This Privacy Policy describes how LunaOS ("we", "us", or "our") collects, uses, and shares information when you use our platform, website, CLI tools, APIs, and related services (collectively, the "Service").
1. Information We Collect
Account Information: When you create an account, we collect your name, email address, and organization name. If you sign up via a third-party provider (e.g., GitHub), we receive your profile information from that provider.
Payment Information: Payment processing is handled by LemonSqueezy. We do not store your credit card details. LemonSqueezy provides us with subscription status, plan type, and billing history.
Usage Data: We collect anonymized usage analytics including pages visited, features used, agent run counts, API call volumes, and error rates. This data helps us improve the Service.
Technical Data: We automatically collect IP addresses, browser type, device information, and request metadata for security, rate limiting, and service reliability.
Content You Provide: When you use our agents, workflows, or RAG features, we process the code and data you submit. We do not use your content to train models.
2. How We Use Your Information
- Provide, maintain, and improve the Service
- Process transactions and manage your subscription
- Send transactional emails (account confirmations, billing receipts, security alerts)
- Detect, prevent, and address security incidents and abuse
- Analyze aggregate usage patterns to improve product quality
- Provide customer support
We do not sell your personal information. We do not use your data for advertising.
3. Third-Party Services
We use the following third-party services to operate the platform:
- LemonSqueezy — payment processing and subscription management
- Cloudflare — hosting, CDN, DNS, edge compute (Workers, D1, KV, Vectorize)
- Plausible Analytics — privacy-friendly, cookie-free website analytics
- GitHub — OAuth authentication and repository integrations
Each third-party service processes data according to their own privacy policy. We only share the minimum information necessary for each service to function.
4. Data Retention
We retain your account data for as long as your account is active. Usage analytics are retained in aggregate form for up to 24 months. Run logs and workflow execution data are retained for 90 days on the Free plan and 365 days on paid plans, after which they are automatically deleted.
When you delete your account, we remove your personal data within 30 days. Some anonymized, aggregate data may be retained for analytics purposes.
5. Data Deletion and Your Rights
You may request deletion of your account and all associated data at any time by emailing [email protected] or through your account settings.
6. GDPR Rights (EEA Residents)
If you are located in the European Economic Area, you have the following rights under the General Data Protection Regulation:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your personal data
- Portability: Request your data in a structured, machine-readable format
- Restriction: Request that we limit processing of your data
- Objection: Object to processing based on legitimate interests
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
7. Security
We implement industry-standard security measures including encryption in transit (TLS), hashed API keys (SHA-256), role-based access control, and regular security audits. All data is processed on Cloudflare's edge infrastructure with SOC 2 and ISO 27001 certifications.
8. Cookies
We use Plausible Analytics, which does not use cookies and does not track individual users. We may use essential cookies for authentication sessions. We do not use tracking or advertising cookies.
9. Children's Privacy
The Service is not intended for children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us and we will promptly delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the revised policy.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at: