Privacy Policy
How Starlight collects, uses, stores, and protects personal data for customers, the people they contact, and visitors.
Last updated:
Info
1. Who We Are and What This Policy Covers
Starlight Software LLC, a California limited liability company ("Starlight", "we", "us", or "our"), operates the Starlight platform at joinstarlight.com, the Starlight Chrome extension, and public booking pages under joinstarlight.com/book (together, the "Service"). This Privacy Policy explains how we collect, use, share, and protect personal information.
It covers three groups of people:
- Customers and users: people who sign up for Starlight, their teammates, and visitors to our website. For this group Starlight is the controller (the "business" under US state laws)
- People our customers contact: prospects and leads whose business contact details are researched, enriched, or messaged through the Service; people whose public posts appear in Social; people in networks our customers import; and invitees who book meetings through a customer's booking page. For this group the customer is the controller and Starlight is a processor ("service provider") acting on the customer's instructions under our Data Processing Addendum
- Visitors: anyone reading our website or docs without an account
Where we act as a processor, the customer who contacted you decides why and how your data is used; this policy describes what we do with it on their behalf and the choices you have with us directly.
2. Personal Information We Collect
From customers and users
- Account data: name, email address, and profile photo from Google sign-in or the email magic link; company name, website, and the product and ideal-customer description you provide or we generate from your website during onboarding
- Billing data: plan, block usage, and invoices. Payment details are collected and stored by Stripe on its hosted pages; card numbers never reach Starlight
- Content you create: search queries, briefs, outreach drafts and edits, signatures, notes, Agent configurations, chat messages to the assistant, and meeting notes
- Integration data: when you connect Gmail or Outlook we access only threads that Starlight started plus replies to them, never your wider inbox; when you connect a calendar we read event details to show meetings and prepare notes; when you connect HubSpot, Salesforce, or Attio we sync the contact and company records you choose
- Imported network data: if you use Your Network, the connection exports you upload from LinkedIn, Google, Instagram, or X (names, profile URLs, emails where present). Only import lists you are permitted to share
- Extension data: described in full in Section 16
- MCP and OAuth clients: the client name, the scopes you approve, and a log of tool calls made by AI assistants you connect
- Referral data: your referral code, and the email addresses and sign-up status of people who sign up with it
- Technical data: IP address, browser and device type, operating system, referrer URL, and request logs collected by our hosting provider; aggregated, cookieless page analytics
- Communications: support emails, feedback you submit in the docs, and your response to in-app surveys
About people our customers contact
- Business contact and professional data: name, job title, employer, work email, business phone number (revealed only on request), LinkedIn URL, location, employment history, and company firmographics. Sourced from Apollo.io and other B2B data providers, the prospect's public LinkedIn or X profile, the customer's CRM, or the customer's imported network
- Research facts: publicly available information about a person or company gathered by AI web search to personalize outreach, cached for 72 hours
- Public posts: the text, author, URL, and engagement counts of public posts on X, Reddit, LinkedIn, and review sites that match a customer's listening criteria, and the author's public profile when it can be matched to a business contact record
- Buying signals: funding rounds, hiring, job changes, and news about companies and the people who work there, from Apollo.io and web search
- Engagement data: delivery status, opens, clicks, replies, and LinkedIn connection acceptances for messages sent through the Service
- Booking data: the name, email, timezone, and answers an invitee enters on a customer's public booking page, and the resulting meeting details
Data about others
Several features let customers provide information about other people: importing a network, syncing a CRM, adding contacts, or inviting teammates. Customers must have the right to share that information with us, and may only use it as described in our Acceptable Use Policy.
3. How We Use Personal Information
For people in the EEA, UK, and Switzerland, the table also states the legal basis we rely on under the GDPR and UK GDPR. Where we act as a processor, the legal basis is the customer's and is documented in the DPA.
| Purpose | Examples | Legal basis |
|---|---|---|
| Provide the Service | Lead search, drafting, sending, scheduling, inbox sync, Agents, MCP access | Contract (Art. 6(1)(b)) |
| Billing and account administration | Subscriptions, block accounting, invoices, tax records | Contract; legal obligation (Art. 6(1)(c)) |
| Service communications | Verification emails, booking confirmations, notifications, security alerts | Contract |
| Security and abuse prevention | Rate limiting, suppression lists, detecting misuse, enforcing the AUP | Legitimate interests: keeping the Service and recipients safe |
| Improve the Service | Aggregate usage analysis, draft-quality scoring, debugging with logs | Legitimate interests: building a better product |
| Personalize outreach on a customer's behalf | Research, signals, social listening, AI drafting about prospects | Processor acting on customer instructions; the customer's legitimate interest in B2B outreach |
| Referrals and promotions | Attributing sign-ups, granting bonus blocks | Contract; legitimate interests |
| Legal compliance and claims | Responding to lawful requests, defending claims, honoring opt-outs | Legal obligation; legitimate interests |
We do not use personal information for targeted advertising, and we do not make decisions with legal or similarly significant effects about anyone by solely automated means.
