Privacy Policy
Effective Date: March 8, 2026
1117 Productions LLC (operating as Lunar Guide, referred to as "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains what information we collect through the Lunar Guide app and website, how we use and share that information, and the choices you have regarding your data. By using the Lunar Guide app or any related services, you agree to the collection and use of information in accordance with this Privacy Policy.
1. Information We Collect
We collect several types of information from and about users of our app, including:
Account Information: When you create an account, we collect personal identifiers such as your name (or username) and email address. This information is necessary to register your account, verify your identity, and communicate with you.
Profile and Demographics: We collect your birth date (or general date of birth information, such as birth month and year) because it is used to provide personalized astrological readings. The app is designed for adults, so providing your birth date also helps confirm you meet our age requirements.
Voice Journal Entries: If you use the voice journaling feature, we collect the audio recordings you create and their text transcriptions. These voice notes are stored securely in our database (powered by Google Firebase). Your journal entries are considered private content:
- They are used internally to provide the service to you — for example, the app's AI Spirit Guide processes the text of your entries to generate personalized guidance.
- They may be reviewed by automated systems (and, in rare cases, by our team) only for purposes of quality control, improving our services, or investigating a support issue or suspected policy violation. We do not publish your voice notes or share them with other users.
Location Information: We may collect or infer approximate location data about you. We do not ask for GPS or precise location through the app, but we may determine a general location (such as city or country) based on your IP address or device time zone settings. This is used to localize content and for analytics; it is not used to track your real-time movements.
Device and Usage Data: We automatically collect certain information about the devices you use to access Lunar Guide and how you interact with our service:
- Device Information: Device type, operating system version, unique device identifiers, browser type, and app version.
- Log and Usage Information: Dates and times you log in, features you interact with, IP addresses, crash reports, and performance metrics.
Cookies and Similar Technologies: When you visit our website or use the app, we (and authorized third parties) may use cookies, beacons, and similar technologies to collect information (see Section 4 for details).
Third-Party Account Data: If you sign up or log in via a third-party account (e.g., Sign in with Google), we receive certain information from that third party, including your name, email address, and profile image. Our use of Google API data complies with the Google API Services User Data Policy, including the Limited Use requirements.
We limit our collection to information necessary to fulfill the purposes described in this policy. Some data (like an email address and birthdate) is required to create an account and provide core services.
2. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or any other jurisdiction subject to the General Data Protection Regulation (GDPR) or equivalent legislation, we process your personal data only when we have a valid legal basis. The legal bases we rely on are:
Contractual Necessity (Article 6(1)(b) GDPR): We process your account information, journal entries, payment records, and subscription data because it is necessary to perform our contract with you — i.e., to provide the Lunar Guide service you signed up for. Without this processing, we cannot operate your account or deliver core features.
Legitimate Interests (Article 6(1)(f) GDPR): We process certain data (such as usage logs, device identifiers, fraud signals, and crash reports) based on our legitimate interest in:
- Keeping our services secure and preventing fraud or abuse.
- Improving the performance and quality of the app.
- Understanding aggregate usage trends to develop better features. We balance these interests against your rights and freedoms and do not use legitimate interests as a basis where our interests are overridden by your rights.
Consent (Article 6(1)(a) GDPR): We rely on your consent for:
- Sending promotional emails and newsletters.
- Placing non-essential cookies and tracking technologies (e.g., advertising pixels, analytics cookies) in EEA/UK jurisdictions where consent is required.
- Processing data through AI profiling where it goes beyond what is strictly necessary for the core service. You may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal (see Section 8 for your rights).
Legal Obligation (Article 6(1)(c) GDPR): We process data where required to comply with applicable laws, including financial record-keeping, tax obligations, and responding to lawful government requests.
Special Category Data: Astrological birth data (birthdate) may be considered general personal data rather than special category data under GDPR. However, if you voluntarily include health-related, religious, or other sensitive information in your journal entries, we process this data solely on the basis of your explicit consent (Article 9(2)(a) GDPR) for the purpose of providing personalized guidance. You may withdraw this consent at any time by deleting the relevant entries or your account.
