All documents

Privacy Policy

How STARHASH collects, uses, shares, and protects your personal data, including biometric data and images, under Brazilian data protection law (LGPD).

Last updated:August 18, 2026

This Privacy Policy describes how STARHASH ("STARHASH", "we", "us") processes the personal data of influencers, companies, visitors, and other users ("you") of our digital influencer creation platform, website, and related services (together, the "Platform").

We process personal data in accordance with the Brazilian General Data Protection Law (Law No. 13.709/2018, "LGPD") and other applicable rules. By using the Platform, you confirm that you have read and understood this Policy. Where processing relies on your consent, particularly for sensitive data, it will be requested prominently and may be withdrawn at any time.

1. Who controls your data

The controller of the personal data processed on the Platform is [LEGAL ENTITY NAME], registered under company tax ID (CNPJ) No. [CNPJ], with its registered office at [FULL ADDRESS].

Our Data Protection Officer (DPO) can be reached at [email protected] for any matter relating to this Policy or to the exercise of your rights.

Bracketed placeholders must be confirmed and completed with the official company details before publication.

2. What data we collect

2.1. Data you provide directly

  • Account data: name, email, phone, username, password (stored encrypted), and account information.
  • Professional profile data: bio, social networks, niche, audience metrics, and other information you choose to include.
  • Company data (for corporate clients): legal name, tax ID, legal representative, address, and billing information.
  • Images and media you upload to the Platform, including photos of your face, body, guided poses, lookbooks, and other materials used to generate or refine your digital representations.
  • Communications: messages, support requests, and responses to surveys or forms.

2.2. Data collected automatically

  • Usage and device data: IP address, browser type, operating system, device identifiers, pages visited, and actions taken on the Platform.
  • Cookies and similar technologies, as detailed in our Cookie Policy.
  • Technical logs and access records, kept in accordance with the Brazilian Internet Civil Framework (Law No. 12.965/2014).

2.3. Data from third parties

  • Data from social login providers and social networks you choose to connect (for example, public profile information and metrics via official integrations such as the Instagram Graph API).
  • Data from payment processors about transaction status (we do not store full card numbers).

3. Sensitive and biometric personal data

The nature of the Platform involves processing sensitive personal data, particularly biometric data. By uploading photos of your face and body, you provide physical and biometric characteristics, including facial geometry and natural marks such as tattoos, vitiligo, and heterochromia, which are used to create and refine faithful digital representations of you.

Processing of this sensitive data is carried out based on your specific, prominent consent, under Article 11 of the LGPD. Consent is requested when you upload images and may be withdrawn at any time, in which case we will cease processing and delete the images and biometric data, except where retention is legally required and except for the proof records described in section 3.1, whose retention is necessary for the regular exercise of rights.

  • We do not use your biometric data for surveillance, nor to identify you in third-party databases, in public images, or anywhere outside the Platform. Within the Platform, use is limited to creating your digital representations and, if you separately consent, to the identity proof described in section 3.1.
  • We do not sell or trade your biometric data.
  • We apply enhanced technical and access-control safeguards to this data.

3.1. Proof of identity when accepting contracts (optional)

With your specific, separate consent, requested prominently during sign-up, we generate a record proving that it was you who accepted a given contract. This record contains only irreversible codes (hashes) derived from your facial signature, from the references to your identity-verification files, and from your date of birth, together with the date, the time, and the identifiers of the contract and of the consent in force at that moment.

  • What data is used: only the derived codes described above. The record does NOT contain your images, your facial signature, your identity documents, or any biometric data in readable or reconstructable form.
  • Purpose: to prove the authorship and authenticity of your contractual acceptance (pre-constituted evidence), based on your consent to process sensitive data (LGPD art. 11, I) and on the regular exercise of rights in legal proceedings (art. 11, II, "d").
  • How it works: each record is chained to the previous one through the preceding record's code, so removing, reordering, or altering any past record makes the chain inconsistent and detectable. For the same reason, records are only appended, never edited or deleted.
  • Retention: we keep the records while the contracts they refer to may still be disputed, observing the applicable statutes of limitation, and delete them afterwards.
  • Withdrawal: you may withdraw this consent at any time, and no new record will be generated from then on. Records already generated remain, because they are precisely the proof of the contracts you have already accepted; deleting them would also erase your own evidence. As they contain no readable biometric data, keeping them does not re-expose your biometrics.
  • This consent is independent: refusing or withdrawing it does not prevent your sign-up, your use of the Platform, or the execution of contracts.

Preliminary wording, drafted by the engineering team and pending legal review before final publication. The retention periods and the legal basis in this section 3.1 must be confirmed by counsel.

