StarryAI
Graded against 804 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.
Watch: Privacy and data use
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
Enumerates the specific purposes for which personal information may be collected, held, used, and disclosed, and restricts further processing to purposes compatible with those listed; also permits combination of personal information with general research data from trusted sources, imposing both use-limitation restrictions and a conditional permission for data combination.
Identifies AWS as a subprocessor providing server infrastructure and contractually restricts AWS from using stored data for its own purposes; identifies Cloudflare as a subprocessor that temporarily caches generated images for delivery with automatic purging, establishing data handling restrictions and retention limits applicable to named subprocessors.
This clause obligates the company to perform international transfers of personal information in accordance with applicable law and to protect transferred data to the same standard, addressing data residency and cross-border transfer compliance requirements.
Scores derived from 19 enriched findings — same verbatim citations as below. AI-generated, not legal advice.
- Data handling is conditional — 3 privacy or retention clauses warrant review before using StarryAI at scale.
Derived from AI-enriched analysis of the verified findings below — informational only, not legal advice.
How to read this page: Overall risk rates what StarryAI's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Policy benchmark
rubric v1.0 — how this is scoredIP/output assessment pending — terms of service not yet verified This lens receives a band only once its source document has been captured and read in full.
Know where this document lives? Point us to the URL or PDF and the pipeline will verify it.
Based on 49 verified, verbatim-cited findings below — read the citations.
Automated assessment against a published rubric — not legal advice.
Partially verified — Privacy Policy — Verified (read in full, 31 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Terms not yet captured
AIRIN has not yet captured a gate-verified Terms of Service document for this platform.
- Privacy PolicyVerified - read in full - 31 citationsstaticLast captured 2026-06-08
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
This clause identifies the company as a Data Controller under GDPR and enumerates the legal bases for processing personal information, including consent, contract performance, legitimate interests, and legal compliance, establishing binding legal processing obligations.
" We, starryai, Inc., are a Data Controller with respect to the personal information you provide to us. We will only collect and use your personal information when we have a legal right to do so, on the following grounds: Consent: Where you..."
This clause establishes the company's discretionary right to modify the privacy policy and obligates it to post changes publicly, notify users of significant changes, and obtain consent or provide opt-out opportunities where required by law.
" At our discretion, we may change our privacy policy to reflect updates to our business processes, current acceptable practices, or legislative or regulatory changes. If we decide to change this privacy policy, we will post the changes here..."
Identifies AWS as a subprocessor providing server infrastructure and contractually restricts AWS from using stored data for its own purposes; identifies Cloudflare as a subprocessor that temporarily caches generated images for delivery with automatic purging, establishing data handling restrictions and retention limits applicable to named subprocessors.
"AWS stores this data because it provides the underlying server infrastructure on which our application operates. AWS is contractually restricted from using the data for its own purposes. Privacy policy: https://aws.amazon.com/privacy/ Cl..."
This clause permits the company to share personal information with named categories of third-party service providers and business partners, and allows transfer of personal information in corporate transactions such as mergers or acquisitions.
" Service Providers and Business Partners: We share personal information with third-party service providers who assist us in operating our app and delivering our services. This includes IT and infrastructure providers, cloud hosting and stor..."
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" 2.4 In-App Activity We collect information related to your activity within the app, including prompts and inputs you provide to generate images, images you create or save, credits usage and purchase history, and subscription and transaction history. This information is used to provide and improve our services and to personalize your experience. 2.5 Third-Party Authentication If you choose to sign in using a third-party service such as Sign in with Apple or Google, we may receive certain information from those providers, such as your name and email address, in accordance with your privacy settings on those platforms. 2.6 Analytics and Attribution Data We use third-party analytics and attribution tools (such as Facebook SDK and AppsFlyer) to help us understand how users interact with our app and to measure the effectiveness of our marketing. These tools may collect device identifiers, usage data, and other behavioral information. Please refer to the respective privacy policies of these third-party providers for more information on their data practices. 2.7 User-Generated Content We consider “user-generated content” to be materials (text, image, and/or video content) voluntarily supplied to us by our users for the purpose of publication on our platform, website, or re-publishing on our social media channels. All user-generated content is associated with the account or email address used to submit the materials. "
Describes collection of in-app activity data (prompts, images, credits usage, transaction history) and states the purposes for which that data is used (providing/improving services, personalization); imposes a use-limitation obligation tying data use to stated purposes. Also discloses third-party authentication data sharing with Apple and Google.
