Privacy policy
Who processes your data
The data controller for the StashFlow Android app (package eu.stashflow.app) is DURIN s.r.o.. Contact: info@stashflow.eu.
What we process and why
- Account
- email and password, or the identity from Google, Facebook or X sign-in (identifier and email, and a name if the provider passes one). Purpose: creating and signing in to your account.
- Content you share into the app
- the link, the post's text and any text you paste yourself (a caption the app could not load, for instance). Purpose: turning it into a recipe, a place or a card.
- Derived data
- the recipe with its ingredients, the place with coordinates, the category, the translation into your app language. Purpose: showing it in the app.
- Your notes, ratings, favourites, collections, shopping list and meal plan
- These stay with us; they are not sent to the third parties below.
- Location
- only if you turn on “Nearby place alerts” or showing your own position on the map. For alerts, location is evaluated on your device and StashFlow does not send it to its own servers or store it. For showing your own position the app uses the system location permission, and the map is rendered by the Google Maps SDK (see below).
- Diagnostics
- only if you opt in: error messages and how far start-up got, app version, Android version and phone model. Never your saved links, items or notes.
- Technical processing records and feedback
- which service was called for an item, with what outcome, how long it took and what it cost; and, when you re-run an item, delete it shortly after saving or correct a pin, a record of that. These may contain the place name, address and coordinates from the item and similar detail needed to judge the result.
Recipients
Turning a shared post into an item involves these services; each one receives only what its task needs:
| Recipient | What it receives | Why |
|---|---|---|
| Supabase | all account and content data | database, sign-in, storage and the app's server functions |
| Anthropic | the shared post's text and metadata, pasted text, a place name | classifying the post, extracting ingredients and places, translation, finding an address |
| Apify | the address of a public Instagram post | fetching the public post content |
| Google (Geocoding API, Places API) | a place name or address from the post | finding coordinates |
| OpenStreetMap / Nominatim | a place name or address from the post | finding coordinates |
| Google Maps (SDK in the app) | technical data about map requests — device and request metadata, IP address, SDK identifier, map interactions and crash metrics, to the extent Google declares for the Maps SDK and its terms govern | rendering the map |
| Google, Meta (Facebook), X | that service's sign-in data | only if you sign in through it |
We do not sell your data and do not use it for advertising. The providers above operate under their own terms and privacy policies.
Security
Each account can only read its own data (row-level security). Sensitive server-side credentials used by the server functions (Anthropic, Apify and server-side Google geocoding) are not sent to the app. Transport is encrypted (TLS).
Retention and deletion
- Account and content data is kept for as long as the account exists.
- Deleting the account (in the app or by email, see Delete account) removes the account, sign-in identities, profile, items including recipes, ingredients and places, collections, meal plan, shopping list, notes, ratings and subscription data — and the technical processing records, diagnostic reports, conversion feedback and pin corrections made by the account are deleted together with the account. Account-bound data is removed immediately.
- Technical processing records and diagnostic reports are kept for at most 90 days and then deleted automatically even without an account deletion. Conversion feedback and pin corrections (name, address, coordinates) are kept for the lifetime of the account and deleted with it.
- Conversion results for public links are kept in a shared cache that is not tied to an account; a cache entry is deleted 30 days after processing. Thumbnail images of public posts that nothing references any more (no item and no cache entry) are removed by a daily clean-up once they are older than 7 days.
Your rights
You may access, correct, export, restrict and delete your data, and object to processing. Write to info@stashflow.eu; we answer within 30 days at the latest. You may also complain to the supervisory authority responsible for you.
Changes
When this policy changes, the effective date above changes with it. Material changes are announced in the app.

