LEGAL · PRIVACY

Privacy Policy

This Policy explains how Starry Night (SilverRiver) collects, uses, stores, discloses, and protects personal data in its consumer services, and how you can exercise your privacy rights.

Last updated
2026-09-30

1. Scope

This Policy applies to the Starry Night website, interactive stories, accounts, community and comment interactions, cloud progress, points, subscriptions, and other consumer-facing services. Separate rules may apply to administration accounts, personnel, or business partners.

This Policy is a privacy notice. It does not treat every processing activity as consent-based. Where separate consent is required, we will provide a specific notice and choice in the relevant feature.

2. Personal data we collect

  • Account and authenticationEmail address, display name, avatar, account identifiers, verification status, sign-in and session data. Better Auth handles password authentication on our application server; plaintext passwords are not stored in business records.
  • Birth year and monthWe use the birth year and month you provide to determine which story ratings you may access. We do not collect the exact day of birth, and you may correct this information in Account.
  • Third-party sign-inIf you choose Google or Apple sign-in, we receive data within the permission scope, such as an account identifier, email address, name, avatar, or Apple private relay address.
  • Public interactionsCommunity posts, comments, replies, likes, images attached to posts or comments, and the display name and avatar shown with them. The interface identifies the audience before you submit a public interaction.
  • Stories and gameplayStories and chapters opened, chapter entitlements, reading progress, cloud saves, story runtime data, player name, sync status, and conflict-resolution records.
  • Transactions and supportWhen those features are live, this may include points, subscriptions, orders, refunds, ledger records, and information you provide to support. Full payment credentials are handled by the actual payment provider under its policy.
  • Technical and security dataOur servers and infrastructure providers may automatically process IP address, browser and device type, operating system, access time, request identifiers, errors, and security events to deliver, troubleshoot, secure, and prevent abuse of the Services.

3. Cookies and local storage

You can clear local data in your browser settings, but clearing essential cookies signs you out and clearing unsynced saves may lose progress. The Services do not currently configure advertising cookies or cross-site behavioral advertising. If non-essential analytics or advertising technologies are introduced, we will update this notice and obtain consent where required.

  • Essential sign-in cookies`sr_user_session` and any chunked cookies maintain sign-in, refresh sessions, and protect accounts. They are necessary to provide the service you request.
  • Local preferences and savesLocal Storage, Session Storage, and IndexedDB may hold language, game-engine preferences, unsynced progress, and local saves.
  • Resource cachesCache Storage and browser caches may hold chapter resources and character avatars to avoid repeated downloads and provide more reliable play.

4. How we use personal data

  • Provide the ServicesCreate and manage accounts, authenticate users, sync progress, deliver stories, support community and comment interactions, and process transactions.
  • Personalize your experienceDisplay your name and avatar, restore play state, and remember language and essential preferences.
  • Security and operationsValidate requests, rate-limit abuse, diagnose errors, protect accounts, maintain availability, and keep necessary audit records.
  • Communications and performanceSend verification, password reset, transaction, and important service messages, and respond to questions and rights requests.
  • Legal obligationsComply with accounting, consumer protection, cybersecurity, privacy, and other applicable law, and handle disputes or lawful requests.

5. Public content and other users

Public community posts, comments, replies, images attached to posts or comments, display names, and avatars may be viewed, quoted, or shared by anyone who can access the relevant page. Do not post unnecessary real names, contact details, addresses, identity documents, financial, health, or other sensitive information, or another person's data without authority.

When you close your account or request deletion, we generally delete or de-identify public content that remains linked to you. If limited content must be retained to preserve conversation context, investigate abuse, resolve disputes, or meet legal duties, we limit what is retained and remove account identifiers that are no longer needed.

6. Service providers and disclosures

We do not disclose personal data to unrelated third parties except at your direction, as necessary to provide the Services, to address lawful requests, to protect users and the Services, or in a lawful merger, acquisition, or asset transfer. We do not currently sell personal data or share it for cross-site behavioral advertising.

  • Better Auth and PostgreSQLBetter Auth provides account authentication and session management on our application server. PostgreSQL stores account and service data; its location depends on the region configured for production hosting.
  • Cloudflare R2Stores files needed for stories, community, and account features. Some public assets may be cached through a content delivery network.
  • VercelHosts the website and handles server requests; it may process IP addresses, device and browser data, request times, and security logs.
  • Cloudflare TurnstileWhen human verification is enabled, it helps detect automated traffic and protect sign-up, sign-in, and password reset. Cloudflare may process IP addresses, browser and device signals, and verification results.
  • Google and AppleUsed only when you actively choose the corresponding OAuth sign-in method and authorize account data to be returned.
  • Necessary operational providersProduction hosting, content delivery, email, payment, support, or security vendors may process data only as needed to provide their contracted service. The production list must be confirmed and maintained before launch.

8. Retention

  • Accounts and profilesGenerally retained until the account is closed or deletion is requested, after which data no longer needed is deleted or de-identified.
  • Public content and cloud progressGenerally retained until you delete the content or save, close the account, or the relevant service ends, subject to the limited cases in section 5.
  • Orders, ledgers, and refundsRetained for applicable accounting, tax, consumer protection, fraud prevention, and dispute periods. Closing an account does not erase financial records we must legally retain.
  • Security, error, and audit logsKept for the shortest period needed for abuse prevention, troubleshooting, incident investigation, and provider-plan requirements, with extensions where an incident or law requires it.
  • Backups and local dataBackups age out through normal rotation. Browser-local data normally remains until you clear site data, the browser removes it, or the Services clear it.

9. International data transfers

Providers, project regions, CDN nodes, or support personnel may be outside your country or region. Before a transfer, we assess necessity, recipients, data categories, storage location, and safeguards, and use data processing agreements, standard contractual terms, access controls, encryption, or other appropriate measures as applicable.

When personal data from the European Economic Area, United Kingdom, or Switzerland is transferred to a location not recognized as providing adequate protection, we use the EU Standard Contractual Clauses, the UK Addendum, or another valid transfer mechanism where applicable, and assess whether supplementary safeguards are needed.

10. Data security

We use technical and organizational measures proportionate to risk, including encryption in transit, session protection, role- and row-level access controls, private storage and time-limited access, least privilege, audit records, backups, and incident response. No measure guarantees absolute security. If an incident may affect your rights, we will remediate and notify as required by applicable law.

11. Your rights

Depending on applicable law, you may have rights to know or access, correct, copy or export, delete, restrict or object, withdraw consent, close your account, and complain to a regulator. You may also request an explanation or object to a solely automated decision that significantly affects you.

Users in the European Economic Area, United Kingdom, or Switzerland may also complain to their local data protection authority. Where a U.S. state privacy law applies, users may have additional rights to know data categories, correct or delete data, obtain a copy, opt out of sale or targeted-advertising sharing, limit sensitive-data use, and appeal a denied request. We do not currently sell personal data or share it for cross-site behavioral advertising.

Submit requests through the support channels made available in the Services. We may verify account control or identity and collect only what is necessary for verification. If law allows us to refuse or limit a request, we explain the reason and any available appeal.

12. Children

There is no minimum age to create an account. Story access is rated using birth year and month: users under 14 cannot enter stories, users aged 14–17 can enter regular stories only, and users aged 18 or older can enter stories marked 18+.

We use birth year and month only for content ratings and related safety controls. Where applicable law requires additional measures for minors' data, we will restrict affected features, delete data, or take other appropriate steps as required.

13. AI-assisted features

If AI-assisted features are later offered to consumers, we will explain the purpose, data scope, provider, and available choices before data is sent to the actual AI provider. Unless we separately and clearly disclose it and obtain consent where required, we do not use private account data, cloud saves, or unpublished content to train general-purpose AI models.

14. Changes and contact

We may update this Policy when the Services, providers, or law change and show the last-updated date at the top. We will separately notify you of material changes by an in-product notice, email, or another appropriate method. A new purpose requiring consent is not accepted merely because you continue using the Services.

For questions about this Policy, our processing, or a rights request, use the support channels made available in the Services.