Privacy policy
Starly answers your customers, which means it reads what they write. This is what gets stored, who else sees it, how long it survives, and what you can make us do about it.
Last updated 2026-08-14
Starly is an AI assistant that answers a business's customers on its website widget, on its WhatsApp number, and inside its Gorgias helpdesk. It is operated by Starly, incorporated in Israel, at starly.chat. Privacy requests go to avivk6@gmail.com and reach a person who can act on them. We are too small to have appointed a data protection officer, and would rather say so than invent one.
Two relationships, kept apart
There are two kinds of personal data here. One is the account data of the businesses using Starly: your name, your email, your settings, the credentials you paste in. For that, Starly is the controller, and this policy is the promise.
The other is everything your customers say to your assistant. That data is yours: you are the controller, we are the processor, and we hold it and run it through a model because you asked us to. A customer who writes to us directly wanting their conversation deleted is passed to you, with our help answering in time, rather than acted on behind your back.
What a conversation actually contains
A conversation is a thread of turns: what the customer wrote, what the assistant replied, a timestamp on each, the channel, a trace of how the reply was built, and anything a tool attached to it. There is no visitor profile behind that. We do not store IP addresses, browser fingerprints, user agents or advertising identifiers, and there is no analytics tag, advertising pixel or tracking cookie anywhere in the widget or the dashboard. What we hold is what somebody typed.
The channel adds details of its own, and those are personal data too. A WhatsApp conversation is identified by the customer's phone number, because that is what WhatsApp is. A Gorgias conversation carries the ticket id, the message id, the helpdesk channel, and the customer's email address and first name as Gorgias sends them. Beyond that, a conversation holds whatever the customer chose to type. We cannot predict that and we do not filter it.
With lead capture on, the form's answers are stored as a lead, one per conversation, and the form can ask for four things only: name, email, phone and order number. Beside it we record what was done with the lead — emailed to your teammate, POSTed to your webhook, pushed to Klaviyo, and whether it was also subscribed to a marketing list. That last flag is a consent record, kept per lead rather than guessed later from a setting that has since changed.
What we hold about you, the business
- Your account: name, email, role, and whether it is disabled. Sign-in runs through Firebase Authentication, so a password lives there and never with us.
- Each business you run: name, site address, headline, logo, currency, time zone, opening hours, and every assistant setting from the bot's name to its daily token budget.
- Its knowledge: cards you wrote, cards extracted from a crawl of your own public site, the version history of both, and the imported product catalog.
- Credentials for whatever you connected: a Shopify access token, Gorgias API key or OAuth tokens, a WhatsApp channel token, a Klaviyo private key. None is ever returned by the API once saved, to anyone, including you.
- Push subscriptions, one per browser that agreed to them, so a handoff can reach you.
- An activity feed for support and abuse work: who signed in, and that a message was sent, with its first 120 characters as a preview. It is the one place our staff see a fragment of a customer message without opening a transcript.
- Contact lists you upload for outreach. Our terms require that everyone on them already has a relationship with your business.
Cookies and browser storage
The dashboard sets one cookie: an httpOnly, SameSite=Lax session cookie lasting seven days, or thirty minutes for an administrator working inside your account. There is no second cookie, and no consent banner, because there is nothing to ask consent for.
The widget sets no cookies at all. It keeps two things in the visitor's own browser storage: the id of the conversation they are in, so returning within seven days continues the thread, and whether the bubble already showed its invitation. It tells our server the path of the page it loaded on, so the bubble can say something different on your promotions page; the path, not the full address, and it is not stored. A business can also show a consent notice linking to its own policy.
The model that writes the replies
Every customer-facing reply is generated by OpenAI's API. We send that business's knowledge and instruction cards, the recent turns of that one conversation, and the customer's new message. We do not train any model on your data or your customers', and under the API terms we use, neither does the provider. When you ask us to read your website, an extraction model turns the crawled public pages into knowledge cards; that step runs on OpenAI by default and can be pointed at Anthropic instead.
Who else the data reaches
Each of these processes data on our instruction, or on yours. Several are here only because you connected them.
- OpenAI — generates every reply, and by default the extraction from your site.
- Anthropic — an alternative model for that extraction step, never in the path of a reply.
- MongoDB Atlas — the database: conversations, leads, knowledge, products, settings, accounts.
- Heroku — the platform the application runs on.
- Cloudflare R2 — file storage for logos, widget imagery and uploads.
- Firebase Authentication (Google) — dashboard sign-in.
- Resend — the only thing that sends email: sign-in links, invitations, lead notifications.
- Firecrawl — reads your public website when you ask for a scan.
- Gorgias — your helpdesk: messages in by webhook, replies back into the ticket.
- Whapi — the gateway to your own WhatsApp number, both directions.
- Shopify — read access to discounts, so quoted codes exist. We do not write to your store.
