Last updated: September 2026
Who we are
Stublet is a subletting platform operated in Israel. We are the controller of the database that stores your information and are responsible for how it is processed.
This policy applies to the Stublet mobile app (iOS and Android) and the website at stublet.app. It explains what we collect, why, with whom we share it, and what rights you have under Israel's Protection of Privacy Law, 5741-1981 (including Amendment 13, effective 14 August 2025).
Privacy contact: [email protected].
What we collect
Information you give us directly:
- Account details: name, phone number, and/or email (depending on the sign-in method you chose)
- Profile: optional profile photo and short bio
- Listings: title, description, photos, property type, city, neighborhood, optional street address you provide, availability dates, price and deposit amount (display only - Stublet does not process payments)
- Chat messages and attachments
- Booking requests and reports you file
Information collected automatically while you use the app:
- Device identifier and push token (FCM) so we can deliver notifications
- Platform, app version, OS version, system language, last-login timestamp
- Aggregate analytics events (e.g. "listing viewed", "search performed") - we do not intentionally include phone numbers, emails, names, or text you typed. Events may be linked to an internal account or installation identifier. PostHog and Firebase Analytics receive network requests and may observe the source IP needed to deliver them; client-side filtering does not make a promise that a provider never sees network metadata. Google Analytics on the website is subject to the same limitation
- Session Replay (masked screen recording) is currently disabled in the app and on the website. If we enable it in the future, this policy will be updated first to describe its consent, masking and retention terms
- Crash and error reports, after redacting sensitive fields (passwords, OTPs, tokens, phone numbers and emails never enter the logs)
- The IP address a request reaches our server from. We read it at request time to rate-limit traffic, to prevent abuse of verification-code sending (for example a flood of codes to dozens of different numbers from one source), and to spot suspicious access attempts against the admin endpoints. It is not stored on your profile and does not enter your usage history: it lives in short-lived counters that expire on their own, and in the server logs
Your device contacts (entirely optional, and only if you allow it):
If you choose to use "find friends", the app asks your permission to read your address book. If you allow it, the numbers are normalized to the international format and put through a SHA-256 hash on the device itself. Only the hashes leave the device, in batches of up to 1000 per request, and the server compares them against the equivalent hashes of registered users' numbers so it can tell you which of them are already here. Hashes are difficult to reverse directly, but phone-number hashes can be matched against guesses, so we treat them as personal data rather than anonymous data.
The names, numbers, and addresses of your contacts are never sent to us and are never stored by us. Nor are the hashes you sent: they serve the comparison for that one request and are discarded straight after it. What we do store is a hash of your own phone number, so that a friend who has you in their address book can find you the same way. The permission stays yours throughout: you may decline it, you may revoke it at any moment in your device settings, and the rest of the app works without it.
Your device location (optional, and only if you allow it):
Maps in the app can show a dot marking where you are, so you can see where listings sit relative to you. For that the operating system asks you for location permission. The position is read by the map component on the device itself: it is not sent to our servers, not stored by us, and does not affect how results are ranked or filtered. If you decline, the maps simply render without that dot.
Client-side storage:
- In the app: a local store on your device (MMKV) that keeps your preferences, listing drafts, cached content, and a Terms/Privacy receipt containing the accepted document versions and timestamp; your sign-in session is kept on the device by Firebase Authentication
- On stublet.app: the Google Analytics measurement cookies, a localStorage key called "stublet-theme", a localStorage key used by our second measurement tool PostHog (in the form "ph_..._posthog"), and a sessionStorage key called "stublet-campaign". Each one is set out in full - its name, what it does, how long it lives, and how to opt out - in the "Cookies and similar technologies" section further down this page
We do not request date of birth, government ID numbers, payment details, or financial information for registration, and we do not process sublet payments. Users can still include such information in messages, attachments, listings, reports or support requests; do not upload information that is not needed.
Providing this information is not legally required. Without it we cannot provide the service (e.g. without a phone number you cannot register and publish a listing).
