Privacy Policy
Stash: Calculator Photo Vault · stashphotovault.com
Last updated: 2 October 2026
This privacy policy applies to the website stashphotovault.com (Part A) and to the application "Stash: Calculator Photo Vault" ("Stash", "the App", Part B), both published by Eduard Bruch. Stash is an encrypted file vault that allows users to securely store photos, videos, documents, audio files, and other files on their device. The App includes a guest vault, intruder detection, and secure notes.
We take your privacy seriously. This policy explains in detail what data the website and the App collect, how it is processed, where it is stored, and what rights you have.
1. Data Controller
Part A: The website stashphotovault.com
2. Hosting
This website is hosted by Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. When you visit, technically necessary data is processed (IP address, date and time, requested URL, referrer, browser and operating system) to deliver the pages and keep the service secure. Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is reliable and secure delivery of the website. Vercel acts as our processor under an agreement pursuant to Art. 28 GDPR. Server logs are kept only as long as needed for operation and security and are then deleted. Transfers to the USA rely on the European Commission's adequacy decision of 10 July 2023 (EU-US Data Privacy Framework, Art. 45 GDPR), under which Vercel is certified. More information: Vercel Privacy Policy.
3. No Cookies, No Analytics, No Third-Party Content
This website sets no cookies, uses no analytics or audience measurement, and stores nothing on or reads nothing from your device. Apart from the hosting described in Section 2, we embed no advertising trackers, social media plugins or external fonts; fonts are served from our own server.
Links to the Apple App Store take you to Apple. Once you reach the App Store, Apple is the controller for any further processing.
4. Contact by Email
If you e-mail us, we process your name, e-mail address and message to answer your request. Our mailbox is operated through an e-mail service provider. Legal basis is Art. 6(1)(b) GDPR where the request concerns a contract or an app, otherwise Art. 6(1)(f) GDPR (interest in answering). We delete the correspondence once the matter is closed, unless statutory retention duties apply.
No data protection officer has been appointed as there is no legal obligation to do so. You are not obliged to provide personal data. No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
Part B: The App
5. Fundamental Principle: On-Device Only
We do not operate any servers that receive, store, or process your data. All vault content — including photos, videos, documents, audio files, notes, and settings — is stored on your device; it leaves your device only as an encrypted backup that you start yourself (Section 6.9). We have no technical ability to access, view, retrieve, or recover any of your encrypted data. We cannot see what you store, how you use the App, or how often you open it.
6. Data We Collect and Process
6.1 Vault Content (Photos, Videos, Documents, Audio, Files)
Files you import into the vault — including photos, videos, PDFs, documents, MP3s, audio files, and any other file type — are encrypted using AES-256-CBC encryption with a randomly generated 256-bit key and per-file initialization vectors (IV). Encrypted files are stored locally in the App's sandboxed storage directory. The encryption key is stored in the iOS Keychain, protected by the operating system's hardware-backed security.
Files are never transmitted to any external server, cloud service, or third party, except as part of an encrypted backup to your own cloud account that you start yourself (Section 6.9). Thumbnails for photos are also encrypted and stored locally. Non-image files (documents, audio, etc.) do not generate thumbnails.
6.2 PIN Code
Your PIN is stored as a salted SHA-256 cryptographic hash in the device's local database. A unique random salt is generated for each PIN and stored alongside the hash. The original PIN is never stored in plaintext.
To protect against brute-force attacks, the App enforces a lockout policy after multiple failed PIN attempts: 30 seconds after 5 failed attempts, 5 minutes after 10, and 30 minutes after 15 or more.
6.3 Guest PIN
If you set up a guest PIN, it is stored as a separate salted SHA-256 hash with its own unique salt, under the same conditions as the main PIN. The guest PIN opens a separate vault containing only items you have explicitly placed in the guest vault. This feature provides an additional layer of privacy.
6.4 Secure Notes
Notes created within the App are encrypted on-device using the same AES-256-CBC encryption as vault files. Both the note title and content are encrypted before storage. Encrypted notes are never transmitted externally, except inside an encrypted backup that you start yourself.
