Privacy Policy

Effective Date of this Privacy Policy: September 5, 2026


1. Introduction and Data Controller


Protecting your personal data is important to us. This Privacy Policy explains what data we collect, for what purposes we process it, and what rights you have regarding your personal data.


This Privacy Policy applies to the use of the mobile application Lunaletics (hereinafter referred to as the “App”) on smartphones and tablets and to the website www.lunaletics.com (hereinafter referred to as the “Website” or “homepage”).


Data Controller


The controller within the meaning of the General Data Protection Regulation (GDPR) is:


Lunaletics GmbH

Merianstr. 31, 80637 Munich, Germany

Email: info@lunaletics.com


Privacy contact


For questions about data protection and to exercise your rights as a data subject, contact:

Lunaletics GmbH

Merianstr. 31, 80637 Munich, Germany

Email: info@lunaletics.com


Data Protection Officer


A data protection officer within the meaning of Article 37 GDPR has not currently been appointed. Please send all privacy inquiries to the contact address above.


Age and minors


The App and Website are intended exclusively for persons aged 18 and over. Use by younger persons is not permitted. We do not knowingly collect personal data from minors. If we become aware that data of a person under 18 has been stored, we will delete it. The service is not directed at children under COPPA (under 13) or comparable laws.


1.1 Jurisdiction-Specific Information for the United Kingdom (UK)


This Privacy Policy also applies to users located in the United Kingdom, in accordance with the applicable data protection laws under the UK Data Protection Act 2018 in conjunction with the UK GDPR (United Kingdom General Data Protection Regulation).


The controller for the purposes of the UK GDPR is the same as the controller named above under Article 4(7) of the EU GDPR.


A representative in the United Kingdom within the meaning of Article 27 UK GDPR has not currently been appointed. You may exercise your rights directly against the controller named above.


To exercise your data protection rights in the United Kingdom, you may contact the relevant supervisory authority:


Information Commissioner’s Office (ICO)

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, UK

https://ico.org.uk


1.2 Jurisdiction-Specific Information for Switzerland


This Privacy Policy also applies to users residing in Switzerland and complies with the provisions of the Swiss Federal Act on Data Protection (revFADP / revDSG).


The controller processes personal data in accordance with the principles of purpose limitation, proportionality, and data security pursuant to the revFADP.


A representative in Switzerland within the meaning of Article 14 revFADP has not currently been appointed. You may exercise your rights directly against the controller named above.


Under the revised Swiss data protection law (revFADP), we refer to “personal data” as “personal information” or “Personendaten”, as legally defined.


You have the right to access, rectification, erasure, and objection in accordance with Articles 25 et seq. of the revFADP.


The competent supervisory authority in Switzerland is:


Federal Data Protection and Information Commissioner (FDPIC / EDÖB)

Feldeggweg 1, 3003 Bern, Switzerland

https://www.edoeb.admin.ch


1.3 Jurisdiction-Specific Information for Canada


For users in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) and the enhanced requirements under the Québec Act respecting the protection of personal information in the private sector (Bill 64) apply in addition to this Privacy Policy.


Legal basis and purpose

Personal data is processed exclusively for the purposes stated in this Privacy Policy and on the basis of the user’s consent. Health and sensitive data will only be processed if the user has given explicit consent.


Transfer outside Canada

Data may be transferred to our processors located in the European Union or other countries. In doing so, we ensure that an adequate level of protection is maintained (e.g., through EU Standard Contractual Clauses).


User rights

Under Canadian law, users have in particular the following rights:

• Access to their personal data stored by us

• Correction of inaccurate or incomplete data

• Withdrawal of consent with effect for the future

• Deletion of data, insofar as no statutory retention obligations apply

• Information about cross-border data transfers


Contact for Canada

Questions or concerns from Canadian users can be directed to the contact details of the controller provided above. For Québec, Managing Director David Schulten is the person in charge of the protection of personal information (reachable at the same contact details). Upon request, we will provide additional information about our safeguards for data transfers outside Canada.


1.4 Jurisdiction-Specific Information for Australia


For users in Australia, the Privacy Act 1988 (Cth) applies in addition to this Privacy Policy.


