← ShakerGames

StashIt – Privacy Policy

Last updated: August 8, 2026

StashIt does not collect anything about you.

That is the whole policy. The rest of this page explains what it means in practice, because “we don’t collect data” is a sentence every app says and few mean literally.

StashIt is published by ShakerGames. It is not a game, and it is covered by this page rather than by the ShakerGames games policy — those apps behave differently, and blurring them together would describe neither honestly.

What we collect

Nothing.

We have no server. There is no database anywhere with a row for you in it, because there is no database anywhere.

What happens to your files

Your files stay on your device.

Every file you add is encrypted on the device with AES-256-GCM, using a key derived for that individual file from a master key held in the device’s Keychain. That master key is stored as device-only and is deliberately excluded from your iCloud backup, so it is not copied off the device by iCloud, by an encrypted backup, or by device transfer.

We cannot read your files. Not because we promise not to — because we do not have them and do not have the key.

When the app uses the network

Only when you ask it to, and only to a place you specified:

There is no other outbound traffic. The app never contacts us, because there is no “us” to contact.

When a readable copy exists

Three moments, all of which you initiate.

Export

Choosing Export a copy decrypts the file to a temporary location so it can be handed to another app. That copy is deleted when StashIt locks, goes to the background, or switches vaults. There is no size limit on it — whatever you can put in the vault, you can take back out.

The Files folder

StashIt appears as a location in the Files app so you can save things into it. Files sitting in that folder are not yet in the vault and are not encrypted — they become vault content when you import them, which is always an explicit choice.

Sharing into StashIt from another app

This one is worth reading properly, because the encryption is not immediate and the app cannot make it so.

When you send a file to StashIt from a share sheet, the share extension copies it into a private container shared between StashIt and its own extension, and stops. At that point it is not encrypted. The extension deliberately has no access to the vault key: it runs in its own process, and a second copy of that key in a second process is a second place for it to be lost. It also has no way of knowing which vault you would want the file in.

That staged copy is written with iOS complete file protection, so it is unreadable while the device is locked, and it lives inside the app’s sandbox where no other app can reach it. StashIt encrypts it and deletes the plaintext the next time you open your real vault — never the decoy, so a file you sent to the vault cannot end up in the library you would hand over under pressure. Until that happens, it is sitting there readable to the app itself.

Once a file leaves StashIt, whatever receives it governs what happens next. If you export to another app, that app’s terms apply, not ours.

Photos, Files and permissions

StashIt asks for no library-wide access to anything.

Bringing something in from Photos uses Apple’s own photo picker, which hands the app only the items you picked and does not grant access to the rest of your library — which is why the app never shows an “allow access to your photos” prompt. Files works the same way. Nothing is ever swept up in the background: a file enters the vault because you pointed at it, and for no other reason.

Face ID and Touch ID

Used only to unlock the app. Biometric data never leaves Apple’s Secure Enclave and is never available to StashIt — iOS answers “yes” or “no”, and that is all the app receives.

Children

StashIt is not directed at children, collects nothing from anyone, and therefore collects nothing from children.

What we cannot do for you

We cannot recover your passcode. We cannot recover your files. There is no override, no master key held in escrow, and no support process that ends in getting you back in. This is the direct cost of the design: any door we could open for you is a door someone else could open too.

The same is true one level down. A folder’s own passcode cannot be recovered either, and neither can a folder you have hidden: a hidden folder whose passcode is forgotten stays on the device and still counts towards the app’s storage, but nothing left in the app can list it again. The app says so, in those words, before it hides anything.

If your device is lost, wiped or replaced, the contents of the vault are gone with it. Keep a separate copy of anything you cannot afford to lose.

Data requests

If a government agency or anyone else demands your data from us, we have nothing to give them. We are not being brave about that — we genuinely hold nothing.

Note that this says nothing about what can be recovered from the device itself. Anyone with physical access to your unlocked device, or with the forensic capability to examine it, is a different problem, and one no app running on that device can solve.

Your rights

We hold no data about you, so there is nothing for us to disclose, correct, export, or delete on request. Everything StashIt saves is on your own device and under your control: deleting the app removes it entirely, and takes the encryption key with it.

Changes to this policy

If this ever changes — if a future version of the app collects anything at all — the change will be described here and in the app’s release notes before that version ships. The date at the top is when this page was last edited.


Product Support

Trouble with StashIt? Email us at ipod@300zx.org and we’ll get back to you as soon as possible.

Bear in mind what support cannot do, above: if the passcode is gone, so is the vault, and no amount of correspondence changes that.

Contact

Questions about this policy? Email us at ipod@300zx.org.