StarryAI procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | medium | “ The personal information we collect is stored and/or processed in the United States and the European Union, or where we or our partners, affiliates, and third-party providers maintain facilities. The countries to which we store, process, or transfer your personal information may not have the same data protection laws as the country in which you initially provided the information. If we transfer your personal information to third parties in other countries: (i) we will perform those transfers in accordance with the requirements of applicable law; and (ii) we will protect the transferred personal information in accordance with this privacy policy.” | Captured 2026-06-08Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We keep your personal information only for as long as we need to. This time period may depend on what we are using your information for, in accordance with this privacy policy. For example, if you have provided us with personal information as part of creating an account with us, we may retain this information for the duration your account exists on our system. If your personal information is no longer required for this purpose, we will delete it or make it anonymous by removing all details that identify you. However, if necessary, we may retain your personal information for our compliance with a legal, accounting, or reporting obligation or for archiving purposes in the public interest, scientific, or historical research purposes or statistical purposes.” | Captured 2026-06-08Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “All third-party providers are contractually required to provide the same or equal level of protection for face data as described in this policy. 3.6 Storage of Face Data Face data is stored on secure servers located in the United States and the European Union. We apply industry-standard encryption and access controls to protect face data from unauthorized access, disclosure, or misuse. Access is restricted to personnel who require it to perform their job functions. 3.7 Retention of Face Data We retain face data only for as long as necessary to fulfill the purposes described above: Uploaded images containing faces are retained for no longer than 7 days following delivery of the generated output and are then automatically deleted, unless you have saved them to your account Raw images containing your face that are saved to your account are deleted within 30 days of processing if not actively saved by you Processed facial feature data is deleted when you remove the relevant content or close your account Upon account deletion, all face data is permanently deleted within 90 days It may take up to 90 days to fully complete the deletion process. During this time, your data will not be accessible to other users. Some copies may remain in backup storage and will be cleared in due course. We may also retain certain information where required for legal obligations or harm prevention. You may request deletion of your face data at any time by contacting us via the “Contact Us” section below.” | Captured 2026-06-08Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “Uploaded images containing biometric data are automatically deleted within 7 days of delivering the generated output, and all biometric data is permanently destroyed within 90 days of account deletion. You may request deletion of your biometric data at any time by contacting us via the “Contact Us” section below.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ third-party providers who handle face data are required to apply appropriate security measures consistent with this policy and to provide the same or equal level of protection for face data as described herein.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “AWS stores this data because it provides the underlying server infrastructure on which our application operates. AWS is contractually restricted from using the data for its own purposes. Privacy policy: https://aws.amazon.com/privacy/ Cloudflare — Used as a content delivery and performance optimization service. Cloudflare may temporarily cache generated images or processed outputs in order to securely deliver them to the user. Cached content is automatically purged according to Cloudflare’s caching policies, typically within hours to days depending on configuration. Cloudflare temporarily stores this data solely to enable secure and efficient delivery of generated content to the user. Cloudflare is contractually restricted from using the data for identification, advertising, or profiling purposes. Privacy policy: https://www.cloudflare.com/privacypolicy/ OpenAI — Used as AI infrastructure for certain AI generation features. Prompts, images, and related input data may be transmitted to OpenAI in order to generate AI outputs requested by the user. According to OpenAI’s API data usage policy, data submitted through the API is not used to train models and is retained for up to 30 days for abuse monitoring purposes before being deleted. OpenAI stores this data temporarily for the purposes of processing the request and for abuse and misuse monitoring as described in their privacy policy. Privacy policy: https://openai.com/policies/row-privacy-policy/ API data controls: https://developers.openai.com/api/docs/guides/your-data/ We do not permit any third-party processor to use face data for identification, advertising, or profiling purposes. ” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Where the disclosure of your personal information is solely subject to Australian privacy laws, you acknowledge that some third parties may not be regulated by the Privacy Act and the Australian Privacy Principles. If any such third party engages in any act or practice that contravenes the Australian Privacy Principles, it would not be accountable under the Privacy Act, and you will not be able to seek redress under the Privacy Act.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ 3.5 Third-Party Processors of Face Data and Their Privacy Practices To provide AI image generation features, certain data (including images that may contain a user’s face or derived facial feature data) may be processed by the following trusted third-party infrastructure providers. Each provider’s face data storage practices are described below: Replicate — Used to run machine learning models that generate images based on user inputs and uploaded images. Images or derived feature data may be temporarily processed by Replicate during model execution. Replicate processes images only during model execution and does not retain them after the job completes. Replicate does not store face data beyond the time required to complete the processing request. Face data is processed solely to execute the AI model and return the generated output. Replicate is contractually restricted from using the data for any other purpose. Privacy policy: https://replicate.com/privacy Data retention: https://replicate.com/docs/topics/predictions/data-retention Amazon Web Services (AWS) — Used for cloud infrastructure and secure storage required to process user requests and deliver generated images. Images uploaded by users, including images that may contain faces, are stored on servers hosted on AWS. AWS stores face data on our behalf as a cloud infrastructure provider. The data is stored for the duration necessary to process requests and deliver results, and is subject to the retention periods described in Section 3.7 below. ” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Service Providers and Business Partners: We share personal information with third-party service providers who assist us in operating our app and delivering our services. This includes IT and infrastructure providers, cloud hosting and storage providers, payment processors, analytics and attribution platforms, error tracking and monitoring tools, marketing and advertising partners, and professional advisors such as lawyers and accountants. Corporate Transactions: In the event of a merger, acquisition, asset sale, or similar transaction, your personal information may be transferred to the acquiring entity as part of that transaction. We will notify you of any such change in ownership or control of your personal information. Legal and Compliance: We may disclose your information to courts, regulatory authorities, law enforcement agencies, or other third parties where required by law, or where necessary to establish, exercise, or defend our legal rights or those of others. Affiliates and Related Entities: We may share your information with our parent company, subsidiaries, affiliates, employees, contractors, agents, and business partners where necessary to provide our services or manage our business. Promotions: If you participate in any competition, sweepstakes, or promotion we run, relevant personal information may be shared with the sponsors or promoters of that promotion. 7.1 We Do Not Sell Your Personal Information starryai, Inc. does not sell your personal information, including face data, biometric data, or any other category of personal information, to any third party for monetary or other valuable consideration. This applies to all users regardless of location.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ When you use AI image generation features in the app, the following data may be transmitted to AI infrastructure providers to process your request:” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ This data is transmitted securely and used only to generate the requested output. It is not used to identify individuals or build biometric profiles. 4.1 Disclosure and Consent Before using features that process images containing faces or other personal data, the app clearly discloses what data will be collected and transmitted, and to whom. The app requests your explicit permission before sending any such data to third-party providers. By choosing to proceed with these features, you consent to the processing of your uploaded images and related data by our AI infrastructure providers for the purpose of generating the requested results. You may decline to use these features at any time, in which case no face data or personal images will be transmitted. 4.2 Third-Party Data Protection Standards All third-party providers with whom we share personal data, including face data, are contractually required to provide the same or equal level of protection for that data as described in this privacy policy. These providers are prohibited from using the data for any purpose other than performing the services we have engaged them to provide.” | Captured 2026-06-08Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.