Privacy Policy
We built the platform to give users clarity about biomarker and supplement data - not to monetize that data. This page explains what we collect, why we collect it, and how we handle it.
The platform uses only the minimum data needed to authenticate accounts, analyze uploaded labs, and support saved reports when a user explicitly stores them.
1. Overview
Luneri Health ("we," "us," or "our") operates the Luneri research and analysis platform at this website. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and your rights regarding that data.
By using the platform, you agree to the practices described in this policy. If you do not agree, please discontinue use.
2. Data We Collect
Account data. When you create an account, we collect your email address and a hashed password. You may optionally provide a display name.
Bloodwork data. If you use the Analyze feature, you may upload lab result documents (PDF or image) or enter values manually. Uploaded files are parsed locally in the browser, reviewed by you, and only confirmed biomarker rows are sent to our server when you save or run analysis.
Usage data. We collect standard server logs including IP address, browser type, pages visited, and timestamps. This data is used solely for security monitoring and aggregate analytics.
Communications. If you contact us via the contact form or email, we retain that correspondence to respond to your inquiry.
3. How We Use Your Data
We use collected data to:
- Provide, operate, and improve the platform and its features
- Authenticate your account and maintain session security
- Process reviewed bloodwork biomarker rows to generate analysis output and saved history when you confirm an upload
- Send transactional emails (password reset, account notifications) - we do not send unsolicited marketing email
- Monitor for abuse, fraud, and security threats
- Comply with applicable legal obligations
We do not sell your personal data to third parties. We do not use your bloodwork data to train AI models or for any purpose beyond generating your personal analysis.
4. Data Retention
Account data is retained for as long as your account is active. If you delete your account, your email and profile data are permanently deleted within 30 days.
Raw bloodwork uploads are not persisted to our database in v1. Only the confirmed biomarker rows you choose to analyze or save are stored as panel history.
Server logs are retained for 90 days for security purposes and then deleted.
6. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access - request a copy of the personal data we hold about you
- Correction - request that inaccurate data be corrected
- Deletion - request that we delete your account and associated data
- Portability - receive your data in a machine-readable format
- Restriction - request that we limit how we process your data
- Objection - object to certain types of processing
To exercise any of these rights, contact us at the address in Section 9. We will respond within 30 days.
7. Security
We implement industry-standard security measures including TLS encryption in transit, bcrypt-hashed passwords, row-level security policies on all database tables, and regular dependency audits.
No system is perfectly secure. If you discover a security vulnerability, please contact us immediately rather than disclosing publicly.
8. Minors
This platform is not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has created an account, contact us and we will delete it promptly.
9. Contact
For privacy-related inquiries, data access requests, or to report a concern, contact us via the contact form at /contact or by emailing the address on file with Vercel for this domain.
We will acknowledge privacy requests within 5 business days and resolve them within 30 days.
10. Changes to This Policy
We may update this policy periodically. When we do, we will update the "Last updated" date above. Material changes will be communicated to registered users via email at least 14 days before taking effect.
Continued use of the platform after changes become effective constitutes acceptance of the revised policy.