6.5 Biometric Data (Face ID / Touch ID)
If you enable biometric unlock, authentication is handled entirely by the operating system's LocalAuthentication framework. The App never receives, stores, processes, or transmits your biometric data. It receives only a boolean success or failure result from the operating system. No fingerprint templates, facial geometry, or biometric identifiers are accessible to the App at any time.
6.6 Intruder Detection Photos
When you enable the intruder detection feature (premium only) and an incorrect PIN is entered, the App captures a photograph using the device's front-facing camera. These photographs are:
- Encrypted using the same AES-256-CBC encryption as vault files before being saved to disk
- Stored locally on your device only
- Never transmitted to any external server or third party
- Accessible only after successful authentication within the App
- Deletable by you at any time from within the App
The intruder detection feature is disabled by default and requires your explicit opt-in. It captures only when triggered by a failed PIN attempt, not continuously.
Legal basis: Art. 6(1)(a) GDPR (your explicit consent when enabling the feature) and Art. 6(1)(f) GDPR (legitimate interest in protecting the security of your device and personal data).
6.7 Temporary Decrypted Files
When you open a file to view or share it, the App temporarily writes a decrypted copy to the device's temporary directory. These temporary files are automatically deleted when the vault is locked, when the App moves to the background, or when the operating system clears temporary storage.
6.8 Recovery Key
If you generate a recovery key, the App stores a salted SHA-256 hash of the key along with a PBKDF2-wrapped copy of your encryption master key (100,000 iterations). The recovery key plaintext is shown to you once and is never stored by the App. The wrapped master key can only be unwrapped with the correct recovery key. This data is stored locally and never transmitted externally.
6.9 Cloud Backup (iCloud / Google Drive)
Stash offers optional encrypted backup to iCloud or Google Drive. When you create a backup, the App wraps your encryption master key using PBKDF2-HMAC-SHA256 (100,000 iterations) derived from your PIN, then uploads the encrypted vault files, a copy of the database, and the wrapped key to your personal cloud storage account. All files remain AES-256 encrypted throughout.
We do not have access to your iCloud or Google Drive account. The backup is stored in your personal cloud storage and can only be decrypted with your PIN. Backups are initiated manually by you and are never created automatically.
6.10 App Settings and Preferences
Your app settings (biometrics toggle, intruder detection toggle, auto-lock preferences, etc.) are stored locally in the App's SQLite database. These are never transmitted externally, except inside an encrypted backup that you start yourself.
7. Subscription Data and Third-Party Services
7.1 In-App Purchases
Subscriptions and one-time purchases are processed by Apple (App Store). We do not have access to your payment information, credit card number, or billing address. Subscription status is verified through RevenueCat, Inc. (San Francisco, USA), which receives anonymized transaction identifiers from Apple to confirm your subscription status.
The App does not sign in to RevenueCat with an account, name or email address. RevenueCat links your purchases only to a random, anonymous user ID that the RevenueCat software in the App creates on your device. RevenueCat does not receive any vault content, personal files, PIN, biometric data, or personal identifying information beyond what Apple provides as part of the standard purchase verification process.
Legal basis: Art. 6(1)(b) GDPR (performance of contract). Data transfer to the USA is covered by the EU-U.S. Data Privacy Framework. See RevenueCat's Privacy Policy.
7.2 iCloud and Google Drive (Optional Backup)
If you choose to use the cloud backup feature, encrypted backup data is uploaded to your personal iCloud (Apple) or Google Drive (Google) account. Authentication with Google Drive uses the standard Google Sign-In SDK. We do not receive or store your Google or Apple credentials. The backup data stored in your cloud account is fully encrypted and cannot be read without your PIN.
Legal basis: Art. 6(1)(a) GDPR (your explicit consent when initiating a backup). See Google's Privacy Policy and Apple's Privacy Policy.
8. Analytics, Tracking, and Advertising
The App does not use any analytics frameworks (no Firebase Analytics, no Crashlytics, no Mixpanel, no Amplitude, no Flurry, or similar). The App does not contain any advertising SDKs or ad networks. The App does not track your usage behavior, feature interactions, session duration, or any other telemetry. No usage data is collected, stored, or transmitted. We have zero visibility into how you use the App.