4. AI and Automated Processing
Starlight uses third-party AI models to write drafts, judge draft quality, score lead fit, plan searches, research prospects, summarize meetings, and power the chat assistant and Agents. Different models handle different jobs; the providers and their roles are listed on the Sub-processors page. When AI features run:
- The relevant prospect context, your product description, and your instructions are sent to the model provider for that call, through the Vercel AI Gateway or directly to the provider
- We do not train models on your data, and our provider agreements do not permit providers to train on it. Where a provider offers zero-data-retention terms, we enable them
- Models may run web searches to gather publicly available information about a prospect or company; results are cached briefly and then discarded
- Content from prospects and public posts is passed to models as untrusted data, never as instructions
- AI-generated scores and recommendations are advisory. A person reviews drafts before they are sent unless a customer has deliberately enabled an autopilot setting, which only ever sends drafts the AI judged as ready and within caps the customer controls
5. How We Share Personal Information
We do not sell personal information and we do not share it for cross-context behavioral advertising. We share it only as follows.
Sub-processors
Vendors that process data on our behalf to run the Service. The full list, with locations, transfer safeguards, and a change log, is maintained on the Sub-processors page, which is the authoritative version of the summary below.
| Service | Purpose | Location |
|---|---|---|
| Vercel, Inc. | Application hosting, serverless compute, cookieless analytics, and the AI Gateway that routes our model calls | United States |
| Supabase, Inc. | Authentication and the production Postgres database (AWS us-east-2) | United States |
| Amazon Web Services, Inc. (Amazon Bedrock) | Hosts the primary outreach-writing model (Moonshot AI's Kimi K2.5) in AWS US regions. Starlight pins every writer call to this host through the Vercel AI Gateway, so prompts never reach Moonshot AI's own API | United States |
| Meta Platforms, Inc. | Judging, planning, and chat agent reasoning (Muse Spark) | United States |
| xAI Corp. | Research, web and X search, query parsing, signal and social scanning (Grok) | United States |
| Anthropic, PBC | Outage fallback for the writer and judges (Claude) | United States |
| Google LLC | Grounded reply drafting with Google Search (Gemini); also the Gmail and Calendar APIs you connect | United States |
| OpenAI, L.L.C. | Draft revision pass and outreach fallback tier (GPT-5.6) | United States |
| Apollo.io (ZenLeads Inc.) | Lead search, contact and company enrichment, phone reveals, job-change detection | United States |
| Resend, Inc. | Transactional email from Starlight itself (welcome, invites, notifications, booking confirmations) | United States |
| Clearout | Email address verification before a draft is sent | India |
| Stripe, Inc. | Subscription billing, hosted checkout, and the billing portal | United States |
| SerpApi, LLC | Google Maps results for Local search; Google results for Reddit threads and G2/Capterra reviews | United States |
| HarvestAPI (Aventra Technologies Limited) | LinkedIn public post search for Social listening | Hong Kong |
| Reddit, Inc. | Reddit Data API to read the full text of public threads surfaced in Social | United States |
| Logo.dev | Company logos shown in the app | United States |
| MapTiler AG | Map tiles for Local search and the Metrics globe, loaded by your browser | Switzerland |
| OpenStreetMap Foundation (Nominatim) | City boundary outlines for Local search, fetched server-side | United Kingdom |
Services you connect
When you connect your own accounts, we exchange data with those providers on your instruction, under your agreement with them:
| Service | Purpose | Data exchanged |
|---|---|---|
| Gmail and Google Calendar | Send outreach, read replies to threads Starlight started, sync meetings | Outreach messages, reply threads, calendar events |
| Microsoft Outlook and Microsoft 365 Calendar | Send outreach, read replies to threads Starlight started, sync meetings | Outreach messages, reply threads, calendar events |
| HubSpot, Salesforce, Attio | Two-way contact sync with your CRM | Contact and company records you choose to import or export |
| LinkedIn, X, Reddit (via the Chrome extension) | Deliver approved messages and read your own messaging and search results in your browser | Nothing is sent to these platforms by Starlight's servers; see the Chrome Extension section of the Privacy Policy |
Other recipients
- Your team: teammates in your Starlight company can see the workspace's contacts, drafts, and activity
- AI clients you authorize: MCP and OAuth clients you connect receive the data their tool calls return
- Recipients of your messages: the content you send, your name, signature, and booking links
- Professional advisors: lawyers, accountants, and insurers, under confidentiality