How we use it
Your information is used only for:
- Operating the service: sign-in, showing relevant listings, messaging, and booking requests
- Showing social context and degrees of separation so you can decide who to engage with
- Finding people you already know who use the app, by comparing hashes of phone numbers, and only if you allowed access to your contacts
- Ranking the discovery feed by social trust and your preferences (recent searches, saved listings, dismissed listings)
- Understanding product usage, improving the experience, and diagnosing issues - via aggregate analytics and crash/error diagnostics
- Identity verification through Firebase Authentication (phone, email, Google, Apple, Facebook)
- Safety and fraud prevention: detecting abuse, suspending abusive accounts, reviewing reports
- Push notifications for new messages, followers, and listing updates
- Responding to support requests
We do NOT use your information for third-party advertising. We do NOT sell your information.
Your rights
Under Israel's Protection of Privacy Law, 5741-1981 (including Amendment 13, 2025), you have:
- Right of access: receive a description of the information we hold about you
- Right to rectification: update inaccurate or out-of-date information
- Right to deletion: request deletion of your account and the personal data tied to it (full details on the "Account & Data Deletion" page)
- Right to restrict processing: ask us to stop processing your data for specific purposes
How to exercise: email [email protected] with the details of your request. We will respond within the period required by applicable law. We respond in Hebrew, English, or Arabic, per your choice.
Managing push notifications: under Settings > Notifications in the app you can independently toggle three notification types: new messages, new followers, and listing updates. Alongside them sits a "detailed notifications" switch, which decides whether the sender name and message text appear in the notification body on your lock screen; it is off by default.
Your account also stores a separate preference marker for marketing content. It is off by default for every user, and it cannot currently be changed from inside the app because no Settings switch is wired to it. If we add such a switch, or if we begin sending marketing content, we will update this policy before the change rather than after it.
If you are not satisfied with how we handled your request, you can contact the Privacy Protection Authority at the Israel Ministry of Justice, 22 Kanfei Nesharim St., Jerusalem.
How long we keep your data
As long as your account is active we keep your data so you can keep using the service.
After account deletion (full details on the "Account & Data Deletion" page):
- Identifying fields (name, phone, email, profile photo) are nulled immediately
- Your listings move to inactive and the host snapshot on each one is nulled
- Your social-graph relationships, your photos in storage, and your push tokens are deleted
- Active sessions are terminated
What may remain: booking requests you sent or received (without your identifying information), reports filed against you (for safety reasons), aggregate analytics events that don't identify you personally, and data subject to an active legal hold.
Our service providers keep the data they hold under their own policies, and those periods differ from one another. There is no single figure:
- Firebase Analytics, Crashlytics, Sentry and PostHog: retain data according to the configured project and vendor retention settings. We send deletion requests where the provider supports them
- Cloudflare R2: we request deletion of account media when the account is deleted; provider backups and replicas may persist for the provider's documented backup period
The same provider caveats appear on the "Account & Data Deletion" page. If you ever find the two pages disagreeing, write to us.
Security
We apply standard technical and organizational safeguards:
- HTTPS / TLS for all traffic between the app and the servers
- Encryption at rest at every storage provider (MongoDB Atlas, Cloudflare R2)
- Access keys scoped to backend servers - no key reaches a client device
- Redaction of sensitive fields (passwords, OTPs, tokens, phone numbers, emails) before they enter the server logs
- Automatic session revocation on account deletion
That said, no system is 100% secure. Keep your sign-in details safe and contact us immediately if you suspect your account has been compromised.
Children
Stublet is for users 18 and over. Subletting requires legal capacity to enter contracts.
We do not collect date of birth. At sign-up you confirm you are 18 or older (Section 1 of the Terms of Service). If we identify a user under 18, we delete the account immediately.
Parents who discover that a child opened an account by mistake: email [email protected] and we will expedite deletion. For the full child-safety policy, including zero tolerance for CSAE, see the "Safety & Moderation" page.
Contact and policy updates
For any privacy question, request, or complaint:
Email: [email protected]
Policy updates: we may update this policy from time to time. A material update (new data categories, a new service provider, expanded uses) is surfaced in the app before you continue using it. A cosmetic update is reflected by the "last updated" date at the top of the page and the revision number beside it. If you want to know what changed between two revisions, or to receive the text that was in force on a particular date, write to [email protected] and we will send it to you.
Israeli regulator: Privacy Protection Authority, Ministry of Justice, 22 Kanfei Nesharim St., Jerusalem.