4. Why we use your data (purposes and legal bases)

We process personal data for the purposes below, each supported by an LGPD legal basis:

  • Create and manage your account and provide the Platform: performance of a contract.
  • Generate, refine, and deliver your digital representations and images from uploaded media: performance of a contract and, for biometric data, consent.
  • Process payments, Starcoins, and payouts between influencers and companies: performance of a contract and legal/regulatory obligation.
  • Ensure security, prevent fraud and abuse, and comply with legal obligations: legitimate interest and legal compliance.
  • Improve the Platform, run aggregate analytics, and develop new features: legitimate interest, respecting your rights and expectations.
  • Send operational communications and, with opt-in, marketing communications: performance of a contract and consent.

5. Processing for AI generation

The images you upload are processed by artificial intelligence models to generate visual content (for example, new poses, outfits, and scenes) while preserving your identity and natural marks. This processing may occur on AI infrastructure providers we engage, acting as processors under our instructions.

  • We use your data to generate content you request or, for campaigns, content you authorize under a contract with a company.
  • We do not use your images to train third-party AI models or general-purpose models outside the scope of your own digital representation, absent specific consent.
  • AI-generated content may contain imperfections and is not a real photograph; we treat fidelity to your identity as a core requirement, but the output is an AI-assisted creation.

6. Who we share data with

We do not sell your personal data. We may share it in the following situations:

  • Processors and service providers: cloud infrastructure, AI processing, payment processors, email, analytics, and support, always contractually bound to process data only on our instructions.
  • Between campaign parties: strictly necessary data may be shared between an influencer and a contracting company to perform a contract.
  • Legal compliance: public authorities, when required by law, court order, or to defend rights.
  • Corporate transactions: in a merger, acquisition, or reorganization, data may transfer to the successor, subject to this Policy.

7. International data transfers

Some of the AI processing and cloud infrastructure providers we use are located outside Brazil, including in the United States. In such cases, international transfers occur under the conditions and safeguards of Chapter V of the LGPD, adopting contractual clauses and adequate measures to protect your data at the level guaranteed in Brazil.

8. How long we keep your data

We retain personal data for as long as necessary to fulfil the purposes for which it was collected, under the following criteria:

  • Account and profile data: while the account is active.
  • Images and biometric data: while necessary to provide the service or until consent is withdrawn, whichever comes first.
  • Transaction and billing data: for the periods required by tax and accounting law.
  • Application access logs: for the minimum legal period under the Internet Civil Framework.

Once the period or purpose ends, data is securely deleted or anonymized, except where retention is permitted by law.

9. How we protect your data

We adopt technical and organizational measures to protect personal data against unauthorized access, loss, alteration, or improper disclosure, including encryption in transit and at rest for sensitive data, role-based access control, audit logging, and environment segregation.

No system is completely immune to incidents. If a security incident occurs that may pose relevant risk or harm to you, we will notify you and the Brazilian Data Protection Authority (ANPD) as required by the LGPD.

If you identify a vulnerability or suspect a security incident, please report it to us as soon as possible at [email protected].

10. Your rights as a data subject

Under Article 18 of the LGPD, you may, at any time and upon request, exercise the following rights:

  • Confirm that processing exists and access your data.
  • Correct incomplete, inaccurate, or outdated data.
  • Request anonymization, blocking, or deletion of unnecessary data or data processed unlawfully.
  • Request portability of your data to another provider.
  • Obtain information about the sharing of your data.
  • Withdraw consent and be informed of the consequences of refusal.
  • Object to processing based on legitimate interest.

To exercise your rights, contact our DPO at [email protected]. We may request additional information to confirm your identity. You may also petition the ANPD.

11. Cookies and tracking technologies

We use cookies and similar technologies for authentication, security, preferences, and usage analysis. For details on which cookies we use and how to manage them, see our Cookie Policy.

12. Children and adolescents

The Platform is intended solely for people aged 18 or over. We do not knowingly collect data from minors. If we identify a minor account, we will delete the data and close the account. If you believe a minor has provided us data, contact [email protected].

13. Changes to this Policy

We may update this Policy from time to time. The version in force is always the one published on this page, with the "Last updated" date shown at the top. Material changes will be communicated by reasonable means. Continued use of the Platform after an update represents agreement with the revised Policy.

14. Contact us

Questions, requests, or complaints about this Policy or the processing of your data may be sent to our DPO:

  • Email: [email protected]
  • Controller: [LEGAL ENTITY NAME], CNPJ [CNPJ]
  • Address: [FULL ADDRESS]

Highlighted bracketed sections will be completed by the legal team before publication.

Privacy Policy · STARHASH