Starlog records meetings and turns them into transcripts, summaries, decisions and action items. This page explains what data that involves, why we keep it, who helps us process it, where it goes and what you can ask of us. It covers people who use Starlog, people on the waiting list, and people who are recorded in a meeting without using Starlog themselves.
Who is responsible
Entity Investment AG, Sonneggstrasse 10, 9100 Herisau, Switzerland (UID CHE-161.152.467) runs Starlog and is the controller for the data described here. Write to admin@starlog.pro about anything on this page.
When a business uses Starlog for its own team, that business decides what is recorded and is the controller of its meetings; we process them on its behalf under our data processing agreement.
What we keep
- Your account: your name, your email address, the passkeys you sign in with (only their public part; the secret never leaves your device), which password manager each lives in and the kind of phone and browser it was made on, your plan and what you used of it, the companies or teams you belong to, and what you agreed to in Settings and when.
- Meetings you record: the audio, the transcript, who said what, the summary, decisions and action items, and the names you type for the people in the room.
- Files and notes in your own space and in the companies or teams you belong to, including what Starlog files there for you.
- Questions you ask Starlog and its answers.
- Google data, only if you connect a Google account (see below).
- Use: on which days you used Starlog and what your meetings and questions cost us, so we can run fair plans and see what to improve.
- Visits to the website: counted without cookies and without storing anything in your browser. For each page we keep the kind of page, the site and campaign a visit came from, the country your browser's time zone points to, the kind of device and browser, and a code made from your address and browser with a key that changes every day. Your address itself is never stored. We also note a tap toward the waiting list or the app, and a place taken on the list, with the same daily code. Page views and these taps are deleted after 13 months.
- The waiting list: your email, what you chose to tell us (name, company, role, country, what you would use Starlog for), and when you agreed to be emailed.
Why, and on what basis
| What for | Legal basis |
|---|---|
| Running your account and the features you use: recording, transcribing, summarising, filing, answering questions, sharing with the people you choose | Our contract with you (GDPR Art. 6(1)(b)) |
| Signing you in safely, preventing abuse, keeping the service running and secure | Our legitimate interest in a safe service (Art. 6(1)(f)) |
| Counting visits and use to improve Starlog and price it fairly | Our legitimate interest (Art. 6(1)(f)); no cookies, no profiles |
| The waiting list and its emails | Your consent (Art. 6(1)(a)), which you can withdraw at any time |
| Improving Starlog's own transcription with the recordings in your private space and the corrections you make (Help improve Starlog in Settings: on unless you turn it off on personal plans, off unless you turn it on on Team and Enterprise; company, team and secure meetings are never used) | Our legitimate interest in transcription that works (Art. 6(1)(f)); you can object at any time by turning it off in Settings, and nothing new is used after that |
| Emails about your account (a code to confirm your address, a link back in after a lost phone, your trial, your hours, a warning before deletion) | Our contract with you; we never send marketing |
| Keeping records the law requires | Legal obligation (Art. 6(1)(c)) |
Meetings can contain anything people say, sometimes sensitive things. We process them only to give you the transcript and what follows from it, and never to profile anyone.
People recorded who do not use Starlog
If you were in a meeting someone recorded with Starlog, their recording, its transcript and summary are kept in their account or their company's space. The person who recorded must tell everyone present, and in some countries needs everyone's agreement; Starlog asks them to, and reminds them on the Record screen. Speaker names come from the names the recording person types in, or from which phone heard a voice loudest. Starlog does not keep voice prints and does not recognise people across meetings. If the person who recorded has Help improve Starlog on, a recording in their private space may also be used to improve Starlog's own transcription, on the basis of our legitimate interest in transcription that works (Art. 6(1)(f)). This includes the recording from your phone if you joined their meeting as a guest: it follows their answer, and you have none of your own. It is never sold or shared and never leaves Starlog, company, team and secure meetings are never used, and you can object by writing to admin@starlog.pro. To ask about a recording you are in, write to the person who recorded it or to admin@starlog.pro.
Who helps us
We use a few providers to run Starlog. Each processes data only for us, under a contract. The full list, with what each does and where, is on sub-processors. In short: Hetzner hosts Starlog in Germany, with backups in Finland; pyannoteAI and ElevenLabs turn audio into text and tell who spoke; Anthropic writes summaries and answers; Brevo sends our emails and counts, anonymously, whether an email was opened (that count is not linked to you); Google only when you connect your own Google account.
If you connect your own AI assistant with a key (Settings, Your AI), Starlog answers what that assistant asks for, and what it reads leaves Starlog for the assistant's provider, under your own agreement with that provider. That provider is not one of ours. A key only reads, you can remove it at any time, and a secure meeting is readable that way only after you unlock it for export yourself.