Legal basis and purpose

Personal data is processed exclusively for the purposes stated in this Privacy Policy and only with the user’s consent. Health and sensitive data are processed solely with explicit consent.


Transfer outside Australia

As data is processed on servers located within the European Union and in some cases in third countries, appropriate safeguards (e.g., EU Standard Contractual Clauses) are implemented to ensure a level of protection consistent with Australian law.


User rights

Users in Australia have in particular the following rights:

• Access to their personal data stored by us

• Correction of inaccurate, incomplete, or outdated data

• Withdrawal of consent with effect for the future

• The right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if they believe their privacy rights have been violated


Contact for Australia

Inquiries from Australian users can be directed to the controller’s contact details provided above.


1.5 Jurisdiction-Specific Information for Brazil


For users residing in Brazil, the provisions of the Lei Geral de Proteção de Dados (LGPD, Law No. 13.709/2018) apply in addition to this Privacy Policy.


Legal basis and purpose

Personal data will only be processed for the purposes described in this Privacy Policy. Health data and other sensitive data are processed exclusively based on your explicit consent.


International data transfers

As data processing may occur on servers located within the European Union and, in some cases, in third countries, we implement appropriate safeguards (such as EU Standard Contractual Clauses) to ensure an adequate level of data protection in compliance with the LGPD.


User rights under the LGPD

In accordance with the LGPD, users have the following rights:

• Confirmation of whether personal data is being processed

• Access to the personal data we hold about you

• Correction of incomplete, inaccurate, or outdated data

• Anonymization, blocking, or deletion of unnecessary or excessive data

• Portability of data to another service provider (where technically feasible)

• Withdrawal of previously granted consent with future effect

• Information about data sharing practices and the ability to object to processing

• The right to lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD)


Contact for Brazil

Brazilian users may direct any questions or concerns to the Controller using the contact details provided in Section 1. The same contact serves as the person to whom LGPD requests (Encarregado) may be addressed.


2. General Information on Data Processing


We process personal data exclusively in accordance with applicable data protection laws, in particular the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). Your data is only processed where permitted by law or where you have given your consent.


2.1 Legal Bases for Processing


The processing of your personal data is based on the following legal grounds:

Article 6(1)(a) GDPR – Consent

(e.g. for health data, newsletter subscription, feedback submission)

Article 6(1)(b) GDPR – Performance of a Contract

(e.g. for registration, use of the App, payment processing)

Article 6(1)(f) GDPR – Legitimate Interests.

Our legitimate interests are in particular: secure and uninterrupted operation of the App and Website, error analysis and stability, handling contact requests, occasional email requests to improve the quality of the App, and—where not already required for the contract—delivering video content you have requested.

Article 9(2)(a) GDPR – Explicit Consent for processing special categories of personal data

(particularly health-related data such as menstrual and cycle information)

Section 25 TDDDG (German Telecommunications Digital Services Data Protection Act, formerly TTDSG) – storing or accessing information on your end device where this is strictly necessary for a service you have expressly requested, or where you have consented.


These legal bases apply accordingly under the UK GDPR and the UK Data Protection Act 2018.


2.2 Recipients of Personal Data


Your personal data is only shared with third parties where this is necessary to fulfill a contract, required by law, or where you have explicitly consented. This includes, for example, payment providers, hosting services, and email distribution providers.


Data may be shared in particular with:

Processors under Article 28 GDPR (e.g. hosting by Supabase, website hosting by Hostinger)

Platform providers (e.g. Apple, Google)

Payment processors (e.g. RevenueCat)

Support and feedback tools (e.g. Sentry, Wiredash)

Email distribution service providers (Brevo)

Video streaming (Vimeo)


2.3 Data Transfers to Third Countries


Some of the services we use may process personal data outside the European Union, particularly in the United States, or are established there. In such cases, we ensure that an adequate level of data protection is maintained, for example by concluding Standard Contractual Clauses (SCCs) issued by the European Commission or by implementing other appropriate safeguards. Details are set out in Section 6.


2.4 Data Processing on Our Behalf (Data Processing Agreements)


We work with selected service providers under data processing agreements in accordance with Article 28 GDPR. These processors act strictly on our instructions and are contractually bound to adhere to strict data protection requirements.


