Privacy policy
Last updated: 30 September 2026
Lunastak is an AI strategy coach at app.lunastak.io, with a marketing site at lunastak.io. It is operated by Humble Ventures Pty Ltd (ABN 18 627 466 631), an Australian company ("we", "us"). We handle personal information under the Australian Privacy Principles in the Privacy Act 1988 (Cth).
This policy covers Lunastak only. The Humble Ventures privacy notice covers our consulting work.
You're using Lunastak to think through sensitive strategic questions, so this policy is specific about what we keep, where it goes, and what happens when you delete it. For a shorter overview, see How we handle your data.
Questions or requests: privacy@lunastak.io.
What we collect
Your account
- Your email address, and your name if you sign in with Google.
- Sign-in records: session tokens, and for Google sign-in the tokens Google issues to us. We never store a password: you sign in with a magic link or with Google.
- Usage counters, such as how many AI requests your account has made.
If you use Lunastak without signing up, we create a guest account identified by a random ID in a cookie. When you sign up, your guest work moves to your account and the guest account is deleted.
What you put into Lunastak
- Conversations with Luna. Everything you write and every reply, saved so you can pick up where you left off.
- Uploaded documents. We read the file on our own servers and don't keep the file or its full text. We do keep the file's name, type and size, any note you add about it, and the themes we draw from it. Each theme has a title, a summary, and one or more excerpts copied word for word from the document. We read the first 15,000 characters of each document's text.
- Context bundles from Lunastak's AI instructions or plugin. Your source material stays in the AI tool you used. We receive only the bundle file you upload. We keep the summaries, excerpts and tags inside it, and the source names it lists. We don't keep the file itself. We store whatever text your tool put in the bundle, so review it before uploading.
- What we build from all of this: ground truths (the themes) and the evidence quotes behind them, Lunastak's running summaries of your strategy, and your Decision Stack with its version history. Some of this text is copied into version history and generation records, so earlier versions can be shown.
How you use Lunastak
- Product analytics. Which pages you view and which controls you click, linked to your account. We record that something was clicked, not the text on it. Once you sign up, it's also linked to your email address in PostHog. Collected with PostHog, Statsig and Vercel Analytics. PostHog events go through our own domain on the way to PostHog. We don't record sessions, and we use no advertising trackers.
- Error reports (Sentry), without session replay. They're set up not to include your name or email. An error message can occasionally include technical detail from the request that failed.
- Server logs (Vercel). These can include identifiers and short labels derived from your content, such as a document's file name or a conversation's title. They don't include whole messages or documents.
- Internal notifications. When someone signs up or hits a usage threshold, a message with their email address goes to our team's Slack.
How we use it
- To run Lunastak: hold your conversations, extract themes, and generate and update your strategy.
- To sign you in and send the emails you asked for: sign-in links, and product emails you can unsubscribe from.
- To understand which parts of Lunastak help and where people get stuck, and to fix errors.
- To protect the service: usage limits, and investigating abuse.
We don't sell your information, and we don't use it for advertising. Neither we nor our AI provider train AI models on your content (see Anthropic below).
Who processes it for us
Lunastak runs on these providers. Each one handles only what it needs to.
| Provider | What for | What it receives | Where |
|---|---|---|---|
| Anthropic (Claude API) | All AI features | Your conversations, document text (up to 15,000 characters per document), bundle contents, and what we derive from them | United States |
| Neon | Our database | Everything we store, listed above | Singapore |
| Vercel | Hosting, server logs, Vercel Analytics | All requests as they pass through; logs as described above | United States |
| PostHog | Product analytics | Usage events; your email once you sign up | United States |
| Statsig | Feature flags and analytics | Usage events, with your account ID | United States |
| Sentry | Error monitoring | Error reports | United States |
| Resend | Your email address and name, and the emails we send you | United States | |
| Sign-in, if you choose it | You sign in with Google, and Google sends us your name and email | n/a | |
| Slack | Internal team notifications | Email addresses and technical error messages | United States |
Anthropic doesn't use API data to train its models, and deletes API inputs and outputs within 30 days under its commercial terms.
Uploaded files are read on our own servers. We pull the text out of a PDF, Word file or text file inside Lunastak itself. The file isn't sent to a separate extraction service.
Overseas transfers
Our database is in Singapore and most of our other providers are in the United States, so your information will be processed in both. Some providers may process it in other countries while delivering their service. We choose providers that publish independent security certifications, such as SOC 2, and that offer data processing terms.
Who can see your projects
- You. Every project belongs to one account, and requests for a project's data are checked against its owner.
- People you share a link with. Share links are off by default. When you turn one on, anyone with the link can see the project's name, its context summary and its Decision Stack. They can't see your conversations, documents or ground truths. The link works until you turn sharing off or delete the project. It doesn't expire on its own, and turning sharing back on restores the same link.
- Everyone, for our demo projects. A few showcase projects built from public information are open to anyone, read-only. Your projects are never demos.
- Us, when needed. We look at a project's contents only to support you, investigate a problem or protect the service.
Deleting your data
Delete a project. A signed-up user can do this from inside the app at any time. It permanently deletes the project and everything in it from our database: conversations and messages, document records and the themes drawn from them, ground truths and evidence, and your strategy with its version history.
What you can't yet delete on its own:
- a single conversation;
- a document that has produced ground truths;
- an individual ground truth. Removing one in the review hides it from your project; it isn't erased.
To remove these, delete the project they belong to. Guest users can't delete anything in the app; email us and we'll do it.
Delete your account. Email privacy@lunastak.io and we'll delete your account and all its projects within 7 days. We'll also remove you from our email provider and analytics tools.
What remains after deletion:
- Database restore history. Our database can be rolled back to an earlier point for a short window, currently 6 hours. Deleted data stays recoverable for that long, then it's gone.
- Our providers' own copies expire on their schedules. For example, Anthropic deletes API data within 30 days.
- Logs, error reports and analytics events from before the deletion are kept until they expire under each tool's retention settings. They hold identifiers and usage details.
Guest data: a guest account you don't sign up from stays until you ask us to delete it.
Security
- Your data is encrypted, both on its way to us and where it's stored.
- There's no password to steal. You sign in with a link we email you, or with Google.
- Your projects are private to your account. No other user can open them unless you turn on a share link.
- Access to the database is restricted to us, and we use it only to support you, fix a problem or protect the service.
Lunastak is an early-stage product and isn't SOC 2 certified. If you have specific compliance requirements, get in touch: we'll tell you plainly what we can and can't do.
If a data breach is likely to cause you serious harm, we'll tell you and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.
Cookies
We use cookies to keep you signed in, to recognise a guest session, and for product analytics (PostHog, Statsig, Vercel Analytics). We don't use advertising cookies.
Your rights
You can ask us to give you a copy of your information, correct it, or delete it. You can also unsubscribe from product emails at any time using the link in each email. Email privacy@lunastak.io.
If you're unhappy with how we've handled a request, contact us first. If it's still unresolved, you can complain to the Office of the Australian Information Commissioner.
Changes
If we change how we handle your data, we'll update this page and the date at the top. We'll email you about significant changes.