Privacy Policy
Last updated: July 2026
Summary
- Stora holds your WhatsApp message content, media, contacts, and group data in decrypted, plaintext form — we do not use end-to-end or zero-knowledge encryption, and we can read what we back up.
- What we collect: Your name and email, and the WhatsApp content you choose to back up — messages, media, contacts, group data, and whatever else your plan captures.
- Why: To provide the Stora backup and archive-exploration service, and to process payments via Paddle.
- How long: Depends on your plan; the ban-risk acknowledgment record is kept indefinitely for audit purposes. See the retention table below.
- Who else sees it: Our sub-processors — Hetzner (storage), Paddle (billing), Resend (email), Sentry (errors), PostHog (analytics, cookieless).
- Your rights (EEA/UK): Access, rectification, erasure, portability, objection, restriction. Contact privacy@storabackup.com.
- Backed-up data: Stora acts as a processor; you are the controller for the WhatsApp content you back up — it is your own account data. See the Data Processing Agreement.
1. Plaintext Custody of Your WhatsApp Content
Stora runs as a linked device on your WhatsApp account. To sync, search, and export your message history, Stora decrypts the content WhatsApp's end-to-end encryption protects. We hold your message text, media (photos, videos, voice notes, documents), contact names and phone numbers, and group membership and rosters in decrypted, plaintext form on our servers. This is not a zero-knowledge or end-to-end-encrypted backup — Stora, not only you, can read what we store. We are stating this plainly here, as the central fact of what this product does, not as a detail inside a section about security measures.
On a plan with a limited history window, we decrypt your full WhatsApp message history into our sync infrastructure's database before filtering it down to the window your plan includes; only the entitled window is written to your long-term archive. Rows from that intermediate database — including messages outside your plan's window — persist in our nightly database backup (pg_dump) for up to 7 days.
2. Controller and Processor (GDPR Article 13)
For your account information and payment data, Stora is the data controller. We determine the purposes and means of processing.
For the WhatsApp content you back up, you are the data controller and Stora acts as a data processor under your instructions — the archive is your own account data. Our obligations are set out in the Data Processing Agreement (DPA).
3. Categories of Personal Data We Process
Account Data (controller role)
Name, email address, and password hash when you create an account. Necessary for service delivery — contractual basis under GDPR Article 6(1)(b).
WhatsApp Content Backed Up (processor role)
Message text, media, voice notes, and documents; contact names and phone numbers; group membership and rosters; call metadata; and status updates from people you follow. Exactly what is captured depends on the scope you choose and your plan.
Credential-Recovery Posture
Stora stores your archive unencrypted at the application layer — there is no user-held passphrase, no bring-your-own-key (BYOK) option, and no encryption key protecting the archive that could be lost. Losing your Stora password does not lock you out of your archive: you reset it by email like any other account, the same way you would for any web service. This is a consequence of the plaintext-custody posture stated above, not a separate encryption feature.
IP Addresses and User-Agent Strings (controller role)
Stora captures the client IP address and user-agent string for certain account actions, including the ban-risk acknowledgment described in the retention table below, and writes them to an audit log. Under Breyer v Germany (CJEU C-582/14), dynamic IP addresses constitute personal data. We process this data on the basis of legitimate interest (GDPR Article 6(1)(f), Recital 49) to maintain security, investigate abuse, and produce compliance evidence.
Payment Information (controller role)
Payment processing is handled by Paddle (merchant of record). We do not store credit card numbers. Paddle processes payment data under their own privacy policy and PCI DSS compliance. Lawful basis: contract (GDPR Article 6(1)(b)).
4. Third-Party Data: Your Contacts and Group Participants
Your archive also contains personal data belonging to people who are not Stora customers: the names and phone numbers of your contacts, message content sent by other people in your conversations, and group participant rosters and membership history. These people have not created a Stora account and have not agreed to our terms. We state this fact plainly; how it interacts with data-protection law for people outside our customer relationship is a question we are working through with legal counsel and do not attempt to resolve here.
