Privacy Policy

Last updated: 8 September 2026

This policy explains what Luna collects, why, who else sees it, and how to get rid of it. It covers the Luna iOS app and the Luna API behind it.

Luna is operated from Ontario, Canada by Adam Badar, trading as Axonal Labs. Canadian federal privacy law — PIPEDA — governs how we handle your personal information, and where you live somewhere with its own rules, such as the EU, the UK or a US state, those apply to you as well.

The short version: Luna works by knowing details about your life, so it stores those details and sends them to the AI provider that writes your stories. We do not sell them, and we do not use them for advertising.

1. What we collect

The questions Luna asks when you first open it

Onboarding asks, in this order: your name, the city you live in, your age, your gender, whether you have children and — only if you say yes — each child's age, what you want to change, why it matters, what is standing in your way, your relationship status and — only if you say you have a partner — their name, what you appreciate about them and what you want to feel more of in that relationship, the people who matter most to you and how they matter, what you do for work and how you feel about it, an open question asking what we should know to understand you better, whether anything from your past still shapes what you want, where you are living in the life you want and what kind of home that is, and an optional box for anything else you want the stories to know.

Every one of these questions can be skipped except your name. Skip is a visible control beside Continue, not a hidden one, and nothing is chosen for you in advance. A question you skip is not stored, not sent, and not guessed at: the app clears anything half-typed on the way past and omits the field from the request entirely rather than sending it empty.

Your name is the one exception, and it is required because the whole app is addressed to you by it. The final free-text box has no separate Skip because its own button reads "Skip" until you type something.

You can use Luna having answered only your name, and you can come back later and answer more, or change or delete any answer, in Settings. What you lose by skipping is fidelity: a story that does not know you have children will not mention them.

Two of these deserve to be called out rather than left in a list.

We do not ask your sexual orientation. Luna used to, on a screen of its own, and the answer was sent with every story request. It is gone: the question is deleted, the app cannot send it, our server refuses the field if anything tries, and the answers already given have been deleted from the database. We are saying so plainly rather than quietly dropping a line, because if you used an earlier version of Luna you told us, and you are entitled to know what happened to it.

Gender we do still ask, and "Prefer not to say" is recorded as the value unspecified rather than left blank. That is deliberate and not the same as skipping: it tells the model not to assume, where an absent answer would let it assume. Skipping records nothing. Your answer reaches the model once, converted into which pronouns to use, and never as the raw answer itself.

Your children — ages only. We do not ask their names. If you say yes, we ask each child's age, with no limit on how many you add. We store it as a single line — for example a 6-year-old, a 9-year-old — attached to your account, we send it to the AI provider that writes your stories, and it appears in your data export. It is deleted when you delete your account.

Luna used to ask for each child's first name, so that a story could say "Ana" rather than "your daughter". That is a better story and we stopped anyway: a child's name is personal information about someone who has not been asked and cannot agree, and it was reaching our AI provider in every story you generated, not only the ones about family. The field is gone, and the names given under the earlier version have been deleted from our database. If you used Luna before September 2026 and entered them, that is what happened to them.

The age still tells the stories what they need — a story written for the parent of a four-year-old is not the story written for the parent of a fifteen-year-old. The question is optional; skipping it stores nothing.

Your partner, and the people who matter to you. If you tell us you are in a relationship, engaged or married, we ask your partner's first name and what you appreciate about them, and that person is added to the list below. We ask who else Luna should know matters most, and for each person you may give a name, a short description of how they matter, or both — "Sara (best friend)", "my mum (complicated)". The same plain statement applies as for children: you are giving us information about other people, who have not been asked and cannot agree, and describing them in terms they did not choose. We store it as a single line attached to your account, send it to the AI provider that writes your stories, and include it in your data export. It is deleted when you delete your account.

The name is optional. A person you describe without naming reaches the story as "my mum" rather than as a name, which lets a story know your mother matters without us holding her name. The whole question can be skipped, and the stories still work.

Your age is stored as the number you type, not as a band and not as a date of birth. Your city is the words you type — we do not read your device's location, and Luna has no location permission at all.

Everything else

Account. When you first open Luna we create an anonymous account keyed to your device's vendor identifier, so the app works before you sign in. That identifier is stored as your account key. We also store your locale and timezone, and the time you were last seen.

