Starlight Search Inc. ("Starlight," "we," "our," or "us") operates the Pulsar web-based IDE (the "Service"). This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have over it.
1. Information we collect
Account information
When you sign up, our authentication provider (WorkOS AuthKit) collects your name, email address, and a hashed credential (or OAuth identifier). We store a corresponding user record in our database along with the organization you belong to.
Workspace content
Projects you create in Pulsar contain files you upload or that the AI agent writes on your behalf. These files are stored in isolated per-project storage (encrypted per-user volumes) in the United States. We do not train models on your workspace content.
Usage data
We log API requests, sandbox lifecycle events, model-usage cost, and error traces to operate, secure, and bill the Service. These logs are retained for up to 90 days.
Billing information
Payments are processed by Stripe. We receive a subscription status and customer identifier. We do not store your full card details.
2. How we use information
- Provide, maintain, and improve the Service.
- Enforce plan limits (daily model-usage budget, project counts, storage caps).
- Detect abuse, fraud, and security incidents.
- Communicate with you about your account, incidents, and material changes.
- Comply with applicable legal obligations.
3. Model providers and subprocessors
When you use bundled AI models, your prompts and relevant workspace context are transmitted to the model provider for inference. We currently route managed models (GLM-5, Minimax M2.5) through Amazon Bedrock in the AWS regionus-east-1 (United States). Bedrock's terms prohibit provider-side retention for model training of customer data in the standard path.
Other subprocessors include:
- Railway: application hosting.
- Neon: managed Postgres database.
- Fly.io: sandbox execution (Fly Machines) and file storage (Fly Volumes).
- AWS Bedrock: managed model inference (see above).
- WorkOS: authentication and directory sync.
- Stripe: subscription billing, payments, and tax compliance.
- Exa: optional web search queries invoked by the agent.
- PostHog: product analytics, including account identifiers for signed-in users (EU).
- Langfuse: agent-run observability and tracing, including prompts and responses (EU).
4. Google user data
Pulsar offers an optional integration that connects your Google account so the AI agent can act on the mail, files, and events you already have. This integration is off by default. No Google data is accessed until you complete Google's consent screen and explicitly grant permission.
What we access and why
- Gmail: message content, metadata, and drafts, so the agent can search, summarise, and triage your mail and compose replies you ask it to write.
- Google Drive: the files you direct the agent to, so it can read them into a project and write its output back.
- Google Calendar: events and availability, so the agent can use your schedule as context and create events at your request.
We request the narrowest scopes that support the features you enable. Access tokens are held encrypted at rest and are used only to serve requests you originate.
Limited Use
Pulsar's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not use Google user data for advertising, we do not sell it, we do not transfer it to third parties except as necessary to provide or improve the feature you are using, to comply with applicable law, or as part of a merger or acquisition, and we do not allow humans to read it unless we have your affirmative consent, it is necessary for security purposes or to comply with applicable law, or the data has been aggregated and anonymised.
Models and Google data
When the agent works on Google content at your request, the relevant portion of that content is sent to the model provider for inference on the same terms described in section 3. Google user data is never used to train, retrain, or fine-tune any AI model, ours or anyone else's.
Retention and revoking access
You can disconnect your Google account at any time from Settings in Pulsar, which revokes our tokens and stops all further access. You can also revoke access from your Google Account permissions page. On disconnection we delete the stored tokens. Google content the agent has already written into your workspace remains there until you delete it, in line with section 5. To request deletion of Google user data we hold, email [email protected].
5. Data retention
Account and billing records are retained for the life of your account plus a limited period required for tax, accounting, or legal purposes. Workspace files persist until you delete them or your account is terminated. Sandbox containers are ephemeral and auto-terminate after idle timeout.
6. Your rights
Depending on your jurisdiction (GDPR, UK GDPR, CCPA/CPRA, India DPDP, etc.) you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. You can exercise these rights by emailing [email protected]. We will respond within 30 days.
7. International transfers
The Service is operated primarily from infrastructure located in the United States. Certain subprocessors process data in the European Union: product analytics (PostHog) and agent-run observability (Langfuse). Depending on where you access the Service, your data may be transferred to and processed in the United States or the European Union. Where required (for example, for users in the EEA or UK) we rely on Standard Contractual Clauses and equivalent legal mechanisms.
8. Security
We encrypt data in transit (TLS 1.2+) and at rest. Legacy provider-key credentials, if present on your account, are encrypted with AES-256-GCM using keys stored separately from the ciphertext. No security system is perfect; you use the Service at your own risk.
9. Children
The Service is not directed at children under 16. We do not knowingly collect personal data from children.
10. Changes
We may update this policy from time to time. Material changes will be notified by email or in-app. Continued use of the Service after a change constitutes acceptance.
11. Contact
Starlight Search Inc. · [email protected]