AI-generated interpretation, not legal advice.
" At our discretion, we may change our privacy policy to reflect updates to our business processes, current acceptable practices, or legislative or regulatory changes. If we decide to change this privacy policy, we will post the changes here and on our website. If the changes are significant, or if required by applicable law, we will contact you and all our registered users with the new details and links to the updated or changed policy. If required by law, we will get your permission or give you the opportunity to opt in to or opt out of, as applicable, any new uses of your personal information."
This clause establishes the company's discretionary right to modify the privacy policy and obligates it to post changes publicly, notify users of significant changes, and obtain consent or provide opt-out opportunities where required by law.
AI-generated interpretation, not legal advice.
" Please be aware that any content you submit for the purpose of publication will be public after posting (and subsequent review or vetting process). Once published, it may be accessible to third parties not covered under this privacy policy."
Disclaims responsibility for publicly submitted content once published, noting it becomes accessible to third parties not covered by the privacy policy; limits the company's privacy obligations with respect to user-submitted public content.
AI-generated interpretation, not legal advice.
" We may collect, hold, use, and disclose information for the following purposes, and personal information will not be further processed in a manner that is incompatible with these purposes: To provide you with our app and platform’s core features and services To enable you to access and use our app, associated platforms, and associated social media channels To run competitions, sweepstakes, and/or offer additional benefits to you We may combine voluntarily provided and automatically collected personal information with general information or research data we receive from other trusted sources to provide you with an enhanced experience of our app and services."
Enumerates the specific purposes for which personal information may be collected, held, used, and disclosed, and restricts further processing to purposes compatible with those listed; also permits combination of personal information with general research data from trusted sources, imposing both use-limitation restrictions and a conditional permission for data combination.
AI-generated interpretation, not legal advice.
"AWS stores this data because it provides the underlying server infrastructure on which our application operates. AWS is contractually restricted from using the data for its own purposes. Privacy policy: https://aws.amazon.com/privacy/ Cloudflare — Used as a content delivery and performance optimization service. Cloudflare may temporarily cache generated images or processed outputs in order to securely deliver them to the user. Cached content is automatically purged according to Cloudflare’s caching policies, typically within hours to days depending on configuration. Cloudflare temporarily stores this data solely to enable secure and efficient delivery of generated content to the user. Cloudflare is contractually restricted from using the data for identification, advertising, or profiling purposes. Privacy policy: https://www.cloudflare.com/privacypolicy/ OpenAI — Used as AI infrastructure for certain AI generation features. Prompts, images, and related input data may be transmitted to OpenAI in order to generate AI outputs requested by the user. According to OpenAI’s API data usage policy, data submitted through the API is not used to train models and is retained for up to 30 days for abuse monitoring purposes before being deleted. OpenAI stores this data temporarily for the purposes of processing the request and for abuse and misuse monitoring as described in their privacy policy. Privacy policy: https://openai.com/policies/row-privacy-policy/ API data controls: https://developers.openai.com/api/docs/guides/your-data/ We do not permit any third-party processor to use face data for identification, advertising, or profiling purposes. "
Identifies AWS as a subprocessor providing server infrastructure and contractually restricts AWS from using stored data for its own purposes; identifies Cloudflare as a subprocessor that temporarily caches generated images for delivery with automatic purging, establishing data handling restrictions and retention limits applicable to named subprocessors.
AI-generated interpretation, not legal advice.
" When we collect and process personal information, and while we retain this information, we will protect it within commercially acceptable means to prevent loss and theft, as well as unauthorized access, disclosure, copying, use, or modification. Although we will do our best to protect the personal information you provide to us, we advise that no method of electronic transmission or storage is 100% secure, and no one can guarantee absolute data security. You are responsible for selecting any password and its overall security strength, ensuring the security of your own information within the bounds of our services."
This clause establishes a security obligation to protect personal information within commercially acceptable means while simultaneously disclaiming absolute security guarantees, limiting the company's liability by noting that no electronic transmission or storage method is 100% secure.
AI-generated interpretation, not legal advice.
" We use cookies to provide you with the best possible experience. They also allow us to analyze user behavior in order to constantly improve the website for you."
This clause discloses the company's use of cookies for user experience optimization and behavioral analytics, establishing notice of data collection practices and the purposes for which cookies are used.
AI-generated interpretation, not legal advice.