3. Third-Party Services and How We Use Data
Lunar Guide relies on several third-party services to operate effectively. We share your information with these third parties only to the extent necessary to provide and improve our services.
Google Firebase (Cloud Storage and Database): All your personal information and content (account details, voice note transcripts, usage logs) are stored in Firebase's cloud databases. Firebase is operated by Google and complies with high security standards; data is encrypted at rest and in transit.
Google Services (Authentication & Integration): We integrate Google Sign-In for convenient and secure authentication. Lunar Guide may optionally offer features syncing with Google Calendar or Tasks, which requires your explicit consent and is governed by Google's policies. Our use of Google API data complies with the Google API Services User Data Policy, including Limited Use requirements.
Artificial Intelligence Providers (OpenAI and Anthropic): Lunar Guide's "Spirit Guide" feature uses AI technology. When you engage with the Spirit Guide, the relevant text input (transcription of your voice note or typed question) is sent to OpenAI or Anthropic for processing. We do not send personal identifiers (name, email) unless present in your journal content. Both providers are bound by data processing agreements that prohibit using your data to train their public models. AI providers may monitor submitted content for safety and abuse prevention under automated processes and strict privacy controls.
Eleven Labs (Voice Processing): We use Eleven Labs for text-to-speech or voice analysis features. Only the minimum necessary data (text to synthesize or audio to analyze) is sent. Results are returned to the app for your use.
Stripe (Payment Processing): All payments (credits and subscriptions) are processed by Stripe, Inc. Your credit card numbers, CVC, and other sensitive payment details go directly to Stripe — we never see or store them on our servers. Stripe is certified to PCI DSS Level 1, the highest grade of payment data security. Stripe may share with us limited billing information (billing address, card type, last four digits) for record-keeping, fraud prevention, and tax compliance. By making a payment, you agree to Stripe's Terms of Service and Privacy Policy. Stripe acts as a data processor for payments under our data processing agreement with them.
Analytics and Advertising Partners: We use Google Analytics, Microsoft Clarity, Facebook Pixel, TikTok Pixel, and similar tools to understand app usage and measure advertising effectiveness. These tools collect usage data and may set cookies. See Section 4 (Cookies and Tracking Technologies) for more detail and your opt-out choices.
4. Cookies and Tracking Technologies
Our website and web application use cookies and similar tracking technologies. This section explains what we use, why, and how you can control them.
4.1 Types of Cookies We Use
Essential (Strictly Necessary) Cookies: Required for the website or app to function (e.g., session authentication, security tokens, load balancing). These cannot be disabled without breaking core functionality.
Preferences Cookies: Remember choices you make, such as your preferred language, time zone, or theme settings. These are not strictly necessary but improve your experience.
Analytics Cookies: Collect aggregated, pseudonymous information about how users interact with our site and app. We use:
- Google Analytics: Tracks page views, session duration, feature usage, and traffic sources. You can opt out via Google's Analytics Opt-out Browser Add-on.
- Microsoft Clarity: Records anonymized session replays, heatmaps, and click patterns to help us improve UX. Clarity excludes sensitive form fields by default, and we configure it to avoid capturing personal content.
Advertising and Tracking Pixels: We employ tracking technologies on our marketing pages to measure ad campaign effectiveness:
- Facebook Pixel: Reports conversion events (sign-ups, visits) back to Facebook/Instagram to measure ad performance and enable retargeted advertising. Governed by Meta's Data Policy.
- TikTok Pixel: Similar tracking for TikTok ad campaigns.
- Other Platforms: We may use equivalent tools for Snapchat, Google Ads, or other platforms.
These pixels do not provide us with your personal profile on those platforms; we receive only aggregated or anonymized campaign statistics.
4.2 Your Cookie Choices
Cookie Consent Banner: When you first visit our website (or as required by your jurisdiction), you will be shown a cookie consent banner. You may accept all cookies, reject non-essential cookies, or customize your preferences. If you are in the EEA or UK, non-essential cookies will only be activated after you provide consent.
Browser Settings: You can set your browser to refuse some or all cookies, or to alert you when cookies are sent. Note that disabling essential cookies may break site functionality.