2.5 Access to End Devices (Section 25 TDDDG)


Where we store information on your end device or access it (e.g. session tokens, local helper values, embedded Vimeo videos, technically necessary website logs), Section 25 TDDDG applies in addition.


Strictly necessary for the service you have requested—and therefore without separate consent under Section 25(2) TDDDG—are in particular:

session tokens for login

local helper values for App operation (e.g. completion of the starter guide)

retrieval of videos you start in the App

technically necessary website server logs for security and operability


The Website does not set cookies and does not use analytics or marketing pixels or any other non-essential access to your end device. A cookie banner is therefore not currently required. If this changes, we will obtain your prior consent under Section 25(1) TDDDG.


2.6 Source of the Data


Most data is obtained directly from you (entries in the App or Website, newsletter subscription, email contact, feedback).


In addition, we receive data from third parties or generate it ourselves:

Apple, Google, and RevenueCat transmit transaction and subscription status linked to your user account

your device or browser transmits technical data (e.g. language, time zone, IP address)

cycle phases, ovulation date, and energy level are derived by us from your input

Sentry and Wiredash generate technical diagnostic data in the event of errors or feedback

for occasional quality questions we use the email address of your user account (see Section 3.11)


2.7 Whether Providing Data Is Required


Providing your email address and signing in with a one-time code is required to conclude the contract and use the App. Without this data we cannot create a user account.


Health and cycle data are required for the App’s core function (cycle-adapted training). Without your explicit consent we cannot provide the App; use without these data is not possible. You give this consent separately at registration. Withdrawal is effected by deleting your user account, because the App cannot function without these data.


Newsletter, feedback, optional contact, and answering quality questions by email are voluntary. Not providing this data, or objecting to quality emails, has no effect on use of the App.


3. What Data Is Collected?


When using our App and Website, the following categories of personal data may be collected. This data is obtained either through your active input, through the use of features, or automatically via your device or browser.


3.1 Registration and Login Data


To create and manage your user account, we collect:

Email address

One-time login code (OTP) sent to your email address

User ID (assigned automatically)

Session and refresh tokens (stored locally on the device in encrypted form)


We do not collect or store a password. Authentication is performed exclusively via email and a one-time code.


3.2 Health and Cycle Data (Special Category of Data)


To provide personalized content and functionality, we collect or generate—with your explicit consent—the following information:

Entered period start dates

Duration of period and cycle (estimate and later adjustments)

Distinction between confirmed and extrapolated cycles

Derived information such as cycle phases, estimated ovulation date, and energy level derived from the phase

Self-assessed fitness level

Strength levels per movement group (e.g. pull, push, bend, squat)

Health-related workout types (e.g. period pain relief)


This information constitutes special categories of personal data under Article 9 GDPR and is only processed with your explicit consent. The App does not replace medical advice or diagnosis.


3.3 Training and Activity Data


To track and analyze your training activities, we collect:

Workout type, status, and selected video or audio workouts

Performed exercises (movement group, level, target and completed repetitions or duration)

Date, time, and progress (including level changes)


3.4 Technical Data


To operate the App and Website and for troubleshooting and security, we process technical data where it arises in connection with the respective service:

Device language setting and time zone

Device type, operating system, and comparable technical details

IP address (in particular for website access, authentication, video playback, and error reports)


We do not collect location data. We do not operate our own in-app usage or click tracking (no collection of app launches, clicks, or visited screens for analytics purposes).


Further technical data may arise in connection with the services described in Section 5.


3.5 Payment Data


For access to paid content and subscriptions, we process the following:

Payment provider: RevenueCat (in combination with Apple or Google)

Linking of your user ID to the subscription status

Transaction ID, product ID, and payment status (transmitted by Apple, Google, or RevenueCat, not entered by you)


Note: No credit card or bank account data is stored in the App itself.


