Privacy Policy
Last updated: October 2, 2026
LunaRabbit ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our services, including:
- LunaRabbit Chat — AI chat assistant available at lunarabbit.ai and as a mobile app (iOS/Android). Features include web search, financial data retrieval, image generation, deep research, file analysis, and voice input.
- LunaRabbit Office — AI productivity tools for Microsoft Office™ and Google Workspace™ (Google Sheets™, Microsoft Excel™, Microsoft Word™, Microsoft PowerPoint™, and a standalone web editor).
- LunaRabbit Code — an AI coding assistant provided as a VS Code extension with a local engine and CLI (
lunarabbit-engine). - LunaRabbit Drive — file storage, sharing, and version management at drive.lunarabbit.ai.
Collectively referred to as the "Services."
Geographic scope. The Services are intended for users in South Korea, the United States, and other supported regions. They are not directed to, or intended for, residents of the European Economic Area (EEA) or the United Kingdom, our mobile apps are not distributed there, and we do not target, market to, or monitor individuals in those regions. This Policy is framed around the laws that apply to our supported markets (primarily Korea's PIPA and US privacy law).
1. Information We Collect
Account Information
When you create an account, we collect:
- Email address
- Password (stored in hashed form; we never store plaintext passwords).
- Display name
Usage Data
We automatically collect:
- Feature usage statistics (which tools and functions you use)
- Performance metrics (response times, error rates)
- Device and browser information
- IP address (for rate limiting and security)
Chat Data (LunaRabbit Chat)
When you use LunaRabbit Chat, we collect:
- Conversations: Your messages and AI responses are stored on our servers until you delete them (see Section 6).
- Tool usage: When you use built-in tools (web search, financial data, image generation), the queries you submit and results received are stored as part of your conversation.
- Voice input: If you use voice input, your audio is sent to a third-party speech-to-text service (OpenAI speech-to-text API) for transcription. We do not store audio recordings; only the resulting text is retained as part of your conversation.
- Generated images: Images created by the AI image generation tool are stored in Cloudflare R2 object storage and retained as part of your conversation history until you delete them (or delete the conversation or your account). You can delete generated images at any time.
- File uploads: Files you attach to messages (images, PDFs, Office documents, etc.) are uploaded to Cloudflare R2, processed for AI context, and retained for the duration of the conversation. Accepted file types are limited to a whitelist of safe formats. Files are scanned for malware indicators (VBA macros, ActiveX controls). You can delete uploaded files at any time.
- Deep Research: When you use the Deep Research feature, the AI performs multiple automated web searches and reads web pages to compile a research report. Search queries, fetched page content, and the final report are stored as part of your conversation. Research activity traces (steps, sources, duration) are retained alongside the report.
- Screen width: Your device's viewport width (in pixels) is sent with each message to optimize response formatting. This is a single number (e.g., 375) and cannot identify you.
- Acquisition source: If you reach us through a marketing link, the campaign label in the link (e.g.
utm_source) and the platform you started checkout from (web/iOS/Android) may be recorded with your account so we can understand which channels bring new users. This is a first-party record used only for our own aggregate reporting — it is never shared with, or sent to, any advertising network (we do not use the Meta Pixel, Meta Conversions API, or similar ad-tracking tools). - User memory: LunaRabbit Chat may proactively save facts you share (name, preferences, interests) to personalize future responses. You can view, edit, and delete saved memories at any time via Settings. Memory personalization is enabled by default for signed-in users except in Temporary Chat. It is a service personalization feature separate from the optional Model improvement consent, and you can turn personalization off in Settings.
- Quality feedback: When you provide thumbs-up or thumbs-down feedback on AI responses or generated images, this feedback is stored alongside the associated message. Anonymized feedback (with personal identifiers removed) may be used to improve service quality regardless of whether you have opted in to training-data use.