Analytics Opt-Out: Use Google's Analytics Opt-out Browser Add-on to prevent Google Analytics tracking. For Microsoft Clarity, you may disable JavaScript from Clarity's domain in your browser or privacy tool.
Ad Personalization: Manage Google ad personalization at Google's Ads Settings. To opt out of third-party interest-based advertising more broadly, visit the Network Advertising Initiative opt-out page or Digital Advertising Alliance opt-out portal.
Do Not Track: Some browsers send "Do Not Track" signals. We currently do not alter our data collection practices in response to Do Not Track signals, but your consent choices via our cookie banner govern non-essential tracking.
5. How We Use Your Information
We use the information we collect for the following purposes:
To Provide and Maintain the Service: Create and manage your account, generate personalized horoscope readings and Spirit Guide responses, save your journal entries, process transactions, and integrate with external services at your request.
To Improve and Customize Your Experience: Analyze usage patterns to identify popular and problematic features, optimize content delivery, conduct A/B testing, and improve overall UX.
To Communicate with You: Send account and support communications (confirmations, password resets, policy updates, support responses) and, with your consent, promotional emails and newsletters. You can opt out of promotional communications at any time.
To Process Payments: Process transactions via Stripe, maintain purchase records, handle billing disputes, and comply with financial reporting obligations.
To Enforce Our Terms and Policies: Monitor for suspicious or unauthorized activities, review content where violations are suspected, and apply automated filters to prevent AI misuse.
For Safety and Legal Compliance: Meet applicable laws and regulations, respond to lawful government requests, and protect the safety of our users and the public.
For Automated Decision-Making and AI Profiling: See Section 8 below.
6. Data Breach Notification
In the event of a personal data breach, we have established procedures to respond promptly and meet our legal obligations.
Containment and Assessment: As soon as we become aware of or reasonably suspect a security breach, we will act immediately to contain it, assess its scope and severity, and determine the categories and approximate volume of personal data involved.
GDPR 72-Hour Notification: If we determine that a breach is likely to result in a risk to the rights and freedoms of individuals (including EEA/UK residents), we will notify the relevant supervisory authority (e.g., the applicable EU Data Protection Authority or the UK Information Commissioner's Office) within 72 hours of becoming aware of the breach, where feasible. If notification cannot be made within 72 hours, we will provide the notification with a reasoned explanation for the delay.
User Notification: If a breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay via the email address associated with your Lunar Guide account. This notice will include:
- A description of the nature of the breach.
- The categories and approximate number of personal data records affected.
- The likely consequences of the breach.
- The measures taken or proposed to address the breach, including steps to mitigate its possible adverse effects.
- Contact information for our privacy team so you can obtain further information.
U.S. State Breach Notifications: To the extent required by applicable U.S. state data breach notification laws (including Utah's laws), we will notify affected users and, where required, state authorities in accordance with those laws.
Documentation: We maintain an internal record of all data breaches, including those that do not require notification, as required by GDPR Article 33(5).
7. International Data Transfers
Lunar Guide is operated from the United States. If you are located outside the United States — including in the European Economic Area (EEA), the United Kingdom, or other countries with data protection laws — your personal data will be transferred to and processed in the United States and potentially other countries that may not provide the same level of data protection as your home country.
Safeguards for EEA/UK Transfers: Where we transfer personal data from the EEA or UK to countries not recognized by the European Commission or UK government as providing an adequate level of data protection (including the United States), we rely on appropriate safeguards, including:
- Standard Contractual Clauses (SCCs): We use the European Commission's approved Standard Contractual Clauses (Module 2: Controller to Processor and Module 1: Controller to Controller, as applicable) with our service providers and data processors outside the EEA. These clauses impose contractual obligations on both parties to protect your data.
- UK Addendum: For transfers from the United Kingdom, we use the applicable UK International Data Transfer Addendum to the EU SCCs or the UK's own transfer mechanisms.
- Adequacy Decisions: Where the European Commission or UK government has issued an adequacy decision for a recipient country, we may rely on that decision.
Third-Party Processors: Our primary international processors include Google (Firebase, Analytics, Cloud), OpenAI (USA), Anthropic (USA), Eleven Labs (USA), and Stripe (USA). Each has either agreed to SCCs, relies on adequacy decisions, or participates in approved frameworks. You can contact us to obtain copies of applicable SCCs or further information about the safeguards in place.
Your Rights Regarding International Transfers: If you would like more information about how we protect your data when it is transferred internationally, or to exercise your rights in relation to transferred data, please contact us at support@lunarguideapp.com.
8. Automated Decision-Making and AI Profiling
Lunar Guide uses artificial intelligence to deliver its core service. This section explains how automated processing works and your rights in connection with it.
Personalized Astrological Guidance (Spirit Guide): Our AI analyzes the text transcription of your voice journal entries, your birth date, and any prompts you provide to generate personalized astrological guidance. This is a form of automated profiling. The outputs (astrological insights, reflective prompts, or Spirit Guide responses) are generated algorithmically based on patterns in your input and astrological data.
Legal Basis: We process your data for AI profiling on the basis of your consent (Article 6(1)(a) / Article 22(2)(c) GDPR), which you provide when you use the Spirit Guide feature. You may withdraw consent by discontinuing use of that feature or deleting your account.
No Solely Automated Decisions with Legal or Significant Effects: We do not make decisions that produce legal effects or similarly significant effects on you (such as credit decisions, insurance pricing, or employment decisions) solely by automated means. Our AI generates informational and entertainment content — it does not make binding decisions about you.
AI Accuracy Limitations: AI-generated content is inherently probabilistic and may occasionally be inaccurate, outdated, biased, or unexpected. Astrological guidance and Spirit Guide outputs are generated for informational and entertainment purposes only and do not constitute professional advice of any kind (see Section 5.2 of our Terms). We make no warranty that AI outputs are accurate, complete, or suitable for your circumstances.
Content Moderation: Automated content filtering is applied to inputs and outputs of our AI feature to detect and prevent misuse (e.g., attempts to generate harmful content). This automated screening does not result in legal decisions affecting you, but may result in your request being declined or your account being flagged for review.
Your Rights: You have the right to:
- Request human review of any automated profiling output that you believe is inaccurate or unfair.
- Express your point of view and contest automated outputs.
- Opt out of AI profiling by simply not using the Spirit Guide feature, or by requesting account deletion.
Contact us at support@lunarguideapp.com to exercise these rights.
9. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes for which we collected it, including satisfying legal, accounting, or reporting requirements.
Active Account Data: Account information, journal entries, preferences, and credit balances are retained for the duration of your active account.
Account Deletion Timeline: When you request account deletion (via support@lunarguideapp.com or in-app settings), we will permanently delete or fully anonymize your personal data within 30 days of verifying your request. During this period, your account may be deactivated and inaccessible.
Backup Retention: Data may persist in encrypted backup systems for up to an additional 30 days after deletion from active systems, after which it is purged from backups. Backup data is isolated and not used for active processing.
Transactional Records: Purchase records, subscription history, and billing records are retained for 7 years following account deletion, as required for financial reporting, tax compliance, and audit purposes. These records are retained in pseudonymized or minimized form where possible.
Legal Holds: If we are required to retain specific data due to a legal obligation, pending litigation, or regulatory investigation, we will hold onto the relevant information for as long as legally required.
Voice Journal Entries: Individual voice notes and transcriptions you delete from within the app are removed from active storage immediately and purged from backups within 30 days. Deleting your account triggers deletion of all journal content on the same timeline as above.
AI Processing Logs: Logs of AI requests (without full journal content) may be retained for up to 12 months for performance monitoring, abuse prevention, and service improvement.
Analytics and Logs: Application logs and analytics data are retained for 12 months, after which they are aggregated or deleted. Crash reports are retained for 90 days.
10. Your Data Protection Rights
10.1 GDPR Rights (EEA and UK Users)
If you are located in the European Economic Area, United Kingdom, or another GDPR-regulated region, you have the following rights regarding your personal data:
Right of Access (Article 15): Request a copy of the personal data we hold about you and information about how we process it.
Right to Rectification (Article 16): Request correction of inaccurate or incomplete personal data.
