Privacy Policy — Lunoria
English version 1.3 · Effective date: 2026-08-06 · Applies to the Lunoria application (web/PWA + iOS/Android) · Available languages: polski, Deutsch, français, español (see "Language of this Policy" in Section 13 below).
1. Who is the controller of your data
The controller of personal data within the meaning of Article 4(7) GDPR is:
LUMA Sp. z o.o. (full name: LUMA Spółka z ograniczoną odpowiedzialnością, a
Polish limited liability company)
registered office in Warsaw, ul. Gawronia 15, 04-785 Warsaw, Poland
entered in the National Court Register (KRS) under number: 0001244636
Tax Identification Number (NIP): 9522285489, National Business Registry Number (REGON):
544875680
contact email for data-protection matters:
[email protected]
2. What Lunoria is (processing context)
Lunoria is a conversational entertainment application — an AI astrologer, tarot reader, and numerologist. Lunoria is for entertainment purposes only and does not replace medical, financial, legal, or psychological advice. Content (horoscopes, tarot readings, numerology, chat responses) is generated by an artificial intelligence model based on information you provide.
Local-first architecture, as a matter of technical fact. Your birth data (date, and optionally time and place of birth) and the content of your conversations with Lunoria are stored only on your device (in your browser's/app's storage) and are not saved in our database. When you have a conversation, its content is transmitted in real time through our intermediary (stateless proxy) server solely to pass it to the AI model and return the response to you — our server does not store the content of that conversation or your birth data. The AI model provider (Anthropic, USA) processes this data under a data processing agreement (DPA) and the cross-border transfer mechanism described in Section 6, and by default retains it for up to 30 days on its own servers for safety/legal-compliance purposes, unless we are using a Zero Data Retention arrangement.
Daily horoscope notifications — the same local architecture. If you enable the daily horoscope reminder in Settings, the schedule for that notification (the date and time it is shown) is planned and stored only on your device, using the native mechanism of the operating system (iOS/Android) — we do not use any external push-transmission service (we do not register your device with Firebase Cloud Messaging, the Apple Push Notification service, or the Expo Push Service), and we do not generate any device token associated with this feature. The notification's content is generic and identical for all users of a given language (e.g., "Your horoscope for today is ready") — it does not include your zodiac sign or any other personalized content, partly so that it remains uninformative to anyone glancing at your phone's lock screen. Luma does not know on which device this feature is enabled, or which zodiac sign is associated with it — the only information that reaches us in connection with this feature is the single timestamp described in Section 3 below, used solely to measure the feature's effectiveness.
Note on special categories of data (Article 9 GDPR / equivalent US and Australian concepts of sensitive information). A request for a horoscope, tarot reading, or numerology analysis, by itself, is not treated as revealing "religious or philosophical beliefs" within the meaning of Article 9 GDPR. However, free-form conversation with Lunoria may incidentally reveal sensitive information (e.g., about health, sexual orientation, or beliefs) — the local-first architecture minimizes this risk at the source (no persistent storage on our side), but does not eliminate in-transit processing by the AI model provider. This qualification is confirmed for the EU/GDPR framing in this Section, and separately for US law (California's statutory definition of "sensitive personal information") in Section 14 below. This assessment applies equally to the content of the push notifications described above, for the same reasons (generic content, independent of zodiac sign, with no diagnostic or evaluative element).
3. What data we process, for what purpose, and on what legal basis
| Category of data | Examples | Purpose of processing | Legal basis (GDPR) |
|---|---|---|---|
| Anonymous session identifier |
A non-meaningful, randomly generated technical identifier (UUID) assigned by Supabase
Auth on first launch of the Application (the signInAnonymously()
function) — without an email address, password, name, or any
registration. Lunoria does not offer user accounts or login.
