For technical evaluators & buyers

Security & data handling

Everything you need to evaluate Stash before adopting it for your team. Plain answers, no marketing.

On this page

  1. What data is stored and where
  2. Account isolation
  3. Authentication (Google OAuth)
  4. Encryption in transit and at rest
  5. Data use — no training, ever
  6. Data export and deletion
  7. Teams and pricing

1. What data is stored and where

Stash stores two categories of data:

Short answer Your email + records. US cloud, industry-secure servers. No other personal data collected.

Stash does not read your Claude conversation history. It only sees what Claude explicitly passes to the Stash MCP tools (the text of records you store and search queries).


2. Account isolation

Each account gets its own dedicated store. Records in Account A are physically separate from records in Account B — there is no shared table, no join, no query that can cross accounts. The MCP connector is scoped to a single account via the OAuth token; unauthenticated requests are rejected with 401.

Short answer A dedicated per-account store. No cross-account access is possible at the data layer.

This is relevant for consultants and agencies with client confidentiality requirements: Client A's records cannot surface in Client B's searches.


3. Authentication

Stash uses standard Google OAuth 2.0 — the same flow used by thousands of SaaS products. You sign in with your Google account; Stash receives a scoped token, verifies it with Google, and issues its own session. Stash never sees your Google password.

Short answer Standard Google OAuth 2.0. No proprietary auth. Revokable at any time from your Google account settings.

4. Encryption

Short answer HTTPS throughout. AES-256 at rest. No plaintext storage.

5. Data use — no training, ever

Stash does not use your records to train any model. Your data is used only to serve your queries. It is not shared with Anthropic, not used to improve Claude, and not used to train any Stash model (Stash has no AI model — it is a record store with full-text search).

Short answer Your records are never used for training. Stash has no ML pipeline.

6. Data export and deletion

You own your data. You can:

Short answer Export on request. Full deletion on cancel (30-day backup window, then permanent). Plain text format — no lock-in.

7. Teams and pricing

Stash is currently individual-account billing. Each person on your team signs up with their own Google account and manages their own connector. There is no shared team account or centralised admin console in v1.

Honest about where we are Stash is a new service. Team management features (shared billing, admin view, team exports) are on the roadmap but not yet built. If you need centralised team management today, we are not the right fit yet — come back in Q3 2026 or email us to discuss.

Pricing is flat monthly per account. No per-query overage charges. No surprise billing. See the pricing section on the main page.

Pricing may change as we exit early access. Existing paid subscribers are notified at least 30 days in advance of any change. Cancel anytime — no lock-in.

Questions we haven't answered?

Email us directly. We reply within one business day.

Email hello@stashlite.com Back to Stash