3.6 Consent Records


To document your data protection consents, we store:

Timestamp of acceptance of the Privacy Policy and Terms of Service

Timestamp of explicit consent to health data processing

For newsletter subscription via the Website: timestamp, content of the consent, and the double opt-in confirmation


3.7 Website Access Data


When visiting our website www.lunaletics.com, our hosting provider automatically collects server log files, including:

IP address

Date and time of access

Accessed pages or files

Referrer URL (if provided)

Browser and operating system used


These data are used exclusively to ensure smooth operation of the website, for troubleshooting, and for IT security purposes. They are not combined with App account data. Access takes place, where strictly necessary for secure operation, on the basis of Article 6(1)(f) GDPR and Section 25(2) TDDDG. Logs are generally deleted after no more than 14 days, unless a longer retention is required to investigate security incidents.


The Website does not set cookies and does not embed analytics, marketing, or social-media tools.


Hosting provider: Hostinger International Ltd., Lithuania

Server location: France (EU)

Privacy policy of the provider: https://www.hostinger.com/privacy-policy


3.8 Newsletter


You can subscribe to our email newsletter via our homepage. Newsletter subscription is currently not available in the App.


The email address is used solely to send information about the Lunaletics App, new features, offers, or health-related content.


Subscription is voluntary and requires separate opt-in consent on the Website, confirmed by double opt-in: after signing up you receive an email with a confirmation link. Your address is added to the list only after you click that link.

Legal basis: Article 6(1)(a) GDPR – Consent. To demonstrate consent we store the time and content of the consent and the double opt-in confirmation.


You may revoke your consent at any time with future effect, e.g., by clicking the “Unsubscribe” link in any email or by contacting us using the details provided above.


Newsletter distribution is handled via the service Brevo. Your email address is transmitted to Brevo and processed there solely for the purpose of sending the newsletter. Brevo does not use open or click tracking for our newsletter.


Your email address is only used for sending the newsletter and is not shared with third parties. The newsletter contains general information about the App; it is not personalized using your cycle or health data from the App.


3.9 Contacting Us


If you contact us via email, the personal data you provide (e.g., email address, name, message content) will be used exclusively to respond to your inquiry.


Legal basis:

Article 6(1)(b) GDPR – pre-contractual steps or performance of a contract, or

Article 6(1)(f) GDPR – our legitimate interest in effective communication.


Your data will not be shared with third parties and will only be retained as long as necessary to process your inquiry. See the general section on data deletion and your rights as a data subject.


3.10 Local Storage on the Device


We store locally on your device:

Session tokens for login (encrypted in secure storage)

Technical helper values, e.g. whether the starter guide has been completed


These data remain on the device and are removed on logout or account deletion. The storage is strictly necessary for the App operation you have requested (Section 25(2) TDDDG).


3.11 Quality Feedback by Email


From time to time we email individual users to ask what they like about the App. The sole purpose is to improve the quality of the App. This is not advertising, a newsletter, or other direct marketing. We do not send offers, product announcements, or promotional content.


Recipients are selected at random or based on recent active use of the App (e.g. sign-in or use within a given period). Health, cycle, and training data are not used for selection and are not mentioned in the message.


We process:

the email address of your user account

your user ID, where needed for internal assignment

any reply you send (free text)


We send these emails ourselves. No email distribution service provider is used (in particular not Brevo). The data is not shared with third parties.


The legal basis is Article 6(1)(f) GDPR (our legitimate interest in improving the App and its quality of use). Participation is voluntary. You may object to being contacted at any time—informally by replying to the email or by writing to info@lunaletics.com. After an objection we will not contact you again for this purpose.


We keep replies only as long as needed to evaluate the feedback and then delete them.


4. How Is This Data Used?


We process your personal data solely for the purpose of providing, improving, and securing the App and Website, as well as fulfilling our contractual and legal obligations. Each category of data is used for the following specific purposes:


4.1 Registration and Login Data

Creation and management of your user account

Authentication via email and one-time code

Maintaining your session

Linking your personal data within the App

occasional, non-promotional individual questions to improve the quality of the App (see Section 3.11)


4.2 Health and Cycle Data

Creation of a personalized cycle and training profile

Adapting training recommendations based on your cycle history and current phase

Display of cycle phases, period history, and derived information (e.g. energy level)

Adapting exercise selection to your strength and fitness level


These data fall under special categories of personal data as defined by Article 9 GDPR and are only processed with your explicit consent.


