stashrelay/privacy

privacy

What we collect, and what we don't.

stashrelay moves content you choose between your AI apps. It runs on a small set of personal data — an account with our sign-in provider, the items you stash (encrypted at rest), and coarse anonymous usage counts. This page lays out exactly what that means.

Last updated August 31, 2026

Who's responsible

stashrelay is operated by Merendon Cloud, LLC, a Delaware limited liability company in the United States. References on this page to “we” or “us” mean Merendon Cloud, LLC — the controller of the personal data described below. This page covers stashrelay on every domain we serve it from, whichever address brought you here.

What we collect

Your account. Sign-in is handled by Clerk, our identity provider. Your email address, sign-in credentials, and profile live with Clerk — our own servers never store them. To stashrelay you're an account ID, and in our datastore even that ID appears only as a one-way pseudonymous code.

What you stash. Each item is a name you choose, a short summary, and the content itself. The summary and content are encrypted before they're written to storage (details below). The item's name and its timestamps (when it was stashed, when it expires) are stored readably, along with housekeeping details like rate-limit counters — the service needs those to list, order, and expire items on schedule. So give items boring names and keep the secrets in the body.

API keys. If you create an API key on the settings page, we store the label you give it, its permission level, when it was created, and a one-way hash used to check the key when a client presents it. The key itself is shown to you once and never stored — if it's lost, revoke it and create another.

How you use it. Each tool call is counted as a usage event: which tool ran, the outcome, and a few coarse labels such as a size bucket or whether a stash replaced an existing item — never account IDs, item names, summaries, or content. Tool calls and website visits are both counted by Vercel Web Analytics, which is cookieless: it computes a short-lived session hash from the request's IP address and browser user-agent that resets every 24 hours and never leaves their infrastructure.

What we don't do

  • We don't read, scan, or moderate what you stash. No code path logs item content, and there's no admin screen that displays it.
  • We never send your content to an AI model, and no third party ever sees it in readable form — outside our application it exists only as the encrypted records our datastore holds. Readable content goes to exactly one place: back to a client you connected.
  • We don't sell or rent personal data, don't run ads, and don't track you across the web.
  • We don't store passwords or payment card numbers on our servers — sign-in lives with Clerk.

Encryption, honestly

Item content and summaries are encrypted at rest with AES-256-GCM. Each user's items are encrypted with a key derived for that user alone, from a master key that lives only with our application — the datastore never sees it. If the storage provider were compromised, or a backup leaked, the stashed content in it would be unreadable ciphertext.

This is server-side encryption, not end-to-end encryption, and we'd rather say so plainly than let the word “encrypted” overpromise. Our application decrypts your items to serve them back to your clients, so the machinery to read content exists on our side; what we've built around it is restraint — nothing in the service reads, logs, or analyzes decrypted content beyond returning it to you. If end-to-end secrecy is a hard requirement, a clipboard you didn't encrypt yourself shouldn't hold it.

Everything also travels encrypted in transit (TLS).

Who we share it with

We don't sell or rent personal data. These are the parties involved in running stashrelay:

  • Clerk — sign-in and the authorization screen for connecting clients. Holds your email, credentials, and profile. Never receives stash content.
  • Vercel — hosting, and the cookieless analytics described above. As the host, your requests (including stashed content in transit) pass through infrastructure they run.
  • Upstash — the datastore. Receives encrypted content and summaries, plus readable item names, timestamps, and operational metadata (timestamps and limits), filed under a pseudonymous account code. API key records (label, permission level, timestamps, and the one-way key hash) live here too. Never receives your email, the encryption key, or an API key in usable form.
  • The clients you connect. When you approve an AI client on the authorization screen, that client can access your basic profile (such as name and email) and read or write your stash to the extent you granted. From there your content is in that client's hands and governed by its policies — connect clients you trust, and if you stop trusting one, stop using it and contact us to revoke its access.

stashrelay is operated from the United States and its data is processed there; in transit, requests may pass through our hosting provider's global network.

Cookies and local storage

The website uses Clerk's session cookies to keep you signed in. Your theme choice (light or dark) is kept in your browser's local storage. There are no advertising cookies and no third-party analytics cookies — the analytics above run cookielessly. The clipboard API itself doesn't use cookies at all; connected clients authenticate with access tokens.

Data retention

Retention is the product: stashrelay is a clipboard, and clipboards forget. Every item has a fixed lifetime (1 hour item lifetime) and never lasts more than seven days.

An expired item can never be retrieved again, and pop, discard, and clear take effect immediately — the data is removed from the live datastore in the same operation, not flagged for later cleanup. After your last item expires or is removed, the stored record for your account expires from the datastore on its own — within at most one item lifetime afterward, never more than seven days. The storage provider's backups may briefly retain copies; in those, your content and summaries are unreadable ciphertext without our key, though the readable item names and timestamps described above would be in them too.

Account data (your email and profile at Clerk) persists for as long as your account exists. Anonymous usage events are retained as aggregate statistics under Vercel's retention policy.

Your rights

  • Access. Your stash is short-lived and fully visible to you — the list and read tools show everything we hold. For a copy of anything else (which is little more than your account record), email hi@stashrelay.io.
  • Correction. Stashed items aren't edited in place — stash again under the same name to replace one. Account details can be updated through your account settings.
  • Deletion. clear deletes all stashed content instantly, and expiry deletes it within days regardless. To delete your account itself, email us and we'll remove it — any remaining stash data expires from our datastore on its own within at most seven days.
  • Export. There's deliberately nothing long-lived to export — if you want an item somewhere, read it out to any client before it expires.
  • Email. The only emails you'll receive are ones you trigger yourself — sign-in codes, sent through Clerk. sent through Clerk. There's no marketing list to opt out of.

Children

stashrelay isn't directed at children under 16. If you believe a child has provided personal information to us, contact us and we'll remove it.

Changes

We'll update this page when our practices change. Material changes get a refreshed “Last updated” date at the top.

Contact

Questions about anything on this page — hi@stashrelay.io.