Back to home

Privacy Policy

Last updated: February 2026

Lunarosa is committed to protecting your privacy. This policy explains how we handle your data.

Information We Collect

Account Information: Phone number or email address for authentication purposes only.

Health Data: Period dates, flow intensity, symptoms, and notes you choose to log. This data is encrypted on your device before being stored on our servers.

Technical Data: Basic device information (browser type, operating system) for security and troubleshooting purposes.

Zero-Knowledge Encryption

Your health data is encrypted with keys that only you possess.

We use client-side encryption, meaning your sensitive data is encrypted on your device before it ever reaches our servers. We cannot read, access, or share the contents of your private health data.

Important: If you lose your PIN and recovery key, we cannot restore your data. This is by design to protect your privacy.

Data Sharing

We do not sell your personal data to anyone.

We do not share your health details with advertisers, data brokers, or any third parties for marketing purposes.

We use limited third-party services:

  • Twilio: For SMS verification only (phone number used solely for authentication)
  • Vercel: For hosting (São Paulo, Brazil servers, encrypted at rest)
  • PostHog: For anonymous usage analytics (sign-up and onboarding funnel only — no health data is ever collected or sent)

We do not use advertising networks or analytics that track your health data. Our analytics measure only anonymous sign-up conversion events to improve the experience.

Your Rights

We honor these rights for all users, regardless of location:

  • Access: View all your data anytime within the app
  • Export: Download your data in a portable format
  • Delete: Request full account deletion at any time
  • Correct: Update or modify your data as needed

We comply with LGPD (Brazil), GDPR (EU), and other applicable privacy regulations.

Data Retention

Active accounts: Your data is kept until you choose to delete it.

Inactive accounts: Accounts inactive for 2 years may be automatically deleted.

When you delete your account, all associated data is permanently removed from our servers.

SMS & WhatsApp Communications

By providing your phone number and opting in to receive SMS and WhatsApp messages from LunaRosa for account authentication, you agree to the terms of this Privacy Policy. Message and data rates may apply. You may receive recurring messages related to authentication and security only.

Contact Us

If you have questions about this privacy policy or your data, contact us at:

Email: support@lunarosa.app

Get Started — Free