4.3 Training and Activity Data

Recording and visualization of your training activities

Progress tracking within the App

Personalized training suggestions


4.4 Technical Data

Ensuring technical functionality of the App and Website

Display in the correct language and with accurate dates

Error analysis and IT security


4.5 Payment Data

Managing in-app purchases and subscriptions

Verifying and assigning transactions to your user account

Integration with payment processor RevenueCat (including Apple or Google, where applicable)


Note: No credit card or bank account data is stored directly within our App.


4.6 Consent Data

Documentation of your data processing consents

Management of your consent preferences (e.g. health data, newsletter)

Demonstrating compliance with GDPR requirements


4.7 Automated Decision-Making and Profiling


We do not engage in automated decision-making within the meaning of Article 22 GDPR or the corresponding provisions of the UK GDPR that would produce legal effects concerning you or similarly significantly affect you.


To provide the service, we evaluate your cycle and training information in order to adapt content and exercise suggestions to your current cycle phase and fitness level. This personalization is used solely to perform the contract and has no legal effect.


5. Use of Third-Party Services and Tools


To provide and improve our App and Website, we rely on carefully selected third-party services. These providers process data either on our behalf (as data processors) or under their own responsibility. Where required, we have entered into data processing agreements (DPAs) in accordance with Article 28 GDPR.


We currently do not use push notifications or installation/marketing tracking (e.g. Appsflyer).


5.1 Supabase (Authentication & Database)


We use the service Supabase, provided by:


Supabase Inc.

970 Toa Payoh North, #07-04, Singapore 318992


Supabase handles user management (registration and login via email and one-time code) and stores your App data, including health-related data, in a PostgreSQL database. It also sends the one-time code to your email address. Storage takes place on servers located within the EU. The provider is established in Singapore; access from a third country therefore cannot be completely ruled out. Where required, we rely on EU Standard Contractual Clauses (SCCs).


5.2 Sentry (Error Monitoring)


To monitor app stability and log errors, we use Sentry, operated by:


Functional Software, Inc. (Sentry)

45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA


Technical data (e.g., device type, operating system, error code, timestamp) may be transmitted. In addition, a screenshot of the currently displayed screen may be sent when a crash occurs. Text and images in this screenshot are automatically masked. Health, cycle, and other sensitive content are not recognizable from it. Only the video player may remain unmasked to diagnose playback issues; it does not display health data.


Processing is based on our legitimate interest in ensuring the stability and security of the App (Article 6(1)(f) GDPR). Error reports are processed on servers located in the EU (data center in Frankfurt). The provider is established in the United States.


5.3 Wiredash (User Feedback)


For in-app user feedback (e.g., bug reports, feature suggestions), we use:


Wiredash GmbH

Balanstraße 73, 81541 Munich, Germany


Wiredash processes your free-text input, technical metadata and—where available—your user ID and email address so that we can assign follow-up questions. Processing takes place strictly under our instructions, as a processor under a data processing agreement (Article 28 GDPR). There is no fixed statutory retention period for this data; under the storage-limitation principle (Article 5(1)(e) GDPR) we keep it only as long as needed to handle the report and then delete it.


5.4 RevenueCat (Payment Management)


We use RevenueCat, operated by:


RevenueCat, Inc.

633 Taraval Street, Suite 101, San Francisco, CA 94116, USA


RevenueCat manages in-app purchases and subscription tracking. It processes transactional data (e.g., product ID, purchase status, timestamp) and links this data to your user ID. Complete payment details (e.g. credit card data) are not stored by us or by RevenueCat.


Processing is based on contractual necessity (Article 6(1)(b) GDPR).


5.5 Apple App Store & Google Play Store


In-app purchases and App downloads are processed via:

Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland


Both providers operate as independent data controllers, especially with regard to payment processing and store analytics. Please consult their respective privacy policies for more details:

Apple: https://www.apple.com/legal/privacy

Google: https://policies.google.com/privacy


5.6 Vimeo (Video Streaming)


To embed and provide video content within our App, we use the service Vimeo, operated by:


Vimeo Inc.

