STARWIRE is an entertainment intelligence platform operated from India. This policy explains what personal data we collect, why we collect it, how we protect it, and what rights you have under the Digital Personal Data Protection Act, 2023 (DPDP Act). Please read it carefully before using starwire.world.
1. Who we are
Data Fiduciary: STARWIRE (operated by Metavp369, Mumbai, India)
Platform: starwire.world and associated subdomains (creator.starwire.world, enterprise.starwire.world, api.starwire.world)
Contact: privacy@starwire.world
We are the Data Fiduciary as defined under the DPDP Act, 2023. Where we engage third-party service providers to process data on our behalf, they act as Data Processors under our instructions.
2. Data we collect
2.1 Account data
- Email address (required for registration)
- Password (stored as a bcrypt hash — we never store your plaintext password)
- Display name (optional)
- Account role (consumer, creator, enterprise admin)
- Registration timestamp
2.2 Usage data
- Entities you follow (celebrities, films, studios)
- Stories you read and watchlist items you save
- Search queries you submit
- Feed personalisation signals (follows, engagement patterns)
2.3 Creator submission data
- Entity submissions (celebrity or film information you submit for verification)
- Submission text and any supporting links you provide
- Verification outcome and AI confidence score
- Your submission history and reputation score
2.4 Enterprise and watchlist data
- Watchlist subscriptions (entity selections, alert thresholds)
- Slack webhook URLs you configure (stored encrypted at rest)
- Alert delivery history
2.5 Live streaming and chat data
- Chat messages you send in live rooms (retained for 48 hours, then automatically deleted)
- Presence signals (join/leave events, not stored beyond the session)
- Room creation and moderation actions (admin accounts only)
2.6 Technical data
- IP address (used for brute-force lockout; not linked to your profile beyond security purposes)
- Browser type and device information (standard server logs)
- JWT session tokens (stored as secure, HttpOnly cookies)
2.7 Data we do NOT collect
- Payment card details (handled entirely by Stripe — we never see or store them)
- Government-issued identity documents
- Biometric data
- Precise real-time location
3. How we use your data
We use your personal data only for the purposes for which it was collected:
- Providing the service — authenticating your account, personalising your feed, delivering alerts and watchlist notifications
- AI-powered intelligence — generating StarScore™, BuzzMeter™, and sentiment analysis for entertainment entities (see Section 4)
- Creator verification — processing entity submissions through our AI verification pipeline (see Section 5)
- Security — detecting and preventing brute-force login attempts, fraud, and abuse
- Product improvement — aggregate, anonymised analytics to understand how features are used
- Legal compliance — meeting our obligations under Indian law including the DPDP Act, 2023
We do not use your personal data for advertising profiling or sell it to third parties.
4. AI and LLM processing
STARWIRE uses Claude Sonnet (Anthropic) to generate entertainment intelligence — sentiment analysis, trend momentum scores, and entity rationale displayed on StarID profiles and the Newsroom.
What data is sent to the LLM
- Entity names (celebrities, films, studios) — these are public figures and public information
- Aggregated signals (social reach metrics, article volume counts from NewsAPI) — no personal user data
Caching
LLM responses are cached in our MongoDB database with a 6-hour TTL (time-to-live) index. Cached data is automatically purged after 6 hours and refreshed by our background worker. This reduces the number of LLM calls made and ensures response times remain fast for users.
What is NOT sent to the LLM
Your email address, password, follow history, watchlist, chat messages, or any other personal account data is never sent to any external AI provider.
Anthropic's data handling
Queries sent to Anthropic's API are governed by Anthropic's Privacy Policy. STARWIRE uses the API in a manner that does not include personal user data in prompts.
5. Creator submissions
When you submit an entity (celebrity or film) through the Creator platform:
- Your submission text is passed to Claude Sonnet for AI verification. The prompt contains only the submission content — not your email or account details.
- A confidence score (0–100) is returned and stored alongside your submission.
- Submissions scoring ≥70 are auto-approved; 40–69 enter human review; below 40 are auto-rejected.
- Approved submissions are added to the STARGRAPH™ entity database with source marked as 'creator' and reputation marked as 'Rookie'.
- Your submission history is linked to your account and visible to you at all times.
- Rejected submissions and their AI confidence scores are retained for 90 days for appeals and quality review, then deleted.
6. Enterprise and watchlist data
Enterprise accounts and per-brand Watchlist subscriptions involve additional data handling:
- Watchlist subscriptions — your selected entities, alert thresholds (1–100%), and optional Slack webhook URLs are stored in our database. Webhook URLs are stored encrypted at rest.
- Alert delivery — when a StarScore threshold is breached, STARWIRE sends a notification to your configured Slack webhook. The payload contains entity name, score delta, timestamp, and a link to the Enterprise dashboard. No personal user account data is included in Slack payloads.
- Admin access — STARWIRE platform administrators can view aggregate subscription statistics. Individual subscription contents are accessible only to the account that created them.
7. Live streaming and chat
- Chat messages — messages you send in live rooms are retained for 48 hours, then automatically deleted by a MongoDB TTL index. They are not used for any profiling or analytics purpose.
- Presence data — join/leave events are broadcast in real time via WebSocket and are not stored beyond the active session.
