Trust & transparency

Security and privacy

Plain-language details about what Star-Launcher can access, what leaves your computer, and how each official release is checked.

What the application does

Star-Launcher coordinates user-selected game launch methods, controller preparation, companion applications, keybind charts, and web resources. It can start local programs and Steam launch commands that you configure. It does not replace official game launchers or bypass their security requirements.

Star-Launcher normally runs with your Windows user permissions. It requests a normal Windows administrator prompt only when you explicitly enable an action that needs it, such as applying certain controller settings or starting a verified third-party installer. Star-Launcher cannot approve that prompt for you.

Local data

Application settings are stored under %APPDATA%\Star-Launcher. They include game settings, controller presets, local application paths, preferences, and captured window positions. Star-Launcher does not provide an account system or store game passwords, two-factor codes, or payment information.

Settings > Preferences > Delete all saved app data removes Star-Launcher settings after confirmation and removes its current-user Windows startup entry.

Network connections

The application can contact the official Star-Launcher website to check the stable update feed and download an update you approve. The optional controller-tool update screen checks the official GitHub releases for vJoy, HidHide, and Joystick Gremlin only when you open that workflow. Web resources open in your selected browser.

The desktop application contains no advertising SDK, telemetry SDK, crash-reporting service, or background analytics client. The public website uses Cloudflare Web Analytics for aggregate visits and page views; that website measurement is separate from the desktop application.

Release and update safeguards

Official portable releases contain a small expected file set and publish SHA-256 fingerprints for the executable and ZIP. The in-app updater requires HTTPS on star-launcher.com, validates update metadata, download size, and SHA-256, rejects unsafe ZIP paths or unexpected package contents, and keeps rollback copies while replacing portable application files. User settings are stored outside that replacement set.

Starting with version 5.0.2, automatic controller-tool installer downloads must come from the approved official GitHub release repository, pass Windows Authenticode trust validation, and match the expected publisher. Unsupported or unverifiable releases remain manual-only.

Version 5.1.1 publishes an automated test summary, SPDX dependency inventory, and Microsoft Defender scan result tied to its exact hashes. The scan is one antivirus-engine result, not an independent source-code audit.

Checksums prove that two files are identical; they do not by themselves prove who created the software. Star-Launcher releases are not yet Authenticode-signed. Code signing is planned as an additional publisher-identity safeguard.

AI-assisted development

AI tools may assist with implementation, testing, documentation, and review. Feature decisions, security scope, release approval, packaging, and publication remain under human direction. AI output is not treated as an independent security audit. Stable releases must pass repeatable tests and artifact checks, and security-sensitive changes receive focused review.

Report a vulnerability

Email star.launcher.support@gmail.com with the subject SECURITY: Star-Launcher vulnerability report. Include the version, affected feature, reproduction steps, practical impact, and sanitized evidence.

Never send passwords, authentication codes, API keys, donor information, or unrelated personal files. Please do not publicly disclose an unpatched issue before there has been a reasonable opportunity to investigate and correct it. The project aims to acknowledge reports within three business days and provide a status update at least every seven days while actively investigating.

Limits of this information

No software can honestly be described as risk-free. These statements describe the supported release and are reviewed when security-relevant behavior changes. Third-party games, launchers, controller tools, and websites remain governed by their own publishers and security practices.