330 West 34th Street, 10th Floor, New York, New York 10001, USA


Videos are loaded in the App via an embedded web view (player.vimeo.com). Technical information (e.g., IP address, browser type, device type, access timestamp) and potentially user interactions (e.g., playback start, pause, video completion) may be collected and transmitted to Vimeo. Access to the end device takes place, where necessary, to provide the videos you have requested and is in that respect strictly necessary under Section 25(2) TDDDG.


This processing is based either on the necessity to fulfil our contract with you (Art. 6(1)(b) GDPR) or on our legitimate interest (Art. 6(1)(f) GDPR) in providing functioning multimedia content.


Such data processing may involve transfers to the United States. Vimeo relies on EU Standard Contractual Clauses (SCCs) in accordance with Art. 46 GDPR to ensure an adequate level of data protection.


Further information on Vimeo’s data processing can be found at:

https://vimeo.com/privacy


5.7 Brevo (Newsletter Distribution)


We use Brevo to manage and distribute the email newsletter subscribed via our homepage. The provider is:


Brevo SAS

106 Boulevard Haussmann

75008 Paris, France


Brevo processes personal data, in particular email addresses, solely on our behalf and exclusively for the purpose of sending newsletters. Processing is based on the user’s consent pursuant to Art. 6(1)(a) GDPR after double opt-in. Our newsletter does not use open or click tracking.


We have entered into a data processing agreement with Brevo in accordance with Art. 28 GDPR. Data processing takes place on servers located within the European Union.


Further information about data protection at Brevo can be found at:

https://www.brevo.com/legal/privacypolicy/


6. Data Transfers to Third Countries


Most of the processing of personal data takes place within the European Union (EU) or the European Economic Area (EEA). However, we use services that are established outside these regions or that may access data from there.


6.1 Processing within the EU


For the following providers, operational data processing takes place on servers within the European Union:

Hostinger: website hosting on servers in France (EU)

Wiredash: established and processing in Germany (EU)

Brevo: established and processing in France (EU)

Supabase: storage of authentication and App data on servers in Germany (EU). The provider is established in Singapore; access from a third country cannot be completely ruled out.

Sentry: error reports are processed in the Frankfurt data center (Germany). The provider is established in the United States.


6.2 Transfers to Third Countries


The following providers may involve the transfer of personal data to third countries, or access from there cannot be ruled out:

RevenueCat Inc. (USA)

Apple Inc. / Apple Distribution International (App Store)

Google LLC / Google Ireland Limited (Play Store)

Vimeo Inc. (USA, video streaming)

Functional Software, Inc. / Sentry (USA, despite EU data center)

Supabase Inc. (established in Singapore, despite EU servers)


Where the relevant country is not covered by an adequacy decision of the European Commission (or the provider is not certified under the EU-U.S. Data Privacy Framework), such transfers are only carried out under appropriate safeguards, including:

Use of EU Standard Contractual Clauses (SCCs)

Additional protective measures (e.g., encryption, access controls)


6.3 Notice of Residual Risks


Despite the safeguards in place, when data is transferred to third countries—especially the United States—it cannot be entirely ruled out that government authorities may gain access to personal data. In such cases, EU residents may have limited legal remedies or means of redress.


6.4 Your Rights


You have the right to receive information about the safeguards used for data transfers to third countries. Upon request, we will provide you with a copy of the Standard Contractual Clauses used for such transfers.


7. Retention and Deletion of Data


We retain personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy or until you request its deletion, unless statutory retention obligations require longer storage.


7.1 Retention Until Account Deletion


Account data, health, cycle, and training data, as well as related consent timestamps, are stored for as long as a user account remains active.


You can delete your account at any time in the App. Upon account deletion, the associated App data will be permanently erased, unless statutory retention obligations apply. Session data stored locally on the device is removed on logout or account deletion.


