Privacy Policy

LunaRabbit ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our services, including:

Collectively referred to as the "Services."

1. Information We Collect

Account Information

When you create an account, we collect:

Usage Data

We automatically collect:

Document Data

When our Services become available, we will access your active document content to provide context for AI responses. Specifically:

We plan to expand to additional platforms (Google Docs™, Google Slides™, Microsoft PowerPoint™, Microsoft Word™) in the future. When these platforms become available, similar data access policies will apply, and this Privacy Policy will be updated accordingly.

We do not access data from other files, closed documents, or documents you are not actively working with. During a conversation, the AI may read additional content from your active document as needed to complete your request.

Document content sent for AI processing is used to generate a response. Image-upload caches and transient processing artifacts are deleted within 24 hours; custom function result caches are retained for up to 30 days as described in Section 6.

Conversation History (Cloud Storage)

Effective May 11, 2026: chat conversations are stored on LunaRabbit servers (cloud-only) for up to 365 days from creation, after which they are automatically deleted. This change replaces the previous "session-memory only" model and was made so you can resume conversations across devices and recover history if you switch browsers.

Anonymized Pattern Use (Opt-in)

If you opt in via the Disclaimer modal at sign-up or the in-app Settings menu, we may retain a de-identified snapshot of each conversation turn for the following purposes:

De-identification uses industry-standard techniques: named-entity recognition for personal names and organizations (Latin and CJK scripts), regex matching for emails, phone numbers, IP addresses, payment-card numbers, and government-issued identifiers. The retained data is associated only with an HMAC-derived session hash (never your user ID) and is intended to qualify as anonymous information under GDPR Recital 26. We acknowledge no de-identification process is perfect and continuously improve our techniques.

Both Free and Paid plans: opt-in is independent of your subscription tier. Default is opt-out (we collect nothing for AI improvement until you affirmatively enable it). You can withdraw consent at any time via Settings. Note that already-incorporated patterns in our fewshot database or fine-tuned models cannot be retroactively removed, but no new patterns will be extracted from your conversations after withdrawal.

Legal basis: GDPR Art. 6(1)(a) explicit consent + Art. 7(3) right to withdraw. Korean PIPA Art. 22 별도 동의 (separate consent) requirement satisfied via the dedicated checkbox.

Custom Function Inputs

When you use our custom AI functions (such as =LR.AI(), =LR.TRANSLATE(), =LR.WEB()), the prompt text and parameters you supply are stored as part of your usage history for analytics, billing accuracy, and abuse prevention. This information is associated with your account and is distinct from conversation content. You may export or delete this data at any time using the rights described in Section 8.

2. How We Use Your Information

We use your information to:

3. Third-Party Sub-Processors

To deliver our Services we share data with sub-processors under their commercial API or DPA terms. They fall into three categories:

The complete current list — including each sub-processor's purpose, region, and DPA URL — is published at lunarabbit.ai/subprocessors. We give at least 30 days' advance notice on that page before adding any new sub-processor that materially changes the categories of data we share.

Default behavior on commercial API tiers is no training on customer data — this is contractually guaranteed and not subject to opt-in toggles. If you opt in to anonymized pattern use (Section 1), de-identified snapshots may additionally be sent to AI model providers for engineering analysis and future fine-tuning of LunaRabbit's own models.

Engineering Analysis (Internal). Authorized LunaRabbit personnel may review individual conversations for the limited purpose of debugging regressions, improving prompt quality, or investigating user-submitted error reports. This is human review of stored data — it does not send data to AI model providers and does not update any model's weights. Access is SSO + IP-allowlist gated and logged for audit. The same policy applies to "Improvement / Error Report" attachments you opt-in to submit.

4. International Data Transfers

Your data may be transferred to and processed in the United States and other countries where our AI service providers operate. We rely on your consent and, where applicable, standard contractual clauses or other lawful transfer mechanisms to ensure adequate protection of your data. These jurisdictions may have different data protection laws than your country of residence.

5. Data Security

We implement industry-standard security measures:

6. Data Retention

7. Cookies and Local Storage

Our Services use browser local storage and session storage to maintain your authentication state and preferences. We do not use third-party tracking cookies. Essential storage is required for the Services to function and cannot be disabled.

For full details on what we store and how to manage it, see our Cookie Policy.

8. Your Rights

Depending on your location, you may have the right to:

To exercise any of these rights, contact us at [email protected]. For data export, you can also use the self-service "Download My Data" option in the add-in's menu, which provides a JSON file containing your profile, transaction history, and usage records.

California Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale of personal information. We do not sell your personal information.

Our Services do not respond to "Do Not Track" (DNT) browser signals because there is no industry-accepted standard for DNT. However, we do not engage in cross-site tracking.

European Economic Area (EEA) and UK Residents (GDPR)

If you are located in the EEA or UK, the following additional provisions apply:

9. Google API Services User Data Policy

LunaRabbit's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

10. Children's Privacy

Our Services are not intended for children under the age of 13 (or the minimum age required by applicable law in your jurisdiction). We do not knowingly collect personal information from children under 13. By creating an account, you represent that you meet the minimum age requirement in your jurisdiction. If we learn that we have collected personal information from a child under the applicable minimum age, we will promptly delete that information.

11. Data Breach Notification

In the event of a data breach that affects your personal information, we will notify affected users via email within 72 hours of becoming aware of the breach, as required by applicable law.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on our website or sending an email to your registered address. Your continued use of the Services after such changes constitutes acceptance of the updated policy.

13. Data Retention After Account Deletion

Upon account deletion, your personal identifiers (email, name, IP address) are removed immediately. Anonymized, aggregated usage data (such as feature usage counts, response time metrics) that was previously de-identified during your use of the Service is retained indefinitely for service improvement, consistent with Section 6. This data cannot be used to identify you.

14. AI-Generated Content Transparency

In anticipation of the EU AI Act transparency requirements (Art. 50, effective August 2026), all content generated by our AI services is proactively labeled as AI-generated within the user interface. When our AI agents produce text, formulas, code, or other outputs, a visible indicator is displayed alongside the response. This ensures you can always distinguish AI-generated content from human-authored content.

AI-generated outputs should be reviewed before use. We do not guarantee the accuracy, completeness, or fitness of AI-generated content for any particular purpose.

15. Payment Processing (Merchant of Record)

When paid plans are introduced, payments will be processed through a third-party payment processor that acts as our Merchant of Record (MoR). The identity of the processor is disclosed at checkout. Under that arrangement:

16. Contact Us

If you have questions about this Privacy Policy, contact us at: