Legal

OpenSTAR — App Privacy Policy

This policy explains what the OpenSTAR application for Android collects, what it sends, what never leaves your device, and what you can ask STAR SOURCE LTD to do with your information.

Last updated: 10 September 2026

1. Scope of this policy

This policy applies to the OpenSTAR mobile application published by STAR SOURCE LTD (“we”, “us”, “the company”), a private limited company registered in England and Wales under company number 17443871, with its registered office at 128 City Road, London, EC1V 2NX, United Kingdom. We are the data controller for the information described here.

The website at starsource.uk is covered by a separate website privacy policy. Where the two differ, this page governs the application.

2. In short

OpenSTAR is a client for a private connection service. It needs an account to work, so it handles the credentials for that account and a small amount of technical information about the device it is installed on. It does not build a profile of you, it carries no advertising or analytics libraries, and it does not sell information to anyone.

  • We do not collect your location.
  • We do not access your contacts, photos, files, microphone or camera.
  • We do not log the websites, addresses or services you connect to.
  • The app contains no advertising network and no third-party analytics.
  • We do not sell or rent personal information, to anyone, for any purpose.

3. What the app sends to our servers

Account credentials

To sign in, the app sends the username and password you type to our service, which returns an access token. This is the only way the service can tell your account from anyone else’s. Your password is stored on the device in encrypted storage protected by the Android keystore, because the connection software must present it each time a tunnel is established. It is not transmitted to any third party.

Device information

When you sign in, the app also sends:

  • A device name — the manufacturer and model reported by Android, for example “Samsung SM-G991B”. It lets you recognise your own devices on your account. It is not a serial number and does not identify you personally.
  • The application version, so the service knows which version is calling and can tell you when a newer one exists.
  • A device identifier generated by the app itself — a random value created on first run and stored only on that device. It is deliberately not derived from any hardware identifier, advertising identifier or phone number, and it cannot be linked back to you or to any other app. Its only purpose is to count how many devices are using one account, so that account limits can be enforced. Uninstalling the app discards it permanently.

Connection and usage records

Our service records the volume of data your account transfers, the times your account connects and disconnects, which of our servers it used, and the network address the connection came from. This is what makes an account quota, a device limit and basic fault diagnosis possible, and it is the ordinary operating record of any connection service.

We do not record what you do through the connection. We do not log the websites you visit, the addresses you request, the names you look up, or the contents of your traffic, and we do not inspect, analyse or sell that traffic.

4. What stays on your device and is never sent

The list of installed applications

OpenSTAR offers split tunnelling, which lets you decide that particular applications should or should not use the connection. To draw that screen, Android requires the app to declare the QUERY_ALL_PACKAGES permission, because from Android 11 an app cannot otherwise see what else is installed — and we cannot know in advance which application you will want to choose.

That list is read only to display those choices. Your selection is stored locally on the device and passed to Android’s own connection service. Neither the list of installed applications nor your selection is ever transmitted to us or to anyone else.

Diagnostic log

The app keeps a technical log of the connection process on the device so that a problem can be investigated. It stays on the device, and it is sent nowhere automatically. If you choose to share it with support, you are sending it deliberately and you can read it first.

5. Permissions the app requests, and why

  • Internet and network state — to establish the connection and to notice when the network changes.
  • Foreground service — Android requires an ongoing notification while a connection is active, so that you always know it is running.
  • Notifications — to show connection status and messages from your provider. You may refuse this; the connection still works.
  • Query all packages — solely for the split tunnelling screen described above.
  • Receive boot completed — required by the connection engine to schedule its own background work reliably.
  • VPN service — Android asks for your explicit consent the first time, in its own dialog, before any connection can be created.

6. Legal basis for processing

  • Contract — authenticating your account, enforcing quotas and device limits, and providing the service you signed up for.
  • Legitimate interests — keeping the service secure and available, and preventing abuse of accounts and infrastructure.
  • Legal obligation — where we are required to keep records or respond to lawful requests.
  • Consent — where we ask for it explicitly. You may withdraw it at any time.

7. How long we keep it

  • Account details — while the account exists, and for a reasonable period afterwards where accounting or legal obligations require it.
  • Connection and usage records — kept for a short operational period, normally not more than 12 months, then deleted or overwritten.
  • Device identifiers — kept while the device is associated with the account, and discarded when it is removed or the app is uninstalled.

When information is no longer needed for the purpose it was collected for, we delete it.

8. Sharing and third parties

We do not sell or rent personal information. The application contains no advertising software development kits and no third-party analytics. We share information only where necessary:

  • With providers who host our infrastructure, acting on our instructions under a written agreement.
  • Where we are required to do so by law, or to establish, exercise or defend legal claims.

We operate internationally, so information may be processed outside the United Kingdom. Where that happens we rely on an adequacy decision or appropriate safeguards such as standard contractual clauses.

9. Security

Traffic between the application and our service is encrypted in transit. Credentials held on the device are stored in encrypted preferences protected by the Android keystore. Access to systems holding account records is restricted to people who need it.

No system can be guaranteed completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office and, where required, the people affected.

10. Your rights

Under UK data protection law you have the right to:

  • Ask what personal information we hold about you and receive a copy of it
  • Ask us to correct information that is inaccurate or incomplete
  • Ask us to delete information where there is no continuing reason for us to hold it
  • Ask us to restrict how we use your information while a concern is resolved
  • Object to processing carried out on the basis of legitimate interests
  • Ask for information you provided to be transferred to you or another organisation
  • Withdraw consent where our processing is based on it

We respond within one month and there is no charge. If you are unhappy with how we have handled your information you may complain to the Information Commissioner’s Office, the UK supervisory authority, though we would appreciate the chance to address your concern first.

11. Deleting your account and your data

You can ask us to delete your account and the information associated with it at any time by writing to the address below. We will confirm the request and complete it without undue delay, other than any records we are required by law to retain. Uninstalling the application removes the credentials, the device identifier and the diagnostic log held on that device.

12. Children

OpenSTAR is intended for adults and is not directed at children. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

13. Changes to this policy

We may update this policy as the application changes or to reflect legal requirements. The date at the top of this page shows when it was last revised, and material changes will be reflected here before they take effect.

14. Contacting us

Privacy enquiries and requests about your information can be sent to:

STAR SOURCE LTD
128 City Road
London
EC1V 2NX
United Kingdom
Company No. 17443871

Email: legal@starsource.uk

You can also use our contact form.