Data & Privacy

How Starlight handles your data.

|

Data Sources

Lead Data

Lead information (names, titles, companies, contact info) comes from third-party B2B data providers with access to 250M+ verified business contacts. This data is publicly available business information.

Email Content

Outreach messages are generated by AI based on your settings and publicly available prospect information. Sent messages and replies are stored in your Starlight account and accessible only to your team.

Security

Encryption

  • OAuth tokens (Gmail, Outlook, Google Calendar, Outlook Calendar, HubSpot) are encrypted with AES-256-GCM before storage
  • Database connections use TLS encryption in transit

Authentication

Starlight uses passwordless authentication exclusively:

  • Google OAuth — delegates authentication to Google
  • Magic Links — one-time login links sent to your email

No passwords are stored in the system.

Session Management

You can terminate all active sessions from Settings → Security → Sign Out Everywhere.

Email Handling

  • Starlight only reads and tracks email threads initiated through the platform
  • Your personal inbox is never accessed or scanned
  • Connected email permissions can be revoked at any time from the Connectors page or your Google/Microsoft account settings

Data Retention

  • Your data is retained for as long as your account is active
  • Deleting your account permanently removes all associated data
  • Blacklisted email addresses are retained to prevent future outreach to those contacts

Third-Party Services

Starlight relies on these providers to run. The authoritative list, with locations, transfer safeguards, and a change log, is the Sub-processors page; this table is generated from the same source.

ServicePurposeData Shared
Vercel, Inc. Application hosting, serverless compute, cookieless analytics, and the AI Gateway that routes our model calls All application traffic, request logs, model prompts in transit
Supabase, Inc. Authentication and the production Postgres database (AWS us-east-2) Account data and all application data at rest
Amazon Web Services, Inc. (Amazon Bedrock) Hosts the primary outreach-writing model (Moonshot AI's Kimi K2.5) in AWS US regions. Starlight pins every writer call to this host through the Vercel AI Gateway, so prompts never reach Moonshot AI's own API Prospect business context, your product and brief, cached research facts
Meta Platforms, Inc. Judging, planning, and chat agent reasoning (Muse Spark) Prospect business context, drafts being evaluated, your instructions to the agent
xAI Corp. Research, web and X search, query parsing, signal and social scanning (Grok) Prospect names and companies for research, search queries, public post text
Anthropic, PBC Outage fallback for the writer and judges (Claude) Same as the model it stands in for
Google LLC Grounded reply drafting with Google Search (Gemini); also the Gmail and Calendar APIs you connect Reply threads being drafted, prospect context
OpenAI, L.L.C. Draft revision pass and outreach fallback tier (GPT-5.6) Drafts being revised and their prompt context
Apollo.io (ZenLeads Inc.) Lead search, contact and company enrichment, phone reveals, job-change detection Search filters, names, companies, LinkedIn URLs submitted for matching
Resend, Inc. Transactional email from Starlight itself (welcome, invites, notifications, booking confirmations) Recipient name and email, message content
Clearout Email address verification before a draft is sent Recipient email addresses
Stripe, Inc. Subscription billing, hosted checkout, and the billing portal Billing name, email, payment method (card numbers never reach Starlight)
SerpApi, LLC Google Maps results for Local search; Google results for Reddit threads and G2/Capterra reviews Search queries (business types, locations, keywords); no account data
HarvestAPI (Aventra Technologies Limited) LinkedIn public post search for Social listening Keyword phrases; no account data
Reddit, Inc. Reddit Data API to read the full text of public threads surfaced in Social Thread identifiers; no account data
Openmart, Inc. Local-business database behind Local search: business listings (name, address, phone, website, published inboxes, social links, ratings, ownership) and owner / decision-maker contact lookup for businesses you search The business category and area you search, and the website domains and names of businesses in your results; no account data
TinyFish, Inc. Web search for Reddit threads, public LinkedIn posts, and G2/Capterra reviews in Social listening, and fetching the public pages those searches return (thread and post bodies, cited news articles) Search keyword phrases and public page URLs; no account data
Logo.dev Company logos shown in the app Company domain names only
MapTiler AG Map tiles for Local search and the Metrics globe, loaded by your browser Your IP address and the map area viewed
OpenStreetMap Foundation (Nominatim) City boundary outlines for Local search, fetched server-side Place names only

The Starlight Chrome extension acts locally in your browser to send LinkedIn and X messages and run the read-only scans you enable. Your LinkedIn and X credentials are never shared with Starlight. Every data flow is described in the Chrome Extension section of the Privacy Policy.

Contact

For data privacy questions, contact privacy@joinstarlight.com.

Was this page helpful?