- Authorities: where we believe in good faith that disclosure is required by law or necessary to protect rights, safety, or property
- Business transferees: in connection with a merger, acquisition, financing, or sale of assets, with notice to you where required
6. Data Retention
We keep personal information for as long as needed for the purposes above, then delete or anonymize it. The criteria are the nature and sensitivity of the data, the purpose it serves, and our legal obligations. Current retention periods:
| Data | Retained |
|---|---|
| Account and workspace data | Life of the account; deleted when you delete the account |
| Prospect, lead, and contact records | Life of the customer's account, or until a verified deletion request from the person concerned |
| Outreach drafts, sent messages, replies | Life of the account |
| AI research cache | 72 hours |
| Connected-account tokens (email, calendar, CRM) | Until you disconnect the integration or delete the account; encrypted at rest |
| Extension tokens | Until revoked from Connectors or the account is deleted |
| Suppression (unsubscribe) list | Indefinitely, so an opted-out address is never contacted again |
| Billing records | As required by tax and accounting law, typically 7 years |
| Hosting and request logs | Per our hosting providers' standard retention, typically 30 days or less |
| Backups | Rolling backups kept by our database provider are overwritten within its standard window; deleted data ages out of them |
7. Security and Incident Notification
We use technical and organizational measures designed to protect personal information: TLS for all data in transit, encryption at rest, AES-256-GCM encryption for integration tokens, passwordless authentication, per-workspace isolation enforced by database row-level security, least-privilege access, and a vulnerability disclosure program. Details are on the Security page. No system is perfectly secure, and we cannot guarantee the security of your information.
If a personal data breach occurs, we will notify affected customers without undue delay and, where we are the controller and the law requires it, the relevant supervisory authority within 72 hours of becoming aware, in accordance with GDPR Article 33 and applicable US state breach-notification laws. Where we are a processor, we notify the customer so they can meet their own obligations.
8. International Data Transfers
Starlight is based in the United States and our production infrastructure is hosted there. If you use the Service from the EEA, UK, or Switzerland, your personal information is transferred to and processed in the United States, which does not have an adequacy decision from the European Commission. For those transfers we rely on the European Commission's Standard Contractual Clauses (2021/914), the UK International Data Transfer Addendum, and the Swiss variations, as set out in our DPA. Several of our sub-processors are also certified under the EU-US Data Privacy Framework; the Sub-processors page shows which. You can ask us for a copy of the safeguards in place by emailing privacy@joinstarlight.com.
9. Your Choices and Rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you and learn how it is used
- Correct inaccurate information
- Delete your information (account deletion is in Settings, and removes all workspace data, messages, and integration tokens)
- Export your data in a portable format (contacts and messages export from the app)
- Object to processing based on legitimate interests, including direct marketing, and restrict processing while a dispute is resolved
- Withdraw consent where processing is based on consent, without affecting prior processing
- Opt out of marketing: use the unsubscribe link in any marketing email; service emails continue while you have an account
- Revoke any connected integration, extension token, or MCP client at any time from Connectors and Settings
- Appeal a decision we make on your request, and complain to your data protection authority
How to exercise them
Email privacy@joinstarlight.com. To protect your data we verify requests: if you have an account, write from the account's email address or from inside the app; if you were contacted by a customer, write from the address that was contacted, or tell us which address it was. An authorized agent may submit a request on your behalf with written permission from you, and we may confirm the request with you directly. We respond within 30 days (45 days where state law allows and we tell you why), free of charge unless requests are manifestly excessive. We never discriminate against you for exercising your rights.
Do Not Track and Global Privacy Control
We do not sell or share personal information or serve targeted advertising, so there is nothing for a Do Not Track or Global Privacy Control signal to opt you out of. We treat every visitor as opted out of those activities already.
10. Information for People Our Customers Contact
If you received a message from a company using Starlight, that company chose to contact you and is the controller of your information for that campaign. This section is our notice to you under GDPR Article 14 and similar laws.
