Effective 29 August 2026
Privacy follows the authority boundary.
The public Department OS release does not create accounts, sell inference, collect provider credentials, or send learning-workspace content to a model.
Starlight Intelligence privacy policy details
This policy covers starlightintelligence.ai, its public Department OS APIs and MCP endpoint, and the Starlight Growth Studio plugin. The operator is Frank Riemer / Starlight, Amsterdam. Questions may be sent to frank@frankx.ai.
What the current release handles
- Ordinary web request data may be processed by the hosting provider for delivery, abuse prevention, diagnostics, and security logging.
- The configurator sends only the five product-fit selections shown in its form. The response is deterministic and is not generated by a model.
- The public MCP endpoint processes the arguments required for its read-only catalog and planning tools. It applies bounded in-memory rate limiting using request network information.
- The learning workspace keeps the entered brief and evidence draft in the browser. Export happens as a local download; the current implementation does not submit that draft to Starlight.
- Email messages are processed to answer the request and maintain necessary correspondence.
What the current release does not collect
There is no Starlight account, checkout, advertising tracker, behavioral profile, provider-key form, managed agent runtime, or server-side Academy submission in this release. The plugin does not bundle, request, proxy, or resell model-provider credentials.
Your inputs and third-party runtimes
The plugin runs inside the runtime you choose. Codex, Claude, Grok, Antigravity, Hermes, OpenClaw, model providers, connectors, and any sources you open have their own data practices and terms. Store secrets only in the runtime's approved secret mechanism. Do not place confidential data, personal data, credentials, or private memory in a public package, prompt, log, or evidence draft.
Purpose, retention, and sharing
Request data is used to deliver and secure the service, compile the requested public plan, diagnose reproducible defects, and respond to communications. Starlight does not sell personal data. Hosting and infrastructure providers may process limited data as service providers. Retention follows operational and security need; client-side learning content is not retained by Starlight unless you separately send it.
Your choices
You may use the published skill without the website or MCP endpoint. You may ask about data associated with a direct communication, request correction or deletion where applicable, or raise a privacy concern by email. Applicable legal rights depend on your location and the nature of the request.
Changes
This policy will be updated before accounts, payments, managed runtimes, server-side learning submissions, or materially different analytics are introduced. The effective date above identifies this version.