1. Who we are
Northstar ("Northstar", "we", "us") provides an AI-native due-diligence platform for financial transactions. Our customers are businesses; we process information on their behalf to run deal workspaces, organize documents, track requests and obligations, and manage deal-related communications. This policy explains what we collect, how we use it, and the choices you have. It applies to northstarapp.ai and the Northstar application.
2. Information we collect
- Account information. Name, work email address, and organization details, provided when you or your organization creates an account.
- Customer content. Documents, deal data, requests, notes, and other material you or your counterparties upload to or create in a deal workspace.
- Connected mailbox data. If you connect a Microsoft or Google mailbox, we sync email messages as described in Sections 3 and 4.
- Meeting content. Where your organization enables call capture, recordings and transcripts of deal-related meetings.
- Usage and log data. Technical information such as IP address, browser type, and product activity, used for security and reliability.
3. Connected mailboxes
Connecting a mailbox is optional and per-user: each person connects (and can disconnect) their own account from Settings. When a mailbox is connected, Northstar syncs email so that deal-related correspondence appears alongside the deal it belongs to, and sends email you compose in the product from your own address. Junk, deleted, and draft messages are excluded from sync. Disconnecting stops synchronization and revokes Northstar's access credentials for that mailbox.
4. Google user data
If you connect a Gmail or Google Workspace account, Northstar requests the following Google scopes: gmail.readonly (read your email so deal-related messages and attachments can be organized into the correct deal workspace) and gmail.send (send messages that you compose and explicitly choose to send from within Northstar), together with your basic profile (name and email address) to identify the connected account.
Northstar's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We only use Google user data to provide and improve the user-facing features described above. We do not use it for advertising, and we never sell it.
- We do not transfer Google user data to third parties except to the service providers listed in Section 7 as necessary to provide these features, to comply with applicable law, or as part of a merger or acquisition with prior notice.
- Humans do not read your Google user data except (a) with your explicit permission (for example, a support request), (b) where necessary for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) in aggregated, anonymized form for internal operations.
- We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
5. How we use information
We use the information above to provide the service: operating deal workspaces, routing communications to the right deal, extracting and tracking requests and obligations, generating summaries and answers grounded in your deal content, securing the platform, and providing support. We use aggregated or de-identified usage information to improve the product.
6. AI processing
Northstar uses large language models to power product features such as document classification, email routing, and grounded question answering. Your content is processed by our AI service providers solely to deliver these features under agreements that prohibit them from using your content to train their models. As noted in Section 4, Google user data is never used to train generalized AI or machine learning models.
7. Sharing and service providers
We do not sell personal information. We share information only with: (a) your organization and the deal participants you or your organization choose to share it with in the product; (b) service providers that host and process data on our behalf — including Amazon Web Services (cloud hosting and storage), Anthropic (AI processing), Clerk (authentication), and, for connected mailboxes, Microsoft and Google (as the mailbox providers); (c) authorities where required by law; and (d) a successor entity in connection with a corporate transaction, with notice.
8. Security
All data is encrypted in transit (TLS) and at rest. Mailbox access credentials are additionally envelope-encrypted at the application layer. Access to production systems is restricted and audited. No system is perfectly secure, but we design for least privilege and defense in depth.
9. Retention and deletion
We retain information for as long as needed to provide the service to your organization. Disconnecting a mailbox stops synchronization and revokes our access credentials for it. You or your organization can request deletion of your data by contacting us; we will delete it within a commercially reasonable period except where retention is required by law.
10. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information. Because Northstar processes most information on behalf of business customers, we may direct your request to the organization that controls your workspace. To exercise a right, contact us at the address below.
11. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above, and we will notify customers of significant changes.
12. Contact
Questions or requests: support@northstarapp.ai