The short version
- