Skip to content
Lunara

Privacy Policy

How the Lunara service processes and uses information.


Lunara Inc. (the "Operator"), which operates Lunara (the "Service"), explains below the information processed by the Service and how it is used.

1. Information we process

Some features are available without an account. Login, synchronization, community features, and AI conversation history use an account and server storage.

CategoryInformation processedStorage and processing location
Account and authenticationSocial login provider user identifier, email, name and profile image supplied by the provider, authentication sessions and tokensSupabase Auth, user device
Age and consentBirth year, consent text version, consent timestampSupabase
Profile and preferencesUsername, display name, profile image, bio, interests, travel pace, transportation preferences, dietary and avoidance information, and other preferences entered by the userSupabase and user device
Travel plansOrigin and destination, dates, party size, itinerary, packing list, saved places, app settingsPrimarily the user device. Necessary information may be sent to the Operator's backend and external services when AI, search, or synchronization features are used
CommunityPosts, comments, photos, videos, tags, cities, likes, follows, saves, meetup information and participation, blocking informationSupabase, Cloudflare R2. Public posts, profiles, reactions, and meetup participation may be visible to other users
Messages and reportsDM participants, messages and read timestamps; reported subject, reason, details, and processing statusSupabase. DMs are restricted to participants; reports to the reporter and authorized operations personnel
NotificationsDevice push token, device type (iOS, Android, web), registration and revocation timestamps, notification delivery queue records (message identifier, conversation identifier, recipient, sender, timestamp)Supabase, Cloudflare Workers, the Expo push service, and Apple and Google push servers. Notification bodies do not contain message content; only a generic phrase such as “You have a new message” is sent
Aurora personalization (AI features)User questions, travel inputs, device preferences included in requests, server-stored AI memory and saved history, AI responses, conversation identifiers and history, personalization summaries and feedback, generation countsCloudflare Workers·AI Gateway, Anthropic, Supabase
Payments and subscriptionsStore type, product ID, transaction and original transaction IDs, event ID and type, purchase, expiration and refund timestamps, purchase and subscription status, entitlement tier, one-time entitlement grant, use and revocation records, and the user ID that links a transaction to the account (stored in the payment ledger and, for App Store purchases, also placed in the purchase request sent to the store)App Store and Google Play, Cloudflare Workers, Supabase. Raw notification data received from the stores is stored with the payment ledger through the Worker and is deleted within seven days once the minimum fields needed to confirm payment status have been copied. The Operator does not directly collect or store card numbers or other store payment-method information
Media uploadsSelected image and video files, file format and size, object keys linked to the uploading userCloudflare Workers, Cloudflare R2, Amazon Web Services (automated harmful-content assessment). Media attached to posts may be served through public URLs
Feature queriesPlace and address search terms, flight numbers and dates, travel city coordinates, route origin, destination and departure timeGoogle, Kakao, Mapbox, Apple or the device operating-system provider, AeroDataBox and RapidAPI, Open-Meteo, Operator backend
Visit verificationCurrent location coordinates and accuracy checked at the destination when the user enables visit verification, together with the trip ID, destination and datesThe current location is processed transiently in a Cloudflare Worker only during the distance and accuracy check and is not stored. Supabase stores only the verification result without coordinates, the rule version and the trip snapshot
Content queriesRemote image URLs displayed in the app, YouTube video identifiers, thumbnails and playback requests, network and device information such as IP addresses during connectionsUnsplash, Google and YouTube. Home-screen YouTube thumbnails load when the screen opens; videos play when the user selects them
Booking links and affiliate measurementTarget URL, platform, category, screen and destination label, link token, click identifier, timestamp, partner, whether affiliate parameters were applied, and conversion postback click_id, status, transaction identifier, settlement amount, currency and timestampCloudflare Workers, KV and operational logs; booking and map providers selected by the user. Link records do not contain a user ID
Error diagnosticsError type, message and stack, app version, device and operating-system information, diagnostic context explicitly attached by the Operator such as error codes and feature areas, network information during connectionsSentry. sendDefaultPii is false, but we cannot guarantee that error messages or stacks contain no user input
Security and abuse preventionIP address during API requests, request timestamp and path, authentication and usage-limit resultsCloudflare Workers, Rate Limiting and operational logs. Used to prevent abnormal requests and automated abuse and maintain service stability

The device's current location is used only when you press the map's 'My location' button, or when you select 'Continue' in the visit-verification notice and grant location permission. During visit verification, the current location coordinates and accuracy are sent to a Cloudflare Worker over HTTPS and used transiently only to judge the distance to the destination and the accuracy; the coordinates themselves are not stored in the Worker, the Supabase database or app storage. Places, addresses and coordinates you enter in an itinerary may, however, be sent to external services to provide weather, search and route features.

Photos and videos are uploaded only when you select them yourself. Images are re-encoded before upload, and upload stops if this fails. The server implements image and video moderation and removal of MP4 location metadata. Locations displayed within the video itself are outside this removal scope (code checked 2026-09-14). These paths are deployed on the production server, together with the private-media reference setting (deployment checked 2026-09-22).

2. Purposes of processing

  1. Creating accounts, login, maintaining sessions, and checking age and consent status
  2. Providing travel planning, packing lists, search, weather, transportation and AI recommendations
  3. Providing community features including profiles, posts, comments, meetups, DMs, saves and follows
  4. Receiving reports, preventing abuse, reviewing content and protecting users
  5. Managing usage limits and service stability, and diagnosing errors
  6. Product usage analytics only with the user's separate permission
  7. Connecting external booking and map links, and measuring clicks, affiliate results and conversions for booking links that use the tracking redirector
  8. Verifying purchase and subscription status, granting and restoring entitlements, reflecting refunds and cancellations, and handling payment inquiries

3. Public information and access

  • Usernames, display names, profile images, bios, public posts, comments, photos, videos, likes, follows and meetup participation may be visible to other users.
  • Access policies restrict DM text and read status to participants in that conversation.
  • Travel preferences, birth year, consent status, AI conversations and personalization information are restricted to the user and servers with the permissions required to provide the Service.
  • Reports are restricted to the reporter and authorized operations personnel. After account deletion, they may be retained for safety measures and dispute handling with the reporter's identifier removed.

4. Retention and use periods

InformationRetention basis
On-device trips and settingsUntil the user deletes them in the app or uninstalls the app. Copies may remain under the operating system's backup and restore policies
Account, profile, preferences, community, DMs and AI recordsUntil the user deletes the relevant item or account. A successful account deletion request is designed to cascade-delete rows associated with the account in Supabase
ReportsThe reporter's identifier is removed when the account is deleted; report details are retained for 3 years for safety measures and dispute handling
Notification tokens and delivery recordsUntil the user logs out, turns off notification permission or deletes the account. Delivery queue records become subject to cleanup once the notification is delivered or retries end, and are deleted together with the rows linked to the account when the account is deleted
Public mediaUntil the deletion job associated with the post or account deletion request completes for R2 objects and caches. The deletion queue, retry job and cache purge settings are deployed on the production server (deployment checked 2026-09-22).
Worker and AI Gateway logsThe Operator's policy is 30 days for general operational logs, and 1 year for personal-information-system operator access records and security-incident investigation records. Request and response payload storage in AI Gateway is kept off, so no copy of the payload remains on the Operator's side. Neither Cloudflare's public policy nor the contract (Cloudflare Customer DPA v6.4) specifies a retention period for its own operational logs (checked 2026-09-22).
Access records constituting communication confirmation dataUnder Article 41 of the Enforcement Decree of Korea's Protection of Communications Secrets Act, the minimum records within that scope (IP address, user identifier, access time) are kept separately from other information for 3 months and then destroyed; they are not retained beyond that period.
Records confirming the collection, use and provision of location informationBecause the server does not store the current location, no such records are generated at present. If the server begins processing location information, the records will be logged automatically under Article 16(2) of Korea's Act on the Protection and Use of Location Information and retained for 6 months before destruction.
Sentry error eventsThe Operator's policy is 30 days for error events, transactions and spans alike, and the organization's retention setting is aligned to that value. The Operator's organization (lunara-inc) is on the Developer plan, whose event retention period is 30 days (checked 2026-09-22). Provider backups are deleted within 90 days of creation.
Anthropic API inputs and outputsAnthropic retention policy provides for deletion following receipt or generation within 30 days (rechecked 2026-09-06). If flagged for usage-policy violations, inputs and outputs may be retained for up to 2 years and safety classifier scores for up to 7 years. Legal obligations, separate agreements and long-term retention services may create exceptions. The Operator's organization has no Zero Data Retention agreement in place, so this 30-day standard applies as stated (checked 2026-09-22). Aurora’s default models in the code are claude-haiku-4-5, claude-sonnet-5 and claude-opus-4-8 (code checked 2026-09-07; the production environment may override them).
Raw data received for payment verificationAfter the minimum items needed to confirm payment status are extracted, the raw data is deleted within 7 days. The retention period for the transferred transaction records follows the statutory retention item below
Copies remaining in backups and cachesAfter deletion from active data, backup copies expire within 30 days, and removal from the content-delivery cache is requested immediately at the time of deletion. If a backup is restored, the deletion request is applied again right after restoration
Booking links and affiliate measurementCloudflare KV link records containing the target URL, platform, category, screen and destination label: 90 days after registration or re-registration. Click and conversion operational logs: 6 months for booking-link performance measurement and fraudulent-click prevention
Contract, withdrawal, payment and service-supply records5 years under Article 6 of the Enforcement Decree of Korea's Act on the Consumer Protection in Electronic Commerce. Before enabling paid payments, we will configure and verify that transaction identifiers, products, and payment, supply, withdrawal and refund records are separated from account data, retained for the statutory period after account deletion, and then destroyed.