Code Data (LunaRabbit Code)
A LunaRabbit account and sign-in are required to use LunaRabbit Code. When you use it:
- Sent for processing: Your requests and attached images; the contents and paths of working-folder files read by the agent; commands it runs and their output; project rules files such as
CLAUDE.mdandAGENTS.md; and theMEMORY.mdindex of personal memory stored on your PC. Our server in AWS Seoul processes these inputs and sends AI inference requests for the default tier primarily to Fireworks AI in the United States, with Together AI in the United States as backup if the Fireworks key is absent or its service is unavailable. If you select a higher tier, inference requests are sent to Anthropic and OpenAI in the United States. Code web searches send query strings to Serper; when you use webFetch, our server fetches the URL you specify directly. The engine masks recognized secret-value patterns before transmission, but this cannot guarantee that every secret is removed. - Stored on our servers: Work-session records (requests, responses, tool-call records, change summaries, and the first 64 KiB of each change diff); the original inputs sent to the AI, including original attached images; and display records used to restore the session view. We do not upload or retain a server-side index of your code structure.
- Kept on your PC: Checkpoints in private Git refs within your repository, personal memory files, and engine settings remain local. The
MEMORY.mdindex described above is an exception: its contents are sent when included in AI input. - Retention and deletion: Server-side Code records are kept until you delete the work session or your account; there is no automatic time limit. Deleting a session removes its related records, with orphaned blobs and images cleared by garbage collection. Account deletion removes all associated Code data. Local files and checkpoints on your PC remain under your control.
Drive Data (LunaRabbit Drive)
A LunaRabbit account and sign-in are required to use LunaRabbit Drive. WebDAV access uses a separate app password. When you use Drive:
- Sent to our servers: Files you upload or update, file and folder names, sharing choices, search requests, and WebDAV requests. Our servers also process files to generate thumbnails for supported PDF and Office formats.
- Stored on our servers: File bytes and versions are stored in Cloudflare R2 object storage. Our servers in the AWS Seoul region store the file registry and metadata, including names, sizes, versions, sharing settings, and searchable file text. Drive records metadata for AI-generated files created by other LunaRabbit products; Drive does not itself call AI models for inference.
- Retention and deletion: Files, versions, associated metadata, search text, and thumbnails are retained while the files remain in your account, subject to the applicable plan's storage and retention rules. Deleted files may remain recoverable in Trash until permanent deletion. Account deletion follows the 30-day grace period described in our Terms, after which associated Drive data is deleted.
Mail Connector (Optional, Separate Consent)
Before you connect a mail account, we obtain separate consent for the mail connector (chat:mail_connector) once for each connected account. The append-only consent log records the time, IP address, User-Agent, and terms version.
- Connection information and stored credentials: We store the provider (Google, Microsoft, Naver, Kakao, or iCloud), the connected email address, granted scopes, connection status, token expiration time, last error, audit fields, and encrypted credentials. For Google and Microsoft OAuth connections, the credentials are refresh and access tokens. For Naver, Kakao, and iCloud IMAP connections, we store the app password. These credentials are encrypted at rest using AES-256-GCM. The Google permission is
gmail.readonly(read-only), and the Microsoft Graph permission isMail.Read. - Mail content and AI processing: When you ask LunaRabbit to search or read mail, the
searchEmailandreadEmailtools retrieve it from the provider API or IMAP at that time. We do not store the email body itself. The retrieved mail content is sent to the AI model provider to generate your requested answer. The resulting answer remains in the conversation messages. - Drafts, not sending: Automation may use IMAP APPEND to save a draft in your Drafts folder. LunaRabbit does not send the email on your behalf.
- Disconnecting and Microsoft permissions: Disconnecting immediately deletes the local connector record, including its stored credentials; deleting your LunaRabbit account also destroys the connector record. For Microsoft, LunaRabbit does not call remote revocation. Disconnecting in LunaRabbit deletes only the local record, and the Microsoft app permission remains until you revoke it yourself in your Microsoft account settings.
Account Required (LunaRabbit Chat)
A LunaRabbit account is required to use LunaRabbit Chat. We do not offer anonymous (non-logged-in) access to the chat service, and we do not process chat messages from users who are not signed in.
Document Data
We access your active document content to provide context for AI responses. Specifically:
- Google Sheets™: The content of your active sheet (used range) will be sent to our servers for processing. Sheet names will also be sent for navigation context.
- Microsoft Excel™: The content of your active worksheet (used range), sheet names, and cell formatting data will be sent to our servers for processing. This applies to both Microsoft Excel™ desktop and Microsoft Excel™ Online.
