Privacy Policy
How Star OS collects, uses, discloses, and protects personal information.
Last updated: July 27, 2026
This Privacy Policy explains how Star OS (Star OS, we, us, or our) collects, uses, discloses, and otherwise processes personal information when you use the Star OS website, Console, APIs, documentation, support channels, and related services (collectively, the Services), or otherwise interact with us.
This policy applies to people who use the Services directly. If you access Star OS through an organisation or a Customer Application created by one of our customers, that organisation may control the information it submits to the Services. In that situation, your organisation’s or the Customer Application provider’s privacy notice may also apply. Please contact that organisation or provider for questions about its own practices.
1. Changes to this Privacy Policy
We may update this Privacy Policy as our Services, information practices, or legal requirements change. The Last updated date shows when it was most recently revised. If we make material changes, we may provide additional notice through the Services, by email, or through another reasonable channel. We encourage you to review this policy periodically.
2. Information we collect
The information we collect depends on how you use the Services and how you interact with us. It may include the following categories.
Information you provide
When you create an account, create or join a Project, purchase credits, contact support, or otherwise interact with us, you may provide:
- account and profile details, such as your name, email address, organisation, role, and contact information;
- Project details, member and administrator information, model profile settings, and other configuration choices;
- communications with us, including support requests, feedback, survey responses, and correspondence;
- billing and transaction details, such as the Project receiving credits, amount, currency, payment status, transaction identifiers, and billing-related records; and
- any other information you choose to provide through the Services.
API and service content
When you call our APIs or use features in the Console, we process the content needed to fulfil the request. This may include prompts, messages, text, code, files, parameters, model identifiers, request metadata, generated output, and other content you submit or receive through the Services. Depending on how you use the Services, this content may contain personal information or confidential business information.
You are responsible for ensuring that you have the necessary rights, notices, consents, and other legal bases to submit this content to Star OS. Avoid sending sensitive personal information unless it is necessary for your use case and you have assessed that use in light of your legal obligations.
Information collected automatically
When you access the website or Console or call the APIs, we and service providers acting on our behalf may automatically collect technical and usage information, such as:
- IP address, approximate location derived from IP address, device identifiers, browser type, operating system, language, and network information;
- access dates and times, pages or features viewed, referring pages, interactions, and diagnostic information;
- API request and response metadata, including timestamps, endpoint, Project identifier, model identifier, token or usage measurements, status codes, latency, error information, and security events; and
- log, audit, fraud-prevention, and security information used to operate and protect the Services.
We may use cookies, local storage, and similar technologies to keep you signed in, remember preferences, protect the Services, understand service performance, and improve the website and Console. Browser controls may allow you to limit or delete certain cookies. Some features may not function correctly if you disable them.
Information from third parties
We may receive information from third parties that help us provide the Services, such as authentication providers, payment processors, fraud-prevention providers, infrastructure providers, and organisations that invite you to a Project. The information received depends on the third party and your settings, but may include account identifiers, contact details, payment confirmation, payment-method metadata, transaction status, and risk signals. We do not receive full payment card numbers when a third-party processor handles a card payment.
3. How we use information
We use personal information to:
- provide, maintain, personalise, and improve the Services;
- create and administer accounts, Projects, API keys, access controls, and model configuration;
- process purchases, apply credits to the selected Project, measure usage, issue billing records, and prevent payment fraud;
- authenticate users, protect accounts, detect and investigate security incidents, enforce rate limits, and prevent misuse;
- respond to questions, provide support, send service announcements, and communicate about your account or Projects;
- monitor performance, debug errors, develop new features, and produce aggregated or de-identified analytics;
- comply with applicable law, enforce our agreements, protect the rights and safety of Star OS and others, and respond to valid legal requests; and
- carry out another purpose disclosed to you when the information is collected or otherwise with your consent.
Where applicable law requires a legal basis for processing, we rely on one or more of the following: performing our contract with you; pursuing our legitimate interests in operating, securing, and improving the Services; complying with legal obligations; and your consent where required. You may withdraw consent when consent is the basis for processing, although this will not affect processing that occurred before withdrawal.
4. How we disclose information
We may disclose personal information in the following circumstances:
- Within a Project. Project administrators and other authorised Project members may be able to view information associated with that Project, including Project configuration, billing and usage information, and request-related information according to their access.
