"Stash exhibits high-risk privacy practices comparable to Facebook/TikTok by collecting extensive sensitive financial data (bank credentials, SSN, government IDs, biometrics), sharing with multiple third parties including advertising networks and corporate affiliates, and implementing pervasive cross-device behavioral tracking for ad targeting. Data retention is indefinite with no clear deletion mechanism, and the policy lacks explicit safeguards for AI/LLM training despite stated data uses. The combination of financial data sensitivity, broad third-party access, and sophisticated tracking creates substantial privacy risks."
stash Privacy Concerns & Scorecard
Financial data shared with multiple third parties including banking verification services, consumer reporting agencies, Plaid Inc., and unspecified marketing partners for advertising purposes
Stash collects extensive sensitive financial data including bank account login credentials, full credit/debit card numbers, Social Security numbers, and government-issued identification documents
No explicit opt-out mechanism for AI/LLM training despite data use statement; policy allows unilateral policy changes with continued use as acceptance
Third-party advertising companies receive personal information and post-conversion data for automated profiling, optimization, and targeted advertising without explicit data type restrictions
Data retention period is vague and indefinite; data retained 'as long as necessary' with no explicit deletion timeline specified after account closure
No recommended actions at this time.
Automate your privacy
Connect your accounts to TrueTerms to automate these privacy actions and monitor policy changes.
Data Collection & Tracking
Personal Information Collected
Account creation, identity verification, regulatory compliance, KYC/AML requirements
Financial service provision, account management, fraud detection, investment services, credit/risk assessment
Service personalization, location-based features, compliance, fraud prevention
Technical service delivery, security, ad targeting, device fingerprinting
Service improvement, personalization, advertising targeting, product analytics, user experience optimization
Account management, customer communication, verification, security
Quality assurance, training, dispute resolution, compliance
Targeted advertising, product recommendations, risk assessment, marketing personalization
Cross-Platform Tracking
Stash explicitly tracks users across multiple sites, services, and devices through cookies, web beacons, pixel tags, and advertising identifiers (IDFA/AdID) for cross-context behavioral advertising and retargeting. The policy states data is disclosed to third parties for tracking 'across different sites, services, and devices' and that 'personal information and discloses personal information to third parties for advertising and marketing on Services and elsewhere based on users' online activities over time and across different sites, services, and devices.'
Tracking Methods:
Cookies (First & Third-Party)
HTTP cookies and browser storage used to track user activity, preferences, and advertising interactions across sessions and websites
Web Beacons & Pixel Tags
Embedded invisible tracking pixels and beacons in web pages and emails to track user visits, clicks, and engagement with marketing content
Advertising Identifiers
IDFA (iOS) and AdID (Android) collected from mobile devices to enable cross-app and cross-device behavioral advertising and retargeting
Device Fingerprinting
Collection of device characteristics (OS, browser, device ID, network information) to create unique device identifiers for tracking and security
Login & Authentication Tracking
Tracking of login data, authentication methods, and account access patterns for security and personalization
Third-Party Analytics SDKs
Mixpanel and Braze analytics platforms embedded in app/website to track user behavior, engagement, and custom events across sessions
AI & Data Training
stash uses your content to train AI
Below is what's used and how (if at all) you can object.
What Content Is Used
Personal Financial Data
Bank account information, transaction history, account balances, and financial behavior used for LLM training
Behavioral Data
Browsing history, search history, click-stream data, and engagement patterns used for LLM training
Inferred User Profiles
Algorithmically-generated psychological and behavioral profiles used for LLM training and model improvement
How to Object
No opt-out available
This service does not currently provide a public way to opt out of AI training.
Why We Analyzed stash
TrueTerms automatically audits privacy policies and data practices using advanced machine learning to keep you informed and protected. This scorecard is based on the latest available public terms of service and privacy policies as of 2026.