Privacy Policy
Last updated: 2026-07-25
Data Controller: Michael Cosby ·
privacy@stowbook.app
This policy will be updated when a trading name is registered.
If you want the technical version of how this is enforced rather than the legal one, see the security page.
1. What Stowbook is
Stowbook is a home inventory application. This policy covers the Stowbook mobile applications for iOS and Android, the Stowbook web application at app.stowbook.app, this website at stowbook.app, and the backend services operated by Michael Cosby.
2. Data we collect and why
2.1 Account data
When you create an account we collect your email address and store a hash of your password — never the password itself. We also store the region you select at signup (United States or European Union), which is fixed for the life of the account, and your language preferences if you set them. We use this to authenticate you and to operate the service. Legal basis: performance of a contract.
When you set or change a password, a short fragment of its hash (the first five characters, which cannot be reversed to recover the password) is checked against a public breached-password database so we can warn you if the password has appeared in a known breach. Your password, your email address, and your identity are never sent. Legal basis: legitimate interests (account security).
2.2 Inventory data
Everything you add to Stowbook — items, containers, rooms and locations, photos, document attachments, custom fields, notes, values, and any barcode or tag numbers you record — is stored in your account. You put it there; it belongs to you. Legal basis: performance of a contract.
Original photo uploads: when you add a photo, the original file is held briefly in a staging area while it is converted to the compressed format we store long-term. Original uploads are automatically deleted on a scheduled basis after conversion; the current window is stated in the retention table in § 6.
2.3 AI identification data
When you use the AI scanning feature, the photo you take is sent to a cloud AI vision provider for identification. The photo is then stored in your Stowbook account, in your chosen region, as part of the item you created. The text returned by the AI (item name and description) is stored both in your account and in a usage ledger.
Current provider: Google LLC (Vertex AI). Google processes the image to return an identification result under a data processing agreement, and does not use your images to train its models. See cloud.google.com/terms/data-processing-addendum.
Change of provider: we may change AI provider — for example to a provider operating within our existing hosting infrastructure, such as Amazon Bedrock. Any provider we use will be bound by equivalent terms: processing only, no use of your content for model training, and processing within the region you chose. The provider in use at any time is named in the sub-processor table in § 3, and we will update this policy and notify you as described in § 9 before a change takes effect.
Usage ledger: We maintain a log of AI credit usage for dispute resolution — so you can verify that two charges in quick succession were two distinct scans, not the same scan processed twice. Ledger entries include the timestamp, a thumbnail, and the item name returned. After 90 days, ledger entries are automatically reduced to a timestamp and credit count only; the thumbnail and item name are deleted. You may request early reduction of any ledger entry at any time by contacting privacy@stowbook.app.
Scanning is optional. If you never use it, no image or inventory content is ever sent to an AI provider.
Legal basis: performance of a contract (AI identification is a paid feature); legitimate interests (dispute resolution record).
2.4 Payment data
If you purchase a subscription or AI credits, payment is processed by Stripe, Inc. on the web, or by Apple or Google for purchases made inside the mobile apps. We do not receive or store your card details. We receive and store a record of the transaction (amount, currency, date, purchase type, and a transaction identifier from the payment provider) and your subscription status. Legal basis: performance of a contract; legal obligation (financial records).
Financial records kept after account deletion: We keep a record of each purchase you make (a subscription payment or an AI credit pack) for up to 10 years, even after you delete your account. This is a legal requirement under applicable tax and financial record-keeping laws, and we also rely on these records to resolve payment disputes.
Each of these records contains only the transaction amount, the currency, the date, the type of purchase, a transaction ID from the payment provider, and an anonymous account identifier. It does not contain your name, your email address, or any of your inventory content. Once your account is deleted, the anonymous account identifier cannot be linked back to you by Stowbook — we have no internal way to connect it to you again.
2.5 Sharing with other people
Stowbook lets you grant another Stowbook user access to part of your inventory. If you do, that person can see the items you shared with them, and — depending on the permission level you chose — may be able to change them. To make this work we store the grant itself (who you shared with, what, and at what permission level).
We also keep an audit log of changes made by people you have shared with, so you can see what they changed. Audit entries are automatically deleted after 90 days. Revoking a share stops future access; it does not un-see anything already seen. Legal basis: performance of a contract; legitimate interests (giving you an account of changes made to your data by others).
2.6 Connected applications
You can optionally connect third-party applications — including AI assistants — to your Stowbook account, and issue access tokens for them. If you do this, those applications can read and modify the inventory data you authorise, and whatever they do with it is governed by their terms, not ours. We store the tokens you have issued and per-token rate-limiting counters so you can review and revoke access at any time. No application has access unless you explicitly grant it. Legal basis: consent; performance of a contract.
2.7 Email we send you
We send transactional email — account verification, password resets, sharing invitations, and important service notices — via Amazon Simple Email Service. We do not send marketing email.
Suppression records: if an email to you hard-bounces or you mark one of our emails as spam, we permanently record that email address on a suppression list so we stop sending to it. This record persists even after account deletion, and contains only the email address, the reason, and the date. Keeping it is what prevents us from mailing that address again. Legal basis: legitimate interests (protecting mail deliverability and respecting a recipient's refusal); legal obligation (anti-spam law).
