Privacy
Squish Stash & Wish Privacy Policy
Effective date: August 25, 2026
1. Scope
This Privacy Policy explains how Squish Stash & Wish handles information when the app or its public support and privacy pages are used. It describes the app as it currently operates.
2. Information the app stores or receives
No accounts or login
The app does not currently provide account registration, login, user profiles, or cloud synchronization. It does not ask for a name, mailing address, phone number, or account email address.
Information stored on the device
The app stores the following information locally on the user’s device so its features work between sessions:
- products and colors marked as owned;
- products and colors added to the wishlist;
- locally learned barcode-to-product matches;
- user-entered product image URL overrides;
- the locally cached status of the permanent app unlock.
The app does not upload collection, wishlist, learned barcode, or image-override information to an Squish Stash & Wish account or database because no such account or synchronization service is currently implemented.
Support communications
If a user emails support, the support contact receives the sender’s email address and any information the sender chooses to include. That information is used to respond to the support request.
Public webpage access
When someone visits the public support or privacy pages, the hosting provider may process standard technical request information, such as an IP address, browser type, requested page, and request time, to deliver and protect the website.
3. Camera, barcode scanning, and product images
Camera access is requested only when the barcode scanner is used. The camera view reads supported barcode values so the app can look up a NeeDoh product. The app does not use the scanner to take, save, or upload camera photographs or video.
If a barcode is not recognized, the user may associate that barcode with a catalog product. That learned match is stored locally on the device.
The app displays product images hosted by Schylling and various retailers. Loading a remote image causes the device to connect to the image host, which may receive standard network information such as the device’s IP address and browser or app request information. If a user enters a replacement image URL, the app checks and loads that URL directly from the chosen host. The replacement URL is stored locally.
5. Purchases, Apple, and RevenueCat
Squish Stash & Wish offers a permanent full-app unlock. Apple processes the App Store transaction. The app uses RevenueCat to request available purchase offerings, initiate or restore a purchase, and determine whether the permanent unlock entitlement is active.
Apple and RevenueCat may process purchase-related information such as the product purchased, transaction and entitlement status, an app-installation or customer identifier created by their systems, and technical information needed to provide and troubleshoot purchasing. The app does not receive or store full payment-card details. The current app code does not attach an Squish Stash & Wish account, username, or login email to RevenueCat.
6. How information is used
Information handled by the app is used to:
- remember the collection, wishlist, colors, and local preferences;
- recognize products from barcode values;
- display catalog and user-selected remote product images;
- prepare user-requested wishlist sharing;
- process, restore, and verify the permanent purchase entitlement;
- respond to voluntary support requests;
- operate and secure the public support and privacy pages.
7. Sharing and third-party services
Squish Stash & Wish does not sell personal information. Information may be handled by the following third parties for the described functions:
- Apple App Store: processes purchases, restores, and related App Store transaction information. Apple Privacy Policy.
- RevenueCat: manages purchase offerings and entitlement status using its SDK. RevenueCat Privacy Policy.
- Replit: hosts the public app landing, support, and privacy pages and may process standard web request logs. Replit Privacy Policy.
- User-selected communication services: receive wishlist or support content when the user chooses to send it through an email, messaging, or sharing app.
- Product image hosts: receive ordinary network requests when the app loads catalog images or a user-entered image URL.
The current app does not include advertising networks, behavioral analytics, session recording, third-party crash reporting, location tracking, contact access, or push notifications.
8. Retention and security
Locally stored app information remains on the device until it is changed by the user, removed through an available app control, or the app’s stored data is deleted through the device operating system or by uninstalling the app. Some items, such as learned barcode matches, do not currently have an individual delete control inside the app.
Purchase and transaction information is retained by Apple and RevenueCat according to their own policies and legal obligations. Support emails are retained as reasonably needed to respond and keep a record of the request.
Reasonable care is used in the design of the app, but no storage or transmission method can be guaranteed to be completely secure. Users should use their device’s security features and avoid including sensitive personal information in wishlist messages or support emails.
9. Children’s privacy
The app may appeal to younger collectors. The current app does not ask users to state their age and does not include an age gate or a parental-consent system. A parent or guardian should supervise a child’s use of camera scanning, purchases, external links, email, and sharing features.
Children should not include personal information in wishlist messages, support emails, or user-entered image URLs. If a parent or guardian believes a child has sent personal information to the support contact, they may use the contact information below to request review or deletion. This section does not claim that the app is certified as compliant with the Children’s Online Privacy Protection Act or any similar law.
10. User choices and deletion
- Camera permission can be denied or changed in device settings.
- Users control whether wishlist or support content is sent through another app.
- Owned and wishlist selections can be changed in the app, and an individual product image override can be removed.
- All locally stored app information can be removed by deleting the app’s data through the device operating system or uninstalling the app.
- Questions about support emails can be sent to the contact below. Apple and RevenueCat requests are governed by their respective privacy processes.
11. Changes to this policy
This policy may be updated when the app’s features or services change. The effective date at the top of this page will be revised when an updated policy is published.
12. Contact
For privacy questions or requests, email alexdomanjr@gmail.com.