We also support Microsoft Word™, Microsoft PowerPoint™, and a standalone web editor. Similar data access policies apply to all platforms. Additional platforms (Google Docs™, Google Slides™) may be added in the future.
We do not access data from other files, closed documents, or documents you are not actively working with. During a conversation, the AI may read additional content from your active document as needed to complete your request.
Document content sent for AI processing is used to generate a response. Image-upload caches and transient processing artifacts are deleted within 24 hours; custom function result caches are retained for up to 30 days as described in Section 6.
Conversation History (Cloud Storage)
Effective May 11, 2026: chat conversations are stored on LunaRabbit servers (cloud-only) until you delete them; we do not delete them automatically on a time schedule. This change replaces the previous "session-memory only" model and was made so you can resume conversations across devices and recover history if you switch browsers.
- What is stored: conversation messages (user prompts and AI responses), conversation metadata (title, timestamps), and tool-call records.
- Retention: kept until you delete them — there is no automatic time-based deletion. When you delete a conversation or your account, it is removed immediately and permanently.
- Your rights: you can delete individual conversations or your entire history at any time via the in-app Settings menu (My Info → Privacy). Deletion is immediate and cascades to all related messages.
- Encryption: encrypted at rest using managed keys. Access is restricted to authenticated requests by you (the conversation owner). Our security measures are described in Section 5.
Anonymized Pattern Use — LunaRabbit Services (Account-Level Opt-in)
By default — and regardless of your consent setting — we do not currently collect, retain, or use your LunaRabbit content to train or improve AI models. The Model improvement feature is not yet active. Turning on Model improvement (via the consent modal or Settings — off by default) does not begin any collection now; it is advance authorization that takes effect only if and when we activate this feature. This single account-level choice covers all LunaRabbit products, including Chat conversations, Office documents and spreadsheets, and coding content. At that point, and only for users who have opted in, we may retain a de-identified snapshot of eligible content for the following planned purposes:
- Retrieval Augmentation (planned): snapshots may be extracted, quality-scored, and stored as fewshot examples in our vector database (Qdrant), to be retrieved as similar-case context for other users' prompts and improve response quality.
- Fine-Tuning (planned): when LunaRabbit develops its own AI models or undertakes directed fine-tuning of third-party models, anonymized patterns may be used as training data for supervised fine-tuning.
De-identification uses industry-standard techniques: named-entity recognition for personal names and organizations (Latin and CJK scripts), regex matching for emails, phone numbers, IP addresses, payment-card numbers, and government-issued identifiers. The retained data is associated only with an HMAC-derived session hash (never your user ID) and is intended to qualify as anonymized/de-identified information under applicable data protection law. We acknowledge no de-identification process is perfect and continuously improve our techniques.
Account-level consent: one opt-in setting applies across all LunaRabbit products tied to your account. Excluded regardless of this setting: Google user data received through Google APIs (such as Google Sheets content and Gmail content read by the Mail Connector) is never used for model improvement (see Section 9). Both Free and Paid plans: opt-in is independent of your subscription tier. Default is off — opt-in is required (we collect nothing for AI improvement until you affirmatively enable it). You can withdraw consent at any time via Settings. Note that already-incorporated patterns in our fewshot database or fine-tuned models cannot be retroactively removed, but no new patterns will be extracted from your LunaRabbit content after withdrawal.
Legal basis (all users): explicit account-level opt-in consent via the Model improvement item in the consent modal or Settings, which you may withdraw at any time. The consent is stored on your account. Your eligible content is not used for model improvement unless this opt-in is present. This satisfies the Korean PIPA Art. 22 별도 동의 (separate consent) requirement and the consent basis recognized under the US CCPA. We do not rely on processing-without-consent provisions (such as PIPA Art. 28-2) for this purpose — model-improvement use is consent-based.
When de-identified data is retained under this opt-in, it is associated only with an HMAC-derived session hash (never your user ID); no re-identification is attempted or permitted, and any downstream recipients are contractually prohibited from re-identification (consistent with the US CCPA definition of de-identified information). We maintain internal pseudonymization review procedures in accordance with PIPC guidelines (가명처리 적정성 검토). Retained data is kept for up to 3 years or until the model-improvement purpose is fulfilled, whichever is earlier, then securely destroyed.
