Effective July 13, 2026
This policy explains what information The Starchive collects, why, and how it's
used — including through the Chrome extension ("The Starchive — Save Page").
"The Starchive," "we," or "us" refers to the operator of the service at
portal.thestarchive.com. We do not sell personal data, and we do
not use it for advertising or tracking.
When you create an account, we collect your email address and a password. Passwords are stored as salted bcrypt hashes — we never store or have access to your plaintext password. If you enable two-factor authentication, we store a TOTP secret used only to verify your sign-in codes.
When you archive a page — through the website or the Chrome extension — we store the page's HTML, linked assets (images, stylesheets, etc.), and a screenshot, along with the URL and the time it was archived. This content is stored to provide the core service: letting you view, organize, search, and share your saved pages later. Archived content is private to your account unless you explicitly create a share link for it.
The extension adds a toolbar button that archives the page you're currently viewing. It requests only three permissions, each used for a specific, narrow purpose:
We do not sell cookie data or any other data collected by the extension, and we do not use it for advertising, tracking, or any purpose unrelated to completing the archive you requested.
Subscription payments are processed by Stripe. We store the resulting subscription status, billing period dates, and invoice records (amounts, status, dates) — we do not store your card number or other raw payment details; those are handled directly by Stripe under its own privacy policy.
We keep a security audit log of account-related actions (sign-ins, password and 2FA changes, subscription changes, and similar events) tied to your account, for security and support purposes. This log is kept on our own infrastructure and is not shared with external analytics or advertising services.
Authorized Starchive staff can access an internal admin tool to help with support requests — for example, viewing account status or, when needed to diagnose an issue, opening a time-limited, single-use link to view the app as you see it. Every such action is recorded in the audit log referenced above.
We retain your account and archived content for as long as your account is active. If you delete your account, we delete your archives (files and records), folders, invoices, subscription records, and audit history, and immediately cancel any active subscription — this is a permanent action and cannot be undone.
Connections to the service are encrypted (HTTPS). Passwords are hashed with bcrypt. Optional two-factor authentication (TOTP) is available on every account.
If this policy changes materially, we'll update the effective date above.
Questions about this policy can be sent to [email protected].