1. What we use
Stashiro uses cookies, local storage, and similar browser technologies to keep users signed in, protect sessions, remember interface choices, store guest boards locally, support billing and checkout, and keep the service secure. Browser storage is also used to cache board data, remember selected boards, support the browser extension handoff, and preserve local demo content.
2. Strictly necessary storage and diagnostics
Necessary cookies and storage are required for core functionality such as authentication, security, paid access, sidebar preferences, guest boards, cloud board caching, billing, and extension-to-web handoff. These are not optional because the product cannot work properly without them.
better-auth.session_token, or its secure production variant, keeps a signed-in session working for up to 7 days.sidebar_stateremembers whether the board sidebar is open for up to 7 days.stashiro_billing_currencyremembers the displayed billing currency for up to 1 year.- Convex and app state identify the account, cloud boards, shared board access, and subscription entitlement.
- Local storage keeps guest boards until they are transferred, deleted, or browser data is cleared.
- Local storage also keeps transfer state, sidebar and board display preferences, quick-add choices, onboarding progress, and the extension's account-scoped board cache and last selected board until the user changes them, signs out where applicable, or clears browser data.
- The extension uses browser session storage for short-lived authentication tokens rather than persistent local storage.
- Stripe Checkout and the Stripe customer portal may use cookies or similar technologies needed for subscription checkout, billing details, invoices, payment methods, fraud prevention, and subscription management.
- Sentry receives technical error and performance diagnostics used to detect incidents and keep the service reliable. It is not used for product analytics.
3. Optional cookies
Stashiro may load optional analytics storage when PostHog or Vercel Analytics is configured. These services process page views, feature interactions, and session analytics to help improve the product.
Where consent is required by law, optional analytics stay off until you accept them. Stashiro does not use analytics consent to enable advertising or the sale of personal data.
stashiro:analytics-consentstores the accepted or rejected choice and its date in local storage until the user changes it, clears browser data, or a material consent-policy version change requires a new choice.- When accepted and configured, PostHog may use
ph_*browser storage. Vercel Analytics may process analytics events.
4. Third-party cookies
Authentication, payment, embedded previews, maps, media players, and websites opened from saved links may use their own cookies or similar technologies under their own policies. Browser settings can usually block or delete cookies, but doing so may break sign-in, checkout, or saved preferences.
Boards can display third-party content such as social posts, videos, map tiles, product previews, travel previews, and shopping previews. Those providers may receive requests from your browser when the content is loaded or interacted with. Stashiro does not control those providers' cookies.
Displaying a saved YouTube card loads YouTube's privacy-enhanced player because the card itself requests that video preview. Where consent is required, other third-party social or media content loads only after the user requests it. Opening an external website is subject to that provider's own policy and controls.
Relevant provider notices include those from PostHog, Vercel, Stripe, and Google.
6. Managing browser storage
You can clear local browser data or use browser privacy controls to delete cookies and local storage. Clearing local storage may delete guest boards that were never transferred to cloud storage.