7.2 Retention by Data Category

Account, health, and training data: until account deletion

Consent records: for the duration of the account and thereafter as long as we need to demonstrate the lawfulness of processing

Newsletter data: until withdrawal of consent (unsubscribe)

Contact inquiries: until the inquiry has been handled and a reasonable follow-up period has expired

Quality feedback by email: the message and any replies only as long as needed for evaluation, then deleted; after an objection we will not contact you again for this purpose

Website server logs: generally no more than 14 days, longer only in the event of security incidents

Sentry error reports (including masked screenshots): 30 days

Wiredash feedback: no fixed statutory retention period; stored only as long as needed to handle the report (storage limitation, Article 5(1)(e) GDPR), then deleted

Newsletter double opt-in records: for the duration of the subscription and thereafter as long as we need to demonstrate consent


7.3 Statutory Retention Obligations


Subscription, contract, and billing-related records may be subject to statutory retention obligations under commercial and tax law (in Germany typically 6 years under the HGB and 10 years under the AO). Where such records are held by us, we delete them only after the applicable period has expired. Payment processing itself is handled by Apple, Google, and RevenueCat.


7.4 Deletion Upon Withdrawal of Consent


If data processing is based on your consent (e.g., health data, newsletter), such data will be deleted immediately upon withdrawal of consent, unless another legal basis or statutory retention obligation applies.


The App cannot provide its core function without health and cycle data. Withdrawal of health-data consent is therefore effected by deleting your user account in the App or by contacting us; a standalone withdrawal while keeping the account is not provided.


8. Consent & Withdrawal


Certain data processing activities—particularly those related to health and menstrual cycle data and the newsletter—are carried out based on your explicit consent in accordance with Art. 6(1)(a) and, where applicable, Art. 9(2)(a) of the GDPR.


8.1 Giving Consent


You provide this consent in an informed manner, e.g., during registration in the App or when subscribing to the newsletter on the Website. Without your consent, the relevant data will not be processed. Health-data consent is a condition for using the App, because the core function cannot be provided without these data. Newsletter consent is voluntary and independent of App use.


Consent in the App specifically covers:

Collection and storage of menstrual cycle data

Derivation of cycle phases, ovulation date, and energy level

Processing of fitness and strength levels

Analysis of activity and training behavior to personalize content based on your cycle


Consent to the newsletter is given separately via the Website (double opt-in).


8.2 Withdrawing Consent


You can withdraw your consent at any time with future effect. This can be done:

for health data, by deleting your user account in the App (the App cannot function without these data) or by contacting us

for the newsletter, via the unsubscribe link in every email

in all cases, by contacting us using the details provided above


Adjusting cycle information in the App changes stored values but is not a withdrawal of consent.


Upon withdrawal, the affected data will be immediately deleted, provided no other legal basis or statutory retention obligation exists for continued processing.


Withdrawal does not affect the lawfulness of processing carried out before the time of withdrawal.


9. Your Rights as a Data Subject


As a user of our App and Website, you have extensive rights under the General Data Protection Regulation (GDPR) with regard to your personal data. You may exercise these rights at any time.


9.1 Right of Access (Art. 15 GDPR)


You have the right to obtain confirmation as to whether or not personal data concerning you is being processed. If so, you may request access to this data as well as additional information (e.g., processing purposes, recipients, storage period).


9.2 Right to Rectification (Art. 16 GDPR)


If your personal data is incomplete or inaccurate, you have the right to request immediate correction or completion.


9.3 Right to Erasure (Art. 17 GDPR)


You may request the deletion of your personal data, provided that no legal obligation or overriding legitimate basis prevents such deletion.


9.4 Right to Restriction of Processing (Art. 18 GDPR)


In certain situations, you may request the restriction of processing—for example, if you contest the accuracy of the data or object to unlawful processing.


9.5 Right to Data Portability (Art. 20 GDPR)


You have the right to receive your personal data in a structured, commonly used, and machine-readable format, or to request transmission of the data to another controller.


9.6 Right to Object (Art. 21 GDPR)


You may object to the processing of your personal data if it is based on our legitimate interests (Art. 6(1)(f) GDPR), for example error analysis, website logs, or quality feedback by email.


Please send your objection informally by email to info@lunaletics.com and describe the processing concerned. We will then assess whether compelling legitimate grounds override your objection. For quality feedback by email, an informal refusal is enough; we will then not contact you again for this purpose.


If you object to processing for direct marketing purposes (e.g. the newsletter), you do not need to give a special reason. For the newsletter you may alternatively use the unsubscribe link in every email (withdrawal of consent). Quality feedback by email is not advertising; you may nevertheless object to it at any time without giving a reason.