Custom Function Inputs
When you use our custom AI functions (such as =LR.AI(), =LR.TRANSLATE(), =LR.WEB()), the prompt text and parameters you supply are stored as part of your usage history for analytics, billing accuracy, and abuse prevention. This information is associated with your account and is distinct from conversation content. You may export or delete this data at any time using the rights described in Section 8.
2. How We Use Your Information
We use your information to:
- Provide and improve our AI services
- Process your AI queries and return results
- Manage your account and billing
- Monitor service health and prevent abuse
- Communicate important service updates
- Enforce our Terms of Service
- At your request, search and read mail from a connected account, generate an answer using the retrieved content, and save an Automation draft to the Drafts folder without sending it
3. Third-Party Sub-Processors
To deliver our Services we share data with sub-processors under their commercial API or DPA terms. They fall into three categories:
- AI Model Processors — receive conversation text, document content, and Code inputs for model inference (OpenAI, Anthropic, Google, Fireworks AI, Together AI). OpenAI also receives image generation prompts and, for image edits, the attached or reference image, to generate images. When the Mail Connector is used, the model processor used for the requested answer also receives the retrieved mail content. fal.ai receives video generation prompts and, for image-to-video generation, the attached reference image. For videos with spoken dialogue, fal.ai also receives the voice audio of the requested line and a keyframe image, both generated by us from your prompt.
- Web Search, Fetch, and Research Processors — receive only search query strings or target URLs you reference (Serper.dev, Jina AI, Perplexity AI).
- Financial Data Processors — receive only ticker symbols or economic indicator IDs for data retrieval (Twelve Data, Finnhub, Federal Reserve FRED).
- Code Execution Processors — receive spreadsheet files you upload, the cell data extracted from them, and the generated code, for execution in an isolated sandbox (E2B). File contents may contain personal data depending on what you upload.
- Infrastructure Processors — host our backend or process request traffic (AWS, Cloudflare, Qdrant Cloud, Microsoft Azure AD). Cloudflare can see request content where TLS terminates, including on the Fireworks fallback route described below.
- Payment Processor — Paddle (Merchant of Record) processes payments; we never see your card details (see Section 15).
Mail Connector content sent for AI processing. When you ask LunaRabbit to search or read mail, the retrieved mail content is sent to the AI model processor used for that response to generate the requested answer. The email body itself is not stored by LunaRabbit, but the resulting answer is stored as part of your conversation.
The complete current list — including each sub-processor's purpose, region, and DPA URL — is published at lunarabbit.ai/subprocessors. We give at least 30 days' advance notice on that page before adding any new sub-processor that materially changes the categories of data we share.
Default behavior on commercial API tiers is no training on customer data — this is contractually guaranteed for OpenAI, Anthropic and Google, and is not subject to any toggle. Together AI's commitment is also contractual, but takes effect through an account-level Zero Data Retention setting, which we have enabled. The video generation provider (fal.ai) is an exception: its terms permit anonymized or aggregated data derived from customer input to be used for its own services and AI model development, with no opt-out offered; we mitigate this by disabling payload storage on every request we send. Our code execution sandbox (E2B) is a further exception: its Terms grant a perpetual, irrevocable, worldwide licence to use and exploit materials submitted to it — scoped to providing the service and operating its business — with no opt-out, and we have not obtained a data processing addendum from it. If you opt in to anonymized pattern use (Section 1), de-identified snapshots may additionally be sent to AI model providers for engineering analysis and future fine-tuning of LunaRabbit's own models.
Engineering Analysis (Internal). Authorized LunaRabbit personnel may review individual conversations for the limited purpose of debugging regressions, improving prompt quality, or investigating user-submitted error reports. This is human review of stored data — it does not send data to AI model providers and does not update any model's weights. Access is SSO + IP-allowlist gated and logged for audit. The same policy applies to "Improvement / Error Report" attachments you opt-in to submit.
4. International Data Transfers
Where we ourselves process your data. LunaRabbit Inc. is a Delaware corporation and processes personal data collected from users in the Republic of Korea in the United States; account data is additionally stored in the AWS Asia Pacific (Seoul) region. This statement is provided under Article 31(1)4 of the Enforcement Decree of Korea's Personal Information Protection Act, which requires an overseas controller that collects Korean users' data directly to name the countries in which it processes that data.
Legal basis for transfer. For Korean users, transfers to the recipients below are made under Article 28-8(1)3(a) of the Personal Information Protection Act — processing entrusted or stored abroad where necessary to perform our contract with you, disclosed through this Privacy Policy. Separate transfer consent is therefore not collected. The items required by Article 28-8(2) are set out in the table and the subsections that follow it.
Your data may be transferred to and processed in countries outside your country of residence. The table below summarizes the principal cross-border transfers:
| Recipient | Country | Data Transferred | Purpose | Retention |
|---|---|---|---|---|
| OpenAI OpCo, LLC | United States | Conversation text, system prompts; image generation prompts and, for image edits, the attached or reference image | AI model inference (GPT), image generation (gpt-image-2) | Up to 30 days (abuse monitoring) |
| Anthropic, PBC | United States | Conversation text, system prompts | AI model inference (Claude) | Up to 30 days |
| Google LLC | United States | Conversation text; text of a requested spoken line for video dialogue (speech synthesis); device push tokens and notification content (FCM) | AI model inference (Gemini), speech synthesis, push notification delivery | Varies by service |
| Together Computer, Inc. | United States | Conversation text, Code inputs, search queries, system prompts (only when used as backup to Fireworks AI) | Open-source model inference — backup if the Fireworks key is absent or Fireworks is unavailable | Zero Data Retention enabled (prompt storage and passthrough both OFF at the organization level) |
| Fireworks AI, Inc. | United States | Conversation text, Code inputs, system prompts | Primary open-source model inference across LunaRabbit products. Its outage fallback route uses a Cloudflare Tunnel, where TLS terminates at Cloudflare on that segment | Zero Data Retention by default; its terms prohibit training on customer data |
| fal.ai (Features and Labels, Inc.) | United States | Video generation prompts; attached reference image for image-to-video generation; for videos with spoken dialogue, generated voice audio of the requested line and a generated keyframe image | AI video generation | Varies by service |
| Apple Inc. | United States | Device push tokens, notification content (APNs) | Push notification delivery (iOS) | Not retained after delivery |
| Amazon Web Services, Inc. | United States | Account data (incl. email), conversation history, usage records, LunaRabbit Drive file metadata and searchable file text | Infrastructure hosting, data storage and backups | Until account deletion |
| Cloudflare, Inc. | Global (United States) | IP addresses, request paths, login/signup requests (incl. email), generated images and LunaRabbit Drive file bytes and versions; Fireworks inference traffic when its Cloudflare Tunnel fallback route is used | CDN, DDoS protection, request proxy, image and Drive file storage; TLS termination on the Fireworks fallback route | Per our retention policy (Section 6) |
| Resend, Inc. | United States | Email address, email content | Transactional email delivery (signup, verification, etc.) | Per our retention policy |
| Paddle.com Market Ltd. | United Kingdom | Name, email, billing address, payment method | Payment processing (Merchant of Record) | Per billing record requirements |
| FoundryLabs, Inc. (E2B) | United States | Uploaded spreadsheet files (XLSX/CSV), extracted cell data, generated code (may contain personal data depending on what you upload) | Code execution in an isolated sandbox (Office Builder mode) | Sandbox terminated at session end; vendor-side retention policy not confirmed |
| Serper LLC (serper.dev) | United States | Search query strings | Google search proxy on the low-cost search tier and for LunaRabbit Code webSearch | Per the recipient's privacy policy |
| Perplexity AI, Inc. | United States | Search query strings | AI-assisted search and synthesis (deep research proposals, Office Solver mode) | Per the recipient's privacy policy |
| Jina AI GmbH (r.jina.ai) | Singapore / Germany | Target URL strings you specify, and page content fetched on our behalf | Page fetch and text extraction (webFetch tool) | Per the recipient's privacy policy |
Mail Connector transfers. When you request a mail search or read, the retrieved mail content is transferred in real time to the AI model processor used to generate the requested answer, under the applicable recipient entry above.
Your primary account data (profile, conversations, usage history) is stored on AWS Seoul (ap-northeast-2). However, it may be transferred to or accessed from the United States and other countries through the infrastructure operator (Amazon Web Services, Inc.) and the sub-processors listed above. We apply safeguards required by applicable law to any personal data so transferred.