If you sign in with Apple, we store the Apple subject identifier and the email address Apple releases to us, which is a private relay address unless you chose to share your real one. Either way we store the address as given. If Apple supplies a name on first sign-in we use it as your display name. We never receive your Apple password.

Each signed-in session also stores the user-agent string your device sent when the session was created.

What you write later. Journal entries, up to 4,000 characters each. The scene you type when you ask for a story. The instruction you type when you ask for a story to be rewritten. These may include names of people close to you, places, and other private facts. From your journal entries an AI model extracts short themes and, where it is confident, new facts about you — a partner's name, a pet's name — which are added to the set your stories are written from. You can see every one of them in Settings.

Preferences. Narration voice, playback speed, ambient bed, listening and reminder times, and whether notifications are on.

Content we generate. The story and affirmation text produced for you, the audio files rendered from it, the word-level timings used to highlight text during playback, every earlier version of a story you have edited, and the instruction you typed to ask for that edit.

Usage. A fixed allowlist of 23 product events, each tied to your account id: app opens, onboarding steps, story requests and outcomes, playback started, completed and abandoned, affirmation views and favourites, journal writes, paywall shown and dismissed, purchase and restore outcomes, share-card exports, vision board opens, settings opens. Each carries a session id, app version, and whatever properties the app attached. Also your streak counts and the usage counters that meter your plan.

Safety. When our moderation checks flag something you wrote, we record the classification, a confidence score, what we did about it, and a SHA-256 hash of the text. We do not store the text itself. This matters most for the crisis classification: the fact that a check fired is retained, what you wrote is not.

Device. App version, locale, timezone, and, only if you turn notifications on, an Apple push token.

Purchases. Your subscription tier, the product id, whether you are in a trial, period dates, and the customer id our billing provider assigns you. We also store the raw subscription events that provider sends us.

Diagnostics. Crash reports and, on a 10% sample, performance traces. These are collected by the app and carry your account id.

We do not collect your contacts, device location, health data, microphone audio, or advertising identifiers, and Luna contains no advertising SDKs. If you set a profile photo, it is chosen through the iOS photo picker, stays on your device, and is never uploaded to us.

2. Why we use it

We do not use your personal content to train our own models, we do not sell it, and we do not use it for advertising or profiling for advertising.

Some of what you tell us is about other people. If you say you have children, we ask for each child's age and never their name. If you say you have a partner, we ask their name and what you appreciate about them. We ask who else matters to you, and accept a name and a short description for each. Those details are personal data about people who are not our users and were not asked. We use them for one thing only: writing your stories. We do not build a profile of any of them, do not contact them, and do not share their details with anyone except the processors listed in §3.

Every one of those questions is optional and every one can be skipped. A person you describe without a name reaches our AI provider as "my mum" or "a six-year-old" rather than as a proper noun, so you can give us the relationship without giving us the person. If you are not in a position to decide this on someone's behalf, please do not enter their details.

3. Who else sees it

We use these processors. Each gets only what its job needs.

Superwall is listed for completeness rather than because it is in use. Its SDK is linked into the app, but Luna draws its own subscription screen and configures Superwall only if the build carries a Superwall key. Builds without one send it nothing at all. It is named here so that the answer does not change silently if that key is ever set.

Provider What it receives Why
Apple Sign in with Apple identity, subscription purchases, push notifications Account, payment, notifications
OpenAI Your story context and the narration audio (see below) Writes the script, renders the narration, transcribes it back for word timings, and screens what you type for safety
RevenueCat Your account id, and the purchase receipts Apple reports to it Subscription entitlement
Superwall Nothing, unless the app is built with a Superwall key. When it is: your account id and paywall events, sent from the app Would decide which paywall to show
Sentry Crash and performance traces, with your account id, sent from the app Diagnostics
Hosting / storage Database, queue, and audio file storage Runs the service

What OpenAI receives, specifically

This is the disclosure that matters most, because the answers you gave in onboarding do not sit in a database waiting to be looked at — they are written into the instructions we send to a third-party AI provider, in plain words, every time a story is made.

