Privacy policy

Effective August 15, 2026

Starpower is operated by JT's Apps & Cattle LLC ("we," "us"), 7700 Windrose Ave, Plano, TX 75024. Starpower lets teams draft emails that their executives review and send from the executive's own mailbox. This policy explains what we collect, why, and the choices you have. Questions: josh@joshthomas.io.

What we collect

  • Account information. Your name, email address, and a hashed password (we never store plaintext passwords). If a workspace admin invites you, we receive your email address from them.
  • Workspace data. Workspace name, subdomain, company domain, membership, and roles (including sender and delegate designations).
  • Email request content. The requests your team writes in Starpower: recipients, subject, body, private notes to the sender, and the audit trail of what happened to each request (submitted, viewed, edited, sent, declined, and by whom).
  • Mailbox connection tokens. When a sender connects Google Workspace or Microsoft 365, we store the OAuth tokens needed to send on their behalf. Tokens are encrypted at rest. The only mail permission we ever request is send Starpower has no ability to read, search, or modify anyone's mailbox.
  • Email engagement data. Emails sent through Starpower include a small tracking image so the requesting team can see whether the message was opened. We record open timestamps and counts for the message; open data is approximate and is not tied to a profile of the recipient.
  • Billing information. Payments are processed by Stripe. We store your plan and subscription status; we never see or store card numbers.
  • Technical data. Session records, IP addresses used for rate limiting and abuse prevention, and standard server logs.

How we use it

To run the product: deliver requests to the right sender, send approved emails through the sender's connected account, show status to the people involved, send transactional notifications (request submitted, sent, declined), enforce workspace access rules, bill subscriptions, and keep the service secure. We do not sell personal information, we do not use your content for advertising, and we do not use your email content to train AI models.

Google user data and Limited Use

Starpower's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we request only the gmail.sendscope; we use it solely to send the specific emails a sender (or their authorized delegate) approves; we do not read Gmail content; we do not transfer Google user data to third parties except as necessary to provide the service, comply with law, or as part of a merger or acquisition with prior notice; and no humans read Google user data except with your explicit permission, for security purposes, or to comply with law. The same principles govern our use of Microsoft's Graph Mail.Send permission.

Open tracking, for recipients

If you received an email sent through Starpower, it was written and approved by people at the organization that emailed you and sent from their own mailbox. The message may include a one-pixel image that records when the message is opened. We record the open event (time and count) for that message on behalf of the sending organization; we do not build profiles of recipients. Contact the sender, or us at the address below, with questions.

Who we share data with

Subprocessors that host and power the service: Vercel (application hosting), Neon (database), Stripe (payments), Resend (transactional email), and Google / Microsoft (sending mail through accounts their users connect). Each receives only what it needs to do its job. We disclose information if required by law, and workspace admins can see the requests within their own workspace as described in the product.

Retention and deletion

We keep workspace data while the workspace is active. Deleting a workspace deletes its requests, memberships, invitations, and audit events. Disconnecting a mailbox deletes the stored tokens, and a sender can additionally revoke Starpower's access at any time from their Google or Microsoft account security settings. To request deletion of your account data, email josh@joshthomas.io.

Security

All traffic is encrypted in transit (TLS). Mailbox tokens are encrypted at rest. Access within a workspace is role-based and re-checked on every request, and workspaces are isolated from one another. Emails can only be sent when the mailbox owner or a delegate they authorized approves the specific message.

Cookies

We use cookies only to keep you signed in across your workspace and our root domain. No advertising or cross-site tracking cookies.

Your rights

You can access and update your profile in the app, disconnect a mailbox at any time, and email us to request a copy or deletion of your personal data. Depending on where you live (for example the EEA, UK, or California), you may have additional rights under local law — write to us and we will honor them.

Children

Starpower is a workplace tool and is not directed to anyone under 16. We do not knowingly collect data from children.

Changes and contact

If we make material changes to this policy we will update the date above and notify workspace admins. Contact: JT's Apps & Cattle LLC, 7700 Windrose Ave, Plano, TX 75024 · josh@joshthomas.io.