For overseas transfers we rely on your consent (collected at account registration) and on data processing agreements with each sub-processor, together with other lawful transfer safeguards, to ensure adequate protection. These jurisdictions may have different data protection laws than your country of residence. For the complete list of sub-processors, see lunarabbit.ai/subprocessors.
Recipients not listed above. Two entries on our Sub-Processors page are deliberately absent from this transfer table. Qdrant Solutions GmbH (Frankfurt) stores only embedding vectors for few-shot retrieval and does not store the underlying text; the stored vectors alone do not identify an individual, so we do not treat them as personal data. Finnhub receives ticker symbols only, with nothing that identifies a user. If that assessment changes, we will add them to the table.
Timing and method of transfer
Personal data is transferred in real time, per request, at the moment you use the relevant feature; we do not run scheduled bulk exports. The method is transmission to each recipient over an encrypted channel. Transfers for infrastructure and storage purposes (AWS, Cloudflare) are continuous for as long as the Service operates.
Contact details of recipients
Each recipient's privacy contact and policy is listed per vendor on our Sub-Processors page. For any question about a cross-border transfer you may contact us at [email protected] and we will act as your point of contact with the recipient.
How to refuse a transfer, and what happens if you do
- How: email [email protected], or delete your account in the app settings. No particular form is required.
- Effect: the core functions of the Service (AI responses, image and video generation, speech synthesis, web search) cannot technically be provided without the AI model processors located outside your country. If you refuse the transfer you will therefore be unable to use all or substantially all of the Service, which in practice is equivalent to closing your account. We state this plainly rather than leaving it to be discovered.
- No penalty for refusing — we do not forfeit fees already paid or charge a cancellation penalty; refunds follow the Refund Policy.
Grievance handling and dispute resolution for cross-border transfers
As required by Article 29-10(1)2 of the Enforcement Decree of Korea's Personal Information Protection Act, we handle complaints concerning personal data transferred abroad as follows:
- Intake: [email protected], received directly by our Data Protection Officer. Even where the incident originates with an overseas recipient, you file with us and we pursue verification and remediation with that recipient.
- Response time: we respond with the outcome, or with the status and an expected date, within 10 days of receipt.
- Dispute resolution: if you disagree with our handling, you may apply to the Personal Information Dispute Mediation Committee (Korea, +82-1833-6972), and we will participate in mediation in good faith. You may also report to the Korea Internet & Security Agency's privacy report centre (privacy.kisa.or.kr).
- Governing law: Korea's Personal Information Protection Act applies to the exercise of these rights, and our agreements with overseas recipients are not permitted to derogate from it.
5. Data Security
We implement industry-standard security measures:
- All data is transmitted over HTTPS (TLS 1.2/1.3). TLS is terminated at Cloudflare and again at our internal origin, so Cloudflare processes request content in the clear; it is listed as a sub-processor for that reason.
- Data at rest is encrypted using managed keys.
- Passwords are stored hashed; we never store them in plain text.
- Mail Connector OAuth refresh/access tokens and IMAP app passwords are encrypted at rest using AES-256-GCM.
- Server access is restricted to authorized LunaRabbit personnel, and production databases are reached only through audited session pipelines with access logging.
- Regular security audits and vulnerability assessments.
6. Data Retention
- Account data: Retained until you delete your account.
- Conversation history (cloud-only since 2026-05-11): Stored on LunaRabbit servers until you delete them; there is no automatic deletion. You can delete individual conversations or your entire history at any time via Settings (immediate, permanent, cascade-delete).
- LunaRabbit Code work sessions: Server-side records and original AI inputs, including attached images, are retained until you delete the session or your account; there is no automatic time limit. Orphaned blobs and images are cleared by garbage collection after session deletion.
- LunaRabbit Drive files: Files, versions, metadata, search text, and thumbnails are retained while the files remain in your account, subject to plan limits. Deleted files may remain in Trash until permanent deletion. Associated Drive data is deleted after the account deletion grace period.
- Anonymized pattern data (opt-in only): If you have opted in, anonymized snapshots (with personal information removed) are retained for retrieval augmentation and future fine-tuning. Retention follows our internal data lifecycle policy; once incorporated into the fewshot database or fine-tuned models, individual patterns cannot be retroactively removed (see Section 1, "Anonymized Pattern Use").
