Legal

Privacy Policy

Last modified: August 14th, 2026

Back to Legal documents

Section 1

Introduction

This policy explains that users must accept the Terms of Service to use StarlixAI's offerings. Incentivai Inc. operates the service from Wilmington, Delaware. The company collects data to provide and improve the Service per the user's agreement with this policy.

Section 2

Definitions

Key terms include API (application programming interface), CCPA (California Consumer Privacy Act), and Cookies (small files stored on your Device). Personal Data refers to information identifying living individuals, while Usage Data comprises automatically collected metrics like duration of a page visit.

Section 3

The Data Controller

Incentivai Inc. (251 Little Falls Drive, Wilmington, Delaware) determines the purposes and means of processing user data. The company partners with OpenAI OpCo LLC, which processes data as a data processor on behalf of Incentivai Inc.

Section 4

Information Collection and Use

The company collects various data types to provide and improve the services offered to users.

Section 5

Types of Data Collected

  • Personal Data — email, name, cookies, and usage information

  • Special categories — health data, political opinions, and biometric identifiers

  • Meta Platform Data — messages, attachments, sender and recipient identifiers from connected accounts

  • Usage Data — IP addresses and unique Device identifiers

Section 6

Use of Data

Data supports service provision, customer notifications, support functions, and analysis, including billing and providing users with news and special offers.

Section 7

Retention of Data

Personal Data persists for the duration of your use of the Service and beyond as necessary. Special categories remain only as long as necessary for the specific purpose. Usage Data undergoes shorter retention except when strengthening security.

Section 8

Transfer of Data

Information may transfer internationally where data protection laws may differ. The company uses standard contractual clauses and complies with the Data Privacy Framework for EU/Swiss transfers.

Section 9

Disclosure of Data

Data disclosure occurs when required to do so by law, during mergers, to service providers, or with your consent.

Section 10

Security of Data

Protections include strong encryption protocols (e.g., SSL/TLS) and access controls. The company maintains regular backups and disaster recovery plans and conducts regular audits.

Section 11

Your Data Protection Rights Under GDPR

EU/EEA residents enjoy rights to access, rectification, erasure, processing restrictions, portability, objection, and complaint filing. Users should email contact@starlix.net to exercise these rights.

Section 12

Your Data Protection Rights under the California Consumer Privacy Act

California residents may request data disclosures, opt out of sales, delete information, and avoid discrimination. The company collected name, email address, and IP address within the last twelve months.

Section 13

Service Providers

Third parties facilitate the service but cannot disclose or use it for any other purpose.

Section 14

Analytics

Google Analytics tracks usage; Google Cloud Platform stores application data; Datadog monitors infrastructure; PostHog analyzes product usage; HubSpot manages customer relations.

Section 15

Payments

Stripe processes payments without storing payment card details. Processors comply with PCI-DSS security standards.

Section 17

Children's Privacy

Services don't target children under sixteen. The company removes collected child data upon discovery.

Section 18

Changes to This Privacy Policy

Updates post to this page with revised effective dates. Continued use signifies acceptance.

Section 19

Contact Us

Questions should be directed to contact@starlix.net.

Section 20

Privacy Policy Addendum

  • Canada — US authorities may access data lawfully; no third-party marketing sharing without consent.

  • Mexico — Users may withdraw consent; the company shares data with business partners and may retain data per Mexican law.

  • Japan — The company manages jointly-used data; no third-party marketing without consent.

  • Republic of Korea — Data disposal occurs when consent revokes, purposes complete, or retention periods expire.