STOWRA

Privacy Policy

Last updated September 16, 2026

This policy explains how Stowra (the web app at app.stowra.app, the public share pages, the Stowra API and the Stowra connector for AI assistants such as ChatGPT and Claude) handles personal data. It is written to meet the EU General Data Protection Regulation (GDPR / RGPD) and the French Data Protection Act.

Who is responsible

The data controller is Yohann Lereclus, an individual based in France who publishes and operates Stowra. For any question about your data or to exercise your rights, write to [email protected].

Personal data we collect

Account data

Workspace content

Activity and connection data

Access requests

We do not ask for and do not want payment card data, health data, government identifiers, precise location, or other special categories of personal data. Please do not store such data in notes or item names.

Why we use it, and on what legal basis

PurposeDataLegal basis
Provide the service: your account, workspaces, sync across devices, sharing and connected apps Account data, workspace content, audit log, API tokens Performance of our contract with you (Terms of Service)
Keep the service secure: authentication, rate limiting, abuse prevention Technical data, account data Legitimate interest in protecting users and the service
Tell you whether a link you published is being read Share-link statistics Legitimate interest in giving publishers a basic readership count
Find and fix bugs Error reports, technical data Legitimate interest in a working service
Decide on access requests and send invitations Access-request answers, email address Steps taken at your request before a contract
Answer your messages and service notices (sign-in, invitations, account changes) Email address, message content Performance of our contract; legitimate interest

We do not sell personal data, show advertising, track you across other sites, build behavioural profiles, or use your content to train AI models.

ChatGPT, Claude and other AI assistants

You can connect Stowra to an AI assistant through our connector (an MCP server). Nothing is shared until you approve the connection on Stowra’s consent screen, where you choose the workspace and what the assistant may do:

How we handle data in this flow:

Data returned to the assistant is then processed by its provider (for example OpenAI or Anthropic) under that provider’s own privacy policy, and may appear in your conversation history there. You can disconnect an assistant at any time in Stowra under Settings → Workspace → API by revoking its token, which ends its access immediately.

Who receives your data

We share personal data only with the following categories of recipients:

The application servers are operated by us in France. Some providers above are based in the United States. Where personal data leaves the European Economic Area, the transfer relies on the EU–US Data Privacy Framework or the European Commission’s Standard Contractual Clauses.

How long we keep it

DataRetention
Account data While your account exists. After you delete your account: 30 days during which you can restore it, then permanently erased.
Workspace content, photos and audit log While the workspace exists. A workspace you alone belong to is erased with your account. In a workspace shared with others, the content stays for the remaining members; your account and membership are removed.
Trashed items Restorable until the workspace is deleted.
Share links Public until you revoke the link or delete the loadout, workspace or account.
Share-link statistics Per-day detail: 13 months. The all-time view count stays with the link for as long as the link exists.
API tokens and connected apps Until you revoke them or delete your account. Expired and revoked tokens stop working immediately.
Server logs Up to 30 days.
Error reports Up to 90 days.
Access-request answers Up to 12 months after the request.
Emails you send us Up to 3 years after our last exchange.
Backups held by our database provider Overwritten on a rolling basis within 7 days.

Your controls and rights

In the app, you can at any time:

Under the GDPR you also have the right to access your data, to rectify it, to erase it, to receive it in a portable, machine-readable format, to restrict or object to its processing, and to set instructions for what happens to it after your death. To exercise any of these — including a full export of your data — email [email protected] from your account’s address. We answer within one month.

If you believe your rights are not respected, you can lodge a complaint with the French data protection authority, the CNIL, or with the authority of your EU country of residence.

Cookies and local storage

Stowra uses no advertising or analytics cookies. The app keeps your session and preferences in your browser’s storage because it cannot work without them. Details are on the Cookies page.

Security

Connections are encrypted with HTTPS. Uploaded photos are kept in private storage and served through short-lived links. Passwords and API tokens are stored only as hashes. Access to production systems is limited to the operator.

Children

Stowra is not intended for children under 15. If you believe a child has created an account, contact us and we will delete it.

Changes to this policy

We will update the date at the top of this page when this policy changes, and tell account holders by email or in the app before any significant change takes effect.

Contact

Yohann Lereclus — [email protected]. See also the Terms of Service, the Legal Notice and Support.