|
Enforcing monthly plan limits, linking subscription/entitlement status to your device | Article 6(1)(b) GDPR — performance of a contract |
| Email address (web-channel purchases only) | An email address provided when purchasing a subscription on lunoria.lumasoft.pl — solely for the payment processor's needs | Issuing a payment confirmation/receipt through the payment processor (Stripe); this does not create an account in the Application — see the sub-processor table in Section 6 | Article 6(1)(b); accounting records — Article 6(1)(c) |
| Birth data | Date, and optionally time and place, of birth | Astrological/numerological calculations necessary to generate a reading | Article 6(1)(b) — processed in transit, not stored server-side (Section 2) |
| Content of your conversation with Lunoria | Chat messages, questions, AI responses | Generating a response; potentially Article 9(2)(a), when content incidentally reveals sensitive information (Section 2) | Article 6(1)(b), combined with Article 9(2)(a) where applicable |
| Payment data | Subscription status, transaction history (RevenueCat/Stripe/Apple/Google) | Managing Plus/Premium subscriptions and top-up purchases | Article 6(1)(b); accounting records — Article 6(1)(c) |
| Content reports (trust & safety) | The quoted excerpt of an AI message you reported (the "Report" button) and the reason for the report | Handling reports of inappropriate AI-generated content (a requirement of Google Play's policy on moderating generative content), moderation, abuse prevention | Article 6(1)(f) — legitimate interest (ensuring the safety and quality of AI-generated content, meeting app-store requirements on moderating generative content, preventing abuse) |
| IP addresses / technical infrastructure logs (Supabase/hosting) | IP address, request timestamp, user agent — generated automatically by the hosting infrastructure while handling requests | Security, abuse prevention, detecting and countering attacks | Article 6(1)(f) — legitimate interest (infrastructure security) |
| Diagnostic / telemetry data (Sentry) | Device model, operating system version, Application version, language/locale, an approximate geolocation derived from the IP address (at country/city level), an anonymous session identifier (UUID), and, for errors reading from local device storage, the name of the storage and the type of operation | Detecting, diagnosing, and fixing technical crashes; keeping the Application stable | Article 6(1)(f) — legitimate interest (Application security and stability, on the same footing as the infrastructure technical logs above) |
| Subscription event log (RevenueCat event log) | Event identifier, event type, store (App Store/Google Play/Stripe Web Billing), app_user_id | Payment reconciliation, subscription auditing, fraud/abuse detection | Article 6(1)(b)/(f) |
| Push notification consent and its timestamp |
A single timestamp (the profiles.local_reminder_enabled_at column),
recorded once — the moment your device schedules the local, daily horoscope
reminder — and never overwritten afterwards. We do not record whether the
notification was displayed or tapped. The notification's own schedule and content
remain only on your device (Section 2) and are never sent to us.
|
Demonstrating that you gave consent to this feature (consent record, Article 7(1) GDPR); solely measuring the effectiveness of this product feature (whether the reminder increases next-day return to the Application) — not profiling, not content personalization, and no marketing beyond the notification itself | Article 6(1)(a) GDPR, together with Article 398 of the Polish Law on Electronic Communications (your consent to communications sent to a telecommunications end-device) — for the reminder feature itself; Article 6(1)(f) GDPR — our legitimate interest in demonstrating consent and measuring the feature's effectiveness, as regards the timestamp itself |
4. AI transparency (EU AI Act, Article 50; US B.O.T. Act)
Lunoria displays a persistent, visible message informing you that you are talking to an artificial-intelligence system, not a human, in every chat session and with every generated reading (horoscope, tarot, numerology). This satisfies both the EU AI Act (Regulation (EU) 2024/1689, Article 50) and, for users in California, the "B.O.T. Act" (Cal. Bus. & Prof. Code §§ 17940–17943) — see the Terms of Service, Section 8, for the exact places this disclosure appears in the Application. AI-generated content may contain errors or inaccuracies.
5. Automated decision-making
Lunoria's readings and responses are generated by an artificial intelligence model (Anthropic Claude). This is not an automated decision producing legal or similarly significant effects within the meaning of Article 22 GDPR — the content is for entertainment purposes only, and any life decisions are made solely by you, at your own responsibility.