To write a story, we send: your display name and how to pronounce it, your pronouns if we hold any, the area of life the story is about, the desire it is about, the scene you typed, themes extracted from your journal in the last 14 days, a one-line summary of up to five recent stories so the new one does not repeat them — and every detail you have given us that is not tied to a single category, written out as a plain list. In practice that list is your age, your gender, your city, your children's ages, your partner's name and what you said about them, the names and descriptions of the other people who matter to you, what you said you want to change, why it matters, what is in your way, anything you typed in the free-text box, and anything the journal extractor has since added. Details that are not tied to a category are treated as facts about who you are, so they go into every story, not only the romantic ones.

To narrate it, we send the full story text. To produce word timings, we send the narration audio back to be transcribed. To screen content, we send the text you typed. When you write a journal entry, the full entry is sent so themes can be extracted from it.

Retention at OpenAI. Every request that sends OpenAI the details you gave us tells OpenAI not to store it. That covers writing a story, editing one, writing your affirmations, and reading your journal entries for themes: all of them go through one code path and that path sets the flag.

Three other requests cannot carry that instruction, because the endpoints they use do not accept it: narration, the transcription that produces word timings, and the safety screening of what you type. Those are handled by OpenAI under its own standard retention policy for API customers, which at the time of writing retains API inputs for a limited period for abuse monitoring and then deletes them. We do not control that period.

Training. OpenAI's published API terms state that content submitted through its API is not used to train its models unless the customer explicitly opts in. We have not opted in. We are describing OpenAI's policy here rather than promising you a private agreement of our own.

What Apple sees in a push notification. The "your story is ready" notification carries the story's title, so the title passes through Apple's push service. Notification content is not stored by us beyond the story itself.

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

We may disclose information if legally required, or to protect someone's safety. If a subpoena covers your data and we are permitted to tell you, we will.

4. Where it lives and how long

Luna is operated from Ontario, Canada. Data is stored on servers operated by our hosting provider and is processed in countries other than Canada, including the United States — our database, file storage and the AI provider that writes and narrates your stories are all outside the country. PIPEDA permits this and requires us to say so plainly: while your information is in another country it is subject to that country's laws, including lawful access by its courts and law enforcement. Where required, we rely on standard contractual clauses for those transfers. Audio files are stored privately and are reachable only through links we sign, which expire after six hours.

expiry on anything you write. Stories, journal entries, the details your stories are written from, product events, safety flags and generation records are all retained indefinitely while your account exists.

purge and there is no grace period. The request removes your user row, and everything attached to it goes with it: your profile, the details we hold about you and your family, your desires, stories and every version of them, affirmations, journal entries, devices, entitlements, usage counters, product events, safety flags, the raw subscription events our billing provider sent us, and your sessions.

fails.** Before any row is removed we write down every audio file we are about to delete, then delete them from storage. A file that deletes successfully is struck off. One that fails keeps its record, with a count of attempts and the last error, and is retried on later deletions until it succeeds. So deletion of your audio is durable rather than instantaneous.

find out. A retry record for a file that has not yet been deleted contains that file's storage path, which includes your former account id, and is kept until the deletion succeeds. After ten failed attempts we stop retrying and the record remains as evidence that a deletion request was not fully honoured. It contains nothing you wrote.

earlier versions, its timings, and its audio file are retained until you delete your account. A data export still includes them, marked as deleted. If you want a story gone completely, delete your account.

new audio file; the previous one stays until the account is deleted.

not a set of working credentials. They last 90 days, signing out revokes them, and expired rows are cleared 30 days after they expire.

database. Our hosting provider may keep short-term operational copies as part of running the service; where it does, those age out on the provider's cycle and the timing is not ours to set. If we start operating scheduled backups we will say so here, with the retention window.

5. Your choices

Settings → "Details we use". Every detail we hold is listed there, including the ones extracted from your journal, and every one of them is editable.

same screen. Note that clearing a field is not the same as deleting it: the save is an update rather than a replacement, so a blank value leaves the stored answer as it was. The app says so on that screen, and names the delete button as the control that actually removes an answer.

account record, your profile, every detail we hold about you including gender, age, city and children's ages, your desires, every story including the ones you deleted and are still held, with the scene you typed, its status, its audio checksum and a download link for the audio, every earlier version of every story, your affirmations, your journal entries with their safety flags, your devices, and your subscription entitlement. Your push token is deliberately excluded so that the file is not itself a way to send you notifications.

records, the internal generation-job records, and raw billing events. All four are deleted with your account. Ask us at the address below if you want them and we will supply them.

require emailing us.

