Under UK GDPR, you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — ask us to correct inaccurate data
  • Erasure — ask us to delete your data ('right to be forgotten')
  • Restriction — ask us to limit how we use your data
  • Data portability — receive your data in a portable format
  • Object — object to processing based on legitimate interests
  • Withdraw consent — where processing is based on consent, you may withdraw it at any time

To exercise any of these rights, contact us at support@stashai.co.uk.

If you believe we are processing your data unlawfully, you have the right to complain to the Information Commissioner's Office (ICO): https://ico.org.uk.

Account deletion: You can delete your account at any time from within the app settings. Upon deletion, your data will be removed from our active systems within 30 days.

9. Children's privacy

The App is not directed at, and we do not knowingly collect personal information from, children. The minimum age to create an account is 13 years old. If you are under 18, you may only use Stash AI with the consent of a parent or guardian.

For users in the EU/EEA, the GDPR age of digital consent varies by country (between 13 and 16). If you are below the digital-consent age in your country, a parent or guardian must consent on your behalf.

If we become aware that we have inadvertently collected personal information from a child below the applicable minimum age, we will delete that data promptly. If you believe a child has provided us with personal information, please contact us at support@stashai.co.uk and we will take steps to remove the information from our systems.

We do not knowingly process the sensitive personal information of any user, of any age, beyond the limited financial data described in this notice. Stash AI does not run advertising and does not share data with advertising networks or data brokers.

10. Do we make updates to this notice?

Yes. We may update this Privacy Notice from time to time to reflect changes in the law or our practices. The 'Last updated' date at the top will always reflect the most recent version. We will notify you of significant changes via the app or by email.

11. How can you contact us?

Stash AI Ltd Data controller — registered in England and Wales, company number 17428170. Email: support@stashai.co.uk

12. How can you review, update, or delete your data?

You can review and update your account information at any time from within the app. To request full data deletion or a copy of your data, email us at support@stashai.co.uk and we will respond within 30 days in accordance with UK GDPR.

Back to top