How we handle your data
You're using Lunastak to think through your most sensitive strategic questions. This page covers what we do and don't do with that data.
The privacy policy is the full statement. Email privacy@lunastak.io with anything neither page answers.
The short version
- Your data lives in an isolated Postgres database on Neon, in Singapore, encrypted in transit (TLS) and at rest.
- We never train AI models on your data. Anthropic, our LLM provider, contractually does not train on API traffic.
- Delete any project — and everything inside it (conversations, ground truths, documents, generated strategy) — at any time, from inside the app.
- We don't keep uploaded files or their full text. We read the file on our own servers and the text becomes ground truths in your project. We do keep the file's name and size, and the excerpts each ground truth quotes. Lunastak reads the first 15,000 characters of each document.
- Our agent instructions run entirely in your own AI. The one line you paste into Claude, ChatGPT, Gemini or Claude Code, and the Lunastak plugin for Claude Code, don't transmit anything to us. You decide what to share, and when.
Where your data lives
| Layer | Provider | What's stored |
|---|---|---|
| Application hosting | Vercel | Requests in transit; server logs with identifiers and short labels, such as file names |
| Database | Neon (serverless Postgres) | Your projects, conversations, ground truths, generated strategy |
| LLM inference | Anthropic (Claude API) | Nothing persisted by us at this layer. Anthropic deletes API data within 30 days and doesn't train on it |
| Document text extraction | Lunastak itself (on Vercel) | Nothing kept. The file is read in memory and discarded; no separate extraction service |
| Resend | Your email address, sign-in links and product emails | |
| Authentication | NextAuth.js (Google OAuth + magic links) | Email address, session tokens |
| Product analytics | PostHog, Statsig, Vercel Analytics | Pages viewed and controls clicked (not the text on them), linked to your account and email |
| Error monitoring | Sentry | Error reports from the app, without your name or email; no session replay |
All data in Neon is encrypted at rest. All connections are encrypted in transit using TLS.
What we store
- Account — email address and authentication state.
- Projects — the boundary that contains everything else.
- Conversations — what you wrote in Talk to Luna, and the replies, so you can resume.
- Ground truths — strategic themes extracted from conversations, documents, and imported context bundles. (Earlier versions of this page called them fragments.)
- Evidence quotes — the exact words each ground truth came from, copied from your messages, documents or bundles.
- Dimensional syntheses — Lunastak's running understanding of your strategy, area by area.
- Generated strategy — your Decision Stack outputs and version history.
- Share link state — whether a project's share link is on, and its token.
What we don't store
- Original uploaded documents. Files are read on our own servers, not sent to an extraction service. Lunastak reads the first 15,000 characters of the text and turns them into ground truths, with evidence quotes copied word for word. The file and its full text aren't kept; its name, type and size are.
- Anything your own AI gathers before you import it. The agent instructions are context-engineering prompts. They run inside the assistant you chose and don't transmit to us.
- Tracking pixels or advertising data. We use PostHog, Statsig and Vercel Analytics for product analytics — to see which parts of Lunastak help and where people get stuck. PostHog events go through our own domain (lunastak.io and app.lunastak.io) on their way to PostHog in the US, so ad-blockers don't drop them. It's product analytics only: no advertising trackers, no session recordings, no data sold or shared.
How AI providers handle your data
Lunastak uses Anthropic's Claude API for all LLM inference. Anthropic's API terms specify that data submitted via the API is not used to train Anthropic models. Claude reads your conversation, extracts ground truths, synthesises themes, and generates your strategy — without retaining it for training.
Document text extraction happens inside Lunastak. The file itself goes to no third party; the first 15,000 characters of its text go to Anthropic, under the terms above.
Your AI never transmits to us
The instructions you paste into your AI, and the Lunastak plugin for Claude Code, are context-engineering prompts. They guide you through structured questions, organise your thinking, and produce a context bundle.
No part of this process transmits data to Lunastak. Everything happens inside the workspace you chose — your terminal, ChatGPT, Gemini, Claude. Documents, transcripts, and conversations stay there.
When you're ready, you upload the bundle to Lunastak. Only then does prepared, intentional context enter our pipeline.
Deleting your data
From inside the app:
- Delete a project — open the project switcher in the header, choose Delete, and confirm. This removes the project and everything in it: conversations, messages, ground truths, evidence quotes, documents, generated strategy, version history. Immediate and irreversible. Only signed-up users can delete a project.
Per-conversation deletion is coming. For now, deleting a project is the way to clear conversation data. The same goes for a single ground truth: removing one in the review hides it from your project, and it's erased when the project is.
To delete your account, email privacy@lunastak.io — we'll process it within 7 days.
What remains after deletion. Our database can be rolled back to an earlier point for a short window, currently 6 hours, so deleted data stays recoverable for that long. Our providers' own copies expire on their schedules: Anthropic deletes API data within 30 days. Logs, error reports and analytics events from before the deletion stay until each tool's retention expires; they hold identifiers and usage details, not your project content.
Access control
- Every project belongs to exactly one user.
- API endpoints enforce ownership on every request. Projects are never accessible to other users — except through a share link you turn on.
- Share links are read-only and off by default. A link shows the project name, a short summary of its context, and the Decision Stack. It doesn't show your conversations, documents or ground truths. Anyone with the link can view it until you switch it off.
- NextAuth.js with HTTP-only secure cookies for sessions. No password storage — auth is magic link or Google OAuth.
- A small number of demo projects (Acquired podcast Decision Stacks for Ferrari, Costco, TSMC, Nike) are flagged as demos and viewable by anyone read-only. They contain only public information.
Beta-stage caveats
Lunastak is in beta. Not yet SOC 2 certified. Built from the ground up by people who've worked with sensitive data in controlled and regulated environments, and who treat privacy, security and safety as first-class architectural concerns.
Specific compliance requirements? Get in touch — we'll tell you what we can and can't accommodate at this stage.
Related
- Lunastak privacy policy — the full statement of what we collect, who processes it and how deletion works.
- Anthropic API privacy — how Anthropic handles API customer data.