Privacy Policy
Last updated: 9 June 2026
This Privacy Policy explains how STOLLIX SOFT S.R.L. ("Stollix", "we", "us", or "our") collects, uses, shares, and protects your personal data when you use the TailStash mobile application (the "App") and related services (together, the "Service").
We are the data controller for your personal data under the EU General Data Protection Regulation (GDPR) and Romanian data protection law.
- Controller
- STOLLIX SOFT S.R.L.
- Trade Register
- J2023002511088
- Fiscal code (CUI)
- RO48746464
- Registered address
- Tudor Arghezi 11, Municipiul Braşov, Braşov, Romania
- Contact
- contact@stollix.com
Please read this Policy together with our Terms & Conditions.
1. A quick summary
TailStash is a private appreciation-journaling app. You write short notes of appreciation to yourself, to individual friends, or to small groups. We have built it to be privacy-respecting:
- We do not use advertising, ad networks, or ad tracking.
- We do not integrate Firebase Analytics or any third-party analytics or behavioural-tracking SDK.
- We do not use crash-reporting SDKs that profile you.
- We do not sell your personal data.
- We do not collect your precise location.
- Your entries are visible only to the specific people you choose (yourself, a friend, or members of a group) - there is no public feed.
We collect only what we need to run the Service, and we explain all of it below.
2. The personal data we collect
2.1 Account and profile data (from your sign-in provider)
You sign in with Google or Apple (we do not offer email/password accounts). When you register, we receive and store:
- A unique account identifier from Firebase Authentication (your
firebase_uid); - Your email address (Apple users may choose Apple's "Hide My Email" private relay, in which case we receive a relay address instead);
- Your first and last name (as provided by Google/Apple - you can edit these later);
- Your profile photo / avatar (optional; you can upload or change it).
You also choose:
- A username (3–30 characters; unique and used so friends can find you);
- A searchability setting (whether you appear in friend search - on by default; you can turn it off).
We automatically detect and store, to make the App work correctly:
- Your time zone (e.g.
Europe/Bucharest) - used to schedule your daily spark and calculate daily limits/streaks; - Your language/locale (e.g.
ro-RO) - used to localize the App and your notifications; - Your account creation date ("join date") - recorded when you register. Your username, avatar, and join date are visible to other users (see Section 4).
2.2 Content you create
- Entries - the appreciation notes you write (text, 1–500 characters), including whether each entry is solo, sent to a friend, or sent to a group, and its delivery/read status (pending, "stashed" as an "Acorn" to read later, or "revealed");
- Images - if you are a premium subscriber, an optional image you attach to an entry;
- Groups - group names and optional group images you create or manage, and your group memberships;
- Boost requests - when you ask friends for support, the short prompt message you write and which friends you direct it to;
- Friend connections - friend requests you send/receive and your accepted friendships.
2.3 Preferences and app state
- Your notification preferences (which alert types are on/off, and your preferred daily-spark time);
- Which in-app tutorials/onboarding steps you have completed;
- Your writing-streak data (consecutive days you have written).
2.4 Technical data needed to deliver notifications and run the App
- A Firebase Cloud Messaging (FCM) device token, so we can send you push notifications;
- Basic app version information (used for compatibility and support).
2.5 Subscription and purchase data
- Your subscription status and plan (free, monthly, yearly, or lifetime), start/expiry dates, and a RevenueCat customer identifier.
Your payment details (card numbers, etc.) are NOT collected by us. All purchases are processed by the Apple App Store or Google Play, and managed through RevenueCat. We only receive confirmation of your subscription status - not your payment instrument.
2.6 What we do not collect
- No precise/GPS location;
- No advertising identifiers;
- No third-party analytics or behavioural-tracking data;
- No contacts list, microphone, or background activity;
- We access your camera/photo library only when you choose to add a profile or entry image, and only the image you select.