- Where your data came from: a B2B data provider (most often Apollo.io), your public LinkedIn or X profile, a public post you made, the customer's CRM, or a network the customer imported. We process business contact details and professional information, not sensitive data
- Why: the customer believed you might be interested in their product based on your role and company. AI wrote the draft; a person at the customer approved it, or the customer chose to let approved drafts send automatically
- How to stop it: reply to the sender, use the unsubscribe link where the message includes one, or email privacy@joinstarlight.com. We add your address to a permanent suppression list checked before every send by every customer, and we delete your contact record on a verified request
- Your rights: everything in Section 9 applies to you. You can also contact the customer directly; they are responsible for responding about their own use
11. Cookies and Similar Technologies
We use strictly necessary cookies to keep you signed in, and cookieless analytics to understand aggregate website usage. We do not use advertising or cross-site tracking cookies. The Cookie Notice lists every cookie and storage key and explains how to manage them, including the consent banner and the Cookie preferences link in the footer of every public page.
12. Children
The Service is for business use by adults. It is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact privacy@joinstarlight.com and we will delete it.
13. State Privacy Rights Notice
This section applies to residents of California, Colorado, Connecticut, Virginia, Texas, Oregon, Utah, Montana, and other US states with comprehensive privacy laws, to the extent those laws apply to us. It supplements the rest of this policy.
Categories of personal information
In the 12 months before the date of this policy we collected the following categories, from the sources and for the purposes described in Sections 2 and 3:
| Category (Cal. Civ. Code § 1798.140) | Examples | Disclosed to |
|---|---|---|
| Identifiers | Name, email, IP address, account ID, LinkedIn URL | Sub-processors; services you connect |
| Professional or employment information | Job title, employer, employment history | Sub-processors; services you connect |
| Commercial information | Plan, block usage, invoices | Stripe; our hosting providers |
| Internet or network activity | Pages viewed, feature usage, request logs | Our hosting providers |
| Communications | Drafts, messages, replies, notes, support emails | Sub-processors; recipients you message |
| Inferences | AI lead-fit scores and draft-quality scores | AI model providers |
We have not sold or shared personal information in the preceding 12 months, and we do not sell or share it. We do not collect or process sensitive personal information to infer characteristics about you. We do not use or disclose personal information for targeted advertising or for profiling with legal or similarly significant effects.
Your rights
You may request to know, access, correct, delete, and obtain a portable copy of your personal information, and to appeal a denial, as described in Section 9, at privacy@joinstarlight.com. Because we do not sell, share, or use personal information for targeted advertising, there is no opt-out to exercise and Global Privacy Control signals are honored by default.
Additional state notices
- California Shine the Light (Civil Code § 1798.83): we do not disclose personal information to third parties for their own direct marketing
- Nevada: we do not sell covered information as defined in NRS 603A. To record an opt-out request anyway, email privacy@joinstarlight.com
- Texas: we do not sell sensitive personal data
- De-identified data: where we create de-identified data, we maintain it as de-identified and do not attempt to re-identify it except to test our de-identification
14. Notice to European Users
This section applies to people in the European Economic Area, the United Kingdom, and Switzerland ("Europe"). "Personal information" in this policy means "personal data" as defined in the GDPR.
- Controller: Starlight Software LLC is the controller for customer, user, and visitor data. For data about people our customers contact, the customer is the controller and Starlight is their processor under the DPA
- Representative and DPO: Starlight has no establishment in Europe and has not appointed a representative under GDPR Article 27 or a Data Protection Officer. Contact privacy@joinstarlight.com for all matters
- Legal bases: set out in the table in Section 3. Where we rely on legitimate interests, we have balanced them against your rights; you may object at any time
- Retention: Section 6
- Transfers outside Europe: Section 8
- Your rights: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent, as described in Section 9
- Complaints: you may lodge a complaint with the supervisory authority where you live or work. EEA authorities are listed at edpb.europa.eu. In the UK, the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, +44 303 123 1113, ico.org.uk. In Switzerland, the Federal Data Protection and Information Commissioner, edoeb.admin.ch
- Sensitive data: please do not send us special-category data (health, biometrics, political opinions, and so on). The Service does not need it and our customers agree in the DPA not to submit it
- Automated decision-making: we do not make decisions about you based solely on automated processing that produce legal or similarly significant effects
15. Google API Services and Microsoft Graph
Starlight's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We only access Gmail and Google Calendar data that is necessary to provide the features you have connected, and we do not use Google user data to train generalized AI or machine learning models.
Our use of data obtained from Microsoft Graph (Outlook and Microsoft 365 Calendar) is likewise limited to providing the features you have connected. We do not transfer, sell, or use Microsoft Graph data for advertising, and we do not use it to train generalized AI models.
16. Chrome Extension
The Starlight Chrome extension is a first-party browser extension, published on the Chrome Web Store, that bridges Starlight with LinkedIn, X, and (optionally) Reddit. It is optional; Starlight works without it. This section describes every data flow it takes part in, as of extension version 1.7.