- Sub-processor retention: OpenAI up to 30 days (abuse monitoring), Anthropic up to 30 days, Google varies, Together AI Zero Data Retention enabled (prompt storage and passthrough both off at the organization level), fal.ai payload storage disabled on every request. None of the text model providers use data for training under commercial API tiers; fal.ai's terms permit anonymized or aggregated derived data to be used for its own AI model development (see Section 3). Providers may apply short-lived performance caching that is not subject to these retention periods.
- AI processing cache: Temporary data (images, context) is deleted within 24 hours. This temporary cache is separate from the original Code inputs retained with a work session as described above. Custom function result caches are retained for up to 30 days to improve performance.
- Mail Connector records: Retained until you disconnect the mail account or delete your LunaRabbit account. Disconnecting immediately deletes the local connector record, including encrypted OAuth tokens or the encrypted IMAP app password. We do not store email bodies; the answer generated from retrieved mail remains in conversation history until you delete that conversation or your account. For Microsoft, local deletion does not revoke the permission held by Microsoft; you must revoke the app permission yourself in your Microsoft account settings.
- Security and audit logs: Connection records (access time, IP address, request path, and processing result) are retained for one year and then deleted. If you delete your account, IP addresses in logs linked to that account are removed immediately; IP addresses in logs not linked to an account (such as login attempts or blocked requests) remain subject to the one-year retention period.
- Usage analytics: Retained in aggregated, anonymized form.
- Billing records: Retained as required by applicable law.
7. Cookies and Local Storage
Our Services use cookies together with browser local storage and session storage to maintain your authentication state and preferences. We do not use third-party tracking cookies. Essential storage is required for the Services to function and cannot be disabled.
For full details on what we store and how to manage it, see our Cookie Policy.
LunaRabbit Chat specific storage:
lr_session(httpOnly, 7-day expiry) — Maintains your login session.lr_refresh(httpOnly, 30-day expiry) — Enables automatic session renewal so you stay signed in.lr_csrf(30-day expiry) — Prevents cross-site request forgery.lr_consent(1-year expiry) — Records your cookie consent preference. Classified as an essential cookie required for the Services to function.lr_theme(1-year expiry, domain.lunarabbit.ai) — Your chosen color scheme, shared across LunaRabbit products so one choice applies everywhere. Holds only that choice and no identifier.
8. Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your account and associated data
- Export a machine-readable copy of your personal data. You can download your data directly from the Settings menu in your account, or by contacting us.
- Restrict processing of your personal data in certain circumstances
- Object to processing of your personal data based on legitimate interest
- Opt out of non-essential data processing (anonymized pattern use — see Section 1, "Anonymized Pattern Use")
Legal representatives. Where applicable law allows a legal representative to act for a data subject, the representative may exercise the rights above on that person's behalf on proof of authority. Our Services are not directed to anyone under 18 and we do not knowingly process children's data (Section 10), so we do not operate a guardian-consent flow.
To exercise any of these rights, contact us at [email protected]. For data export, you can also use the self-service "Download My Data" option in your account Settings, which provides a JSON file containing your profile, transaction history, and usage records.
California Residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale of personal information. We do not sell your personal information.
Our Services do not respond to "Do Not Track" (DNT) browser signals because there is no industry-accepted standard for DNT. However, we do not engage in cross-site tracking.
South Korea Residents (PIPA)
If you are located in South Korea, the following provisions under the Personal Information Protection Act (개인정보 보호법) apply:
- Collection Notice (Art. 15): The categories of personal information we collect and the purposes for which we use them are described in Sections 1 and 2 of this Privacy Policy.
- Third-Party Provision (Art. 17): We provide personal data to third-party sub-processors as described in Section 3 and on our Sub-Processors page. Each sub-processor's purpose, data categories, and region are disclosed.
- Overseas Transfer (Art. 28-8): Personal data is transferred to sub-processors outside Korea (primarily the United States) as described in Section 4. We rely on Article 28-8(1)3(a) — transfer necessary to perform a contract with you, disclosed in this Privacy Policy — so no separate transfer consent is collected. The recipient entities, purposes, data categories, regions, and retention periods are set out in the table in Section 4 and on our Sub-Processors page.