3. How we use your data, and our legal bases
Under the GDPR we must have a lawful basis for each use of your data. These are ours:
| Purpose | Examples | Legal basis (GDPR Art. 6) |
|---|---|---|
| Provide the Service | Create your account; store and deliver your entries to the friends/groups you choose; manage friendships, groups, and boosts | Performance of a contract (Art. 6(1)(b)) |
| Send notifications you have enabled | New-entry alerts, friend requests, daily spark, boost requests | Performance of a contract / your consent via notification settings (Art. 6(1)(b)/(a)) |
| Manage subscriptions | Verify premium status; apply free vs. premium limits | Performance of a contract (Art. 6(1)(b)) |
| Keep the Service secure and working | Authenticate requests; prevent abuse; debug issues; enforce rate limits | Legitimate interests (Art. 6(1)(f)) |
| Localize your experience | Show the App and notifications in your language and time zone | Performance of a contract / legitimate interests |
| Comply with the law | Tax/accounting for purchases; responding to lawful requests | Legal obligation (Art. 6(1)(c)) |
| Communicate with you about the Service | Respond to support requests; send essential service notices | Performance of a contract / legitimate interests |
For notifications specifically: essential service messages rely on our contract with you, while the optional alert types you can switch on or off rely on your consent, which you can withdraw at any time in the App's settings (see Sections 9 and 14).
Providing the account, content, and technical data described in Section 2 is necessary to use the Service: if you do not provide it, we cannot create your account or deliver the Service. Some data is optional (for example, a profile photo or an image attached to an entry), and not providing it only affects that specific feature.
We do not use your data for advertising or for automated decision-making that produces legal or similarly significant effects about you.
4. How your content is shared with other users
TailStash has no public feed. Visibility works like this:
- Solo entries - visible only to you.
- Friend entries - visible only to you (the author) and the single friend you send them to. The recipient may "reveal" (read now) or "stash" (save to read later); they cannot forward them.
- Group entries - visible to the members of the group you post in. Each member individually decides to reveal or stash.
- Boost requests - the friends you select see your prompt and that you requested support; they do not see each other.
- Your profile - your username, avatar, and join date can be seen by other users (e.g. in search and in shared groups). Your first and last name are shown only to people you have accepted as friends. If you disable "searchable", you will not appear in friend search.
If your account is deleted, your past entries may continue to be shown to their recipients with the author displayed as "Deleted User", with no personal details attached (see Section 7).
5. Service providers (processors) and other recipients
We share personal data with a small number of trusted providers who process it on our behalf and under contract, only to run the Service:
| Provider | Role | Data involved |
|---|---|---|
| Google (Firebase Authentication) | Sign-in and identity | Your sign-in identifier, email, name, avatar |
| Google (Firebase Cloud Messaging) | Delivering push notifications | FCM device token, notification content |
| Apple | Apple Sign-In; App Store billing | Sign-in identifier, email/relay, purchase status |
| Google Play | Android billing | Purchase status |
| RevenueCat | Subscription management | RevenueCat customer ID, subscription/plan status |
| Hosting provider | Cloud infrastructure (VPS) hosting our backend servers | All data processed by the Service, including images you upload |
Avatars and entry/group images you upload are stored on servers we operate at our hosting provider, not with a separate third-party storage service.
We may also disclose data where legally required (e.g. valid requests from public authorities), to protect our rights or users' safety, or in connection with a corporate transaction (e.g. merger or acquisition), in which case we will ensure continued protection of your data and notify you where required.
We do not sell your personal data and do not share it with advertisers.
6. International data transfers
Our providers (notably Google, Apple, RevenueCat, and our hosting provider) may process data on servers located outside Romania and the European Economic Area (EEA), including in the United States. Where data is transferred outside the EEA, it is protected by appropriate safeguards - principally the European Commission's Standard Contractual Clauses, and, where the provider is certified, the EU–U.S. Data Privacy Framework. You can request more information using the contact details above.
7. How long we keep your data
- Account and content - kept for as long as your account is active.
- Account deletion - when you delete your account, it is deactivated immediately and enters a 30-day grace period. If you sign back in within 30 days, your account is restored. After 30 days, your account and personal data are permanently deleted (we run automated deletion daily). At that point your profile photo and notification token are removed, and any entries you authored have their author dissociated and shown as "Deleted User".