9.7 Right to Withdraw Consent (Art. 7(3) GDPR)


You may withdraw your previously given consent at any time with effect for the future. The lawfulness of processing carried out prior to withdrawal remains unaffected.


9.8 Right to Lodge a Complaint (Art. 77 GDPR)


If you believe that the processing of your personal data violates data protection laws, you have the right to file a complaint with a supervisory authority. Typically, this is the authority of your place of residence or the location of our company.


For our registered office in Munich, this is:

Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA)

Promenade 18, 91522 Ansbach, Germany

https://www.lda.bayern.de


9.9 Additional Information for Users in the United Kingdom


If you reside in the United Kingdom, the same rights apply under the UK Data Protection Act 2018 in conjunction with the UK GDPR, including:

Right of access

Right to rectification

Right to erasure

Right to restriction of processing

Right to data portability

Right to object

Right to withdraw consent at any time


For questions or complaints, you may also contact the UK supervisory authority:


Information Commissioner’s Office (ICO)

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom

https://ico.org.uk


10. Data Security


We implement appropriate technical and organizational measures to protect your personal data against loss, misuse, unauthorized access, disclosure, alteration, or destruction. These measures are based on the requirements set out in Article 32 of the GDPR.


10.1 Technical Measures

Data Transmission: All data transmissions are encrypted using TLS/SSL protocols.

Access Control: Access to personal data is restricted to authorized personnel with appropriate access rights.

Local session data is stored on the device in encrypted form.


10.2 Organizational Measures

Data Minimization: Only data necessary for the respective purpose is collected.

Access Logging: Access to sensitive systems is logged and regularly reviewed.

Processor Agreements: All third-party service providers are contractually bound to comply with the GDPR.


10.3 Hosting and Infrastructure


Our backend systems (e.g., Supabase) are operated on servers located within the European Union. The storage of health and other sensitive data is carried out with enhanced protective measures.


11. Changes to this Privacy Policy


We reserve the right to update this Privacy Policy to reflect changes in legal requirements, technical developments, or the introduction of new features within the App or on the Website.


11.1 Notification of Changes


In the event of significant changes—particularly if the purposes of data processing or the types of data collected change—we will inform you in a timely manner via the App, the Website, or by email (if provided). Where legally required, we will request your renewed consent.


11.2 Validity of the Current Version


The most current version of this Privacy Policy is always available within the App or on our website.


12. Information for Users from the United States of America (USA)


This Privacy Policy also applies to users residing in the United States of America. It takes into account the applicable data protection laws of the following U.S. states to the extent relevant to our services: California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana, Delaware, Iowa, and Indiana.


We continuously monitor legislative developments in other U.S. states (e.g., Florida, New Jersey, New Hampshire, Nebraska, Minnesota) and will update this Privacy Policy as needed once new regulations become relevant to our services.


This statement reflects the requirements of the applicable data protection laws of the above-mentioned states, particularly the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).


12.1 No Sale or Sharing of Personal Data


We do not sell personal data as defined by the data privacy laws of the above-mentioned states. We also do not share personal data with third parties for advertising purposes or for creating user profiles.


We treat health, cycle, and reproductive information as sensitive personal information. We use it only to provide the App, not for advertising and not for sale or “sharing” under the CCPA/CPRA. Users in U.S. states with consumer health privacy laws (including Washington) may contact us using the details above.


We currently do not offer personalized advertising and do not use your personal data for sale or sharing purposes. If this changes, we will provide a clearly labeled “Do Not Sell or Share My Personal Information” opt-out link, as required by law.


12.2 Your Privacy Rights in the U.S.


Users residing in certain U.S. states have the right to:

Request information about what personal data we collect and how we use it,

Receive a copy of the stored personal data,

Request deletion of their personal data,

Object to the processing of their personal data,

And opt out of the sharing or sale of personal data, if applicable.


Please note that, in order to protect your rights, we may be required by law to verify your identity before processing your request.


To exercise these rights, you can contact us at any time using the contact details provided in the section “Controller”.


We reserve the right to verify your identity before responding to any requests in accordance with legal requirements.