Luna.

Consumer Health Data Privacy Policy · Version 2026-08-17

CONSUMER HEALTH DATA PRIVACY POLICY (UNITED STATES)

Effective date: 2026-08-10

This policy is written and published in English. Translations into other languages are provided for your convenience; where a translation differs from this English text, the English version governs.

This is a standalone Consumer Health Data Privacy Policy as required by the Washington My Health My Data Act. It applies to residents of Washington State (My Health My Data Act, RCW 19.373), Nevada (SB 370), and any U.S. consumer whose consumer health data Luna processes. It is provided in addition to, and prevails over, our general Privacy Notice with respect to consumer health data.

1. WHO WE ARE

icoso consulting S.L. ("Luna", "we", "us"), Calle Juan de Herrera 18, 39002 Santander (Cantabria), Spain (EU), operates the Luna menstrual-cycle and reproductive-wellness app.

Privacy contact: privacy@icoso.es · Data Protection Officer: Daniel Osorio Fernandez.

Luna is a wellness application. It is not a HIPAA covered entity, not a HIPAA business associate, and not an FDA-regulated medical device.

2. WHAT "CONSUMER HEALTH DATA" MEANS HERE

Under the My Health My Data Act, consumer health data is personal information that identifies a consumer's past, present, or future physical or mental health status — expressly including data related to reproductive and sexual health and menstruation. Because Luna is a cycle-tracking app, much of the data you choose to enter is consumer health data, and we treat it as such.

3. CATEGORIES OF CONSUMER HEALTH DATA WE COLLECT

Only data you choose to provide or explicitly enable:

Cycle and reproductive data: period dates, cycle length, bleeding intensity, predicted and estimated phases, ovulation estimates, contraception method, pregnancy and lifecycle state.

Symptoms, moods, basal body temperature, journal entries.

Self-reported health profile: hormone lab values, self-reported conditions, medications, diet, allergies, body measurements.

Imported device health signals, only if you enable Apple HealthKit or Google Health Connect: sleep duration, resting heart rate, body temperature, heart-rate variability, activity and workout minutes, steps — stored as encrypted 7-day summaries.

4. ENCRYPTION BY DESIGN, AND WHAT IT MEANS FOR US

All of the above is encrypted on your device (AES-256-GCM) before it reaches our servers. We store only ciphertext. Whether that ciphertext is readable to us depends on your privacy mode:

Maximum Privacy — the default for U.S. users. The key that decrypts your data is derived from your password together with a Recovery Key that only you hold. No copy of it exists on our servers. We cannot decrypt your consumer health data — not for ourselves, and not for anyone who demands it from us.

Standard mode, if you choose to opt out of Maximum Privacy. Luna additionally keeps an encrypted recovery copy of your key, so that we can restore your access if you are ever locked out of your account. That recovery path means we are technically able to decrypt your data. We use it solely to restore your own access to your account, and never to read your data.

5. SOURCES OF CONSUMER HEALTH DATA

Directly from you — data you enter in the app.

From your device's health platform (Apple HealthKit / Google Health Connect), only after you grant OS-level permission, which you can revoke at any time in your device settings.

We do not buy consumer health data, and we do not obtain it from data brokers or third-party advertising sources.

6. HOW WE USE CONSUMER HEALTH DATA

To provide the core service you requested: cycle tracking, deterministic predictions, insights, reminders.

Only with your explicit opt-in: AI nutrition and lifestyle coaching ("Sofía"). Before any AI request, your device builds anonymized categories — no name, no identifier, no exact dates, no journal free text, no brand or drug names. Processing occurs within the EU (AWS Bedrock, Frankfurt).

We do not use consumer health data for advertising, for profiling for advertising, or to infer characteristics for marketing.

7. SHARING OF CONSUMER HEALTH DATA

We do not share your consumer health data with third parties for their own purposes. We do not disclose it for advertising or sale.

Consumer health data is stored only as ciphertext with our infrastructure provider Hetzner Online GmbH (hosting and database, EU / Germany), which can access ciphertext only and cannot read health data.

Service providers that process non-health, anonymized, or non-identifying data only (full list in our Subprocessors List): AWS and Anthropic (EU, anonymized categories), OpenAI (search terms only), RevenueCat (pseudonymous subscription identifier), Apple and Google (payment), Scaleway (email and backups, EU), Sentry (crash diagnostics, EU). None of these receive readable consumer health data.

We may disclose data only where legally compelled by valid legal process. What we are able to produce depends on your privacy mode (see section 4): for Maximum Privacy accounts — the default in the U.S. — we can produce only ciphertext that we are unable to decrypt. For Standard accounts, the recovery path described in section 4 means decryption is technically possible, and we would produce readable data only where a valid legal process leaves us no lawful alternative.

8. WE DO NOT SELL CONSUMER HEALTH DATA

Luna does not "sell" consumer health data as defined by the My Health My Data Act, and we therefore do not seek the valid authorization that a sale would require. We will not sell consumer health data.

9. YOUR RIGHTS

Regardless of where you live in the U.S., if we hold your consumer health data you may confirm and access the consumer health data we process about you; withdraw your consent to our collection and processing; and delete your consumer health data, including a request that we direct our processors to delete it.

How to exercise: in the app via Settings → Download my data (access and export) and Settings → Delete account (immediate deletion), or by emailing privacy@icoso.es. You can withdraw the health-data collection consent at any time in Settings without deleting your account.

We will honor a deletion request across active systems immediately; encrypted backup copies are purged within the daily backup cycle, within 7 days.

Timeline: we respond within 45 days, extendable once by 45 days where reasonably necessary, with notice.

Appeal: if we decline a request, you may appeal by replying to our decision. If your appeal is denied, you may contact the Washington State Attorney General at www.atg.wa.gov/file-complaint.

No discrimination: we will not deny service, charge a different price, or degrade your experience because you exercised these rights.

10. NO GEOFENCING

Luna does not use any geofence around any healthcare facility to identify or track consumers, to collect data from them, or to send them notifications based on their proximity to such a facility.

11. SECURITY

Health data is encrypted on your device (AES-256-GCM) before upload — in both privacy modes. Our servers receive and store ciphertext only. What differs is where the key lives: in Maximum Privacy mode, the default in the U.S., no copy of it exists on our servers, and we cannot decrypt your data. In Standard mode we additionally hold an encrypted recovery copy of your key, which makes decryption technically possible for us; we use it solely to restore your own access to your account (see section 4). TLS 1.3 in transit, EU hosting, least-privilege access, no public database port, and a logged deletion procedure for restored backups. Full measures are described in our technical and organizational measures record.

12. CHANGES

We will post any update here with a new effective date and, for material changes affecting consumer health data, seek renewed consent where required.