- RTMP stream keys — RTMP credentials for live room hosts are generated by Cloudflare Stream and gated at the API serialiser layer. They are never returned to non-admin accounts and are not stored in logs.
- Keyword moderation — chat messages are screened against a blocklist maintained by platform administrators. Blocked messages are dropped and a toast notification is shown to the sender. The blocklist terms are not disclosed publicly.
- Video content — live video streams are processed and stored by Cloudflare Stream. Cloudflare's data handling is governed by the Cloudflare Privacy Policy.
8. Data retention
| Data type |
Retention period |
| Account data |
Until account deletion |
| LLM cache entries |
6 hours (auto-purged by TTL index) |
| Live chat messages |
48 hours (auto-purged by TTL index) |
| Rejected creator submissions |
90 days |
| Login attempt records |
15 minutes (auto-purged by TTL index) |
| Share card tokens |
24 hours (auto-purged by TTL index) |
| Alert delivery logs |
90 days |
When you delete your account, all personal data associated with your account — including your profile, follows, watchlists, subscriptions, and creator submission history — is permanently deleted in a cascading operation. This deletion is irreversible.
9. Data sharing and third parties
We share your data only with the following categories of third-party processors, each under contractual obligations to protect it:
Infrastructure and hosting
- Emergent — application hosting and database (MongoDB). Data stored in India/US.
- Cloudflare — CDN, DDoS protection, DNS, and (when enabled) live video streaming via Cloudflare Stream.
AI processing
- Anthropic (Claude API) — LLM inference for entertainment intelligence. Only public entity data is included in prompts. No personal user data is transmitted.
News data
- NewsAPI.org — article volume signals used to update entity scores. Only entity names (public figures) are sent as query parameters. No user data is transmitted.
Payments
- Stripe — payment processing for web subscriptions. STARWIRE never sees or stores your card details.
- RevenueCat — mobile subscription management (iOS/Android).
Notifications
- Slack — Enterprise alert delivery to webhook URLs you configure. You control which workspace and channel receives alerts.
We do not sell, rent, or trade your personal data with any third party for commercial purposes. We do not share your data with advertising networks.
Legal disclosures
We may disclose personal data if required to do so by a court order, government authority, or applicable Indian law. We will notify affected users of any such disclosure to the extent permitted by law.
10. Security
We implement the following security measures to protect your personal data:
- Passwords — stored as bcrypt hashes with a cost factor of 12. Plaintext passwords are never stored or logged.
- Authentication — JWT tokens with HttpOnly, Secure, and SameSite=None cookie attributes. Bearer header takes priority over cookie to prevent cross-site session bleed.
- Brute-force protection — login attempts are rate-limited per IP. After 5 failed attempts within 15 minutes, the IP is locked out for 15 minutes. Successful login resets the counter.
- User enumeration protection — unknown email and wrong password return identical error messages so an attacker cannot probe whether an email is registered.
- Transport security — all traffic is served over HTTPS with TLS 1.2+ enforced at the Cloudflare edge.
- Sensitive fields gated at serialiser — RTMP stream keys and other sensitive fields are stripped at the API serialiser layer and never returned to non-admin accounts, regardless of database content.
- RBAC — all admin endpoints enforce role-based access control at the router dependency level. Role is verified on every request, not cached.
Despite these measures, no internet service can guarantee absolute security. If you believe your account has been compromised, contact us immediately at security@starwire.world.
11. Your rights under the DPDP Act, 2023
As a Data Principal under the Digital Personal Data Protection Act, 2023, you have the following rights:
Right to access
You may request a summary of the personal data we hold about you and how it is being processed. Use the Settings → Data Export feature in the app to download a complete copy of your data in JSON format across 8 data categories.
Right to correction
You may update your account information at any time through your account settings.
Right to erasure
You may permanently delete your account and all associated personal data through Settings → Delete Account. This triggers a cascading deletion across all data categories. The operation is irreversible.
Right to grievance redressal
If you have a complaint about how we handle your data, you may contact our Grievance Officer (see Section 15). We will acknowledge your complaint within 48 hours and resolve it within 30 days.
Right to nominate
You may nominate another individual to exercise your data rights on your behalf in the event of your death or incapacity. Contact our Grievance Officer to register a nomination.
Withdrawal of consent
Where we process your data based on consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. Withdrawing consent for essential processing (e.g., authentication) will require account deletion.
To exercise any of these rights, contact us at privacy@starwire.world or use the in-app data controls in Settings.
12. Cookies and tracking
STARWIRE uses the following cookies:
- Authentication cookie — stores your JWT session token. HttpOnly, Secure, SameSite=None. Essential for the service to function. Expires when you log out or after 7 days of inactivity.
We do not use advertising cookies, third-party tracking pixels, or fingerprinting technologies. We do not participate in cross-site tracking.
Standard server access logs (IP address, user agent, request path, timestamp) are retained for 30 days for security and debugging purposes.
13. Children
STARWIRE is not directed at children under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe a child has registered on our platform, please contact us at privacy@starwire.world and we will delete the account promptly.
14. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Display a notice in the app for registered users
- Send an email notification to registered users for significant changes
Continued use of STARWIRE after a policy update constitutes acceptance of the updated terms.