Where retention is otherwise required by law, a security-incident investigation, or dispute handling, information may be retained separately to the extent and for the period necessary for that purpose.

5. External services and overseas processing

The providers below process information while providing the Service, and personal information is transferred overseas to foreign providers among them. Under Article 28-8 of Korea's Personal Information Protection Act, we disclose the transferred information, countries, timing and methods, recipients' purposes and retention periods, and recipient contact details below. The values in the table were recorded after checking the actual account settings and contracts as of 2026-09-22.

5-1. Overseas transfers

RecipientDestination countryInformation transferredTransfer timing and methodPurposeRetention and use periodRecipient contact
Supabase, Inc.Japan (Tokyo region ap-northeast-1, checked 2026-09-22)Account, profile, preferences, UGC, DMs, reports and AI recordsNetwork transfer (HTTPS) during login, synchronization, community use and storage of AI recordsAuthentication, database, real-time messaging and synchronizationThe Operator's project is on the Pro plan, retaining daily managed backups for 7 days, and Point-in-Time Recovery is not used (checked 2026-09-22). User contact information, however, is retained for 60 days after the account is closed (Supabase Privacy Policy Version 3 · 2026-05-13 · EEA/UK/CH addendum item 3(f) "we retain this for as long as you have an account on our services, and for 60 days after you close your account" · checked 2026-09-07).Privacy Policy · privacy@supabase.com
Cloudflare, Inc.United StatesAPI requests and responses, authentication identifiers, AI inputs and responses, uploaded media, current location coordinates and accuracy during visit verification, booking-link, click and conversion information, raw notification data used for payment verification, and network information including IP addressesTransmitted over the network (HTTPS) when API, AI, media-upload, visit-verification or booking-link requests are made and when store receipts are verified or payment-status notifications are receivedWorker API, AI Gateway, Workers AI embedding generation, R2 media storage and delivery, visit-verification distance and accuracy checks, booking-link and affiliate measurement, store receipt verification and payment-status notification intake, security, abuse prevention and operational logsValues set by the Operator — visit-verification coordinates and accuracy are processed in memory only during the check and are not stored; booking-link KV records 90 days; travel-guide cache 30 days. R2 media has no fixed retention period: when a post or media item is deleted, it is queued for deletion and removed by a scheduled job. Neither Cloudflare's public policy nor the contract (Cloudflare Customer DPA v6.4) states a specific period for its own operational logs (checked 2026-09-22).Privacy Policy
Anthropic, PBCUnited StatesTravel information, questions and preference context included in AI requests, and generated responsesNetwork transfer (HTTPS) through the Operator backend during AI itinerary-generation and conversation requestsGenerating AI itineraries, packing lists, conversations and personalized responses; automatically translating community posts, comments and introductionsAnthropic retention policy — API inputs and outputs are deleted within 30 days of receipt or generation. If flagged for usage-policy violations, inputs and outputs may be retained for up to 2 years and safety classifier scores for up to 7 years. The Operator's organization has no Zero Data Retention agreement in place (checked 2026-09-22; see Section 4). Aurora’s default models in the code are claude-haiku-4-5, claude-sonnet-5 and claude-opus-4-8 (code checked 2026-09-07; the production environment may override them).Privacy Policy
Google LLC·YouTubeUnited StatesLogin identifiers, search terms, addresses and coordinates, route and flight inputs, video identifiers, and network and device information for content requests, store transaction and original transaction identifiers, product ID, purchase and subscription statusNetwork transfer (HTTPS) during login, place search, maps, routes and flight queries, YouTube thumbnail loading and video playback. Network transfer (HTTPS) through the device or the Operator backend during Google Play payments, purchase restoration and subscription-status checksGoogle and social login, Places, Maps, Routes, Geocoding, Flights, YouTube thumbnails and embedded videos, Google Play receipt verification and purchase and subscription-status checksGoogle data retention policy — Server-log IP addresses are anonymized after 9 months and cookie information after 18 months; backups may retain them for up to 6 months. The public policy does not state a retention period for queries such as place search terms themselves (checked 2026-08-04). The public policy likewise does not state a retention period for the purchase records the store holds. The Operator's own copies follow the standards in Section 4 — seven days for raw notification data used for payment verification, and the statutory five years for contract, payment and service-supply records. The contract (Google Cloud Data Processing Addendum) §6.1 and §6.2 set no separate retention period and provide only for deletion or return of customer data on termination (checked 2026-09-22).googlekrsupport@google.com (Google Privacy Policy, checked 2026-09-14)