- Subscription/transaction records - purchase and accounting records may be retained for longer where required by tax and accounting law. Under Romanian accounting and fiscal law, such records are generally kept for between 5 and 10 years depending on the document type, after which they are deleted or anonymized.
- Technical data - your FCM push token is removed when you delete your account or disable notifications; other technical data (such as app version) is kept only as long as needed for compatibility and support.
- Backups - residual copies may persist in routine backups for a short period before being overwritten.
8. Account deletion
You can delete your account at any time from the Profile tab in the App: tap Delete Account and confirm. If you no longer have the app installed, you can request deletion as described at tailstash.com/delete-account or by emailing contact@stollix.com. See Section 7 for the 30-day grace period and permanent-deletion process.
9. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data (much of it is editable directly in the App);
- Erase your data ("right to be forgotten") - e.g. by deleting your account;
- Restrict or object to certain processing, including processing based on our legitimate interests;
- Data portability - receive your data in a structured, commonly used, machine-readable format;
- Withdraw consent at any time, where processing is based on consent (e.g. by turning off notification types), without affecting prior processing.
To exercise any of these rights, contact us at contact@stollix.com. We will respond within one month, as required by the GDPR.
You also have the right to lodge a complaint with the Romanian supervisory authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP) - www.dataprotection.ro - or with the authority in your EU country of residence. If you are in the United Kingdom, the UK GDPR applies to you and you may instead contact the Information Commissioner's Office (ICO) - ico.org.uk.
10. Additional rights for United States residents
We make the Service available worldwide. We do not sell your personal data, and we do not "share" it for cross-context behavioural advertising (as those terms are defined under U.S. state privacy laws such as the California Consumer Privacy Act, as amended by the CPRA). We also do not use it for targeted advertising or profiling.
If you are a resident of California or another U.S. state with a comprehensive privacy law (for example Virginia, Colorado, Connecticut, or Utah), you may have the right to:
- Know / access the categories and specific pieces of personal data we have collected about you;
- Delete personal data we hold about you;
- Correct inaccurate personal data;
- Opt out of any sale or "sharing" of personal data, or of targeted advertising - although, as stated above, we do none of these;
- Not be discriminated against for exercising your privacy rights.
To exercise these rights, contact us at contact@stollix.com. We will verify your request through your account sign-in and respond within the time required by applicable law. You may use an authorized agent where the law permits.
11. Your rights in other regions
Wherever you live, you can contact us at contact@stollix.com to exercise the privacy rights available to you under your local law. Depending on your country, additional or equivalent rights may apply - for example under Canada's PIPEDA, Brazil's LGPD (Lei Geral de Proteção de Dados), or Australia's Privacy Act (United Kingdom users are addressed in Section 9 above). We will handle your request in accordance with the law applicable to you.
12. Security
We protect your data using measures appropriate to the risk, including: authenticated, token-based API access (every request requires a valid sign-in token); encryption of data in transit (HTTPS/TLS); access controls limiting who can reach personal data; and reliance on Google/Apple's hardened authentication infrastructure. No system is perfectly secure, but we work to protect your information and to address vulnerabilities promptly.
13. Children
TailStash is not directed to children. You must be at least 16 years old to use the Service (see our Terms & Conditions), and we do not knowingly collect personal data from anyone under 16. For users in the United States specifically, this also means we do not knowingly collect personal data from children under 13, consistent with the Children's Online Privacy Protection Act (COPPA). If you believe a child below the applicable minimum age (16, or 13 in the U.S. for COPPA purposes) has provided us personal data, contact contact@stollix.com and we will delete it.
14. Push notifications
We send push notifications for the alert types you have enabled (new entries, friend requests, daily spark, boost requests, and group activity). You can turn individual alert types on or off, and change your daily-spark time, in the App's settings - and you can disable notifications entirely from your device's system settings at any time.
15. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date and notify you in the App before they take effect. If you do not agree to a material change, you may stop using the Service and delete your account free of charge; your continued use of the Service after a change takes effect means you accept the revised Policy.
16. Contact us
Questions, requests, or complaints about this Policy or your data:
STOLLIX SOFT S.R.L.
Tudor Arghezi 11, Municipiul Braşov, Braşov, Romania
Email: contact@stollix.com