" Our privacy policy covers the use of cookies between your device and our servers. A cookie is a small piece of data that an app may store on your device, typically containing a unique identifier that allows the app servers to recognize your device when you use the app, information about your account, session and/or device, additional data that serves the purpose of the cookie, and any self-maintenance information about the cookie itself. We use cookies to give your device access to core features of our app, to track app usage and performance on your device, to tailor your experience of our app based on your preferences, and to serve advertising to your device. Any communication of cookie data between your device and our servers occurs within a secure environment. Please refer to our Cookie Policy for more information."
This clause defines what cookies are, explains how the company uses them for app access, usage tracking, and personalization, and establishes the scope of cookie-related data collection practices as part of the privacy framework.
AI-generated interpretation, not legal advice.
" We keep your personal information only for as long as we need to. This time period may depend on what we are using your information for, in accordance with this privacy policy. For example, if you have provided us with personal information as part of creating an account with us, we may retain this information for the duration your account exists on our system. If your personal information is no longer required for this purpose, we will delete it or make it anonymous by removing all details that identify you. However, if necessary, we may retain your personal information for our compliance with a legal, accounting, or reporting obligation or for archiving purposes in the public interest, scientific, or historical research purposes or statistical purposes."
This clause obligates the company to retain personal information only as long as necessary for the stated purpose, to delete or anonymize it when no longer needed, and permits retention for compliance with legal obligations, establishing both the retention obligation and the deletion procedure.
AI-generated interpretation, not legal advice.
" Our app may link to external sites that are not operated by us. Please be aware that we have no control over the content and policies of those sites, and cannot accept responsibility or liability for their respective privacy practices."
This clause disclaims responsibility and liability for the privacy practices of externally linked third-party sites not operated by the company, limiting the company's legal exposure for external content.
AI-generated interpretation, not legal advice.
" When you use AI image generation features in the app, the following data may be transmitted to AI infrastructure providers to process your request:"
Introduces the categories of data transmitted to AI infrastructure providers when using image generation features, establishing the scope of data sharing with subprocessors.
AI-generated interpretation, not legal advice.
" 3.5 Third-Party Processors of Face Data and Their Privacy Practices To provide AI image generation features, certain data (including images that may contain a user’s face or derived facial feature data) may be processed by the following trusted third-party infrastructure providers. Each provider’s face data storage practices are described below: Replicate — Used to run machine learning models that generate images based on user inputs and uploaded images. Images or derived feature data may be temporarily processed by Replicate during model execution. Replicate processes images only during model execution and does not retain them after the job completes. Replicate does not store face data beyond the time required to complete the processing request. Face data is processed solely to execute the AI model and return the generated output. Replicate is contractually restricted from using the data for any other purpose. Privacy policy: https://replicate.com/privacy Data retention: https://replicate.com/docs/topics/predictions/data-retention Amazon Web Services (AWS) — Used for cloud infrastructure and secure storage required to process user requests and deliver generated images. Images uploaded by users, including images that may contain faces, are stored on servers hosted on AWS. AWS stores face data on our behalf as a cloud infrastructure provider. The data is stored for the duration necessary to process requests and deliver results, and is subject to the retention periods described in Section 3.7 below. "
Identifies Replicate as a named third-party processor of face data and describes its role in running machine learning models that process images during model execution, establishing the subprocessor relationship and the nature of data processing performed by that subprocessor.
AI-generated interpretation, not legal advice.
" Where the disclosure of your personal information is solely subject to Australian privacy laws, you acknowledge that some third parties may not be regulated by the Privacy Act and the Australian Privacy Principles. If any such third party engages in any act or practice that contravenes the Australian Privacy Principles, it would not be accountable under the Privacy Act, and you will not be able to seek redress under the Privacy Act."
This clause disclaims liability for third parties not regulated by Australian privacy law, limiting the company's accountability and informing users that redress under the Privacy Act may not be available for non-regulated third-party conduct.
AI-generated interpretation, not legal advice.
" This data is transmitted securely and used only to generate the requested output. It is not used to identify individuals or build biometric profiles. 4.1 Disclosure and Consent Before using features that process images containing faces or other personal data, the app clearly discloses what data will be collected and transmitted, and to whom. The app requests your explicit permission before sending any such data to third-party providers. By choosing to proceed with these features, you consent to the processing of your uploaded images and related data by our AI infrastructure providers for the purpose of generating the requested results. You may decline to use these features at any time, in which case no face data or personal images will be transmitted. 4.2 Third-Party Data Protection Standards All third-party providers with whom we share personal data, including face data, are contractually required to provide the same or equal level of protection for that data as described in this privacy policy. These providers are prohibited from using the data for any purpose other than performing the services we have engaged them to provide."
