← Back to Luna
Privacy Policy
Last updated: July 1, 2026
TL;DR: Luna keeps your cycle records on your device. We do not require an account, we do not sync your logs to a cloud server, and we do not monitor your habits. Your cycle stays on your phone.
Medical Disclaimer: Luna is a personal tracking and planning tool. It is not a medical device and does not diagnose, treat, prevent, or monitor any medical or reproductive health condition. Always seek professional advice from a licensed healthcare provider regarding medical concerns.
1. What Data Luna Collects
All logs you enter into Luna are stored exclusively in the app's local database on your device hardware. This includes:
- Your period dates, cycle patterns, and logs.
- Flow intensity levels and irregular cycle markings.
- Daily symptoms (13 categories) and mood states (7 options).
- Private notes (a completely un-analyzed text journal).
Luna processes this data in real-time, on-device, in milliseconds. No server calculations or external processing models are involved in analyzing your cycle inputs.
2. Where Your Data Lives
On your device. Luna does not maintain a server-side database for normal cycle tracking. There are no web accounts, no username/password registration requirements, and no server sync.
If you decide to backup or export your records, you create the backup file (encrypted using AES-256) locally. You are in complete control of where that file is stored (e.g., local storage, email, or a third-party cloud drive).
3. Secure Offline Partner Sharing
Luna Plus includes a Partner Share Mode. This feature is designed to share cycle phases with a partner while maintaining total confidentiality:
- The sharing is done using peer-to-peer offline mechanisms (or end-to-end encrypted direct data paths) without intermediate cloud server aggregation.
- Your partner only sees your current/upcoming cycle phase name and phase-aware helpful tips.
- Your partner never has access to your private symptom list, mood states, log intensity, calendar details, or personal journal notes.
4. Analytics, SDKs, and Surveillance
Luna is completely ad-free and is not integrated with behavioral profiling networks or data broker SDKs. We do not run background telemetry to track app engagement habits or cycle patterns.
5. How Luna Uses the Internet
Luna is designed to function entirely offline. The app uses the internet for only two things:
- Retrieving critical app updates from Google Play.
- Verifying subscription state and billing token verification with Google Play's billing APIs when subscribing to Luna Plus.
Your reproductive data, private notes, and health logs are completely isolated from network requests.
6. App Permissions & Hardware Access
To operate securely, Luna requests minimal system permissions:
- POST_NOTIFICATIONS: To dispatch local push alerts for upcoming cycles. Notifications are scheduled locally and are not managed by a push notification server.
- USE_BIOMETRIC / USE_FINGERPRINT: To lock the app locally. Biometric authentication is handled securely by Android's keystore APIs; Luna never accesses your biometric data.
- SCHEDULE_EXACT_ALARM: To deliver period notifications exactly at the configured time.
- RECEIVE_BOOT_COMPLETED: To reschedule local notifications when you restart your phone.
7. Data Retention & Deletion Rights
Because Luna has no access to your data, you hold full administrative power over your files:
- Retention: Your data remains on your hardware for as long as you keep the app installed. There is no automatic expiration.
- Deletion: You can wipe all logs instantly in the app using Settings → Clear All Data, or by uninstalling Luna. Once deleted, the records are gone forever and cannot be recovered by us.
- Portability: You can export a full backup of your records as a CSV or JSON file anytime via the backup settings page.
8. GDPR and Regional Protections (EU & US)
For users in the European Union (under GDPR) and the United States (including state reproductive data laws like CPRA and Washington's My Health My Data Act):
Our local-first structure aligns directly with data minimization standards. Because your data does not populate external databases, you maintain permanent sovereignty over your personal records. There is no need to file a "right to be forgotten" or "data erasure" request with us, as you can erase all data directly from your device at any time.
9. Contact
If you have any questions or feedback regarding this policy, please reach out to us at:
support@rahatlabs.com