No ads, no public profile, and no sale of your information. Journal text and pattern reports are encrypted before database storage; patterns and weekly reviews start only when you ask.
Information we handle
We collect only the information needed to operate a private, synchronized journal:
- Account information: your email address, Apple or Google account identifier when you use that sign-in option, an internal account ID, and session records.
- Journal information: entries, dates, blocks, checklists, bookmarks, saved pattern reports and their source references, search requests, and files you choose to attach.
- Subscription information: trial dates, entitlement status, and purchase events provided by Apple or RevenueCat. Lunospark does not receive your full payment card details.
- Technical information: IP address, request time, route, device and browser information supplied with requests, and error details needed to protect and operate the service.
- Support information: your email address and anything you include when contacting support.
Drafts and a limited session snapshot may also remain on your device so the journal can continue working during a connection problem.
How we use it
We use this information to authenticate you, synchronize your journal, search your own entries, create a pattern report or weekly reflection only when you request one, store bookmarks and attachments, manage subscriptions, prevent abuse, answer support requests, and maintain the service.
We do not sell personal information. We do not run advertising, build advertising profiles, or use cross-app tracking. Ordinary journal writes do not invoke analysis. Pattern finding starts only after you choose a date range and tap Find patterns. Weekly reflection starts only after you choose a week and tap Review this week. The current version performs both inside Lunospark’s API rather than sending entries to a separate AI provider.
A generated weekly reflection remains temporary until you tap Save reflection. Saving converts your edited text and its source excerpts into an ordinary encrypted journal entry; leaving the review creates no server-side reflection record.
How your journal is protected
Journal blocks and saved pattern reports are encrypted before they are written to the production database. Search uses protected indexes instead of storing the search words alongside the entry. Session tokens are stored as one-way hashes on the server, and web sessions use secure, HTTP-only cookies.
This is server-side application encryption, not end-to-end encryption. The Lunospark API can decrypt an entry after authenticating you so it can return the entry and search your journal. Attachments are kept in private object storage and opened through short-lived signed links, but they do not yet use the same application-layer encryption as journal text.
Service providers
We use a small set of providers to run Lunospark:
- Railway for application hosting, PostgreSQL, and private object storage.
- Resend for one-time sign-in and service emails.
- Apple for Sign in with Apple, App Store distribution, and in-app purchases.
- Google for Google Sign-In when you choose that account option.
- RevenueCat for subscription entitlement management.
These providers receive only the information required for their role. They process information under their own terms and privacy commitments. Information may be processed outside your country, subject to the safeguards required by applicable law.
Legal bases
Where European data protection law applies, we process information to perform the service you request, to meet legal obligations, and for legitimate interests such as security, fraud prevention, reliability, and support. Where consent is the appropriate basis, you can withdraw it at any time without affecting earlier lawful processing.
Retention and deletion
Your journal and account data remain in active systems while your account exists. Expired authentication material and operational logs are retained only as long as needed for security and reliability. When you delete your account, Lunospark removes your entries, pattern reports, bookmarks, attachments, subscription record, challenges, and sessions from active systems.
Residual copies may remain temporarily in restricted provider backups until those backups rotate. They are used only for disaster recovery and are not restored to recreate a deleted account. Legal obligations may require limited records to be retained for longer.
Your choices and rights
From Account settings you can download a portable JSON export, sign out every active session, and permanently delete your account. You can also ask to access, correct, restrict, object to, or receive the personal information we hold about you where those rights apply.
Send privacy requests to [email protected]. We may need to verify that the request belongs to you. You may also complain to your local data protection authority.
Children and changes
Lunospark is not directed to children under 16, or the minimum digital-consent age in their country. If you believe a child has provided personal information without appropriate permission, contact us so we can remove it.
We will update this page when our practices materially change and will provide additional notice inside the service when required.
Contact
Lunospark is the controller of the information described here. Contact us at [email protected] or visit Lunospark Support.