6. Who we share data with — recipients, sub-processors, and independent controllers
We work with trusted providers. Most of them act as processors within the meaning of Article 28 GDPR, with whom we have entered into, or will enter into, data processing agreements (DPAs). Apple and Google are the exception — for native-channel subscription billing (in-app purchases), they act as independent data controllers (Article 4(7) GDPR) — they are not our processors, and processing of transactional data takes place under their own privacy policies and their own controller responsibility. Each entity's role is indicated in the "Role" column below:
| Entity | Role | Location / region | Cross-border transfer mechanism (outside the EEA) |
|---|---|---|---|
| Supabase | Processor (Article 28 GDPR). Managing anonymous technical sessions (Auth, without email/password) and subscription limit/entitlement state. Lunoria's Supabase project has no content tables — it does not store birth data or conversation content. | EU (region to be confirmed with the final project configuration — recommendation: Frankfurt/eu-central-1, consistent with Luma's other products) | SCC in the agreement with Supabase, where sub-processors outside the EEA are used |
| Anthropic (Claude) | Processor (Article 28 GDPR). Generating chat responses, horoscopes, tarot readings, and numerology analyses based on content sent through our stateless proxy — the only AI provider processing your data in real time | USA | Standard Contractual Clauses (SCC, Module 2/3, Decision 2021/914); a data processing agreement (DPA) is being finalized — the status of EU-US Data Privacy Framework (DPF) certification is to be confirmed at source (no unambiguous confirmation of formal certification was found). Anthropic's default retention: up to 30 days, absent a separate Zero Data Retention agreement. For US users, this same relationship is additionally addressed by California's sensitive-personal-information framework in Section 14. |
| RevenueCat | Processor (Article 28 GDPR). Subscription management, synchronization of Plus/Premium entitlements | USA (global infrastructure) | SCC / DPF, where applicable |
| Stripe | Processor (Article 28 GDPR). Card payment processing (web billing, RevenueCat Web Billing) | USA / Ireland (Stripe Payments Europe) | SCC for transfers to the USA, where applicable |
| Apple / Google | Independent data controller (Article 4(7) GDPR) — NOT a processor. Native-channel subscription billing (in-app purchases), under the relevant store's own rules; Apple/Google independently decide the purposes and means of processing transactional data and bear their own controller responsibility for it. | Global (Apple/Google) | Per Apple's/Google's own privacy policies as independent controllers |
| Microsoft (Microsoft 365 / Microsoft Graph API) | Processor (Article 28 GDPR) — infrastructure deployed, currently inactive. Technical backend for sending transactional emails related to a possible, optional email-login mechanism (confirmation, login link, password reset) from [email protected] is deployed (Supabase Auth "Send Email Hook"), but the Application does not currently offer registration, a password, or email login — it operates only on anonymous technical sessions (Section 3), so this mechanism is not currently triggered by any feature of the Application, and no email address of yours currently reaches Microsoft this way. If we offer such an optional feature in the future, this Policy will be updated before it launches. | Microsoft 365 infrastructure (tenant region to be confirmed — EU/global) | SCC / DPF, where a transfer outside the EEA applies |
| Sentry (Functional Software, Inc.) | Processor (Article 28 GDPR). Crash diagnostics and keeping the Application stable — automatic reporting of technical errors. Categories of data processed: device model, operating system version, Application version, language/locale, an approximate geolocation derived from the IP address (at country/city level), an anonymous session identifier (UUID), and, for errors reading from local device storage, the name of the storage and the type of operation. The content of your conversations with Lunoria and your birth data are not sent to Sentry — the Application is configured not to send full personal data and to strip request bodies, parameters, and any authentication tokens from every report before it is sent. Legal basis: Article 6(1)(f) GDPR — the controller's legitimate interest in keeping the Application stable, secure, and quick to repair when it fails, on the same footing as the infrastructure technical logs in Section 3. | EU (Germany) — Sentry's organization operates in the EU region, with its event ingestion point in Germany | Not applicable — processing takes place entirely within the EU, with no transfer outside the EEA |
We do not sell your personal information to any third party, and we do not disclose it for marketing purposes without your consent. For US consumers, see the more specific "we do not sell or share" statement in Section 14.
