Data and security

How staff access works, what is encrypted, and what is audited.

|

Running your business development means Spencer works inside your account on your behalf. That access is deliberate, visible, and revocable. Here is exactly how it works.

How we access your account

  • Only Starlight staff can open a customer account, through an internal surface protected by its own role system
  • When we open your account we act as you for sending and booking, so messages come from your mailbox and meetings land on your calendar. Every action is recorded against the staff member who took it
  • Every entry, exit, credential reveal, and sensitive action is written to an append only audit trail
  • One login per business. There are no team invites, and staff never appear as members of your company

Your credentials

  • Email and calendar connect through Google or Microsoft sign in. Starlight never sees those passwords
  • Your LinkedIn login and, once Spencer is signed in, the LinkedIn browser session are stored with the same AES-256-GCM encryption as your email tokens. Neither is ever returned to a browser except through an audited staff reveal, and revoking access from Connectors deletes both
  • Every connection can be revoked from Connectors at any time

Your data

Your targeting, messaging, prospect list, reply history, and account context stay tied to your account under the terms, privacy policy, and retention terms. If you leave, connected account authorizations are revoked and staff LinkedIn access ends as part of offboarding, and you can delete the account from Settings.

Was this page helpful?