Privacy Policy
What we collect, why, where it lives and how to reach us. Effective 3 October 2026.
Who we are
jstash is run by Neonook Pty Ltd (ABN 80 124 800 853), Australia. We handle personal information in line with the Australian Privacy Principles. Questions or requests: support@jstash.app.
What we collect
- Your account (if you sign in): your GitHub user ID and username, display name, avatar URL, your email if GitHub shares it or you add it, your plan, and when things were created.
- Credentials: API keys, session tokens and edit tokens are stored only as one-way hashes. We can’t read them back.
- Your bins: the JSON you store, plus its name, size and timestamps.
- Usage counts: daily counts of bins created, updated and privately read, per account. For trial use without an account, daily counts per network, keyed by a hash of your IP address (IPv6 by /64) that changes every day.
- Security log: sign-ins, sign-outs, API key changes, claims, account deletion and moderator actions, with a keyed hash of your IP address that changes every month — never the raw address.
- Request logs: for each API request, the time, route, status, duration and the account, key and bin IDs involved. Never request bodies, credentials or cookies.
- If you use an app built with jstash Apps: the documents that app saves for you, with their names, sizes and save times, and when you first and last saved. They’re filed under a one-way hash of your user ID from the app’s login provider; we never receive your password or email address. The app’s developer decides what’s stored, and their privacy policy covers it — ask them first about access or deletion.
- Things you send us: support messages and the reply email you give, abuse reports (your email is optional), and your email if you request a Pro invite or ask to hear about Max.
We don’t use analytics, advertising or tracking cookies. The website sets no cookies. Signing in sets one session cookie on api.jstash.app (30 days) and a short-lived cookie during GitHub sign-in.
Why we use it
To run jstash: store and serve your bins, sign you in, enforce limits, prevent and investigate abuse, answer support requests and reports, and send the Pro invites and news you asked for. We don’t sell personal information or use it for advertising.
Public bins
Anyone with a public bin’s URL can read it. We ask search engines not to index bins, but we can’t control who shares a URL. Don’t put personal information in a public bin. See the acceptable use rules.
Where it’s stored and who helps us
- Cloudflare hosts jstash. Our database and bin storage are located in Cloudflare’s Oceania region. Public bins are also cached on Cloudflare’s global network so they load quickly, and request logs are kept by Cloudflare for a few days.
- GitHub handles sign-in.
- Stripe will handle payments once paid plans launch.
Cloudflare and GitHub are US companies, so some information may be handled outside Australia. They act for us under their own data protection terms. The companies that handle data you store with jstash are listed on our subprocessors page.
How long we keep it
- Account details and bins: until you delete them or your account. Deleting your account removes your personal details straight away and your bins within two hours.
- Trial bins: 7 days, unless claimed.
- Trial usage counts: about two days.
- App documents: until you, the app’s developer or the developer’s account deletes them (account and app deletions finish within two hours). App save counts: about two days.
- Security log entries: kept for security, linked only to an account ID that no longer identifies you once the account is deleted.
- Invite and launch requests: deleted once we’ve invited you or announced the plan.
- Support messages and reports: while we handle them, then up to 12 months.
Your choices and rights
You can see and correct your name and email in the dashboard, and delete your account at any time. To ask for a copy of your information, or for anything else, email support@jstash.app. If you think a bin contains your personal information, report it at jstash.app/report. If you’re not happy with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Security
Everything is served over HTTPS. Credentials are stored only as hashes, public and private bins live in separate storage, and the moderation console sits behind its own sign-in. Report a security issue to support@jstash.app (see security.txt). No system is perfectly secure; if something goes wrong that affects your information, we’ll tell you as the law requires.
Changes
If we change this policy we’ll update the date above, and tell account holders about significant changes.