Mapbox, Inc.United States (primary processing region); passes through CDN caches in multiple regions for performanceCoordinates of up to 25 places saved in an itinerary, travel modeNetwork transfer (HTTPS) during itinerary-route queriesWalking and driving route geometry, per-leg travel time and distanceMapbox Privacy Policy — IP addresses are retained for 30 days (this may be extended for security investigations or legal compliance). The public DPA limits retention to the period of business need for the processing purposes and provides for deletion upon the customer’s written request within 30 days after termination or expiry of the agreement, with exceptions for legal compliance or another lawful basis for retention (Mapbox DPA §7.1·Schedule B §7, checked 2026-09-14).Privacy Policy
Unsplash, Inc.Canada (Calgary, Alberta)Image URLs and network and device information for content requestsNetwork transfer (HTTPS) when images load on destination, guide and feed screensServing remote imagesThe Operator has no separate agreement with Unsplash; the Unsplash API Terms and the public policy apply. The public policy provides for retention as long as needed for the collection purpose and does not state a specific period (checked 2026-09-22).Privacy Policy
Trip.com Travel Singapore Pte. Ltd.SingaporeFlights: origin and destination codes, departure and return dates, party size. Stays: destination name and cityId, check-in and check-out, number of adults. Affiliate click identifier when a tracked link is usedNetwork transfer (HTTPS) when the user selects a flight or accommodation booking linkFlight and accommodation booking search and links, affiliate performance measurementThe Trip.com privacy policy provides for retention until whichever applies of fulfilment of the purpose, objection to the use, or withdrawal of consent, and retains account-related information for as long as the user remains eligible. It does not state a specific period (checked 2026-09-07).Privacy Policy · en_dataprotection@trip.com · 30 Raffles Place, #29-01, Singapore 048622
Klook Travel Technology LimitedHong KongActivity search terms or the selected product path; affiliate click identifier when a tracked link is usedNetwork transfer (HTTPS) when the user selects an activity booking linkActivity booking search and links, affiliate performance measurementThe Klook privacy policy provides for retention only for as long as necessary to fulfil the processing purpose or to comply with applicable law, after which the data is securely deleted or anonymised. It does not state a specific period (checked 2026-09-07).Privacy Policy · privacy@klook.com · 24F, Kinwick Centre, 32 Hollywood Rd, Central, Hong Kong
OpenTableUnited StatesPlace name, date, time and party sizeNetwork transfer (HTTPS) when the user selects a restaurant booking link and when link availability is checkedRestaurant booking links and link-availability checksThe OpenTable privacy policy provides for retention while the account is active and for a period afterwards to allow reactivation, and permits additional retention to maintain analytics, security and audit records, to comply with statutory retention duties, and to handle complaints and disputes and defend rights. It does not state a specific period (checked 2026-09-07).Privacy Policy · privacy@opentable.com · OpenTable, Inc. 425 Market Street, Suite 1200, San Francisco, CA 94105, U.S.A.
Apple Inc.United States (Cupertino, California)Login identifiers, location and address requests permitted by the user, store transaction and original transaction identifiers, product ID, purchase and subscription status, and the user ID placed in the purchase requestTransfer through the device operating system during Apple login and iOS location or geocoding use. Network transfer (HTTPS) through the device or the Operator backend during App Store payments, purchase restoration and subscription-status checksApple login, iOS location and geocoding, App Store receipt verification and purchase and subscription-status checksThe Apple privacy policy provides for retention until the collection purpose is fulfilled or for the period required by law, and states that where retention is necessary it works to keep the data for the shortest period permissible under law. It does not state a specific period (checked 2026-09-07). ("work to retain the personal data for the shortest possible period permissible under law" · Updated July 30, 2025) The public policy likewise does not state a retention period for the purchase records the store holds. The Operator's own copies follow the standards in Section 4 — seven days for raw notification data used for payment verification, and the statutory five years for contract, payment and service-supply records.Privacy policy · Contact form (the policy provides no dedicated privacy email address, only a form and a telephone number)