What the extension stores locally
- Bearer token, issued when you sign in, in
chrome.storage.local. It authenticates the extension to joinstarlight.com. Revoke it any time from Connectors in your dashboard - In-flight dispatch metadata (recipient URL, channel, draft body) in
chrome.storage.session, keyed by tab, while a send is in progress. Cleared when the tab closes or the send reports - Autopilot preference and the day's send count in
chrome.storage.local - Scan run state in
chrome.storage.sessionwhile a background scan task is running, so an interrupted run can be recovered - Learned element selectors in
chrome.storage.local, so the extension keeps working when LinkedIn changes its page markup
What the extension sends to Starlight
- Send-status callbacks: after a draft is sent, the draft ID and outcome (sent, failed, aborted), plus the recipient's LinkedIn member ID read from the conversation so later replies can be matched exactly
- Autopilot poll: while Autopilot is on, a request roughly every 90 seconds for the next draft you have approved. No page data is sent in this request
- Quick Sync: when you run a sync from the Inbox, the extension opens your LinkedIn messaging page in a background tab, opens recent inbound conversations, and sends Starlight the sender's name, profile identifier, last message, and timestamp so replies from people you contacted through Starlight appear in your Inbox. It also records which connection requests were accepted
- Social scan results: when extension-powered scans are on (Social settings, on by default), Starlight queues search tasks for your listening topics. The extension opens your own logged-in LinkedIn content search or X search in a background tab, reads the visible public posts (text, author, profile URL, engagement counts), and sends them to Starlight. It reads only; it never posts, likes, follows, or connects during a scan
- Engagement mining: for competitor watches you enable, the extension opens the competitor's public LinkedIn company page, reads who reacted to its recent posts (name, headline, profile URL), and sends that list to Starlight as prospecting data
- Reddit thread text: if you grant the optional reddit.com permission from the extension's options page, the extension fetches the public text of Reddit threads surfaced in Social from your browser and sends it to Starlight so suggested comments answer the real post
- Selector healing telemetry: when a LinkedIn element cannot be found, the extension sends Starlight a structural snapshot of the page (element roles and labels, no message bodies) so Starlight, sometimes with help from an AI model, can identify the right element. Successful fixes are shared with other users so one person's fix heals everyone
Autopilot
Autopilot is on by defaultand can be turned off from the extension popup at any time. While it is on, the extension delivers drafts you have already approved inside Starlight, one at a time, by opening the recipient's conversation and clicking Send on your behalf, capped at 25 sends per day. It only ever sends drafts that exist because you, your teammate, or an autopilot setting you enabled approved them. With Autopilot off, the extension prefills the composer and waits for you to press Send yourself. Before any automated click, the extension verifies that it is in the right conversation and that the approved text is in the box; if either check fails, it aborts and reports a failure rather than sending.
Background activity
Two things run without you being on a page: the Autopilot poll (while Autopilot is on) and the social scan heartbeat, which checks for queued scan tasks every few minutes and runs at most a handful of read-only scans per day (while extension-powered scans are on). Both stop when you sign out, revoke the token, or turn the feature off. Nothing else runs in the background.
What the extension never does
- Post, comment, like, follow, or connect on your behalf except to deliver a specific draft or comment you approved in Starlight
- Read your personal messages, feed, or profile beyond the surfaces listed above
- Send data to anyone other than joinstarlight.com. All extension traffic flows between your browser and Starlight
- Store or transmit your LinkedIn, X, or Reddit passwords or session cookies
Permissions and host access
- Chrome permissions:
storage(token, preferences, learned selectors),alarms(the Autopilot poll and scan heartbeat),activeTabandscripting(to run the content script in the tab it opens for a send or scan) - Host access:
*.linkedin.com,*.x.com,*.twitter.com, andjoinstarlight.com.*.reddit.comis optional and only granted if you choose to from the options page
Disconnecting the extension
Revoke the extension token from Connectors in your Starlight dashboard, or uninstall the extension from chrome://extensions, which also removes everything it stored locally. After revocation the extension cannot communicate with your account until you sign in again.
LinkedIn, X, and Reddit
LinkedIn, X, and Reddit are not sub-processors: Starlight's servers never log into them and never send them your data. The extension acts in your own browser, under your own account. Your use of those platforms is governed by their terms and privacy policies, and you are responsible for making sure your use of the extension, including Autopilot and scans, complies with them.
17. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes we will notify users by email or in-app notification before they take effect. The "Last updated" date at the top of this page shows the current version; previous versions are available on request.
18. Contact
Privacy questions and requests: privacy@joinstarlight.com. Legal notices: legal@joinstarlight.com. We aim to acknowledge every privacy request within 5 business days and resolve it within 30 days.