Establishes the disclosure and consent procedure for features that process face-containing images, requiring explicit user permission before transmitting data to third-party providers and specifying that proceeding constitutes consent to processing by AI infrastructure providers; also imposes a restriction that transmitted data may not be used to identify individuals or build biometric profiles.
AI-generated interpretation, not legal advice.
" Service Providers and Business Partners: We share personal information with third-party service providers who assist us in operating our app and delivering our services. This includes IT and infrastructure providers, cloud hosting and storage providers, payment processors, analytics and attribution platforms, error tracking and monitoring tools, marketing and advertising partners, and professional advisors such as lawyers and accountants. Corporate Transactions: In the event of a merger, acquisition, asset sale, or similar transaction, your personal information may be transferred to the acquiring entity as part of that transaction. We will notify you of any such change in ownership or control of your personal information. Legal and Compliance: We may disclose your information to courts, regulatory authorities, law enforcement agencies, or other third parties where required by law, or where necessary to establish, exercise, or defend our legal rights or those of others. Affiliates and Related Entities: We may share your information with our parent company, subsidiaries, affiliates, employees, contractors, agents, and business partners where necessary to provide our services or manage our business. Promotions: If you participate in any competition, sweepstakes, or promotion we run, relevant personal information may be shared with the sponsors or promoters of that promotion. 7.1 We Do Not Sell Your Personal Information starryai, Inc. does not sell your personal information, including face data, biometric data, or any other category of personal information, to any third party for monetary or other valuable consideration. This applies to all users regardless of location."
This clause permits the company to share personal information with named categories of third-party service providers and business partners, and allows transfer of personal information in corporate transactions such as mergers or acquisitions.
AI-generated interpretation, not legal advice.
" The personal information we collect is stored and/or processed in the United States and the European Union, or where we or our partners, affiliates, and third-party providers maintain facilities. The countries to which we store, process, or transfer your personal information may not have the same data protection laws as the country in which you initially provided the information. If we transfer your personal information to third parties in other countries: (i) we will perform those transfers in accordance with the requirements of applicable law; and (ii) we will protect the transferred personal information in accordance with this privacy policy."
This clause obligates the company to perform international transfers of personal information in accordance with applicable law and to protect transferred data to the same standard, addressing data residency and cross-border transfer compliance requirements.
AI-generated interpretation, not legal advice.
" We do not aim any of our products or services directly at children under the age of 13, and we do not knowingly collect personal information about children under 13."
This clause restricts the company from intentionally collecting personal information from children under the age of 13 and states that products and services are not directed at that age group.
AI-generated interpretation, not legal advice.
" We only collect and use your personal information when we have a legitimate reason for doing so. We only collect personal information that is reasonably necessary to provide our services to you. We may collect personal information from you when you do any of the following:"
Restricts personal information collection and use to circumstances where a legitimate reason exists and limits collection to what is reasonably necessary to provide services, imposing a data minimization and purpose-limitation obligation on the company.
AI-generated interpretation, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from StarryAI's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
11 verified clausesClauses in StarryAI's policies that work in your favour — commitments the platform made to you.
