Privacy Policy
Service: Starks — One Starks per workspace · Last updated: 11 September 2026
Starks ("the Service", "we", "us") is a multi-tenant platform where each workspace runs a single
configurable Starks agent: role presets and capability packs (Sales, CRM, Content, Inbox, Research,
Calendar, Support, Operations), Company Brain, CRM, content, sales automation, and a Telegram control
plane. Customer data is stored on Starks-controlled
infrastructure (PostgreSQL, object storage on our servers). Selected context necessary to
fulfil AI requests may be transmitted to configured AI inference providers (currently
OpenRouter → Google Gemini) to generate responses. We do not sell your data. Billing for
paid plans is processed by Whop.
1. What we collect
- Telegram identity: your Telegram user ID and username, to operate the bot.
- Autoposting channel connection: if you connect a Telegram channel for autoposting,
we store its Telegram Bot API token, protected with the same authenticated Fernet
encryption, plus your chosen niche, tone, language and posting frequency.
- Telegram group/channel scanning: if you add the bot as an admin to a Telegram
group or channel for lead scanning, we process messages posted there from that point on to
score intent/urgency for you — we do not access message history from before the bot was
added, and we process nothing from groups/channels you have not added the bot to.
- Custom niche description: if you describe your business in free text instead of
picking a preset niche, that description is sent to our AI provider to generate a short
niche label and a pool of content topics; the description and the generated label/topics are
stored so they can keep producing on-topic posts.
- Business contacts: if you use the business assistant, we store the contact cards
you create or import for your own clients/partners/leads — name, email, phone, company,
messaging handles, notes, and consent/unsubscribe status. These are your own contacts, not
data scraped from public social networks.
- Integration credentials: if you connect your own email/SMTP account or another
business integration (Slack, Discord, a generic webhook, SendGrid), we store the connection
settings and any password/API key/bot token/webhook URL, protected with the same
authenticated Fernet encryption used for channel tokens.
- Google Calendar connection: if you connect Google Calendar via OAuth, we store your
Google account's OAuth access and refresh tokens, protected with the same authenticated Fernet
encryption, and your email address to label the connection. We use this solely to
create a calendar event when you schedule a meeting through the assistant — we do not
read, list, or import your existing Google Calendar events, and rescheduling or cancelling a
meeting in the Service does not currently update or delete the corresponding Google Calendar
event. We request only the
calendar.events and userinfo.email
scopes.
- Communications: email drafts and sent messages, conversation threads, meeting
details (title, time, participants, location) and reminders, and campaign content/recipient
lists, all created through the business assistant.
- Content you act on: Telegram group/channel messages you choose to analyze, AI-generated
reply drafts, AI-generated autopost drafts, and leads you save. We do not collect private
Telegram direct messages.
- Usage metadata: scans run, replies and posts published, emails/campaigns sent,
timestamps — for rate limiting and analytics.
- Workspace & AI Agent: chat messages, mission plans and outputs, file attachments,
Company Brain memories, knowledge-base entries, and high-impact learning suggestions that
require your confirmation before they are saved.
- Provider usage metering: per-workspace request and provider-cost aggregates for
billing, quotas, accounting, and abuse prevention.
- Starks configuration & workspace data: Starks profile instructions, assigned Company Brain documents,
KnowledgeSources and KnowledgeChunks, missions, actions, approvals, CRM leads, sales
messages, delivery/reply events, analytics and cost telemetry. Workspace access controls
and retention settings apply to these records.
2. How we use data
- To authenticate you and act on your behalf.
- To analyze public content and generate reply suggestions.
- To generate niche-relevant post drafts for your autoposting channels.
- To publish posts/replies from your connected account or channel — by default only after
your explicit confirmation; on Pro/Agency plans you may opt an autoposting channel into fully
automatic publishing, subject to fixed safety limits (see Terms of Service §3).
- To draft and, only after your explicit confirmation, send emails and campaigns to your own
business contacts, using your connected email integration or a built-in fallback provider, or
deliver approved messages through a connected Slack/Discord/webhook/SendGrid integration; to
schedule meetings and deliver reminders you request.
- To score messages in a Telegram group/channel you add the bot to, so relevant leads there
are surfaced to you.
- To enforce safety limits that protect your account from spam-like behavior, including
outbound-email daily caps, quiet hours, and honoring your contacts' unsubscribe/consent status.
- To run Agent missions, maintain workspace-scoped Company Brain memory, and compute
embeddings for semantic retrieval (vectors stored in our database; text may be sent to the
configured AI provider only to generate those embeddings and responses).
3. Legacy integrations
The primary product is one Starks agent per workspace (Starks Profile, Agent runtime, Company Brain).
Older integrations may remain available on separate legacy paths, but they are not required
for the Starks workspace product and are not the source of workspace knowledge truth. We never
sell your data.
4. Storage & security
Data is stored in PostgreSQL and MinIO object storage on private Starks infrastructure.
Credentials are encrypted at rest and transport is encrypted in transit; content is
workspace-isolated, but it is not end-to-end encrypted because the Service must read
authorized content to run Starks missions and automations. We retain workspace records while the account or
workspace is active and for a limited backup/defence period afterward, then delete or
anonymize them according to the deletion request and legal obligations.
5. Sharing
We do not sell or rent your data. We share data only with infrastructure providers
strictly necessary to run the Service (hosting, the AI model provider for text/content
analysis and generation, Telegram's Bot API to operate your autoposting channel, Google
Calendar API — only if you connect it — to create meeting events, and — only if you connect
them — the SMTP provider you configure, or Slack/Discord/SendGrid/your configured webhook
endpoint, to deliver the messages you approve), and when required by law.
6. Your rights — data deletion
You can remove an autoposting channel, remove the bot from
a Telegram group/channel to stop scanning, or disconnect an email, Google Calendar, or other
business integration at any time from the bot or the web cabinet, or via your Google Account's
third-party access settings. To delete
all your data, send a request through the bot or email the contact below; we will erase your
stored data, including access and bot tokens, autoposting channel settings and generated
content, saved leads, business contacts, email/message history, meetings and reminders,
campaigns, and integration connections.
7. Contact
Email: sturox.company@gmail.com
Starks is operated by Sturox. We are not affiliated with
Meta Platforms, Inc.