Sentry (Functional Software, Inc.)United StatesError, stack, device and app information, diagnostic contextNetwork transfer (HTTPS) when an error occursApp error and performance diagnosticsEvent retention policy applies: the Operator's organization (lunara-inc) is on the Developer plan, so error events are retained for 30 days and transactions and spans for 30 days as well (checked 2026-09-22). Backups are deleted within 90 days of creation.Privacy Policy
Nokia of America Corporation (operator of the Rapid API Marketplace)United States · the group data protection officer is Nokia Corporation in FinlandFlight-number and date query valuesNetwork transfer (HTTPS) through the Operator backend (Cloudflare Worker) during flight queries; the app does not call it directly and authentication keys are stored only on the serverRelaying AeroDataBox flight-information queriesRetained for as long as necessary to fulfil the purposes set out in that policy, and for any period required by legal, tax, accounting or reporting obligations. Only the criteria for determining the retention period (duration of the relationship, legal obligations, legal position) are published; the specific period is set by an internal retention policy (checked 2026-09-07).Privacy Policy · group.dpo@nokia.com · Nokia Corporation c/o Privacy, Karakaari 7, P.O. Box 226, FI-00045 Nokia Group, Finland
AeroDataBox (Timber Bytes LLP)Canada (located in British Columbia, checked 2026-09-22)Flight number and date. The code does not transmit personal-information fields identifying the userNetwork transfer (HTTPS) through the RapidAPI marketplace during flight queriesProviding flight informationThe AeroDataBox privacy policy (Last updated July 31, 2026) contains no retention-period clause at all (checked 2026-09-07). Its only sentence that states a period is limited to Flight Alerts webhook URLs, and the Operator does not use that feature. The separate agreement likewise contains no retention-period clause (checked 2026-09-22).Contact form (the policy provides no dedicated privacy email address)
Open-Meteo (OpenMeteo GmbH)Switzerland (Bürglen, Uri; Swiss law also governs)Travel city coordinates and query timeNetwork transfer (HTTPS) during weather queriesWeather queriesOpen-Meteo Terms of Service — Webserver log files, which may contain coordinates, are deleted after 90 days; only aggregated usage is retainedTerms of Service
Amazon Web Services, Inc. (Amazon Rekognition · Amazon S3)Republic of Korea (fixed to the Seoul region, ap-northeast-2)Original image and video files uploaded by the user and the quarantine object keysNetwork transfer (HTTPS) through the Operator's backend when photos or videos are uploadedAutomated harmful-content assessment of images and videos in postsThe public DPA lets the customer determine the duration of processing and provides for return or deletion at the customer’s request before termination and for 90 days thereafter. The 90 days are not a universal automatic deletion deadline (AWS DPA §1.3.2·§14, checked 2026-09-14). Whether Rekognition inputs are used and stored for service improvement depends on separate settings (Official FAQ, checked 2026-09-14); the Operator applies the AWS Organizations AI services opt-out policy so that inputs are not used or stored for service improvement (2026-09-22). Operator settings are 24 hours after quarantine-object approval, rejection or failure, and 90 days for completed decision jobsAmazon Web Services, Inc., ATTN: AWS Legal, 410 Terry Avenue North, Seattle, WA 98109-5210, United States (AWS Privacy Notice, checked 2026-09-14)
Travelpayouts (Go Travel Un Limited)Hong Kong (registered location of Go Travel Un Limited, Official terms §1.2, checked 2026-09-14)The page address, browser information and other data collected by the script when the website is visitedWhen the affiliate-link automation script runs on every page of the websiteAutomatic conversion of travel links into affiliate links and performance measurementThe contract (partner terms) and the public policy set no separate period and provide for retention while the account remains active (checked 2026-09-22).support@travelpayouts.com (Official terms §7.5, checked 2026-09-14)