9. Device Permissions
The App requests the following device permissions, each for a specific and limited purpose:
- Photo Library (Read): Import photos and videos from your gallery into the encrypted vault
- Photo Library (Write): Export decrypted items back to your gallery (user-initiated only)
- Camera: Capture intruder detection photos on failed unlock attempts (opt-in feature)
- Face ID / Touch ID: Optional biometric vault unlock. No biometric data is accessed by the App.
- File Access: Import files (PDFs, documents, audio, etc.) from the device file system via the system file picker
All permissions are requested at runtime and can be revoked at any time through your device's Settings app. The App functions with reduced capability if permissions are denied.
10. Data Sharing
We do not sell, rent, lease, trade, or share your personal data with any third party. In the App, the only third-party services that receive any data are RevenueCat for subscription verification (Section 7.1) and, optionally, iCloud or Google Drive for encrypted backups you explicitly initiate (Section 7.2). No vault content is ever shared in unencrypted form. No biometric information is ever shared with anyone.
11. Data Retention and Deletion
All data is stored on your device for as long as the App is installed. You can delete individual items, notes, albums, and intruder photos at any time from within the App. Uninstalling the App permanently deletes all locally stored data, including encrypted files and the encryption key. Once deleted, encrypted data cannot be recovered by anyone, unless you have created a backup in your own cloud account.
12. Data Security
- Encryption algorithm: AES-256-CBC with PKCS7 padding
- Encryption key: 256-bit key generated using a cryptographically secure random number generator, stored in the iOS Keychain (KeychainAccessibility.first_unlock)
- Initialization vectors: Unique 16-byte IV randomly generated for each encryption operation and prepended to ciphertext
- PIN storage: Salted SHA-256 one-way hash with a unique random salt per PIN — not reversible
- Brute-force protection: Lockout after failed PIN attempts (30s at 5 attempts, 5min at 10, 30min at 15+)
- Recovery key: PBKDF2-HMAC-SHA256 with 100,000 iterations for master key wrapping
- Intruder photos: Encrypted with AES-256-CBC before being written to disk
- File naming: Encrypted files use randomized UUID filenames that reveal no information about the original file
- In-memory caching: Decrypted data is temporarily held in memory for display and cleared when the vault is locked
Your rights and further information
13. Your Rights Under GDPR
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation:
- Access (Art. 15) — request confirmation of what data we process. Because all App data is stored on your device only, we hold no personal data from the App about you on our systems.
- Rectification (Art. 16) — correct inaccurate data
- Erasure (Art. 17) — delete your data via the App's settings or by uninstalling the App
- Restriction of Processing (Art. 18) — restrict processing of your data
- Data Portability (Art. 20) — receive your data in a portable format
- Objection (Art. 21) — object to processing based on legitimate interest
- Withdraw Consent (Art. 7(3)) — withdraw consent at any time, for example by disabling intruder detection
To exercise any of these rights, contact us at support@eduardbruch.com.
14. California Residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- We do not sell your personal information.
- We do not share your personal information for cross-context behavioral advertising.
- We do not use sensitive personal information for purposes beyond what is necessary to provide the App.
California residents may contact support@eduardbruch.com to exercise their CCPA/CPRA rights.
15. Right to Lodge a Complaint
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. Our competent authority is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Str. 22, 7. OG, 20459 Hamburg
datenschutz-hamburg.de
16. Children's Privacy
The App is not directed at children under the age of 13 (as defined by COPPA) or under the age of 16 (as defined by GDPR). We do not knowingly collect personal information from children. If we become aware that a child has provided personal information, we will take steps to delete such information.
17. International Data Transfers
International data transfers occur through Vercel (USA) for hosting this website (Section 2), through RevenueCat (USA) for subscription verification and, if you opt in, through Apple (iCloud) or Google (Google Drive) for encrypted backups. These transfers are protected under the EU-U.S. Data Privacy Framework. All backup data transferred to cloud services remains AES-256 encrypted. All other App data remains on your device and is never transferred internationally.
18. Changes to This Policy
We reserve the right to update this privacy policy. The current version can always be found on this page, with the date of the last update at the top.
19. Contact
For questions, concerns, or requests regarding this privacy policy or your data, contact:
Eduard Bruch
Kleinfeld 28c, 21149 Hamburg, Germany
Email: support@eduardbruch.com