Sub-processors

The third parties that process personal data to run Starlight, where they are, and how we notify you of changes.

Last updated:

|

A sub-processor is a third party that processes personal data on Starlight's behalf to deliver the Service. This page is the authoritative list referenced by our Privacy Policy and incorporated as Annex 3 of our Data Processing Addendum. Every vendor here is bound by a written agreement with data-protection obligations at least as protective as the DPA, and none may use personal data to train AI models.

Info

Safeguard column: DPF means the vendor is certified under the EU-US Data Privacy Framework (and its UK and Swiss extensions); SCCs means we rely on the EU Standard Contractual Clauses with the UK Addendum; None required means the vendor receives no personal data from Europe in a form that constitutes a restricted transfer (for example, keyword queries or company domains only).

Infrastructure

Sub-processorPurposeData sharedLocationSafeguard
Vercel, Inc.Application hosting, serverless compute, cookieless analytics, and the AI Gateway that routes our model calls All application traffic, request logs, model prompts in transit United States DPF
Supabase, Inc.Authentication and the production Postgres database (AWS us-east-2) Account data and all application data at rest United States DPF

AI models

Sub-processorPurposeData sharedLocationSafeguard
Amazon Web Services, Inc. (Amazon Bedrock)Hosts the primary outreach-writing model (Moonshot AI's Kimi K2.5) in AWS US regions. Starlight pins every writer call to this host through the Vercel AI Gateway, so prompts never reach Moonshot AI's own API Prospect business context, your product and brief, cached research facts United States DPF
Meta Platforms, Inc.Judging, planning, and chat agent reasoning (Muse Spark) Prospect business context, drafts being evaluated, your instructions to the agent United States DPF
xAI Corp.Research, web and X search, query parsing, signal and social scanning (Grok) Prospect names and companies for research, search queries, public post text United States SCCs
Anthropic, PBCOutage fallback for the writer and judges (Claude) Same as the model it stands in for United States DPF
Google LLCGrounded reply drafting with Google Search (Gemini); also the Gmail and Calendar APIs you connect Reply threads being drafted, prospect context United States DPF
OpenAI, L.L.C.Draft revision pass and outreach fallback tier (GPT-5.6) Drafts being revised and their prompt context United States DPF

Lead and company data

Sub-processorPurposeData sharedLocationSafeguard
Apollo.io (ZenLeads Inc.)Lead search, contact and company enrichment, phone reveals, job-change detection Search filters, names, companies, LinkedIn URLs submitted for matching United States SCCs
Openmart, Inc.Local-business database behind Local search: business listings (name, address, phone, website, published inboxes, social links, ratings, ownership) and owner / decision-maker contact lookup for businesses you search The business category and area you search, and the website domains and names of businesses in your results; no account data United States None required

Email and verification

Sub-processorPurposeData sharedLocationSafeguard
Resend, Inc.Transactional email from Starlight itself (welcome, invites, notifications, booking confirmations) Recipient name and email, message content United States SCCs
ClearoutEmail address verification before a draft is sent Recipient email addresses India SCCs

Payments

Sub-processorPurposeData sharedLocationSafeguard
Stripe, Inc.Subscription billing, hosted checkout, and the billing portal Billing name, email, payment method (card numbers never reach Starlight) United States DPF
Sub-processorPurposeData sharedLocationSafeguard
SerpApi, LLCGoogle Maps results for Local search; Google results for Reddit threads and G2/Capterra reviews Search queries (business types, locations, keywords); no account data United States None required
HarvestAPI (Aventra Technologies Limited)LinkedIn public post search for Social listening Keyword phrases; no account data Hong Kong None required
Reddit, Inc.Reddit Data API to read the full text of public threads surfaced in Social Thread identifiers; no account data United States None required
TinyFish, Inc.Web search for Reddit threads, public LinkedIn posts, and G2/Capterra reviews in Social listening, and fetching the public pages those searches return (thread and post bodies, cited news articles) Search keyword phrases and public page URLs; no account data United States None required

Maps and media

Sub-processorPurposeData sharedLocationSafeguard
Logo.devCompany logos shown in the app Company domain names only United States None required
MapTiler AGMap tiles for Local search and the Metrics globe, loaded by your browser Your IP address and the map area viewed Switzerland None required
OpenStreetMap Foundation (Nominatim)City boundary outlines for Local search, fetched server-side Place names only United Kingdom None required

Notes

  • Amazon Web Services, Inc. (Amazon Bedrock): Bedrock does not store prompts or completions and does not use them to train models. The model weights are Moonshot AI's; Moonshot receives no data.
  • Openmart, Inc.: Receives only search terms and the public identity of businesses already in your results (name, website domain). SerpApi remains the fallback provider for Local search.
  • HarvestAPI (Aventra Technologies Limited): Receives only the keyword phrases compiled from your listening skill, never names, emails, or account data, so no personal data is transferred to it.
  • TinyFish, Inc.: Receives only the keyword phrases compiled from your listening skill and the URLs of public pages its own searches returned, never names, emails, or account data, so no personal data is transferred to it.

Services You Connect

These are your own providers. Starlight exchanges data with them only when you connect an account and only on your instruction, under your agreement with that provider. They are listed for completeness and are not sub-processors.

ServicePurposeData exchanged
Gmail and Google Calendar Send outreach, read replies to threads Starlight started, sync meetings Outreach messages, reply threads, calendar events
Microsoft Outlook and Microsoft 365 Calendar Send outreach, read replies to threads Starlight started, sync meetings Outreach messages, reply threads, calendar events
HubSpot, Salesforce, Attio Two-way contact sync with your CRM Contact and company records you choose to import or export
LinkedIn, X, Reddit (via the Chrome extension) Deliver approved messages and read your own messaging and search results in your browser Nothing is sent to these platforms by Starlight's servers; see the Chrome Extension section of the Privacy Policy

How We Notify You of Changes

  • Before a new sub-processor begins processing personal data, we update this page and email the owner of every workspace at least 15 days in advance
  • You may object on reasonable data-protection grounds within that window by emailing legal@joinstarlight.com. If we cannot resolve the objection, you may terminate the affected Service as your remedy, as set out in Section 7 of the DPA
  • Replacing a vendor with an equivalent one, or a vendor changing its own corporate name or hosting region, is announced the same way

Change Log

DateChange
September 2, 2026 Added Openmart, a local-business database that now supplies Local search results in its supported markets and looks up owner contacts for businesses in your results before Starlight falls back to web research. SerpApi remains listed and in use as the Local search fallback.
August 30, 2026 Added TinyFish, which now performs the web searches behind Social listening's Reddit and review discovery and fetches the public pages those searches return. SerpApi remains listed and in use as the fallback search provider and for Local search.
August 20, 2026 First published as a standalone list. Added Amazon Web Services (Bedrock, which hosts the Kimi K2.5 writer model), Meta Platforms, OpenAI, Resend, Clearout, SerpApi, HarvestAPI, Reddit, Logo.dev, MapTiler, and OpenStreetMap Foundation, all of which were already in use but were missing from the table in the Privacy Policy. Writer-model calls were pinned to the Bedrock host the same day; before that the Gateway could route them to Moonshot AI's own API.