Where a provider's privacy-policy link appears in the contact column, contact methods can be found in that document. Information passed to booking partners is passed only when the user selects a booking link; if no link is selected, nothing is passed.

5-2. Domestic processing

The following are domestic providers; personal information is not transferred overseas to them.

ProviderInformation processedProcessing timing and methodPurposeRetention and use periodContact
Kakao Corp.Place search terms, search area, and place names opened in an external mapNetwork transfer (HTTPS) during domestic place searches and KakaoMap link useDomestic place search, external KakaoMap links selected by the userKakao Privacy Policy — Retention is specified by category (for example, rights-infringement reports: 5 years; location-information use and provision records: 6 months), but not for service-usage records such as place search terms (checked 2026-08-04). Information about users who signed in with Kakao is destroyed by the Operator on withdrawal, and may be retained by Kakao for up to one year after withdrawal (checked 2026-09-22).Privacy Policy
NaverPlace names opened in an external mapNetwork transfer (HTTPS) when the user selects a Naver Map linkConnecting external Naver Map links selected by the userThe Naver privacy policy provides for destruction without delay once the purpose of use is fulfilled, while retaining data for the periods set by law — login records 3 months, records on display and advertising 6 months, records on consumer complaints and dispute handling 3 years, records on contracts and withdrawal of subscription and on payment and supply of goods 5 years each, tax-law books and supporting documents 5 years, and records on the circulation of electronic documents through a certified electronic address 10 years. Records confirming the collection, use and provision of personal location information are retained for 6 months or longer (checked 2026-09-07).Privacy Policy · Data Protection Officer Lee Jin-kyu · privacy@naver.com · 1588-3820

You may decline the relevant overseas transfer by not using optional features such as AI, place search, flights and weather, while continuing to use other features such as manually creating itineraries. Where external processing is inherent to a feature, such as login, server synchronization or community, declining that processing means we cannot provide that feature. Overseas-transfer refusal inquiries: support@travellunara.com

5-3. Payment-related disclosure (English translation)

The Korean disclosure above is the legally operative version. This English translation is provided for convenience. If the two versions differ, the Korean disclosure controls to the extent permitted by applicable law.

  • Lunara processes the store, product ID, transaction and original transaction IDs, event type and ID, purchase and subscription status, purchase, expiration and refund timestamps, entitlement tier, one-time entitlement grant, use and revocation records, and the user ID that links a transaction to the account. The user ID is stored in the payment ledger and, for App Store purchases, is also placed in the purchase request sent to the store. These items are processed by the App Store and Google Play, Cloudflare Workers, and Supabase. Raw notification data received from the stores is stored with the payment ledger through the Worker and is deleted within seven days once the minimum fields needed to confirm payment status have been copied. Lunara does not directly collect or store card numbers or other store payment-method information.
  • Apple Inc. and Google LLC receive the store transaction and original transaction identifiers, the product ID, and purchase and subscription status in the United States through HTTPS when a purchase, restore, or subscription-status check occurs; Apple additionally receives the user ID that Lunara places in the purchase request. They use the data to verify the store receipt and the purchase and subscription status. The stores do not publish a retention period for the purchase records they hold; Lunara's own copies follow Section 4 — raw notification data for seven days, and statutory contract, payment, refund and service-supply records for five years. Their retention periods and contact details are stated in the overseas-transfer table above.
  • Deleting a Lunara account does not cancel a subscription purchased on the App Store or Google Play. The store holds the subscription contract and the payment method, so the subscription fee continues to be charged unless it is cancelled separately in the store account settings. Please cancel the subscription in the store before deleting the account.
  • Lunara retains contract, withdrawal, payment, refund, and service-supply records for five years under Article 6 of the Enforcement Decree of Korea's Act on the Consumer Protection in Electronic Commerce. Before activating paid services, Lunara will configure and verify that these statutory records are separated from account data, remain after account deletion for the statutory period, and are then destroyed.