- Subprocessors & data sharingsale/sharing of personal data
“Service Providers and Business Partners: We share personal information with third-party service providers who assist us in operating our app and delivering our services. This includes IT and infrastructure providers, cloud hosting and storage providers, paymen…”
This clause permits the company to share personal information with named categories of third-party service providers and business partners, and allows transfer of personal information in corporate transactions such as me…
📍 § 7 (Disclosure of Personal Information to Third Parties)Jump to exact text → - Data retentiondeletion rights & post-termination survival
“All third-party providers are contractually required to provide the same or equal level of protection for face data as described in this policy. 3.6 Storage of Face Data Face data is stored on secure servers located in the United States and the European Uni…”
Imposes a contractual obligation on all third-party providers to provide the same or equal level of protection for face data as described in the policy; also states that face data is stored on secure servers in the US an…
📍 § 3.5Jump to exact text → - Privacy & data usebreach notification promises
“Your choice: By providing personal information to us, you understand we will collect, hold, use, and disclose your personal information in accordance with this privacy policy. You do not have to provide personal information to us; however, if you do not, it ma…”
This clause informs users of their choice regarding providing personal information, obligates the company to protect information received from third parties in accordance with the policy, and requires third parties provi…
- Breach notice window: comply with laws applicable to us in respect of any data breach
📍 § 13 (Your Rights and Controlling Your Personal Information)Jump to exact text → - Privacy & data use
“We, starryai, Inc., are a Data Controller with respect to the personal information you provide to us. We will only collect and use your personal information when we have a legal right to do so, on the following grounds: Consent: Where you give us consent to c…”
This clause identifies the company as a Data Controller under GDPR and enumerates the legal bases for processing personal information, including consent, contract performance, legitimate interests, and legal compliance,…
📍 § 17 (Additional Disclosures for GDPR Compliance (EU))Jump to exact text → - Moderation & enforcementterms can change anytime
“At our discretion, we may change our privacy policy to reflect updates to our business processes, current acceptable practices, or legislative or regulatory changes. If we decide to change this privacy policy, we will post the changes here and on our website.…”
This clause establishes the company's discretionary right to modify the privacy policy and obligates it to post changes publicly, notify users of significant changes, and obtain consent or provide opt-out opportunities w…
- Terms changes: advance notice promised
📍 § 15 (Changes to This Policy)Jump to exact text → - Privacy & data use
“Complaints: If you believe that we have breached a relevant data protection law and wish to make a complaint, please contact us and provide us with full details of the alleged breach. We will promptly investigate your complaint and respond to you in writing. Y…”
This clause establishes the procedure for users to file complaints about data protection breaches, obligates the company to investigate and respond in writing, and provides the procedure for unsubscribing from communicat…
📍 § 13 (Your Rights and Controlling Your Personal Information)Jump to exact text →
+ 5 more verified clauses of this kind on this platform, cited in full in the report.
📋 Rules you must follow
0 verified clausesWhat StarryAI requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in StarryAI's published policies yet.
What the policies actually cover
10 topics- Product telemetry & usage tracking2 clauses
- Advertising & tracking3 clauses
- Sale or sharing of personal data1 protective1 clause
- Sensitive data (biometric, location, health)1 protective2 clauses
- Children's data1 protective1 clause
- Government & law-enforcement disclosure1 clause
- Data shared with other AI providers3 clauses
- Terms can change at any time1 protective1 clause
- Deletion rights & post-termination survival3 protective4 clauses
- Breach-notification promises1 protective1 clause
12 further verified clauses are cited on this page but not yet assigned a topic.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause allows indefinite, perpetual, or necessity-based retention.
“Certain jurisdictions, including Illinois (under the Biometric Information Privacy Act, or BIPA), Texas (under the Capture or Use of Biometric Identifier Act, or CUBI), and Washington (under its biometric identifier law), impose specific requirements on the collection, use, and storage of biometric data. This section provides additional disclosures to comply with those requirements. When you use face-related featu...”Open source citation
The clause provides a deletion or time-bounded retention path.
“Uploaded images containing biometric data are automatically deleted within 7 days of delivering the generated output, and all biometric data is permanently destroyed within 90 days of account deletion. You may request deletion of your biometric data at any time by contacting us via the “Contact Us” section below.”Open source citation
The clause provides a deletion or time-bounded retention path.
“Under the GDPR, you have the right to: restrict processing of your personal information; object to processing based on our legitimate interests; request a portable copy of your personal information; and request deletion of your personal information. If you terminate or delete your account, we will delete your personal information within 14 days. To exercise any of these rights, please contact us using the details ...”Open source citation
The clause permits sale of personal data or information.
“Service Providers and Business Partners: We share personal information with third-party service providers who assist us in operating our app and delivering our services. This includes IT and infrastructure providers, cloud hosting and storage providers, payment processors, analytics and attribution platforms, error tracking and monitoring tools, marketing and advertising partners, and professional advisors such as...”Open source citation
The clause permits sale of personal data or information.
