Privacy Policy · Version 2026-08-19
PRIVACY POLICY
Last updated: July 2026
1. TERMS AND INTRODUCTION
Luna encrypts your health data on your device (AES-256) before it reaches our servers — all that arrives with us is unreadable ciphertext. In Standard mode, password recovery is possible (the key is secured server-side); only in Max Privacy mode does your Recovery Key alone have access. For the optional AI coaching, your device forms anonymized categories before each request; the encrypted plaintext values (e.g. journal, medication names) never leave your device (see the section "AI-assisted coaching").
As the controller of data processing within the meaning of the GDPR (hereinafter "the APP", "the company", "we"), we take appropriate measures to ensure the security and protection of your personal data when you use the APP. We act as controller because we decide on the purposes and means of processing your personal data. This Privacy Policy explains how we collect, use, store and share your personal data when you visit our websites or interact with one of our services.
2. THE CONTROLLER
The controller for the processing of personal data under the General Data Protection Regulation (GDPR) is:
ICOSO CONSULTING S.L.U. ("Luna FemTech")
Owner and Managing Director: Daniel Osorio Fernandez
Calle Juan de Herrera, Núm 18, Planta 4 y 5
39002 Santander (Cantabria), Spain
VAT ID: ES B55469902
Commercial Register Santander, Sheet S-37849
www.luna-femtech.com
Data protection contact: privacy@icoso.es
User support: support@luna-femtech.com
(c) 2026 All rights reserved.
3. CONTACT DETAILS OF THE DATA PROTECTION OFFICER (DPO)
A Data Protection Officer (DPO) is appointed and can be reached at the following address:
privacy@icoso.es
The appointment of a Data Protection Officer is mandatory under Art. 37(1)(c) GDPR, as the core activity consists of the large-scale processing of special categories of personal data (health data).
4. PROCESSING OF PERSONAL DATA
We process users' personal data only where necessary for proper operation. Collection and processing take place only after the user has given consent. An exception applies where it is impossible to obtain this consent before processing becomes necessary, and in the case of legally or officially mandated processing obligations.
• Identity/contact data: e-mail address, display name/username, OAuth identity (sign-in via Apple/Google).
• Subscription data: pseudonymous (SHA-256) subscription identifier and subscription status. Payment is handled exclusively via the respective store (Apple/Google); we receive no bank, card or billing data.
• Technical data: IP address (max. 7 days for attack detection), device/operating-system information (only in scrubbed crash reports).
• Usage data: information about how you use our app and our products and services.
• App settings: language, colour scheme, reminder-logic metadata.
• Health data: your health data such as cycle, symptoms, moods, basal body temperature, journal, hormone values, self-reported conditions, medications, diet, allergies, contraception method and body measurements are subject to particularly high protection. They are, without exception, encrypted on your device (AES-256-GCM) before transmission — our server holds only ciphertext.
The following principles apply to the processing of health data:
◦ Consent: health data may generally only be processed if the data subject expressly consents.
◦ Purpose limitation: the data may only be used for the previously defined purpose (e.g. cycle tracking and self-observation for wellness purposes).
◦ Data minimisation: only as much data as strictly necessary may be collected.
◦ Security: health data must be stored and protected with particular care (e.g. through encryption).
We process your data among other things through direct interactions (you provide data when you create an account, use features, contact us or send us feedback) and through automated collection of technical data during operation of the app.
Managing and withdrawing consent: You can withdraw any consent given at any time. You manage consent for the optional AI coaching ("Sofía") in the app under Settings; you withdraw the permission for the Health import (Apple HealthKit / Google Health Connect) in your operating system's device settings; you manage your data-protection region in the app under Settings. Withdrawal takes effect for the future and does not affect the lawfulness of processing carried out up to that point.
5. AI-ASSISTED NUTRITION AND LIFESTYLE COACHING ("SOFÍA")
If you use the optional Premium AI-coaching feature, we process — on the basis of your explicit consent (Art. 6(1)(a), Art. 9(2)(a) GDPR) — health-related information in order to provide you with individual, cycle-aware nutrition and lifestyle tips. The information used for this is anonymized on your device before transmission: only categorised patterns are transmitted (e.g. cycle phase, aggregated frequencies of symptoms and moods, diet, allergies, conditions as fixed categories, medications as active-ingredient classes, hormone values without dates). Your name, your user ID, exact dates, journal free text and product or brand names are not transmitted. AI processing takes place via Amazon Web Services (AWS Bedrock) exclusively in the EU region Frankfurt; no transfer of the content to the USA takes place. Inputs are not stored permanently and are not used to train the AI models.
Luna and Sofía serve exclusively wellness, lifestyle and self-observation purposes. They are not intended for the diagnosis, treatment, prevention or prediction of disease. Sofía is an AI-assisted system; responses are generated automatically and may be incomplete, inaccurate or unsuitable for your individual situation. Sofía does not replace medical, psychological or nutritional advice.
There is no solely automated decision-making within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you. Predictions, hints and AI responses serve exclusively self-observation and wellness support.
6. USE OF YOUR DATA
Your contact data (e-mail address) is never shared with third parties. We process usage data and technical data to provide and improve the functionality of the app, to identify and fix problems, and to ensure the stability and security of the services. For further development, we collect and analyse feedback and usage data in aggregated form.
• Fulfilment of contractual obligations: we process your data to fulfil our contracts and ensure the proper use of our services.
• Customer service: to provide support, we process your name, contact data, communication history and the content of your requests.
• Account management: we process your e-mail address and login credentials to authenticate your account and provide you with secure access.
• Compliance with legal requirements: we process your data to fulfil legal, tax and accounting obligations.