Settings or in iOS Settings.

Under Canadian law, whoever you are and wherever you live. Luna is operated from Ontario, so the Personal Information Protection and Electronic Documents Act (PIPEDA) governs how we handle your personal information. Under it you may ask us what personal information we hold about you, what we have used it for and who we have disclosed it to; ask us to correct anything inaccurate or incomplete; and withdraw your consent, subject to legal or contractual restrictions and reasonable notice. Most of that is self-service in the app — see the list above — and anything that is not, we will do at the address in §9. We answer access requests within 30 days.

If you are not satisfied with how we handle it, you can complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca. We would rather you came to us first, but it is your right either way.

Depending on where else you live, you may also have rights to delete, port, or restrict processing, to object to processing, and to complain to your own data protection authority — for example under the GDPR in the EU and UK, or under state privacy laws in the United States. Ask us at the address below and we will not discriminate against you for it.

6. Security

Traffic is encrypted in transit with TLS. Your session tokens are held in the iOS Keychain, not in preferences. Refresh tokens are stored as hashes and are single-use, so reusing one revokes the whole session family. Audio is stored with private access and served only through short-lived signed links. Access to production data is limited to those who need it.

Crash reports are configured not to capture screenshots or your screen's view hierarchy, and the app attaches nothing to them but your account id and the name of the operation that failed. We do not deliberately send anything you wrote to our diagnostics provider, but an error message or a diagnostic breadcrumb can contain fragments of it, and we do not claim that every such fragment is stripped.

No system is perfectly secure. If we discover a breach of security safeguards involving your personal information, and it creates a real risk of significant harm to you, PIPEDA requires us to report it to the Office of the Privacy Commissioner of Canada and to notify you — and we will, as soon as feasible. We keep records of breaches whether or not they meet that threshold, which PIPEDA also requires. Where other laws impose their own deadlines, such as the GDPR's 72 hours to a supervisory authority, we meet those too.

7. Children

Luna is not for children. You must be at least 13 to use it, we do not knowingly collect personal information from anyone under 13, and if you believe a child has given us data about themselves, contact us and we will delete it.

Separately: Luna asks adults about their children — their ages, and nothing else. If you tell us you have children, we ask each child's age and use it to write your stories.

Names entered under the earlier version have been deleted from our database.

of the question we were willing to keep.

child. We do not build a profile of your child, do not use the information for anything except writing your stories, and do not share it with anyone except the processors listed in §3.

yourself in Settings.

If you are your child's parent or guardian, you are the person who can decide this. If you are not, please do not enter their details.

Other people you tell us about

The same is true, without the age question, of your partner and of anyone else you name on the "who matters to you" question. We hold their name and your description of them, we send both to our AI provider to write your stories, and they appear in your data export. They are optional, they can be skipped, and a person given without a name never becomes a proper noun in anything we generate.

They have the same rights over that data as anyone else. If someone you named asks us to remove their details, write to us at the address in §9 and we will remove them, whether or not they are a Luna user.

8. Changes

We will post any update here and change the date at the top. If a change is material, we will tell you in the app before it takes effect.

9. Who we are, and how to reach us

Luna is published by Adam Badar, trading as Axonal Labs, who is the data controller for everything described in this policy. Luna is published by an individual, not a company; Axonal Labs is a trading name and not a separate legal person, and Luna is operated from Ontario, Canada.

PIPEDA requires an accountable individual you can reach, GDPR Art. 13 requires a controller you can identify and contact, and App Review's 5.1.1 question asks the same thing in fewer words. All three are answered by the same person and the same address.

adam@axonal-labs.com medhansh@axonal-labs.com

Either address reaches us. Privacy requests — access, correction, deletion, or withdrawing consent — are handled fastest at medhansh@axonal-labs.com.

Adam Badar, trading as Axonal Labs 1052 Longbow Drive Pickering, Ontario L1V 5W1 Canada