“Certain jurisdictions, including Illinois (under the Biometric Information Privacy Act, or BIPA), Texas (under the Capture or Use of Biometric Identifier Act, or CUBI), and Washington (under its biometric identifier law), impose specific requirements on the collection, use, and storage of biometric data. This section provides additional disclosures to comply with those requirements. When you use face-related featu...”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | audit rights dpa residency | conditional | MEDIUM | 2 |
| All applicable tiers | data retention | conditional | MEDIUM | 4 |
| All applicable tiers | privacy data use | worsens | HIGH | 3 |
| Api | training use | improves | LOW | 1 |
| Government | output ownership | worsens | HIGH | 2 |
| Government | privacy data use | worsens | HIGH | 2 |
| Team / Business | privacy data use | worsens | HIGH | 3 |
| Team / Business | subprocessors data sharing | worsens | HIGH | 2 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: sale or sell on privacy data use
“Service Providers and Business Partners: We share personal information with third-party service providers who assist us in operating our app and delivering our services. This includes IT and infrastructure providers, cloud hosting and storage providers, payment processors, analytics and attribution platforms, error tracking and monitoring tools, marketing and advertising partners, and professional advisors such as lawyers and accountants. Corporate Transactions: In the event of a merger, acquisition, asset sale, or similar transaction, your personal information may be transferred to the acquiring entity as part of that transaction. We will notify you of any such change in ownership or control of your personal information. Legal and Compliance: We may disclose your information to courts, regulatory authorities, law enforcement agencies, or other third parties where required by law, or where necessary to establish, exercise, or defend our legal rights or those of others. Affiliates and Related Entities: We may share your information with our parent company, subsidiaries, affiliates, employees, contractors, agents, and business partners where necessary to provide our services or manage our business. Promotions: If you participate in any competition, sweepstakes, or promotion we run, relevant personal information may be shared with the sponsors or promoters of that promotion. 7.1 We Do Not Sell Your Personal Information starryai, Inc. does not sell your personal information, including face data, biometric data, or any other category of personal information, to any third party for monetary or other valuable consideration. This applies to all users regardless of location.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“Service Providers and Business Partners: We share personal information with third-party service providers who assist us in operating our app and delivering our services. This includes IT and infrastructure providers, cloud hosting and storage providers, payment processors, analytics and attribution platforms, error tracking and monitoring tools, marketing and advertising partners, and professional advisors such as lawyers and accountants. Corporate Transactions: In the event of a merger, acquisition, asset sale, or similar transaction, your personal information may be transferred to the acquiring entity as part of that transaction. We will notify you of any such change in ownership or control of your personal information. Legal and Compliance: We may disclose your information to courts, regulatory authorities, law enforcement agencies, or other third parties where required by law, or where necessary to establish, exercise, or defend our legal rights or those of others. Affiliates and Related Entities: We may share your information with our parent company, subsidiaries, affiliates, employees, contractors, agents, and business partners where necessary to provide our services or manage our business. Promotions: If you participate in any competition, sweepstakes, or promotion we run, relevant personal information may be shared with the sponsors or promoters of that promotion. 7.1 We Do Not Sell Your Personal Information starryai, Inc. does not sell your personal information, including face data, biometric data, or any other category of personal information, to any third party for monetary or other valuable consideration. This applies to all users regardless of location.”Open timeline citation
Latest stance: third party or vendor sharing on audit rights dpa residency
“The personal information we collect is stored and/or processed in the United States and the European Union, or where we or our partners, affiliates, and third-party providers maintain facilities. The countries to which we store, process, or transfer your personal information may not have the same data protection laws as the country in which you initially provided the information. If we transfer your personal information to third parties in other countries: (i) we will perform those transfers in accordance with the requirements of applicable law; and (ii) we will protect the transferred personal information in accordance with this privacy policy.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“The personal information we collect is stored and/or processed in the United States and the European Union, or where we or our partners, affiliates, and third-party providers maintain facilities. The countries to which we store, process, or transfer your personal information may not have the same data protection laws as the country in which you initially provided the information. If we transfer your personal information to third parties in other countries: (i) we will perform those transfers in accordance with the requirements of applicable law; and (ii) we will protect the transferred personal information in accordance with this privacy policy.”Open timeline citation
Latest stance: sale or sell on privacy data use
“Certain jurisdictions, including Illinois (under the Biometric Information Privacy Act, or BIPA), Texas (under the Capture or Use of Biometric Identifier Act, or CUBI), and Washington (under its biometric identifier law), impose specific requirements on the collection, use, and storage of biometric data. This section provides additional disclosures to comply with those requirements. When you use face-related features in the app, we may collect biometric identifiers and biometric information, including facial geometry and landmark data derived from images you upload. We collect this data solely to provide AI-powered image generation features, as described in Section 3 of this policy. We will not collect, capture, or otherwise obtain your biometric data without first providing you with written notice (including through this policy and in-app disclosures) and obtaining your informed, affirmative consent. By choosing to use face-related features in the app after being presented with these disclosures, you consent to our collection and use of your biometric data as described in this policy. We do not sell, lease, trade, or otherwise profit from your biometric data. Biometric data may be disclosed only to third-party service providers who process it on our behalf to deliver the requested functionality, as described in Section 3.5, and who are contractually required to protect it in accordance with this policy. Biometric data is retained only for as long as necessary to fulfill the purposes for which it was collected, as described in Section 3.7.”Open timeline citation
Latest stance: sale or sell on data retention
“Certain jurisdictions, including Illinois (under the Biometric Information Privacy Act, or BIPA), Texas (under the Capture or Use of Biometric Identifier Act, or CUBI), and Washington (under its biometric identifier law), impose specific requirements on the collection, use, and storage of biometric data. This section provides additional disclosures to comply with those requirements. When you use face-related features in the app, we may collect biometric identifiers and biometric information, including facial geometry and landmark data derived from images you upload. We collect this data solely to provide AI-powered image generation features, as described in Section 3 of this policy. We will not collect, capture, or otherwise obtain your biometric data without first providing you with written notice (including through this policy and in-app disclosures) and obtaining your informed, affirmative consent. By choosing to use face-related features in the app after being presented with these disclosures, you consent to our collection and use of your biometric data as described in this policy. We do not sell, lease, trade, or otherwise profit from your biometric data. Biometric data may be disclosed only to third-party service providers who process it on our behalf to deliver the requested functionality, as described in Section 3.5, and who are contractually required to protect it in accordance with this policy. Biometric data is retained only for as long as necessary to fulfill the purposes for which it was collected, as described in Section 3.7.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“In the past 12 months, we have collected the following categories of personal information under the California Consumer Privacy Act (CCPA): Identifiers, such as name, email address, phone number, account name, IP address, and an ID or number assigned to your account Audio or visual data, such as photos or videos you share with us or post on the service Biometric data, such as facial geometry derived from images you submit when using face-related features of the app If you are a California resident, you have the right to request details about the categories and specific pieces of personal information we have collected, the sources and purposes of collection, the categories of third parties we have shared it with, and whether it was sold or disclosed for a business purpose. You also have the right to request deletion of your personal information. To exercise these rights, please contact us using the details below. We do not respond to browser “Do Not Track” signals at this time. We may offer financial incentives permitted by the CCPA that can result in different prices, rates, or quality levels for our services. Any such incentive will reasonably relate to the value of your personal information and requires your prior opt-in consent, which you may revoke at any time. If you are a California resident, you also have the right under California’s “Shine the Light” law to request information regarding the manner in which we share certain personal information with third parties for their direct marketing purposes. To make such a request, please include “California Privacy Rights Request” in the first line of your message along with your name and mailing address.”Open timeline citation
Latest stance: sale or sell on output ownership
“Processed facial feature data generated by our systems for the purpose of image generation 3.2 How We Use Face Data We use your face data solely for the following purposes: To enable AI-powered image generation features that incorporate or are based on your likeness To improve the accuracy and quality of our image generation models We do not use face data to identify you by name in public, to track your movements, or for any advertising or marketing profiling purposes. 3.3 Reasons for Storing Face Data We store face data for the following reasons: To process your AI image generation requests, which requires temporary storage of your uploaded images and derived facial feature data during and after model execution To deliver the generated output to you and allow you to access your results within the app To allow you to re-use previously uploaded face data for additional image generation requests without needing to re-upload, improving your experience and reducing processing time To maintain the integrity of your saved content and account data for as long as your account is active To comply with legal obligations that may require retention of certain records 3.4 Sharing of Face Data with Third Parties We do not sell your face data. Face data may be disclosed to third parties only in the following limited circumstances: To third-party service providers who process data on our behalf (such as cloud computing, storage, and AI model execution providers) and who are contractually prohibited from using it for any other purpose To comply with a legal obligation, court order, or lawful government request In the event of a merger, acquisition, or sale of substantially all of our assets, as described in the “Business Transfers” section of this policy All”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-06-08· verified 2026-06-08verified once — no re-scan in 94 days
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
↑ 22 more findings this quarter vs last (60 vs 38). First scan: June 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of StarryAI's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified StarryAI's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from StarryAI's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.