🔒Your data, your rules

Privacy Policy

What we collect, why, and how we protect it. Written to be readable — no legal soup.

Effective: April 21, 2026Last updated: April 21, 2026GDPR & CCPA aware
Baseline policy for LunOS in private beta. GDPR + CCPA flavored. Not legal advice — have your counsel review before relying on it for regulated clients.

01Who we are

LunOS is the data controller for any personal information you upload or that we collect while you use the Service. We operate under the LunOS brand and you can reach us at [email protected].

02What we collect

Three buckets:

  • Account data: name, email, hashed password, role, language/timezone preferences.
  • Workspace data: the locations, keywords, campaigns, logos, domains, and CRM connections you add to the app.
  • Usage telemetry: minimal server logs (IP, user-agent, timestamps, endpoint hit) for debugging and rate limiting.

We do not run advertising trackers. We do not sell personal data. We do not train third-party AI models on your data.

03How we use it

  • Provide the Service and sync with the integrations you've connected;
  • Keep you signed in securely;
  • Send transactional emails (alerts, invoices, account notices);
  • Debug errors and measure platform health;
  • Comply with legal obligations.

We'll ask before using your data for anything outside this list.

04Third parties

To run LunOS we rely on processors who may handle your data on our behalf. Each is bound by a DPA and only gets the data they need:

DataForSEOSERP + site audit data
GoHighLevelCRM integration (opt-in per client)
Google (GBP API)Business Profile sync
TelegramNotification delivery
Anthropic / OpenAIAI digests (opt-in, key you provide)
DigitalOceanHosting & storage (US/EU region)
CloudflareProxy + DDoS protection
StripeBilling (if enabled)

05Cookies

We use a small number of first-party cookies: one to keep you signed in, one to remember UI preferences, and (optionally) one for billing session state. No third-party advertising cookies. You can clear them any time via your browser.

06Retention

Account data lives as long as your account is active. After account closure we delete or anonymize workspace data within 30 days unless law requires longer retention (for example, invoices). Backups are purged on a 35-day rolling window.

07Security

Passwords are hashed (bcrypt), transport is HTTPS everywhere with TLS 1.2+, and we apply least-privilege access to our production database. If we ever detect unauthorized access to your data, we will notify you within 72 hours as required by GDPR Article 33.

08Your rights

Depending on where you live, you have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate or outdated data;
  • Delete your account and associated data;
  • Export your data in a machine-readable format;
  • Object to or restrict certain processing;
  • Withdraw consent at any time (this doesn't affect prior lawful processing).

To exercise any of these, email [email protected]. We aim to respond within 30 days.

09International transfers

Our servers and some processors are based outside the EU/UK. When we transfer data internationally, we rely on Standard Contractual Clauses or adequacy decisions to keep protection at the GDPR level.

10Children

LunOS is built for businesses and is not intended for children under 16. We do not knowingly collect data from minors.

11Changes

When we change this Policy, we update the "last updated" date at the top. Material changes are emailed to account owners and posted in-app at least 14 days before taking effect.

12Contact & DPO

Privacy questions, data-subject requests, breach reports: