This policy explains how Stowra (the web app at app.stowra.app, the public share pages, the Stowra API and the Stowra connector for AI assistants such as ChatGPT and Claude) handles personal data. It is written to meet the EU General Data Protection Regulation (GDPR / RGPD) and the French Data Protection Act.
Who is responsible
The data controller is Yohann Lereclus, an individual based in France who publishes and operates Stowra. For any question about your data or to exercise your rights, write to [email protected].
Personal data we collect
Account data
- Email address and password (the password is handled and stored hashed by our authentication provider, never readable by us).
- If you sign in with Google: your name, email address and profile picture, as shared by Google.
- Display name, avatar and preferences you set, such as your weight unit.
Workspace content
- Gear items, kits, loadouts, sections, tags, sports, shelves and favourites you create.
- Photos you upload of your gear, and your avatar.
- Participant profiles: names of people you add to trips, who may not have a Stowra account themselves. Only add people you are allowed to name.
- Workspace memberships, roles and invitations (the invited person’s email address).
- Share links you create, with the visibility settings you choose.
Activity and connection data
- An audit log of changes in a workspace: what changed, when, by which member, and whether it came from the web app, the API or an AI assistant. This powers history and undo.
- API tokens and connected apps: the name of each connected client, the permissions (scopes) you granted, and when it was last used. Tokens are stored only as one-way hashes.
- Technical data: IP address, browser user agent, request times and error reports, used to keep the service secure and working.
-
Share-link statistics: for each link you publish, a count of page views, link-preview image
fetches and clicks on its “Made with Stowra” link, per day and per referring website. We store
the day, the host name of the referring site (for example
reddit.com, never the full address) and the counts. We do not store the IP address, browser or any identifier of the person reading your page, and the page sets no cookie and runs no JavaScript.
Access requests
- If you request access through our form, the answers you give there, including your email address.
We do not ask for and do not want payment card data, health data, government identifiers, precise location, or other special categories of personal data. Please do not store such data in notes or item names.
Why we use it, and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Provide the service: your account, workspaces, sync across devices, sharing and connected apps | Account data, workspace content, audit log, API tokens | Performance of our contract with you (Terms of Service) |
| Keep the service secure: authentication, rate limiting, abuse prevention | Technical data, account data | Legitimate interest in protecting users and the service |
| Tell you whether a link you published is being read | Share-link statistics | Legitimate interest in giving publishers a basic readership count |
| Find and fix bugs | Error reports, technical data | Legitimate interest in a working service |
| Decide on access requests and send invitations | Access-request answers, email address | Steps taken at your request before a contract |
| Answer your messages and service notices (sign-in, invitations, account changes) | Email address, message content | Performance of our contract; legitimate interest |
We do not sell personal data, show advertising, track you across other sites, build behavioural profiles, or use your content to train AI models.
ChatGPT, Claude and other AI assistants
You can connect Stowra to an AI assistant through our connector (an MCP server). Nothing is shared until you approve the connection on Stowra’s consent screen, where you choose the workspace and what the assistant may do:
inventory:read— read gear, kits, loadouts, profiles and tags;inventory:write— create, change, trash and undo those records;workspace:read— read the workspace’s name and your role in it.
How we handle data in this flow:
- Minimal inputs. Our server only receives the arguments of each tool call the assistant makes, such as a search term or the item to update. It never requests, reads, reconstructs or infers your chat history.
- Minimal outputs. Tool responses contain only the workspace records relevant to the request, and no internal logs, trace or session identifiers.
- No credentials or sensitive data. The connector never asks for passwords, API keys, one-time codes, payment data, health data, government identifiers or location. Authorization uses OAuth; the assistant holds a revocable token, never your password.
- Visible and reversible changes. Changes made by an assistant are marked as such in the audit log and grouped so you can undo them. Deletions move records to the trash rather than erasing them.
- No public sharing. The connector cannot create share links or publish anything.
Data returned to the assistant is then processed by its provider (for example OpenAI or Anthropic) under that provider’s own privacy policy, and may appear in your conversation history there. You can disconnect an assistant at any time in Stowra under Settings → Workspace → API by revoking its token, which ends its access immediately.
Who receives your data
We share personal data only with the following categories of recipients:
- Other members of your workspace, who see its content and the audit log, according to their role.
- People with a share link you created, who see what that link’s settings make public.
- AI assistants you connect, within the permissions you granted (see above).
- Service providers (processors) acting on our instructions:
- Supabase — database, authentication and file storage, hosted in the EU (Ireland);
- Cloudflare — secure network tunnel and delivery for our self-hosted servers;
- Sentry (Functional Software, Inc.) — error monitoring;
- Tally — the access-request form;
- Google — only if you choose “Continue with Google”.
- Authorities, where the law requires it.
The application servers are operated by us in France. Some providers above are based in the United States. Where personal data leaves the European Economic Area, the transfer relies on the EU–US Data Privacy Framework or the European Commission’s Standard Contractual Clauses.
How long we keep it
| Data | Retention |
|---|---|
| Account data | While your account exists. After you delete your account: 30 days during which you can restore it, then permanently erased. |
| Workspace content, photos and audit log | While the workspace exists. A workspace you alone belong to is erased with your account. In a workspace shared with others, the content stays for the remaining members; your account and membership are removed. |
| Trashed items | Restorable until the workspace is deleted. |
| Share links | Public until you revoke the link or delete the loadout, workspace or account. |
| Share-link statistics | Per-day detail: 13 months. The all-time view count stays with the link for as long as the link exists. |
| API tokens and connected apps | Until you revoke them or delete your account. Expired and revoked tokens stop working immediately. |
| Server logs | Up to 30 days. |
| Error reports | Up to 90 days. |
| Access-request answers | Up to 12 months after the request. |
| Emails you send us | Up to 3 years after our last exchange. |
| Backups held by our database provider | Overwritten on a rolling basis within 7 days. |
Your controls and rights
In the app, you can at any time:
- edit your name, avatar and preferences, and change your email address or password;
- edit, trash, restore and undo workspace content;
- choose what each share link shows, or revoke it;
- see and revoke connected AI assistants and API tokens;
- leave or delete a workspace, and delete your account (Settings → Personal → Profile).
Under the GDPR you also have the right to access your data, to rectify it, to erase it, to receive it in a portable, machine-readable format, to restrict or object to its processing, and to set instructions for what happens to it after your death. To exercise any of these — including a full export of your data — email [email protected] from your account’s address. We answer within one month.
If you believe your rights are not respected, you can lodge a complaint with the French data protection authority, the CNIL, or with the authority of your EU country of residence.
Cookies and local storage
Stowra uses no advertising or analytics cookies. The app keeps your session and preferences in your browser’s storage because it cannot work without them. Details are on the Cookies page.
Security
Connections are encrypted with HTTPS. Uploaded photos are kept in private storage and served through short-lived links. Passwords and API tokens are stored only as hashes. Access to production systems is limited to the operator.
Children
Stowra is not intended for children under 15. If you believe a child has created an account, contact us and we will delete it.
Changes to this policy
We will update the date at the top of this page when this policy changes, and tell account holders by email or in the app before any significant change takes effect.
Contact
Yohann Lereclus — [email protected]. See also the Terms of Service, the Legal Notice and Support.