Right to Erasure / Right to be Forgotten (Article 17): Request deletion of your personal data where (i) it is no longer necessary for the purposes collected, (ii) you withdraw consent and there is no other legal basis, (iii) you object to processing and there are no overriding legitimate grounds, (iv) the data has been unlawfully processed, or (v) erasure is required by law.
Right to Restrict Processing (Article 18): Request that we limit how we use your data in certain circumstances — for example, while we verify the accuracy of data you have disputed, or where processing is unlawful but you prefer restriction over erasure.
Right to Data Portability (Article 20): Request your personal data in a structured, commonly used, and machine-readable format, and have it transmitted to another controller where technically feasible (applies to data processed on the basis of consent or contract).
Right to Object (Article 21): Object at any time to processing based on our legitimate interests (Article 6(1)(f)), including profiling based on those interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your rights, or for legal claims. You also have an absolute right to object to processing for direct marketing purposes.
Right to Withdraw Consent (Article 7(3)): Where processing is based on your consent, withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal.
Rights Related to Automated Decision-Making (Article 22): See Section 8 above.
Right to Lodge a Complaint: You have the right to lodge a complaint with your national or regional data protection supervisory authority at any time. For EEA users, this is the Data Protection Authority in your EU member state. For UK users, this is the Information Commissioner's Office (ICO). A list of EEA supervisory authorities is available at the European Data Protection Board's website.
How to Exercise GDPR Rights: Submit requests to support@lunarguideapp.com with the subject line "Data Rights Request." We will respond within 30 days (or 60 days where permitted for complex requests, with notice). We may require identity verification before processing your request.
10.2 CCPA/CPRA Rights (California Residents)
Under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), California residents have the following rights:
Right to Know: Request disclosure of (i) the categories and specific pieces of personal information we have collected about you; (ii) the categories of sources from which we collected it; (iii) our business purpose for collecting, sharing, or selling it; and (iv) the categories of third parties with whom we share it.
Right to Delete: Request deletion of personal information we have collected from you, subject to certain exceptions (e.g., completing transactions, security, legal obligations).
Right to Correct: Request correction of inaccurate personal information we hold about you.
Right to Opt-Out of Sale or Sharing: You have the right to opt-out of the "sale" or "sharing" of your personal information. Lunar Guide does not sell personal information. We do not share personal information for cross-context behavioral advertising in a manner that constitutes "sharing" under CPRA, except where you have provided consent via our cookie banner for advertising pixels.
Right to Limit Use of Sensitive Personal Information: You may request that we limit our use of sensitive personal information (as defined by CPRA) to the purposes permitted by law.
Right to Non-Discrimination: We will not discriminate against you for exercising any CCPA/CPRA rights. This means we will not deny goods or services, charge different prices, or provide a different level or quality of service because you exercised your rights.
Shine the Light (California Civil Code § 1798.83): California residents may request information about disclosures of personal information to third parties for their direct marketing purposes in the prior calendar year. Lunar Guide does not disclose personal information to third parties for their own direct marketing purposes.
How to Exercise CCPA/CPRA Rights: Contact us at support@lunarguideapp.com or our mailing address. We will acknowledge your request within 10 business days and respond within 45 days (extendable to 90 days with notice). We may require verification of your identity before processing the request.
Authorized Agent: You may designate an authorized agent to submit requests on your behalf. We may require written authorization and will verify the agent's authority before acting on the request.
11. Children's Privacy
The Lunar Guide app is intended for use by adults only. Our services are not directed to children under the age of 18, and we do not knowingly collect personal information from individuals under 18 years of age.
Age Restriction: Users must be at least 18 to create an account and use the app.
No Collection from Children Under 13: We do not intentionally collect personal data from anyone under 13. If we discover that we have inadvertently gathered personal information from a child under 13, we will take immediate steps to delete such information from our records.
COPPA Compliance: We comply with the Children's Online Privacy Protection Act (COPPA), which governs online services directed at children under 13. If you believe a minor has provided us with personal information, contact us immediately at support@lunarguideapp.com.
12. Data Security
We implement a variety of security measures to protect your data from unauthorized access, alteration, disclosure, or destruction.
