Starsill Privacy Policy
Last updated: September 29, 2026
This is the same privacy policy shown in the Starsill app. Leer en español
Who runs Starsill
Starsill is operated by Benjamín Real Calderón in Mexico. You do not need an account to use Starsill.
What Starsill keeps on your device
Starsill stores the following in the app's own storage on your device:
- details of the books you save (book metadata)
- the capture location, if you choose to save one
- the source photos you capture or select
- the text recognized from those photos
How long it is kept
Confirmed books. Once at least 30 days have passed since capture, Starsill tries to delete a confirmed book's source photo and raw recognized text when you open or return to the app. If cleanup fails, it can retry later. This means:
- Deletion does not happen at exactly 30 days.
- If you do not open or return to the app after that point, the photo and text stay on your device. A cleanup error can also delay deletion.
- The 30 days are counted from when the photo was captured, not from when you confirmed the book.
Book details and saved location. These stay until you delete the book or remove the app's data.
Unresolved Inbox items. Photos and recognized text for items still unresolved in the Inbox stay until you delete that Inbox item or remove the app's data. They are not deleted automatically after a set time.
Exports and backups
- A Starsill library export does not include source photos.
- An export includes book details and any saved location or raw recognized text still present in the exported book records. Keep this in mind before you share an export.
- Device or iCloud backups may keep copies of Starsill's local data. They may also restore that data later. Restoring an older backup may bring back data that was in that backup.
- Starsill cannot erase copies you have exported or shared.
Identifying books online (Image Recognition)
Image Recognition is optional. Starsill sends photos online only if you allow Image Recognition. You can always use manual catalogue search instead.
What is sent
If you allow Image Recognition, Starsill makes a new copy of the full photo you captured or selected (a process called re-encoding). It sends that copy through the Starsill gateway and through OpenRouter to the configured recognition providers.
The whole photo is sent, not just the book. The image can include visible background, people, documents and text outside the book. Check what is in the frame before you use Image Recognition.
More than one provider may receive your photo:
- If a provider fails, the image can be sent to the next configured provider.
- If recognition flags the book's text as mirrored (reversed), Starsill may send one horizontally flipped copy of the same photo for one more recognition request.
Hints sent with the image. Locale and country hints (information about language, region and country) are sent with the image.
Location information in photos
- Re-encoding removes the photo file's EXIF metadata, including embedded GPS location, from the copy that is sent.
- Starsill does not send the capture location you saved in the app.
- Starsill does not blur or hide anything visible in the photo itself. If something in the picture reveals personal or location information, such as an address or a document, that is sent as part of the image.
What the Starsill gateway keeps
- The gateway does not durably store (save for later) the image in its application database. This statement covers only that database.
- The gateway can keep the extracted book details, which are draft fields such as title or author, for up to 15 minutes. This supports authenticated recovery, meaning the app can retrieve the result again through a verified request.
- The gateway can keep an operation record for up to 7 days from when the operation starts. Once the draft expires, this record contains no photo or book content.
What other services may keep
OpenRouter, the recognition providers used, Cloudflare and other infrastructure can process your requests. They can also process or keep network records under their own current terms.
Starsill's requests ask for no caching and zero data retention. However, those request settings do not by themselves prove what these providers actually keep.
Finding catalogue matches
Starsill sends book search terms through the gateway to Google Books and Open Library to find catalogue matches. These terms may be extracted from your photo or typed by you. Examples are title, author, language, country, publisher and ISBN.
- Open Library is searched when Google Books finds no exact match or is unavailable.
- Manual catalogue search does not send a photo, but it still sends the search terms you enter.
- When a book cover loads, the service hosting the cover receives the cover's web address and ordinary network information.
- The app labels each result with its source. Google Books results link back to Google Books.
Changing your Image Recognition choice
- Your Image Recognition choice is saved and applies to future captures.
- You can revoke it in Settings to stop future image uploads.
- Revoking does not erase requests or records that infrastructure or providers have already received.
- You can keep using manual catalogue search without sending a photo.
Analytics
Starsill does not send usage analytics until you make a choice in the in-app notice. Choose Continue with analytics to turn them on, or Turn off analytics to keep them off. You can change your choice in Settings.
What Starsill's own events contain. Starsill's custom TelemetryDeck events use:
- fixed event names
- counts
- flags (simple yes/no values)
- broad categories for confidence, latency (how long something took), route, source and outcome
These events do not include book titles, authors, ISBNs, recognized text, source photos or saved locations.
What TelemetryDeck also receives:
- a per-install identifier (an ID tied to this installation of the app)
- standard event time, app, device, operating-system, locale and related metadata
How long it may be kept:
- Events can be buffered, meaning held temporarily before processing.
- Older data may remain in TelemetryDeck's cold storage (long-term archive).
- Turning analytics off stops future Starsill analytics events. It does not delete events already received.
Integrity checks
Apple App Attest and the Starsill gateway use the following to verify network requests and to limit them:
- a device-scoped key identifier
- a public key
- an attestation receipt
- a request counter
Settings has a separate Reset Network Identity action. It asks the gateway to delete its per-install integrity record. Starsill removes the local integrity key only after the server confirms deletion or confirms that the server record is already absent. If the request fails, including while offline, the local key remains so you can try again.
After a successful reset, Starsill needs a new identity before it can make verified network requests again.
Purchases
Apple processes subscription purchases. Starsill receives which product you have and your entitlement status (whether your subscription access is active). Starsill does not receive your payment-card details.
Your choices
You can:
- use manual catalogue search without Image Recognition
- withdraw Image Recognition or analytics permission in Settings
- export your library
- delete individual books or Inbox items
- reset your network identity separately
- remove the app's data
What deleting does not erase. Deleting data in Starsill does not erase:
- earlier backups
- exports
- records held by providers or platforms
- Apple transaction records
- activity on websites you opened from links
Contact and changes
Privacy questions: privacy@starsill.app
If this policy changes materially, it will show a new date. Where needed, Starsill will also show a new in-app notice before the changed processing begins.
About this website
starsill.app is a static website hosted on Cloudflare. It has no analytics scripts, cookies or third-party scripts, and it loads nothing from other websites.
To deliver the pages and protect them from abuse, Cloudflare processes ordinary network information, such as your IP address and browser, under its own terms. Starsill sees only totals from Cloudflare, such as the number of visits and the countries they come from, never who visited.