The Starchive
Log in Start free trial

Privacy Policy

Effective July 13, 2026

This policy explains what information The Starchive collects, why, and how it's used — including through the Chrome extension ("The Starchive — Save Page"). "The Starchive," "we," or "us" refers to the operator of the service at portal.thestarchive.com. We do not sell personal data, and we do not use it for advertising or tracking.

Account information

When you create an account, we collect your email address and a password. Passwords are stored as salted bcrypt hashes — we never store or have access to your plaintext password. If you enable two-factor authentication, we store a TOTP secret used only to verify your sign-in codes.

Archived content

When you archive a page — through the website or the Chrome extension — we store the page's HTML, linked assets (images, stylesheets, etc.), and a screenshot, along with the URL and the time it was archived. This content is stored to provide the core service: letting you view, organize, search, and share your saved pages later. Archived content is private to your account unless you explicitly create a share link for it.

The Chrome extension

The extension adds a toolbar button that archives the page you're currently viewing. It requests only three permissions, each used for a specific, narrow purpose:

  • activeTab — to identify the URL of the page you click the button on, so it can be sent to your account for archiving.
  • cookies — to optionally archive the page as you see it signed in, rather than the logged-out view. Broad access to a site is never granted upfront: the extension asks Chrome for permission to read cookies for that specific page's site (and its parent domain, to cover session cookies scoped that way) only when you click the button, and only for that one site. Chrome shows this as a one-time prompt per site and remembers your choice. If granted, cookies for that site are read fresh at the moment of the click and sent, over HTTPS, to our server along with the page's URL — never cached or stored by the extension itself. If denied, the page is still archived, just as the logged-out view. On our server, forwarded cookies are used transiently to render that one page and are not stored, logged, or retained after the request completes — only cookie names and domains (never values) may appear in diagnostic logs.
  • storage — used solely to remember one optional setting on the extension's Options page: a custom server URL, for testing against a non-production instance. Empty by default. Nothing else is stored by the extension, and this setting never leaves your browser.

We do not sell cookie data or any other data collected by the extension, and we do not use it for advertising, tracking, or any purpose unrelated to completing the archive you requested.

Billing

Subscription payments are processed by Stripe. We store the resulting subscription status, billing period dates, and invoice records (amounts, status, dates) — we do not store your card number or other raw payment details; those are handled directly by Stripe under its own privacy policy.

Audit logs

We keep a security audit log of account-related actions (sign-ins, password and 2FA changes, subscription changes, and similar events) tied to your account, for security and support purposes. This log is kept on our own infrastructure and is not shared with external analytics or advertising services.

Support access

Authorized Starchive staff can access an internal admin tool to help with support requests — for example, viewing account status or, when needed to diagnose an issue, opening a time-limited, single-use link to view the app as you see it. Every such action is recorded in the audit log referenced above.

Data retention and deletion

We retain your account and archived content for as long as your account is active. If you delete your account, we delete your archives (files and records), folders, invoices, subscription records, and audit history, and immediately cancel any active subscription — this is a permanent action and cannot be undone.

Security

Connections to the service are encrypted (HTTPS). Passwords are hashed with bcrypt. Optional two-factor authentication (TOTP) is available on every account.

Changes to this policy

If this policy changes materially, we'll update the effective date above.

Contact

Questions about this policy can be sent to [email protected].

The Starchive

Full-fidelity web page archiving for people and teams who can't afford to lose the page.

Product

  • Features
  • How it works
  • Security
  • Pricing

Account

  • Start free trial
  • Log in
  • FAQ

Company

  • Contact
  • Privacy Policy
  • Terms of Service
© The Starchive · Aeroware.io Made for a web worth remembering.