Your organizational memory isn’t stored with us. It lives in your own Notion workspace.
Your organizational memory isn’t stored with us. It lives in your own Notion workspace, which you control and can disconnect at any time.
We do hold things derived from it — an index of what your memory contains, your chat history, the documents we generate for you, and excerpts of what you upload. Each of these is described specifically below. All of it can be regenerated from your Notion, none of it is authoritative, and we delete it when you delete your organization.
We don’t train AI models on your knowledge. We don’t sell your data. We don’t run ads.
Most privacy policies begin with what a company collects. Ours begins with what we don’t collect, because that is what makes the Platform unusual.
Your organizational memory lives in your Notion workspace, not on our servers. When you connect Notion, you authorize Starling to read from and write to a workspace you own. Your Persistent, Active, and Learning memory — the substance of what your organization knows — is stored there, as plain-text markdown, under your control.
What we hold is derived from it. To serve a session quickly we keep an index of what your library contains, your chat history, your usage records, the documents Starling generates for you, and excerpts of the source material you upload. These are working copies used to operate the Platform.
None of what we hold is authoritative. The index is a fast-access copy, built by scanning your Notion workspace: it holds structural information about your library together with content cached from it — summaries, keywords, section titles, and document text — so a session loads in milliseconds instead of minutes. Because it is built by scanning your workspace, it can be rebuilt the same way. If everything we hold were deleted, nothing of substance would be lost, because it can be regenerated from your Notion. If you delete your Notion workspace, your organizational memory is gone, because that is where it is stored.
That division — your authoritative memory in your own Notion, and a regenerable working copy on our systems — is how the Platform is built, and it is why the deletion section below is short.
Account information. Your name, email address, and organization name, provided by you at signup.
Connection data. An OAuth token authorizing Starling to access the Notion workspace you designate. You can revoke it in Notion at any time, which immediately ends our access.
Derived and operational data:
User Library data. Personal working notes you create in your own User Library are isolated and are never loaded into another user’s session — not your System Librarian’s, not an Owner’s. This is enforced architecturally, not by policy.
Payment information. Processed by Stripe. We receive confirmation of payment and the last four digits of your card. We never see or store your full card details.
Technical data. IP address, browser type, device information, and server logs — standard, and used for security and debugging.
Voice input. If you use realtime voice, your audio streams directly from your browser to OpenAI for transcription. We don’t store the audio; we retain only usage information for billing.
We use aggregated, anonymized usage data to understand how the Platform performs. It can’t identify you or your organization.
We do not use your content for advertising, profiling, or resale.
When you work in Starling, your prompts and the context assembled for them are sent to a third-party AI provider — Anthropic (Claude) as the primary provider, OpenAI as the automatic fallback for text generation and the provider for realtime voice, or Google (Gemini) for the “Analyze with Gemini” feature, depending on the model selected for your organization.
If you use realtime voice, your audio streams directly from your browser to OpenAI for transcription; we don’t store the audio.
These providers process your content under their commercial and API terms, which do not permit them to train their models on it. A provider may retain inputs for a limited period for abuse monitoring, but does not use them for training. This is different from consumer chatbot products, where training on your conversations may be the default.
We choose the model per task. You can see and change your organization’s model selection in the Platform.
Your memory in Notion is retained by Notion under your control, on your terms with them. We don’t set its retention, because we don’t hold it.
Deleting your account does not affect your memory. It remains in your Notion workspace, in plain-text markdown. There is nothing to export from us, because we never held the authoritative copy. If you revoke our access in Notion, our access to your workspace ends immediately.
Deletion on our systems is immediate. When you delete your organization, we permanently delete your account and organization records, sessions and chat history, the memory index, derived documents, uploaded source material, usage and billing records, and our event and audit logs. Deletion cannot be undone. We retain only limited records that the law or our service providers require us to keep — for example, payment and invoice records held by our payment processor, and security and system logs — and only for as long as those purposes require.
We may keep anonymized aggregate statistics that can’t identify you.
To delete your organization, use Settings in the Platform; to delete an individual account, email support@starlingmx.com.
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, or to object to or opt out of certain processing. To exercise any of these, email support@starlingmx.com; we’ll respond within 45 days and won’t discriminate against you for asking. If we deny a request, you may appeal by replying to our response, and we’ll tell you the outcome. The Platform is currently offered only in the United States (see the Terms of Service); we are not offering it in the European Union or the United Kingdom, and this policy does not address the GDPR or UK GDPR.
We use encryption in transit and at rest, access controls, and access logging and monitoring, and we encrypt sensitive credentials such as your Notion authorization token. Your User Library is isolated so that it is not loaded into other users’ sessions.
We’re in beta, and we won’t overstate our security posture. We’re pursuing SOC 2 certification and will state it only once we have it. If security certification is a requirement for you today, contact us before relying on the Platform for sensitive material.
No system is perfectly secure. If we discover a breach affecting your personal data, we’ll notify you and any regulator without unreasonable delay and as required by applicable law, including the New Jersey breach-notification statute (N.J.S.A. 56:8-163).
We use cookies and similar technologies for two purposes: to operate the Starling app, and to understand how our website is used. In the app, we use only cookies necessary to run the service and keep you signed in (authentication and session management). On our website (StarlingMX.ai), we use analytics to measure traffic and improve the site, including Vercel Web Analytics and Speed Insights, which are cookieless. We do not use advertising cookies, and we do not track you across other websites.
Because there is no industry-standard response to browser “Do Not Track” (DNT) signals, we do not respond to them at this time.
The Platform isn’t for anyone under 18, and we don’t knowingly collect data from children.
If we make a material change we’ll notify you by email or in the Platform at least 30 days before it takes effect. The “last updated” date always reflects the current version.