7. How long we keep your data
| Category of data | Retention period | Justification |
|---|---|---|
| Birth data / conversation content | Not stored server-side by Luma (lives locally on your device, at your discretion) | Local-first architecture (Section 2) |
| The same data on Anthropic's side (in transit) | Up to 30 days by default, without Zero Data Retention | Anthropic's retention policy for safety/legal-compliance purposes |
| Anonymous session identifier / limit and entitlement state | For as long as the Application is actively used on a given device. The message-limit usage counter is deleted after 48 hours (an anti-duplication window, not an audit log); unused top-ups expire after 12 months of inactivity. You can also delete the session identifier immediately and yourself, at any time — using the "Delete account" feature described in Section 8 below | Performance of a contract (Article 6(1)(b) GDPR); no data identifying a person |
| Billing data | 7 years | Tax and accounting obligations (Article 6(1)(c) GDPR) |
| Content reports (trust & safety) | Intended: until the report is resolved, plus 12 months. Implementation status: we have not yet configured an automatic, technical mechanism for deleting reports after that period — until it is implemented, deletion/anonymization of older reports is handled manually as part of a periodic data review. Treat the above period as our retention goal, not as a currently technically enforced limit | Time needed for moderation, and an evidentiary period in case of an appeal against a moderation decision or a dispute about reported content |
| IP addresses / technical infrastructure logs | Per the hosting provider's default policy — to be confirmed, typically 30–90 days | Security, abuse prevention (Article 6(1)(f) GDPR) |
| Diagnostic / telemetry data (Sentry) | Per Sentry's default retention policy for the plan we use — the exact period is to be confirmed with the provider before this entry's draft status is fully lifted. We deliberately do not state a number of days here until it is expressly confirmed in the provider's configuration/agreement | Application security and stability, crash diagnostics (Article 6(1)(f) GDPR) |
| Subscription event log (RevenueCat event log) | 30 days | Payment reconciliation and subscription auditing |
Because conversation content and reading history are not stored on our side (local-first architecture, Section 2), you can delete them yourself by clearing your device's/browser's local storage — the "Clear all history" feature in the Application's Settings, available immediately and without any request to us. This feature deliberately does not delete your birth data or your session identifier on our side — that is what the "Delete account" feature is for (both features are described in full in Section 8 below).
Content reports you have submitted are kept for the period shown in the retention table above under Article 17(3)(e) GDPR (establishment, exercise, or defence of legal claims, and the integrity of the moderation process) — after that period they are deleted or anonymized, as the automation described in the table above is rolled out.
8. Your rights
Under GDPR, you have the rights listed below. Exercising them looks different than in a typical app with a user account — we explain this directly, rather than describing an identity-verification procedure that cannot, technically, be carried out for anonymous sessions.
- Access to data (Article 15) — data we actually keep on our side (your subscription limit/entitlement state, any content report you submitted) is not linked to your identity (see the reservation above). All data that actually defines your experience in the Application (birth data, reading and conversation history) is already exclusively in your possession — on your device; the "Export data" feature described below gives you a full, immediate copy of it.
- Rectification of data (Article 16) — you correct your birth data and settings directly in the Application; we do not keep any other personal data on our side that would require correction.
- Erasure of data / the "right to be forgotten" (Article 17) — full description below.
How to delete your data (Lunoria has no "accounts" in the registration/login sense — only technical sessions and local data)
Lunoria does not offer registration or a password-based login, so there is no traditional "account" in that sense. In the Application's Settings, the feature named "Delete account" (in the "Danger zone" section) refers precisely to the anonymous technical session described in Sections 3 and 7. Here is a full breakdown of what you delete, and how:
- Conversation content and reading history — 100% local, on your device: Settings → "Privacy and Security" → "Clear all history" → confirm. Deletion is immediate, carried out entirely on your device, and does not require any request to us — this data was never permanently stored on our side (Section 2). This feature deliberately does not delete your birth data or your session identifier on our side — see the next item for that.
- Birth data, the anonymous session identifier, and the related limit/entitlement state on our side — account deletion: Settings → "Danger zone" → "Delete account" → check the box confirming you understand the operation is irreversible → confirm. Deletion is immediate and fully self-service — it does not require any request to us. The operation permanently erases your anonymous session identifier from our servers, together with the related subscription limit/entitlement state and any content report you submitted (Sections 6 and 7), and additionally deletes your birth data, nickname, and full conversation and reading history from your device, then immediately signs you out. If the operation fails, try again shortly or write to [email protected].