- Service providers. We share information with vendors and processors that provide services on our behalf, such as cloud infrastructure, model hosting or routing, authentication, payments, analytics, security, communications, monitoring, customer support, and professional services. They may process information only as needed to perform services for us and subject to appropriate contractual or legal obligations.
- Third-party models and integrations. To process a request, we may transmit the Input and associated request information to the model or technology provider selected for that request. Additional terms or privacy practices may apply to those third-party services.
- Legal, safety, and enforcement reasons. We may disclose information when we reasonably believe it is necessary to comply with law or a valid legal process; protect the rights, property, security, or safety of Star OS, our users, or others; investigate or prevent fraud, security incidents, or violations of our terms; or establish, exercise, or defend legal claims.
- Corporate transactions. We may disclose information in connection with, or during negotiations of, a merger, financing, acquisition, reorganisation, bankruptcy, sale of assets, or other corporate transaction.
- With your direction or consent. We may disclose information when you ask us to do so or otherwise consent to the disclosure.
We may also use and disclose aggregated or de-identified information that does not reasonably identify you, subject to applicable law.
5. Retention
We retain personal information for as long as reasonably necessary to provide the Services, maintain Project and billing records, meet legal, accounting, tax, and security obligations, resolve disputes, enforce agreements, and protect our business and users. Retention periods vary based on the type of information, the Project settings and activity, the purpose of processing, and applicable legal requirements.
For example, account and Project records may be kept while an account is active; transaction and billing records may be kept for statutory retention periods; and security or operational logs may be retained for a limited period appropriate to troubleshooting, fraud prevention, and platform security. When information is no longer required, we will delete it, de-identify it, or securely isolate it as required or permitted by law.
6. Security
We use administrative, technical, and organisational measures designed to protect personal information against unauthorised access, loss, misuse, alteration, and disclosure. These measures may include access controls, credential protections, logging, encryption in transit where appropriate, and security monitoring.
No internet service, transmission, or storage system is completely secure. You should use strong account credentials, limit access to Projects, protect API keys, rotate compromised keys promptly, and avoid including secrets in API requests or code that may be publicly accessible.
7. International processing
Star OS, our affiliates, service providers, and model providers may process information in countries other than the country where you live. Those countries may have data-protection laws that differ from the laws of your jurisdiction. Where required, we use appropriate safeguards for cross-border transfers, such as contractual commitments or another legally recognised transfer mechanism.
8. Your choices and privacy rights
You can update certain account and Project information through the Console. Project administrators may also manage Project access, configuration, API keys, and billing settings.
Depending on where you live and subject to applicable law, you may have rights to request access to, correction of, deletion of, restriction of, or portability of your personal information, or to object to certain processing. You may also have a right to withdraw consent where processing is based on consent. To make a request, contact Star OS through the support channel in the Console. We may need to verify your identity and authority before acting on a request. If we cannot fulfil a request, we will explain the reason where required by law.
If you receive promotional communications from us, you can opt out by following the unsubscribe instructions in those communications. We may still send non-promotional messages about your account, payments, security, Projects, or use of the Services.
9. Additional information for certain jurisdictions
People in some jurisdictions have additional rights or disclosures under local privacy laws. This section applies only to the extent those laws apply to Star OS’s processing of your personal information.
European Economic Area, United Kingdom, and Switzerland
If you are located in the EEA, UK, or Switzerland, you may have the rights described above, including access, correction, deletion, restriction, portability, and objection. You may also lodge a complaint with a supervisory authority in your place of residence, work, or the location of the alleged infringement. We encourage you to contact us first so that we can try to resolve your concern.
United States
Residents of certain US states may have rights to know, access, correct, delete, or obtain a portable copy of personal information, and to opt out of certain processing activities where applicable. You may use the support channel in the Console to submit a request or, where permitted by law, have an authorised agent submit one for you. We may ask for information to verify the request and the agent’s authority. We will not discriminate against you for exercising privacy rights provided by law.
10. Children
The Services are not directed to children and are not intended for use by people under the age of legal majority in their jurisdiction. We do not knowingly collect personal information from children in connection with the Services. If you believe a child has provided personal information to Star OS without appropriate authorisation, contact us through the support channel in the Console so that we can investigate and take appropriate action.
11. Contact us
For questions, requests, or concerns about this Privacy Policy or our privacy practices, contact Star OS through the support channel in the Console. Your use of the Services is also governed by our Terms of Service.