Data Processing Agreement

The agreement that will cover personal data developers store with jstash. Draft of 3 October 2026.

Draft — not in force. This is published so developers can see what’s coming and tell us what they need. It binds no one and is still being reviewed by a lawyer. Until it’s final, the Terms of Service apply on their own. Feedback: support@jstash.app.

How it works

Cover Page

Agreementjstash Terms of Service at jstash.app/terms, effective 3 October 2026, as updated
ProviderNeonook Pty Ltd (ABN 80 124 800 853), Australia, trading as jstash. Contact: support@jstash.app
CustomerThe jstash account holder who accepts this DPA in the dashboard. Contact: the account’s email address
RolesCustomer is the Controller, or a Processor for its own client. Provider is the Processor, or a Subprocessor
Acceptance and termStarts when the Customer accepts it in the dashboard. Continues until the Customer’s account is deleted and Provider has deleted the Customer Personal Data
Provider Security Contactsupport@jstash.app, as listed in security.txt
Security PolicyCommercially reasonable efforts, including the measures in Annex II. No certifications (no ISO 27001 or SOC 2)
DPA Covered ClaimNone. Provider gives no indemnity beyond the Agreement
DPA Liability CapThe Agreement’s cap (Terms section 9) applies
Governing law and courtsAs in the Agreement: Australia (the state is to be confirmed)
Governing Member StateIreland, for the EEA SCCs and UK Addendum only
Service Provider RelationshipYes: for the CCPA, Provider is a service provider and won’t sell or share Customer Personal Data
Order of precedenceEEA SCCs or UK Addendum, then this DPA, then the Agreement

Annex I: processing details

Servicejstash JSON storage: bins, and jstash Apps (per-user documents behind the Customer’s own login)
Data subjectsPeople who sign in to the Customer’s apps, and anyone whose data the Customer puts in a bin
Personal dataWhatever the Customer or its users choose to save in JSON documents. For Apps also: a one-way hash of each user’s login-provider ID, document names, sizes and save times, and when each user first and last saved. Login tokens and IP addresses are used only during the request; IPs are kept only as keyed hashes that change daily or monthly
Special category dataNot permitted (health, biometric, financial, government identifiers and the like)
FrequencyContinuous: each API request
NatureStoring, serving, caching (public bins only) and deleting documents; verifying login tokens against the provider’s published keys
PurposeTo provide the Service to the Customer, on its instructions
DurationUntil the Customer or its user deletes the data. App or account deletion removes it within two hours; trial bins after 7 days. jstash keeps no backups or old versions

The Customer’s instructions are its API calls, its apps’ calls and its dashboard settings.

Subprocessors

Cloudflare is the only Subprocessor for Customer Personal Data. The current list, with where data is stored and handled, is at jstash.app/subprocessors. Provider will email the account address and update that page at least 10 business days before adding or replacing a Subprocessor. The Customer has 30 days to object; if it can’t be resolved, the Customer’s remedy is to delete its data and close its account.

Annex II: security measures

Encryption in transitHTTPS only, with HSTS on every jstash domain
Encryption at restAES-256 for everything stored, in the database and file storage, with keys Cloudflare manages
Access to app users’ documentsOnly with that user’s login token, verified against the provider’s published keys (signature, issuer, audience, expiry). The product gives neither the Customer nor jstash staff a way to read them
SeparationEach user’s documents are stored under a key built from the app, the login issuer and the user, so no request can reach another user’s data. Websites the app doesn’t list are refused
CredentialsAPI keys, sessions and edit tokens are stored only as SHA-256 hashes. Login tokens are never stored, and request logs show the header as redacted
Data minimisationProvider user IDs are stored only as a one-way hash. IP addresses are kept only as keyed hashes that rotate. Logs never contain request bodies, credentials or cookies
Admin accessThe admin console sits behind Cloudflare Access and an email allowlist. Settings changes need the dashboard session. The Cloudflare and GitHub accounts behind jstash use two-factor sign-in
Abuse limitsPer-user, per-app and per-IP rate limits and daily caps
TestingAn automated test suite covers token checks, user separation and deletion. An external security review was done in October 2026
DeletionDeletes take effect at once; app and account deletions finish within two hours. There are no backups, so deleted data is gone
PeopleOne operator, the director of Neonook. No staff or contractors have production access

Breaches, help, deletion and audits

Breach noticeNotify the Customer without undue delay, and within 72 hours of becoming aware. Share what’s known as it’s learned, and contain and investigate promptly. Notifying isn’t an admission of fault
Requests from individuals and regulatorsPass them to the Customer and don’t answer without its consent, unless the law requires it. An app user deletes everything with DELETE /me; the Customer deletes one user by their login-provider ID
AssessmentsReasonable help with privacy impact assessments, at the Customer’s cost
Deletion at the endDelete only. Return isn’t available for app users’ documents, because neither party can read them; app users can fetch their own through the app before it closes. Bin owners can download their bins first
AuditsOne written security questionnaire a year, sent to the Security Contact. Compliance records kept for 3 years. No third-party audit reports

Australian privacy law

  1. Applicable Data Protection Laws include the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Provider will handle Customer Personal Data as if it were bound by APPs 6 (use and disclosure), 8 (cross-border disclosure) and 11 (security), whether or not the small business exemption applies to either party.
  2. Security Incident also covers any unauthorised access to, disclosure of or loss of Customer Personal Data that could be an eligible data breach under the Notifiable Data Breaches scheme. Provider’s 72-hour notice gives the Customer what it needs to assess the breach within the scheme’s 30 days. The Customer decides whether to notify the OAIC and individuals.
  3. Overseas handling (APP 8). Data is stored in Cloudflare’s Oceania region. Requests are handled in the Cloudflare data centre nearest each caller, which can be outside Australia, and Cloudflare is a US company. The Customer accepts this when it accepts the DPA, and should tell its users.
  4. No other use. Provider won’t use Customer Personal Data for its own purposes, including advertising, profiling or training models.

Changes to the Common Paper Standard Terms

Everything else in the Standard Terms applies as written.

Based on the Common Paper Data Processing Agreement (Version 1.1), free to use under CC BY 4.0. Modified by Neonook Pty Ltd.