We have opted out of training with every one of them: none may use your recordings or text to train their models. Anthropic does not train on data sent through its API, pyannoteAI's terms forbid training on our audio and results, and ElevenLabs' training setting is switched off for our account.
Countries your data goes to
| Country | Why | Safeguard |
|---|---|---|
| Switzerland | Entity Investment AG runs Starlog | Recognised as adequate by the EU |
| Germany (EU) | Our servers and audio storage (Hetzner, Falkenstein) | EU |
| Finland (EU) | Our backups (Hetzner, Helsinki) | EU |
| Netherlands (EU) | ElevenLabs storage | EU |
| France (EU) | Transcription and who spoke when (pyannoteAI) | EU |
| France (EU) | Emails (Brevo) | EU |
| United States | Transcription (ElevenLabs), summaries and answers (Anthropic), Google if you connect it | The EU-US and Swiss-US Data Privacy Framework where the provider is certified; otherwise the EU standard contractual clauses |
| Singapore | ElevenLabs storage | EU standard contractual clauses |
How long we keep it
- Meetings, files and questions: until you delete them or your account ends.
- Free accounts nobody uses for 6 months are deleted, with their recordings, meetings and questions. We email a warning a month and a week before.
- Audio waiting for hours (when an account ran out of hours) is deleted 30 days after it was recorded, never before 2 days after the hours renew, with an email a week before.
- A guest who records from their phone without making an account is signed out after 30 days.
- Website page views and taps: 13 months. Emails we sent: as long as the account exists, so we can show what was sent.
- The waiting list: until you ask us to remove you.
- Daily backups are kept with the same provider, in Helsinki, Finland, for 30 days; what you delete can remain in them for up to 30 days after it is gone from Starlog.
Your rights
You can ask us for a copy of your data, to correct it, to delete it, to limit what we do with it, to receive it in a common format, and you can object to processing based on our legitimate interest. You can withdraw consent at any time. Write to admin@starlog.pro; we answer within a month. You can also complain to a data protection authority: in Denmark Datatilsynet, in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), or the authority where you live or work.
We make no decisions about you by automated means alone.
Google data
Connecting Google is optional, and you choose what to allow on Google's own page.
- Google Drive (files you choose): when an owner or lead of a company chooses files in Google's own file picker, Google shares those files, and no others, with Starlog. Starlog copies them (Google Docs, Sheets, Slides, PDFs and text files) into the company's documents in Starlog, for the people in that company, and copies them again when they change. Starlog cannot see the rest of your Drive, and never changes the files you choose.
- Google Drive (files Starlog makes): when export is on, Starlog writes each meeting as a Google Doc into a folder it creates in your Drive, and touches no other files.
- Google Calendar (read only): when you connect it, Starlog reads the calendars you own or can edit (not ones others share with you to view) at the time of each meeting you record, to find the event it belongs to. It gives the event's title and the names of invited people who belong to the company the meeting is filed in to the AI that writes the summary (Anthropic, see below). Nothing else from your calendar is kept.
An earlier version of Starlog could also copy Gmail into a person's private space and read a whole Drive folder. Starlog no longer asks for either. A connection made then keeps the access it was given until you disconnect it under Settings in the app, and what was copied stays in Starlog until you delete it.
Starlog uses Google data only to provide these features to you. It does not sell it, does not use it for advertising, and does not let people read it except as described above. Starlog's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The tokens that keep a Google connection are stored encrypted on our server and never leave it. When you open Google's file picker, your own browser gets a token that lasts an hour at most and reaches only files chosen with Starlog. You can disconnect Google under Settings in the app at any time, or from your Google account settings.
Starlog's apps for iPhone and Android
The apps show the same Starlog as the browser and keep the same data. What they add: they record with the screen off, keep each recording on the phone until it is uploaded (never in the phone's backups), and ask once, before your first recording or question, whether Starlog may send your recordings to the speech-to-text services and your transcripts and questions to Anthropic, as described under Who helps us. You can take that back in Settings in the app. The apps use the phone's microphone only while you record, and its camera only to scan a meeting's QR code. They contain no advertising or tracking.
Cookies and storage
Starlog uses only cookies that keep you signed in (a guest who records from their phone gets one too). The app keeps recordings on your phone until they are uploaded, and remembers small settings in your browser. We use no advertising or tracking cookies, so there is no cookie banner.
Security
Each company or team in Starlog has its own separate space on our servers, and the people in it see only what their role allows. You sign in with a passkey, never a password. Our AI keys never enter those spaces. Everything travels encrypted.
Changes
When this policy changes in a way that matters, we tell people with an account by email or in the app before it applies.