Encryption: All communications between your device and our servers are encrypted using HTTPS (TLS). Data stored in Firebase is encrypted at rest using industry-standard encryption.
Access Controls: Only authorized personnel with a need-to-know basis can access personal data. All contractors sign strict confidentiality agreements.
Security Testing and Audits: We regularly update software dependencies, conduct internal testing and code reviews, and perform periodic third-party security audits or penetration tests on critical systems.
Monitoring: We use monitoring tools to track access and operations in our infrastructure and to detect suspicious activity.
No Guarantees: While we take reasonable and appropriate security measures, no internet-based service is 100% secure. We cannot guarantee the absolute security of your data. Please use a strong, unique password for your account and notify us immediately at support@lunarguideapp.com if you suspect unauthorized access.
13. Payments and Financial Data
Use of Stripe: All purchases in Lunar Guide are processed by Stripe, Inc. (USA). Stripe is our payment processor under a data processing agreement that governs how Stripe handles your payment data on our behalf.
No Storage of Card Details on Our Servers: We never store your full credit card number, CVC, or PIN on our systems. That information goes directly to Stripe via encrypted channels.
PCI Compliance: Stripe is certified to PCI DSS Service Provider Level 1, the highest standard for payment data security.
What We Retain: We retain a record of the transaction amount, date, subscription status, and the last four digits of your card (as provided by Stripe) for account management and customer support purposes.
Stripe's Privacy Policy: For more information about how Stripe handles your data, please review Stripe's Privacy Policy. By making a payment, you consent to Stripe's processing of your payment data.
14. Email Communications and Opt-Out
Account and Transactional Emails: We send emails necessary for your use of Lunar Guide, including verification emails, password resets, purchase confirmations, receipts, and important service notices. These are required to provide the service and cannot be opted out of while you maintain an account.
Promotional and Newsletter Emails: With your consent, we may send periodic emails about new features, content, special offers, astrology content, or general app updates.
How to Opt Out: Every promotional email includes an "Unsubscribe" link. You can also adjust email preferences in app settings or contact support@lunarguideapp.com. Opt-out requests are processed within 10 business days.
Third-Party Marketing: We do not share your email address with third-party marketers without your explicit consent.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements.
Notification of Material Changes: If we make a significant change, we will notify you by posting a notice in the app, on our website, or by sending an email to your registered address at least 30 days before the change takes effect (where required by law and feasible).
Effective Date: The current Effective Date is always listed at the top of this policy.
Continued Use: Your continued use of the app after the effective date of an updated policy constitutes acceptance of the changes. If you do not agree to the changes, you may delete your account before they take effect.
We encourage you to review this Privacy Policy periodically.
16. Advertising via Google AdSense
We display advertising on certain pages of our website (specifically, our blog) using Google AdSense.
What data may be used: Google and its partners may use cookies or device identifiers to serve ads, measure ad performance, and prevent fraud. We do not pass personally identifiable information to Google for advertising purposes.
Personalized vs. non-personalized ads: In regions requiring consent (e.g., EEA/UK), we obtain your consent before enabling advertising storage or ad personalization via our cookie banner. If you choose "Reject All," you will receive non-personalized ads.
Your choices:
- Manage Google ad personalization at Google's Ads Settings.
- Learn how Google uses partner-site data at Google's Privacy Policy.
- Opt out of third-party interest-based advertising at aboutads.info.
Authorized sellers (ads.txt): We publish an ads.txt file to declare authorized sellers of our ad inventory as recommended by Google AdSense.
17. Contact Us
Your privacy is important to us. For questions, concerns, or to exercise your rights:
Privacy Requests and General Inquiries: Email: support@lunarguideapp.com
Alternate Contact: Email: agentkain@gmail.com
Postal Mail: 1117 Productions LLC (Lunar Guide) 2240 Foothill Drive Salt Lake City, UT 84109 USA
For GDPR-specific inquiries or to reach our privacy team directly, please include "Privacy Request" or "GDPR Request" in your email subject line. We aim to respond to all privacy requests within 30 days.
Thank you for reading our Privacy Policy. We value the trust you place in Lunar Guide and are committed to protecting your data.
