Privacy
What we store, and why
Short version: you can use Starcode without an account, and without telling us who you are. If you make an account, we keep your email address, your display name and the analyses you ran. We do not sell anything to anyone.
If you never sign in
Analysing a text needs no account. When you submit one we store the text itself, along with the report produced from it, because that is the thing you came back to read.
Access to that report is held by a capability token kept in your own browser. We store only a hash of it, which means we can check a token you present but cannot produce one ourselves. The practical consequence is worth stating plainly: if you clear your browser storage, that analysis is unreachable — by you and by us. There is no recovery, because there is no account it belongs to.
If you sign in with Google or GitHub
We ask the provider for the narrowest thing that works: your basic profile and your email address (openid email profile on Google, read:user user:email on GitHub). We never ask for, and cannot read, your mail, files, calendar, repositories or contacts.
From what the provider returns, we keep:
- your email address
- your display name
- your avatar image URL
- the provider’s account identifier, so we can recognise you next time
We never receive your password. We do not store an access token for the provider after sign-in completes, and we do not act on your behalf there afterwards.
What an account accumulates
The texts you submit, the reports produced from them, any files you upload for text extraction, your saved collections and tags, and your settings. That is the product working as intended — an account exists so your analyses persist and can be searched.
If you subscribe
Payments are processed by Stripe. Your card number never reaches this service and is never stored here — you enter it on a page Stripe hosts, and they hold it. What we keep is the minimum needed to know what you have paid for: your Stripe customer and subscription identifiers, your plan, and the subscription’s current status (active, past due, cancelled and so on).
Stripe receives your email address so it can attach the subscription to you and send receipts, and it collects whatever billing details it needs to take a payment. What Stripe does with that is governed by their privacy policy, not ours.
Cancelling is self-service through Stripe’s billing portal, reachable from your billing page. Cancelling ends the subscription; it does not delete your account or your analyses, which is deliberate — losing your saved work because a card expired would be a poor trade.
Security and abuse records
We keep an append-only record of actions that change data or read someone else’s, so an incident can be reconstructed. It stores a hash of your IP address rather than the address itself — enough to notice that many requests came from one source, not enough to identify a person from the record. Your browser’s user-agent string is stored alongside it.
Who else sees your text
When an interpretive analysis runs, the relevant portion of your text is sent to Anthropic for processing. The deterministic half of the platform — language detection, entity extraction, calendar conversion and the whole astronomy engine — runs here and sends your text nowhere.
The chart tools page embeds a third-party widget from Astro·Charts. Anything you type into those charts goes to them, not to us, and that page says so where you can see it. The embed is confined to that one page and cannot read any other.
Our hosting providers necessarily process data in the course of running the service.
Getting rid of it
Deleting an analysis deletes its text, its report and its claims. Deleting your account removes everything attached to it — analyses, documents, uploads, collections, settings and linked sign-in identities — by cascade, in the same operation.
The security record above is the deliberate exception: it survives account deletion, because a trail that disappears when the account does is not a trail. It holds the email address that acted, not the account.
To delete an account, email the address below. If you signed in with a provider, revoking Starcode’s access in your Google or GitHub settings stops future sign-ins but does not by itself delete what is stored here — ask us for that.
Cookies
There is no advertising or analytics tracking on this site. Sign-in state and your anonymous capability tokens are kept in your browser’s own storage, and your theme preference alongside them.
Contact
Questions, corrections, or a deletion request: smsutton3739@gmail.com.
This page describes what the software does, accurately and in plain terms. It is not legal advice, and it is not a substitute for a policy reviewed by a lawyer against the obligations that apply where you and your users live.