Lunas policy

Privacy Policy

How Lunas handles account data, health records, uploaded files, AI requests, sharing, and model-improvement choices.

Last updated: August 25, 2026

What Lunas collects

Lunas collects the account information needed to run the service, such as your email address, display name, plan, authentication records, and security events.

When you choose to use health-data features, Lunas may store uploaded files, extracted text, structured observations, timeline notes, patient records, and chat messages. These records can contain sensitive health information.

How Lunas uses your data

We use your data to provide Chat, Circle, Lab, timeline, file review, sharing, usage metering, support, security, and audit functions.

Lunas is designed so plan, role, ownership, and access checks are enforced server-side. Client-side UI controls are not treated as permission boundaries.

We do not sell sensitive health information or use it for advertising.

AI and model improvement

User health data is not used to train Stethos by default. Training eligibility requires explicit consent, de-identification, and human review before data can be approved for a training dataset.

Model providers may process prompts, retrieved context, and uploaded-file extracts to generate responses. Lunas minimizes unnecessary context and is intended to use provider retention and no-training controls where supported.

Sharing and access

You control whether personal timeline records are shared. Circle and Lab records are access-controlled and should only be shared with people who need to review them.

Audit records may be retained for security, legal, and compliance purposes for up to six years, even after user-facing records are deleted.

If you use Lunas for a covered entity or regulated health organization, you are responsible for having the right authorization, organizational approval, and business associate agreement when required before submitting protected health information.

Your choices

You can export your data yourself at any time: Settings provides a one-click export of your personal record — profile, conversations, health observations, timeline notes, file metadata, consultations, and your consent history — as a single JSON document, on every plan. The export covers file metadata rather than file contents (files are individually downloadable from the Vault), and shared Circle/Lab workspace containers are not yet included.

You can delete your account yourself from Settings. Deletion is confirmed by an emailed code and takes effect after a 30-day grace window, after which stored files and records are permanently destroyed; limited audit records may be retained for security, legal, and compliance purposes.

Records you delete individually (files, notes, chats) are removed from view immediately and permanently destroyed after a retention window of 30 days. Temporary chats are fully deleted within 24 hours.

We evaluate security incidents and provide required notices under applicable health, privacy, and breach-notification laws.

For privacy questions, data requests, or security concerns, contact support@lunas.one.

Waitlist and marketing email

Joining the waitlist stores your email address and the record that you verified it. Request rates are limited by network address to prevent abuse; verification codes are stored only in hashed form.

Marketing email is strictly opt-in: an optional, unchecked box on the waitlist form. Your choice is recorded only after your email address is verified, and it covers occasional product updates and launch news — nothing else.

Every marketing email includes an unsubscribe link. Unsubscribing takes effect immediately for future sends, is synced back to our records, and is never overridden — an address that unsubscribed is not re-added. If you never tick the box, the only email you will receive is your verification code and, later, your access invitation.

Children and family records

Lunas accounts are for adults (18+). We do not knowingly let children open accounts.

A parent or legal guardian may add a child's health records to their own account — Circle family vaults exist for exactly this. Those records belong to the account holder's record set, are protected like everything else here, and are deleted with the account.

Your privacy rights

We build the strongest rights into the product itself, for everyone: export your record as JSON from Settings (access and portability), delete files, notes, chats, or your whole account (deletion), and confirm or correct extracted record values during review (correction).

If you live in a U.S. state with a comprehensive privacy law (such as California, Colorado, Connecticut, or Virginia), those laws grant rights to access, correct, delete, and port your data — which the tools above already honor — and rights to opt out of sale, sharing for targeted advertising, and profiling. Lunas does not sell your data, does not share it for targeted advertising, and does not profile you for such purposes, so there is nothing to opt out of; browser opt-out signals like Global Privacy Control change nothing for the same reason.

For anything the tools do not cover, email support@lunas.one and we will respond as applicable law requires. We do not discriminate against you for exercising privacy rights.

Changes to this policy

When this policy changes materially, we will notify you by email or a prominent notice before the change takes effect, and this page always shows the date of the current version.

Service providers — process your data

Lunas runs on a small set of infrastructure providers. Google Cloud processes AI requests (the Stethos model runs on Vertex AI) and stores uploaded files; Neon hosts our database; Vercel hosts the application. These providers process your data only to run Lunas.

Resend delivers our emails and only ever receives your email address, one-time security codes, generic account or invitation notices with fixed wording, and — only if you opted in — our product-updates mailing list. Never health content.

If you choose to sign in with Google, Google processes your email address and basic profile for authentication. Google sign-in is optional; email codes work without it.

We do not sell your data or share it with advertisers or data brokers. If our provider list changes in a way that affects your data, we will update this policy.

Reference lookups — receive catalogue codes only

Reference links and drug-label lookups query the U.S. National Library of Medicine and openFDA using bare catalogue codes only — no identifiers, no personal values, and nothing about you attached. These services can see that some Lunas server asked about a code, never who asked or why.