5-4. 決済関連の通知(日本語訳)

法的効力を有する開示は上記の韓国語版です。この日本語訳は便宜のために提供します。両者に相違がある場合、適用法令で認められる範囲で韓国語版が優先されます。

  • Lunaraは、ストア、商品ID、取引ID・原取引ID、イベントID・種類、購入・購読状態、購入・満了・返金時刻、利用権限の等級、単品利用権の付与・使用・回収記録、および取引をアカウントに結び付ける利用者IDを処理します。利用者IDは決済台帳に保存し、App Storeでの購入時は購入リクエストに含めてストアにも送信します。これらの項目はApp Store・Google Play、Cloudflare Workers、Supabaseで処理します。ストアから受領した受信データの原本はWorkerを経て決済台帳とともに保存され、決済状態の確認に必要な最小項目へ移した後、7日以内に削除します。カード番号その他のストア決済手段情報をLunaraが直接収集・保存することはありません。
  • Apple Inc.およびGoogle LLCは、購入・復元・購読状態の確認時に、ストアの取引識別子・原取引識別子、商品IDおよび購入・購読状態をHTTPSで米国に移転して受領します。Appleは加えて、Lunaraが購入リクエストに含める利用者IDを受領します。ストアの領収情報と購入・購読状態の確認に利用します。ストアが保有する購入記録の保有期間は、公開ポリシーに明示されていません。Lunara側の控えの保有基準は4項と同じで、受信データの原本は7日、契約・決済・返金・サービス提供の法定記録は5年です。保有期間および連絡先は、上記の国外移転の表に記載しています。
  • Lunaraのアカウントを削除しても、App Store・Google Playで申し込んだ購読は自動的に解約されません。購読契約の当事者と決済手段はストアが管理するため、ストアのアカウント設定で別途解約しないかぎり購読料が請求され続けます。アカウントを削除する前に、ストアで購読を解約してください。
  • Lunaraは、韓国「電子商取引等における消費者保護に関する法律施行令」第6条により、契約・申込みの撤回・決済・返金・サービス提供の記録を5年間保有します。有料サービスを有効化する前に、法定記録をアカウントデータから分離し、アカウント削除後も法定期間中は保有した後に破棄する構成を実装・検証します。

6. Optional analytics and automatic collection

  • We have not implemented advertising-identifier-based ad tracking or data sharing for sale.
  • The PostHog product analytics SDK is included in the code but is not currently initialized on app startup. Even with an API key, the SDK is blocked from running or sending events without the user's explicit opt-in.
  • Optional analytics will be enabled in the future only after disclosing the events collected, purposes and retention periods, and implementing separate consent and withdrawal features.
  • Booking-link and affiliate measurement is separate from PostHog product usage analytics. Link registration and click and conversion measurement occur when the user selects a booking link using the tracking redirector; affiliate parameters may be added to some links. Ordinary map links do not pass through that redirector.
  • Sentry error diagnostics may activate at app startup in builds with a DSN configured. This is separate from optional analytics and processes the error-diagnostic information in Section 1.
  • There are two kinds of app notifications. Packing-list and departure reminders are local notifications scheduled on the device. New DM alerts are remote push notifications; for these, a signed-in user's device push token is linked to the account and stored on the Operator's server. Delivery to that token stops when the user logs out or switches accounts.
  • Remote push notifications do not contain message content. The lock screen shows only a generic phrase such as “You have a new message” and the number of unread conversations; the content can be read after opening the app and signing in.
  • Notifications can be turned off per conversation, and the server does not create push notifications for a muted conversation (the conversation and its unread indicator remain in the app).

7. Destruction procedures and account deletion

You may request account deletion in the app's settings. After server deletion succeeds, account-associated state on the device is also reset.

