Data & Privacy
How Starlight handles your data.
Data Sources
Lead Data
Lead information (names, titles, companies, contact info) comes from third-party B2B data providers with access to 250M+ verified business contacts. This data is publicly available business information.
Email Content
Outreach messages are generated by AI based on your settings and publicly available prospect information. Sent messages and replies are stored in your Starlight account and accessible only to your team.
Security
Encryption
- OAuth tokens (Gmail, Outlook, Google Calendar, Outlook Calendar, HubSpot) are encrypted with AES-256-GCM before storage
- Database connections use TLS encryption in transit
Authentication
Starlight uses passwordless authentication exclusively:
- Google OAuth — delegates authentication to Google
- Magic Links — one-time login links sent to your email
No passwords are stored in the system.
Session Management
You can terminate all active sessions from Settings → Security → Sign Out Everywhere.
Email Handling
- Starlight only reads and tracks email threads initiated through the platform
- Your personal inbox is never accessed or scanned
- Connected email permissions can be revoked at any time from the Connectors page or your Google/Microsoft account settings
Data Retention
- Your data is retained for as long as your account is active
- Deleting your account permanently removes all associated data
- Blacklisted email addresses are retained to prevent future outreach to those contacts
Third-Party Services
Starlight relies on these providers to run. The authoritative list, with locations, transfer safeguards, and a change log, is the Sub-processors page; this table is generated from the same source.
| Service | Purpose | Data Shared |
|---|---|---|
| Vercel, Inc. | Application hosting, serverless compute, cookieless analytics, and the AI Gateway that routes our model calls | All application traffic, request logs, model prompts in transit |
| Supabase, Inc. | Authentication and the production Postgres database (AWS us-east-2) | Account data and all application data at rest |
| Amazon Web Services, Inc. (Amazon Bedrock) | Hosts the primary outreach-writing model (Moonshot AI's Kimi K2.5) in AWS US regions. Starlight pins every writer call to this host through the Vercel AI Gateway, so prompts never reach Moonshot AI's own API | Prospect business context, your product and brief, cached research facts |
| Meta Platforms, Inc. | Judging, planning, and chat agent reasoning (Muse Spark) | Prospect business context, drafts being evaluated, your instructions to the agent |
| xAI Corp. | Research, web and X search, query parsing, signal and social scanning (Grok) | Prospect names and companies for research, search queries, public post text |
| Anthropic, PBC | Outage fallback for the writer and judges (Claude) | Same as the model it stands in for |
| Google LLC | Grounded reply drafting with Google Search (Gemini); also the Gmail and Calendar APIs you connect | Reply threads being drafted, prospect context |
| OpenAI, L.L.C. | Draft revision pass and outreach fallback tier (GPT-5.6) | Drafts being revised and their prompt context |
| Apollo.io (ZenLeads Inc.) | Lead search, contact and company enrichment, phone reveals, job-change detection | Search filters, names, companies, LinkedIn URLs submitted for matching |
| Resend, Inc. | Transactional email from Starlight itself (welcome, invites, notifications, booking confirmations) | Recipient name and email, message content |
| Clearout | Email address verification before a draft is sent | Recipient email addresses |
| Stripe, Inc. | Subscription billing, hosted checkout, and the billing portal | Billing name, email, payment method (card numbers never reach Starlight) |
| SerpApi, LLC | Google Maps results for Local search; Google results for Reddit threads and G2/Capterra reviews | Search queries (business types, locations, keywords); no account data |
| HarvestAPI (Aventra Technologies Limited) | LinkedIn public post search for Social listening | Keyword phrases; no account data |
| Reddit, Inc. | Reddit Data API to read the full text of public threads surfaced in Social | Thread identifiers; no account data |
| Logo.dev | Company logos shown in the app | Company domain names only |
| MapTiler AG | Map tiles for Local search and the Metrics globe, loaded by your browser | Your IP address and the map area viewed |
| OpenStreetMap Foundation (Nominatim) | City boundary outlines for Local search, fetched server-side | Place names only |
The Starlight Chrome extension acts locally in your browser to send LinkedIn and X messages and run the read-only scans you enable. Your LinkedIn and X credentials are never shared with Starlight. Every data flow is described in the Chrome Extension section of the Privacy Policy.
Legal Documents
- Privacy Policy: what we collect, why, and your rights
- Data Processing Addendum: applies to every customer automatically; countersigned copies on request
- Security: hosting, encryption, isolation, and vulnerability disclosure
- Cookie Notice and Acceptable Use Policy
Contact
For data privacy questions, contact privacy@joinstarlight.com.