- Klaviyo — pushes captured leads into your own Klaviyo account, if you switch it on.
- Your browser vendor's push service, for handoff notifications.
We also disclose data where the law compels us, and to a buyer if the business is ever sold, in which case you hear about it first. That is the whole list, and nobody on it is in the advertising business.
Where it is processed, and transfers abroad
Starly is established in Israel, and every provider above runs infrastructure across several countries, most with a United States presence, so data reaching us will in practice be processed outside the European Economic Area and the United Kingdom. Those transfers rely on the European Commission's standard contractual clauses in our providers' terms, or on an adequacy decision covering the destination. If you need our current hosting region in writing, ask rather than guess from this page.
How long things are kept
These windows are enforced by the database itself, not by somebody remembering to run a cleanup.
- Conversations: 30 days by default, counted from the last message rather than the first. A business can set its own window between 1 and 365 days, and 365 is a ceiling nobody can raise. An expiry index does the deleting, on every channel alike.
- Gorgias and WhatsApp delivery logs, and alerts about failed deliveries: 30 days.
- The activity feed, including its 120-character previews: 90 days.
- A WhatsApp thread stays attached to one conversation for 7 days after the last message; the next message starts a fresh one.
- Dashboard sessions: 7 days. An administrator session inside your account: 30 minutes.
- Widget statistics are daily counters — launcher seen, chat opened, seconds in between. No identifiers, nothing traceable to a person.
- Leads, knowledge, product catalogs, integration settings and account records have no expiry. They are kept until you delete them or close the account.
Deleting a business deletes its data with it: knowledge and its history, products, carts, conversations, tools, AI configuration, share and connector links, leads, widget settings, and the Gorgias, WhatsApp and Klaviyo configurations including their credentials. Ask us to close your account and we do the same for the account. Backups age out on their own cycle, so allow a short tail after any deletion.
Why we are allowed to hold it
- Performing a contract: your account, your businesses, your settings, and the conversations we hold to run the service you signed up for.
- Legitimate interests: security, abuse investigation, debugging a channel that stopped working, and short operational logs. Those windows are short precisely because the interest is ours rather than yours.
- Legal obligation: records we must keep, and responses to lawful requests.
- Consent, where it genuinely applies: marketing subscriptions you push to Klaviyo, push notifications you switch on, and the consent notice a business shows in its widget.
For your customers' conversations the lawful basis is yours to establish, not ours. You decide why you are answering them; we process on your instruction.
Your rights under the GDPR and UK GDPR
You can ask us for access to your personal data, correction of anything wrong in it, erasure, a copy in a portable machine-readable form, and restriction of processing while a dispute is open, and you can object to anything we base on legitimate interests. We make no automated decisions with legal or similarly significant effects about anyone.
Write to avivk6@gmail.com. We answer within a month, free, and say so if a request needs the extension the law allows. If it concerns conversations belonging to one of our merchants rather than to us, we tell you which merchant and pass it on. You can also complain to a supervisory authority — in the EEA the one where you live or work, in the UK the Information Commissioner's Office — without coming to us first.
California: your CCPA and CPRA rights
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We never have. There is no "do not sell or share my personal information" link on this site because there is nothing for it to switch off, and if that ever changes, this page changes first.
California residents can ask what we collected and where it came from, get a copy, have it deleted or corrected, and limit the use of sensitive personal information, which we use for nothing beyond running the service. Exercising any of this will not get you worse service or a worse price. Send the request to avivk6@gmail.com; an authorised agent may send it with proof you asked them to. Where we are a service provider to a merchant, we forward the request to them.
Security, stated plainly
Traffic runs over TLS. Sessions are httpOnly cookies with a fixed expiry. Every webhook endpoint we expose is authenticated by a secret held on both sides, because a public URL is not authentication. Shopify access tokens are encrypted with AES-256-GCM under a key kept outside the database, and credentials of every kind are write-only in the interface: once saved, no endpoint returns them. Production access is limited to the people who run the service, and an administrator session inside a customer account expires in thirty minutes.
What we do not have: SOC 2, ISO 27001, or any HIPAA capability. We are certified against nothing, and a vendor questionnaire demanding one of those should be answered with a no. Starly is not built for health records or payment card data, and neither should be typed into it.
Children
Starly is sold to businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If a child has written to one of our merchants' assistants and you want it removed, tell us and we will delete it.
Changes, and how to reach us
The date at the top is the day this text last changed. If a change makes a material difference — a new company on the list above, a longer default retention window, a new category of data — we email account owners before it takes effect.
Privacy requests, questions and complaints: avivk6@gmail.com. The controller for account data is Starly, incorporated in Israel. For conversations flowing through a merchant's assistant, the merchant is the controller and we are their processor; ask and we will tell you which merchant that is.