- Separate Consent for Anonymized Pattern Use (Art. 22): See Section 1, "Anonymized Pattern Use."
- Data Protection Officer: [email protected]
9. Google API Services User Data Policy
LunaRabbit's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only access Google user data necessary to provide the Services: active spreadsheet content for AI processing, and mail content through the read-only
gmail.readonlyscope when you use the Mail Connector. - We do not use Google user data for serving advertisements.
- We do not use Google user data to develop, improve, or train generalized AI or machine-learning models, regardless of your Model improvement setting.
- We do not allow humans to read Google user data unless we have your affirmative agreement, it is necessary for security purposes, or it is required by law.
- We do not transfer Google user data to third parties except as necessary to provide the Services (AI model providers under their commercial API terms, which prohibit the use of customer data for model training), with your consent, for security purposes, or as required by law.
10. Children's Privacy
Our Services are intended for adults and are not directed to anyone under the age of 18 (or the minimum age required by applicable law in your jurisdiction). We do not knowingly collect personal information from anyone under 18. By creating an account, you represent that you are at least 18 years old. If we learn that we have collected personal information from someone under the applicable minimum age, we will promptly delete that information. In all cases, we apply the heightened protections required by Korean law for children under 14, including legal-guardian consent.
11. Data Breach Notification
In the event of a data breach that affects your personal information, we will notify affected users via email within 72 hours of becoming aware of the breach, as required by applicable law.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on our website or sending an email to your registered address. Your continued use of the Services after such changes constitutes acceptance of the updated policy.
13. Data Retention After Account Deletion
Upon account deletion, your personal identifiers (email, name, IP address) are removed immediately. Anonymized, aggregated usage data (such as feature usage counts, response time metrics) that was previously de-identified during your use of the Service is retained indefinitely for service improvement, consistent with Section 6. This data cannot be used to identify you.
14. AI-Generated Content Transparency
Advance notice. LunaRabbit Chat, LunaRabbit Office, and LunaRabbit Code are operated on the basis of generative artificial intelligence. Responses, formulas, code, images, video, audio, and other outputs you receive from those products are produced by AI models. LunaRabbit Drive may store or display AI-generated files made by those products, but Drive does not itself call AI models for inference. This is disclosed in our Terms of Service and on the product surfaces themselves, before you use the Services.
Labeling of generated media. Images and video created by our generation tools are presented on cards labeled "Generated image" and "Generated video" in the conversation view and in your library. Read-aloud and audio-overview features are labeled as such in the interface. These are human-readable indicators, displayed at the point the output is delivered to you.
What we do not currently do. We do not embed a watermark, C2PA provenance manifest, or other machine-readable marking inside generated image, video, or audio files. Once you download, export, or share a generated file, the file itself carries no marking. If you republish AI-generated media outside the Services, disclosing that it is AI-generated is your responsibility.
Where our Services are used by users in the Republic of Korea, these measures are provided under Article 31 of the Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust and Article 23 of its Enforcement Decree, which permit disclosure through the terms of service and human-perceptible labeling.
AI-generated outputs should be reviewed before use. We do not guarantee the accuracy, completeness, or fitness of AI-generated content for any particular purpose.
15. Payment Processing (Merchant of Record)
Payments for paid plans are processed through Paddle.com Market Limited, a third-party payment processor that acts as our Merchant of Record (MoR). Paddle is identified at checkout. Under this arrangement:
- Your card or other payment method is collected and processed by Paddle on its own hosted checkout. LunaRabbit never sees your full payment card details — we only receive a customer identifier and a transaction summary (amount, status, invoice link).
- Paddle handles multi-currency conversion, VAT / GST / US sales tax calculation, and invoice issuance on our behalf as the legal seller of record.
- Paddle's own privacy policy governs the processing of payment data; a link is also provided at checkout.
16. Contact Us
If you have questions about this Privacy Policy, contact us at:
- Email: [email protected]
- Website: https://lunarabbit.ai
- Services: LunaRabbit Chat, LunaRabbit Office, LunaRabbit Code, and LunaRabbit Drive, operated by LunaRabbit Inc.
- Data controller (entity): LunaRabbit Inc., a Delaware corporation
- Mailing address: LunaRabbit Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, United States