Lunas policy

Privacy Policy

How Lunas handles account data, health records, uploaded files, AI requests, sharing, and model-improvement choices.

Last updated: July 4, 2026

What Lunas collects

Lunas collects the account information needed to run the service, such as your email address, display name, plan, authentication records, and security events.

When you choose to use health-data features, Lunas may store uploaded files, extracted text, structured observations, timeline notes, patient records, and chat messages. These records can contain sensitive health information.

How Lunas uses your data

We use your data to provide Chat, Clinic, Lab, timeline, file review, sharing, usage metering, support, security, and audit functions.

Lunas is designed so plan, role, ownership, and access checks are enforced server-side. Client-side UI controls are not treated as permission boundaries.

We do not sell sensitive health information or use it for advertising.

AI and model improvement

User health data is not used to train Stethos by default. Training eligibility requires explicit consent, de-identification, and human review before data can be approved for a training dataset.

Model providers may process prompts, retrieved context, and uploaded-file extracts to generate responses. Lunas minimizes unnecessary context and is intended to use provider retention and no-training controls where supported.

Sharing and access

You control whether personal timeline records are shared. Clinic and Lab records are access-controlled and should only be shared with people who need to review them.

Audit records may be retained for security, legal, and compliance purposes even after user-facing records are deleted.

If you use Lunas for a covered entity or regulated health organization, you are responsible for having the right authorization, organizational approval, and business associate agreement when required before submitting protected health information.

Your choices

You can export your data yourself at any time: Settings provides a one-click export of your personal record — profile, conversations, health observations, timeline notes, file metadata, and your consent history — as a single JSON document, on every plan. The export covers file metadata rather than file contents (files are individually downloadable from the Vault), and Clinic/Lab workspace data is not yet included.

You can delete your account yourself from Settings. Deletion is confirmed by an emailed code and takes effect after a 30-day grace window, after which stored files and records are permanently destroyed; limited audit records may be retained for security, legal, and compliance purposes.

Records you delete individually (files, notes, chats) are removed from view immediately and permanently destroyed after a retention window of 30 days. Temporary chats are fully deleted within 24 hours.

We evaluate security incidents and provide required notices under applicable health, privacy, and breach-notification laws.

For privacy questions, data requests, or security concerns, contact support@lunas.one.

Service providers we use

Lunas runs on a small set of infrastructure providers. Google Cloud processes AI requests (the Stethos model runs on Vertex AI) and stores uploaded files; Neon hosts our database; Vercel hosts the application. These providers process your data only to run Lunas.

Resend delivers our emails and only ever receives your email address, one-time security codes, and generic account or invitation notices with fixed wording — never health content. Reference links and drug-label lookups query the U.S. National Library of Medicine and openFDA using bare catalogue codes only, with no identifiers or personal values attached.

We do not sell your data or share it with advertisers or data brokers. If our provider list changes in a way that affects your data, we will update this policy.