- Billing data held by the payment processor (Stripe in the web channel; Apple/Google in the native channel) — these entities process transactional data as an independent controller (Apple/Google) or a processor (Stripe), under their own policies (Section 6); in the web channel, we will forward your request at your request to the address above.
https://lunoria.lumasoft.pl/en/privacy/#delete-data is a
functional, publicly accessible (accessible without logging in and without the app
installed) description of the user-data-deletion process — meeting Google Play's Account
& Data Deletion requirements and Apple App Review Guideline 5.1.1(v). Even though
Lunoria technically does not maintain user accounts within the meaning of those
requirements, the description above covers the full scope of data the Application actually
processes.
- Restriction of processing (Article 18).
- Data portability (Article 20) — the "Export data" feature in Settings generates a JSON file on your device containing all locally stored data (profile, conversation history, reading history, settings) — instantly, and without needing to contact us, because this data is already exclusively in your possession.
- Objection to processing based on legitimate interest (Article 21).
- Withdrawing consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Article 7(3)).
- Lodging a complaint with a supervisory authority — in Poland: the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, www.uodo.gov.pl. If you live in another EU country, you may lodge a complaint with the competent local authority (e.g., the BfDI in Germany, the CNIL in France, the AEPD in Spain). US, Australian, and Quebec residents have additional, specific complaint routes — see Sections 14, 15, and 16 below.
To exercise the rights above to the extent they require contacting us (see the Article 11 GDPR reservation above), write to: [email protected].
9. Minimum age
The Application may be used by individuals who are at least 16 years old. The statement of full date of birth made on first launch of the Application is verified only locally, on the User's device — it does not reach us and is not an identity verification (see Terms of Service, Section 3). If we learn that data of a person under 16 has nonetheless been processed, that data will be deleted.
10. Data security
We use appropriate technical and organizational measures, including: encryption of data in transit (TLS), an intermediary (proxy) server designed not to log the content of requests or responses (zero storage of content in the database, zero logging of content in monitoring systems), and role-based access control (Row Level Security) for anonymous session and subscription data stored in Supabase.
Safety mechanism for sensitive content. Lunoria includes an automated mechanism that recognizes, in conversation content, signals indicating a possible mental-health crisis — in that situation, the Application immediately displays the number of the appropriate support line for your country. This check happens entirely in memory (in-memory), while a given message is being processed, and does not result in any permanent record — we do not create or store any metadata about such an event (neither the content, nor a timestamp, nor a country) in our database. To the extent this ephemeral scan could constitute processing of health data (Article 9 GDPR), the legal basis is Article 9(2)(c) GDPR — protecting the vital interests of the data subject, in a situation where that person is physically or legally incapable of giving consent. This processing is momentary only (in-memory) and is not recorded or retained in any form.
11. Changes to this Privacy Policy
We will notify you of material changes to this Policy at least 30 days before they take effect (e.g., by email or an in-app notification). Continuing to use the Application after that date constitutes acceptance of the changes.
12. Contact
For data-protection matters: [email protected]
Controller: LUMA Sp. z o.o., ul. Gawronia 15, 04-785 Warsaw, Poland (KRS:
0001244636, NIP: 9522285489, REGON: 544875680)
13. Language of this Policy
Today, this Privacy Policy is published in five language versions: Polish, English, German, French, and Spanish, each equally authentic. Neither is a mere translation of another provided for informational purposes only. You may switch between the available language versions at any time. Where required by the law of your place of habitual residence, the version in your official language (where published) governs the assessment of our compliance with that law.
14. California and other US state privacy rights
If you are a resident of California or another US state with a comprehensive consumer privacy law, this section supplements the rest of this Privacy Policy and describes your additional rights.
Categories of personal information we collect. Based on the categories defined in Cal. Civ. Code § 1798.140, we collect: (a) identifiers (an anonymous session identifier generated by our authentication provider; your email address only if you purchase a subscription through our website); (b) commercial information (subscription and purchase history); (c) internet or other electronic network activity information (technical logs, IP address); and (d), only incidentally and never by design, information that may fall within the statutory definition of "sensitive personal information" under § 1798.140(v)(1)(K) — specifically, the content of your conversations with Lunoria, which you control and which may incidentally reveal your religious or philosophical beliefs, sex life or sexual orientation, or health information, because you chose to share it in a free-form chat. We do not ask for, categorize, profile, or use this information for any purpose other than generating your requested horoscope, tarot, numerology, or chat response, and we do not retain it on our servers (see Section 2, "Local-first architecture") except for a message you affirmatively submit through the "Report content" feature.
We do not sell or share your personal information for cross-context behavioral advertising, and we have not done so in the preceding 12 months.
Your rights. You have the right to: (1) know what personal information we have collected, used, disclosed, or sold about you; (2) delete personal information we have collected from you, subject to certain exceptions; (3) correct inaccurate personal information; (4) opt out of the sale or sharing of your personal information (not applicable — we do not sell or share); (5) limit the use and disclosure of sensitive personal information to what is necessary to perform the services you requested (which is already the only use we make of it, described above); and (6) not be discriminated against for exercising any of these rights.
How to exercise your rights. Because Lunoria does not use accounts, passwords, or email addresses to identify you (see Section 8, "Your rights," which explains the Article 11 GDPR limitation that applies equally here), we may not always be able to verify which session a request relates to. Contact us at [email protected] with as much detail as you can provide (e.g., the approximate date and content of a report you submitted), and we will act on your request to the extent we can locate corresponding data. You may also designate an authorized agent to make a request on your behalf, subject to our ability to verify that authorization.
Shine the Light (Cal. Civ. Code § 1798.83). We do not share your personal information with third parties for their own direct marketing purposes.
15. Australia — your Privacy Act rights
This section applies to residents of Australia and supplements the rest of this Policy. It describes how the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs) apply to Lunoria, and states plainly where we go beyond what the Act strictly requires of us.
What we do for Australian users regardless of the exemption. Consistent with the Australian Privacy Principles, we: collect only the categories of personal information described in Section 3 of this Policy, and no more than reasonably necessary for the purposes stated there (APP 3); do not use or disclose your personal information for a purpose other than the one for which it was collected, except as described in Section 6 or as required by law (APP 6); do not use your personal information for direct marketing without an appropriate basis (APP 7) — Lunoria does not currently send direct marketing communications; take reasonable steps to keep your personal information accurate, complete, and secure (APPs 10–11, and Section 10 of this Policy); and give you access to, and the ability to correct, the limited operational data we hold, on the same terms described for all users in Section 8 (APPs 12–13).
Overseas disclosure. As described in Section 6, your data may be processed outside Australia (in the EU and the United States) by our sub-processors. If the Privacy Act applies to us, APP 8 would require us to take reasonable steps to ensure an overseas recipient does not breach the APPs, and, in some cases, would make us accountable for that recipient's handling of your data as if it were our own act. We apply that same standard of care as a matter of policy, through the DPAs and Standard Contractual Clauses described in Section 6, regardless of whether APP 8 formally binds us today.
Notifiable data breaches. If we experience a data breach likely to result in serious harm to you, we will notify you and, where the Notifiable Data Breaches scheme applies to us, the OAIC, without undue delay.
How to complain. If you are unhappy with how we have handled your personal information, contact us first at [email protected]. If you are not satisfied with our response, and the Privacy Act applies to us, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
16. Quebec, Canada — Privacy Officer and Governance Policy
In accordance with Quebec's Act respecting the protection of personal information in the private sector ("Loi 25"), the person in charge of the protection of personal information for LUMA Sp. z o.o. is:
Our data governance framework includes: retention and destruction rules for the categories of personal information described in this Policy (see Section 7, "How long we keep your data"); defined roles for personnel who may access personal information; and a complaint-handling process — to file a complaint about how we handle your personal information, write to the address above; we will acknowledge your complaint and respond within a reasonable time. Where our processing involves the transfer of personal information outside Quebec (see Section 6, "Recipients and sub-processors"), we conduct a privacy impact assessment appropriate to the sensitivity of the information and the purpose for which it will be used, as required by Loi 25.