Notifications: reminders (e.g. for cycle or intake events) are scheduled and triggered exclusively locally on your device. We operate no external push service for this and store no push tokens; no health data leaves your device for the reminders. You can disable notifications at any time in the app or in your device's system settings.
Health import (Apple HealthKit / Google Health Connect): if you activate this optional feature, we import passive health signals (e.g. sleep, resting heart rate, body temperature) as encrypted summaries in order to improve cycle insights (Art. 9(2)(a)). The permission can be withdrawn at any time in the device settings.
Barcode feature (Premium): when you optionally scan a product barcode, only the barcode number (EAN) is transmitted via our server to the product database Open Food Facts in order to look up the product name. No health data and no user ID are transmitted in the process.
No location processing: Luna does not process any GPS or location data. For the optional place search (e.g. city search), only the search term you enter is transmitted via our server to the map service Nominatim (OpenStreetMap). We derive your data-protection region from the configured device region (country code), not from your precise location.
7. DELETION OF DATA AND RETENTION PERIOD
Your personal data will be deleted or its use restricted as soon as there is no longer any need to store it. However, it may be retained longer where required under applicable EU or national law.
When you delete your account (Settings → Delete account), your data is immediately removed from the active systems. Residual copies in encrypted technical backups are deleted within 7 days as part of the rolling backup cycle. An internal deletion log ensures that data deleted in the meantime does not reappear even if a backup is restored.
• Processing based on consent or legitimate interest: the data is stored until you declare its withdrawal or objection and/or the legitimate interest ceases.
• Contract data: this is retained for the duration of the contractual relationship and thereafter for as long as statutory retention obligations exist (e.g. 10 years under tax and commercial law). Tax-relevant records (e.g. relating to the pseudonymous subscription identifier) are retained to the legally required extent. Actual billing/payment data resides exclusively with the respective store (Apple/Google) and not with us.
8. DATA, COOKIES, LOG FILES AND THIRD PARTIES
When you visit our website or APP, your device automatically transmits log data to our servers (e.g. when logging in or uploading/downloading information). Log data collected: device IP address, system configuration, date and time of access. IP addresses are stored for up to 7 days to detect and prevent attacks; afterwards they are deleted or anonymised. This data is processed on the servers of Hetzner Online GmbH (EU).
Cookies and local storage: the app itself uses no cookies. The website luna-femtech.com uses only technically necessary local storage (localStorage) to save your language choice — we use no tracking cookies, no counting pixels and no analytics.
Processors and sub-processors: detailed information on the transfer of data to our processors and sub-processors can be found in our always-current list at www.luna-femtech.com/sub.
9. YOUR RIGHTS
Under the GDPR you have the rights to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), objection (Art. 21), data portability (Art. 20), withdrawal of consent (Art. 7(3)) and to lodge a complaint with a supervisory authority.
You can initiate access and export (Art. 15/20) directly in the app (Settings → Download data; machine-readable JSON export). Deletion is carried out immediately via Settings → Delete account. The record of consents given is logged; where policy versions change, renewed consent is obtained.
a) Right of access: you can obtain, free of charge and at any time, information about the personal data stored about you and a copy of that data.
b) Right to rectification: you can request the correction of inaccurate or incomplete data.
c) Right to erasure: you can request the deletion of your personal data where no other legal basis for processing applies.
d) Right to restriction of processing: you can request the restriction of the processing of your data.
e) Right to object: you can object at any time to processing based on legitimate interests.
f) Right to data portability: you can receive the data you have provided in a common format and transfer it to other service providers.
g) Right to withdraw consent: you can withdraw your consent at any time with effect for the future (see Section 4).
h) Right to complain: you have the right to lodge a complaint with a supervisory authority. The competent supervisory authority is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, Spain, www.aepd.es. Independently of this, you may also contact the data-protection supervisory authority of your habitual residence or place of work.
10. LEGAL BASIS FOR DATA PROCESSING
The processing operations are based on the following legal bases under the GDPR:
• Performance of a contract (Art. 6(1)(b)): processing is necessary to perform a contract with you or to carry out pre-contractual measures.
• Consent (Art. 6(1)(a); for health data Art. 9(2)(a)): where you give us your explicit consent, we may process your data for the agreed purposes.
• Legitimate interests (Art. 6(1)(f)): security and fraud prevention, stability and technical improvement of products, services and app — provided your fundamental rights and freedoms do not override them.
• Legal obligation (Art. 6(1)(c)): fulfilment of legal, tax and accounting requirements.
11. DISCLOSURE AND TRANSFER OF YOUR DATA TO THIRD PARTIES
To fulfil legal obligations, we may disclose data to public bodies, judicial authorities or other official bodies. Processors and sub-processors act as processors and must have appropriate protective measures in place.
Hosting and AI processing take place entirely within the EU. A transfer to the USA takes place exclusively to OpenAI (image generation; search terms only), RevenueCat (pseudonymous subscription identifier) and Apple/Google (payment) — each safeguarded by EU Standard Contractual Clauses. Details are in the sub-processors list (www.luna-femtech.com/sub).
12. UPDATES AND CONTRACT LANGUAGE
We reserve the right to update this Privacy Policy from time to time, primarily to adapt it to legal changes. The version in force at any given time is published at www.luna-femtech.com/data and takes effect upon publication. In the event of discrepancies between the German and the Spanish text, the Spanish version prevails due to the place of performance.
13. LEGAL NOTICES AND TERMS OF USE
Our Terms of Use (www.luna-femtech.com/terms) contain all legal information as well as the imprint. Use of Luna requires a minimum age of 16 years. Personal terms refer to all possible genders, orientations, legal forms or bodies.