2.8 Diagnostics
The apps send us first-party diagnostic reports — errors, crashes, and basic performance information, together with a randomly generated device identifier, the app version, and the platform. This is our own logging; it is not a third-party analytics or advertising product, it is not used to build a profile of you, and it is not sold or shared. It is used to find and fix bugs. Legal basis: legitimate interests (operating and debugging the service).
2.9 Server logs
Our servers automatically record standard HTTP access logs: IP address, request path, timestamp, response code, and user agent. These logs are used for security monitoring, debugging, and operational purposes. They are not linked to your account for any other purpose, are retained for 365 days, and are not individually accessible or deletable. Legal basis: legitimate interests (security and operation of the service).
2.10 Infrastructure
Stowbook runs on Amazon Web Services. When you sign up, you choose whether your data is stored in the United States (AWS US-East-2, Ohio) or the European Union (AWS EU-Central-1, Frankfurt). These are separate deployments and your data is not copied between them. Your region choice is fixed at signup and cannot be changed afterwards. AWS acts as a data processor under a data processing agreement.
3. Who else processes your data
These are every third party that processes personal data on our behalf. There are no others.
| Processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting, storage, databases, and transactional email delivery | US-East-2 (Ohio) or EU-Central-1 (Frankfurt), matching your chosen region |
| Google LLC (Vertex AI) | AI image identification — current provider (see § 2.3) | United States / European Union |
| Stripe, Inc. | Payment processing for purchases made on the web | United States / European Union |
| Apple Inc. / Google LLC | Payment processing for in-app purchases made on iOS and Android | Per their own terms |
| Have I Been Pwned (Cloudflare-hosted) | Breached-password screening — receives a 5-character hash prefix only, never your password or email | Global CDN |
Applications you connect yourself (§ 2.6) are not our sub-processors — you are granting them access directly, and your relationship with them is your own.
4. What we do not do
- We do not sell your data.
- We do not serve ads.
- We do not use third-party analytics or tracking on this website or in the app.
- We do not send marketing email.
- We do not share your data with any party not listed in this policy.
- We do not use your inventory or photos to train any AI model, our own or anyone else's.
5. Your rights
If you are in the European Economic Area or United Kingdom, you have the following rights under GDPR / UK GDPR.
We extend these same rights to every Stowbook user, wherever you live, whether or not we are legally required to in your jurisdiction. We would rather operate one honest policy than a strong one for Europeans and a weaker one for everyone else.
- Access: You can request a copy of the data we hold about you.
- Portability: You can export your full inventory at any time, free of charge, from within the app.
- Rectification: You can correct inaccurate data directly in the app, or contact us.
- Erasure: You can delete any item, photo, or your entire account from within the app. Deleting your account deletes your inventory data, photos, and account data. Some records survive, and all of them are listed in § 6: deletion markers that tell your other devices and anyone you shared with that the data is gone (deleted automatically within 91 days); reduced AI ledger entries; permanent email suppression records where applicable (§ 2.7); anonymous financial transaction records required by tax law (§ 2.4); and server logs, which cannot be individually deleted but are purged on the standard retention schedule.
- Restriction / Objection: You can ask us to restrict processing or object to processing based on legitimate interests. Contact privacy@stowbook.app.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time — for connected applications (§ 2.6), by revoking the token in the app.
To exercise any of these rights, contact privacy@stowbook.app. We will respond within 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. In the EU, find your authority at edpb.europa.eu. In the UK, contact the ICO at ico.org.uk.
6. Data retention
| Data | Retention |
|---|---|
| Account and inventory data | Until you delete your account |
| Photos and document attachments | Until you delete them or delete your account |
| Original photo uploads (pre-conversion staging copies) | Up to 1 day from upload, then automatically deleted |
| Deletion markers for items you delete (no content — an identifier and a timestamp, so your other devices and anyone you shared with learn the item is gone) | 91 days, then automatically deleted |
| Anonymous account deletion marker (no name, email, or content) | 90 days after account deletion, then automatically deleted |
| Sharing audit log entries | 90 days, then automatically deleted |
| AI ledger entries (full: timestamp, thumbnail, item name) | 90 days from creation, then auto-reduced |
| AI ledger entries (reduced: timestamp + credit count) | Until you delete your account |
| Email suppression records (email address, reason, date — created only on a hard bounce or spam complaint) | Permanent, including after account deletion — this is what stops us contacting the address again |
| Financial transaction records (purchase amount, transaction ID, anonymous account identifier — no name, email, or inventory content) | Up to 10 years, including after account deletion (tax / financial record-keeping laws and payment dispute resolution) |
| Diagnostic reports | 365 days |
| Server logs | 365 days |
7. International transfers
Your inventory data is stored and processed in the region you chose at signup and is not transferred out of it. Some processors listed in § 3 are US-headquartered companies; where personal data is transferred outside the EEA or UK in the course of their services, those transfers rely on the European Commission's Standard Contractual Clauses or an applicable adequacy decision.
8. Children
Stowbook is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child under 13 has created an account, contact privacy@stowbook.app and we will delete it.
9. Changes to this policy
We may update this policy. If we make material changes — including adding or replacing a sub-processor listed in § 3 — we will notify you by email or by a notice in the app before the change takes effect. The "last updated" date at the top reflects the most recent revision.
10. Security
For how Stowbook is built, what we can and cannot see, the limits of what we claim, and how to report a vulnerability, see the security page.
11. Contact
Michael Cosby
privacy@stowbook.app