5. Lawful Bases (GDPR Article 6)
- Contract (Article 6(1)(b)): Account data, payment processing, and the WhatsApp content backup you request — necessary to provide the service you signed up for.
- Legitimate interest (Article 6(1)(f), Recital 49): Audit-log IP address capture, security monitoring, product telemetry — proportionate to our legitimate interest in operating a secure, reliable service.
- Consent (Article 6(1)(a)): PostHog analytics (cookieless; no personal data stored per PostHog's own privacy policy). You may opt out via your browser's "Do Not Track" signal.
6. Data Retention
We retain data according to these defaults:
| Data type | Retention period |
|---|---|
| Free tier archive | 3-day access window (7 days of message history, media capped at 250MB) |
| Snapshot Pass archive | 14-day access window from purchase, one-time |
| Scheduled Vault / Continuous Vault archive | Retained while the subscription is active, plus a 7-day grace period after it lapses |
| Ban-risk acknowledgment record (IP address, user agent, timestamp) | Indefinite — evidentiary/audit purpose, exempt from standard retention pruning; deleted only when the account itself is deleted |
| Audit log (IP addresses, actions) | 90 days by default; longer where configured |
| DSAR export ZIP | 7 days from creation, then auto-deleted |
| Account data after deletion request | Deleted within 30 days of request, unless a longer retention period is required by law |
| Erasure tombstones | Permanent (to prevent re-backup of erased records) |
7. Sub-processors and International Transfers
We use the following sub-processors. The current list, including data categories and regions, is published at /legal/sub-processors/. When we add or change a sub-processor, we notify all account owners by email before the change takes effect.
- Hetzner (Germany) — Backup storage, including decrypted WhatsApp content. Data stays in Germany. Privacy policy.
- Paddle (Ireland / US) — Subscription and one-time-purchase billing. Transfer covered by EU SCCs. Privacy policy.
- Resend (US) — Transactional email. Transfer covered by EU SCCs. Privacy policy.
- Sentry (EU) — Error monitoring; receives anonymised error reports. Privacy policy.
- PostHog (EU) — Product analytics in cookieless mode. No personal data or IP addresses stored. Privacy policy.
8. Your Rights (GDPR Articles 15–22)
If you are in the EEA or UK, you have the following rights. To exercise them, contact privacy@storabackup.com. We respond within 30 days.
- Access (Article 15): Request a copy of personal data we hold about you via a DSAR (Data Subject Access Request). Authenticated users can initiate from the Settings page.
- Rectification (Article 16): Request correction of inaccurate data.
- Erasure (Article 17): Request deletion of your personal data. Backed-up records containing your personal data can be erased per-record, per-person, or account-wide via the Settings page.
- Portability (Article 20): Export your data in JSONL + CSV format from the Settings page.
- Restriction (Article 18): Request that we limit processing under certain circumstances.
- Objection (Article 21): Object to processing based on legitimate interest (e.g., audit-log IP capture).
- Supervisory authority complaint: You may lodge a complaint with your national data protection authority.
9. Security Measures
- All data in transit is protected using TLS 1.3 encryption (HTTPS).
- Stora stores backed-up content unencrypted at the application layer rather than behind a user-held passphrase (see the credential-recovery posture in Section 3) — at-rest encryption below the application layer is whatever Hetzner's storage infrastructure provides; Stora adds none of its own. This is what makes email-based password reset possible without losing your archive, and it also means Stora can read what it stores.
- Access to production systems is restricted to authorised personnel and protected by multi-factor authentication.
- Full security overview: Security page.
10. Cookies
Stora uses session cookies strictly necessary for authentication. PostHog analytics operates in cookieless mode with no persistent identifiers. We do not use advertising cookies or third-party tracking cookies.
11. Changes to This Policy
We may update this policy for operational, legal, or regulatory reasons. For material changes (including sub-processor additions or removals), we will notify account owners by email before the changes take effect. Previous versions are available on request.
12. Contact
For privacy enquiries, DSAR requests, or to exercise any GDPR right: