Privacy Policy
Last updated: 2026-07-14
This Privacy Policy describes how Star Avatars ("we", "us") handles information when you visit our website or request avatar images from the Service.
What we collect
The avatar API is anonymous. We do not require accounts, and we do not set authentication cookies for image requests.
- Seed strings in URLs. The path and query parameters you request (for example /[email protected]?size=64) are processed to generate the image. Do not put passwords, API keys, or other sensitive secrets in seed strings — they appear in URLs, logs, and referrer headers when hotlinked.
- IP addresses. We use your IP address for rate limiting (currently 120 requests per minute per IP) and abuse prevention. Rate-limit counters are temporary.
- Server logs. Our hosting infrastructure may log request metadata such as timestamp, URL, user agent, and response status for operations and security.
- Generated image cache. Avatar output may be cached server-side to improve performance. Cached entries are keyed by request parameters, not tied to personal identity.
What we do not collect
- Names, email addresses, or payment information through the avatar API
- Cross-site tracking or advertising profiles
- Intentional collection of children's personal information
How we use information
We use the information described above to deliver avatar images, enforce rate limits, maintain security, diagnose errors, and improve reliability. We do not sell your data.
Third parties
The marketing homepage may load fonts from Google Fonts. When you hotlink avatar URLs into your own site, your users' browsers contact our servers directly; your application's privacy practices also apply.
We use infrastructure providers to host the Service. They process data on our behalf under their own privacy and security terms.
Retention
Rate-limit data is kept only as long as needed for throttling. Server logs and caches are retained for limited periods appropriate to operations and then rotated or deleted.
Your choices
Use non-sensitive seed values. If you cannot accept URL-based processing or IP rate limiting, do not use the hosted Service — you may self-host the open-source project instead.
Changes
We may update this policy from time to time. The "Last updated" date at the top will change when we do.
Contact
Privacy questions: [email protected]