  • Deleting a Supabase account is designed to cascade-delete its associated profiles, preferences, posts, comments, reactions, meetups, DMs, AI records and usage ledger.
  • Report records may remain with the reporter's identifier removed.
  • Deleting a Lunara account does not cancel a subscription purchased on the App Store or Google Play. The store holds the subscription contract and the payment method, so the subscription fee continues to be charged unless it is cancelled separately in the store account settings. Please cancel the subscription in the store before deleting the account.
  • Public R2 media deletion uses a deletion queue separate from database deletion. Code deletes R2 objects, purges caches, marks completion and retries failures, and a five-minute scheduled job is registered (code checked 2026-09-14). That migration, Worker, retry job and cache purge setting are deployed on the production server (deployment checked 2026-09-22).
  • Operational backups and external processors' copies may be deleted later under each service's deletion and backup policies.

8. Your rights and inquiries

You may request access to, correction or deletion of your information, suspension of processing, or withdrawal of consent. Each right may be exercised as follows.

RightHow to exercise it
AccessView your information directly on the app's profile, trip, and post screens. For information not available on those screens, contact us using the details below
CorrectionUse the app's profile, post, and comment editing features. For information without an editing feature, contact us using the details below
DeletionUse the app's post and comment deletion features. To delete all server information associated with your account, use the account deletion feature in the app settings
Suspension of processingTurn off AI personalization in the app settings (see AI personalization below). To request suspension of other processing, contact us using the details below
Withdrawal of consentTurn off the relevant option on the settings screen for each consent item, or contact us using the details below
  • Contact: support@travellunara.com (Privacy Officer: Section 11)
  • Requests may be made by you, your legal representative, or an authorized agent. A representative or agent making a request must provide documentation confirming their authority.
  • Account ownership verification may be required to protect the requester's rights.
  • Upon receipt of a request, we will take the necessary action within 10 days and notify you of the outcome. If applicable law requires us to defer or refuse action, we will also explain the reasons and how to raise an objection.

The relationship between AI personalization and suspension of processing is as follows.

  • Aurora personalization (AI features) is how the Service provides tailored itineraries and recommendations by default, and consent for it is obtained at sign-up separately from consent for cross-border transfer. You can turn personalization off at any time on the Aurora personalization screen in app settings, and while it is off Aurora gives only general recommendations without your preferences. Turning it off is implemented to update the device setting only after the server processing-stop request succeeds. The server implements disabling personalization and deleting AI source events, feedback, learned preferences, relevant history and memory. To delete all existing conversation history, use account deletion or contact support@travellunara.com (code checked 2026-09-14). The off and on-again round trip was verified on a real device on 2026-09-22.
  • Even after processing is suspended, other information you have entered directly, such as trips and posts, continues to be processed. To delete all server information associated with your account, use the account deletion feature in the app settings.
  • Requests not resolved in the app and inquiries about report handling: support@travellunara.com

9. Security measures

  • We use HTTPS (TLS) for network communications.
  • Supabase Row Level Security and server authentication restrict access to non-public information.
  • Authentication sessions and sensitive on-device items preferentially use supported device secure storage. (Authentication-session secure-storage wiring and separate sensitive-field storage and retry implementation: src/lib/supabaseClient.ts, src/store/index.ts; code checked 2026-09-14)
  • Filters reduce known identifiers in error logs and AI inputs, but cannot guarantee removal of personal information from every free-text input. Users should not include unnecessary personal information in AI questions, posts or DMs.

10. Children's personal information

The Service checks birth years to prevent users under 14 from creating accounts. The minimum registration age in the code is 15. Because only the birth year, rather than the full date of birth, is checked, users near the age threshold may be restricted conservatively. The store content rating does not conflict with this statement or with the sign-up consent wording (checked 2026-09-22).

11. Privacy officer

CategoryDetails
Company name주식회사 루나라 (Lunara Inc.)
Representative한우철
Address충청남도 천안시 동남구 청수14로 68, 505호(청당동, 센타타워)
Business registration number412-86-03903
Corporate registration number161511-0040391
Mail-order business registration number2026-충남천안-2026
Mail-order business registration authority천안시
Privacy officer대표이사 한우철
Contactsupport@travellunara.com

Privacy violation reports and advice: Personal Information Infringement Report Center (privacy.kisa.or.kr / 118 without an area code), Personal Information Dispute Mediation Committee (kopico.go.kr / 1833-6972)

12. Changes to this policy

Changes and their effective date will be announced in the app or on the official website at least 7 days before they take effect. Changes that materially affect or disadvantage users' rights will be announced at least 30 days in advance, with individual notice by email or similar means where necessary.

Supplementary provisions

  • Notice date: 2026-09-23
  • Effective date: 2026-09-23