
Security
Staark is designed to protect parent and child-related information with reasonable safeguards and careful account-scoped access.
Effective Date: June 10, 2026
Staark uses reasonable safeguards and authenticated workflows to help protect account information. No system can be guaranteed completely secure.
1. Overview
Staark takes privacy and security seriously and uses reasonable technical, administrative, and organizational safeguards to protect user information.
We continue to improve our security practices as the platform grows and as parent and caregiver needs evolve.
2. Account Access
Staark users sign in through authentication workflows, including Google sign-in supported by Auth.js.
Account sessions are designed to help keep users signed in while protecting access to account-specific areas of the platform.
Staark does not expose authentication secrets, OAuth tokens, or server API keys in public pages or user-facing exports.
3. User-Scoped Data Access
Authenticated account actions are designed to access only the current user’s data.
Sensitive actions such as account deletion and data export are tied to the authenticated session, not a user_id submitted from the browser.
Server-side routes resolve the signed-in account before reading, exporting, updating, or deleting account-owned records.
4. Payments
Payments, subscriptions, invoices, and billing management are handled by Stripe.
Staark does not store full payment card numbers.
Subscription management and cancellation use Stripe-hosted billing workflows, including checkout and customer portal flows where available.
5. Data Protection
Staark uses reasonable safeguards to protect information against unauthorized access, loss, misuse, or alteration.
Parent and child-related information is stored in account-linked database records and accessed through authenticated server-side workflows.
No system can be guaranteed completely secure, but Staark is designed to limit access to user information and reduce avoidable exposure.
6. AI Data Handling
Staark uses AI to generate personalized recommendations and daily plans based on information provided by parents or caregivers.
Staark does not use parent or child personal information to train public AI models.
AI-generated recommendations should be reviewed by parents or caregivers before implementation.
7. Data Rights
Users can download their data from account settings.
Users can request deletion or delete their account through account settings.
When an account is deleted, active subscriptions are canceled as part of the deletion workflow when a subscription is found.
8. Security Limitations
No system can be guaranteed completely secure. We continue to improve Staark’s security practices as the platform grows.
Users should keep their Google account secure, protect their devices, and contact Staark if they notice unusual account activity.
9. Reporting Security Concerns
If you believe you have found a security issue or vulnerability, please contact us at support@staarkai.com.
10. Related Trust Pages
11. Effective Date
Effective Date: June 10, 2026.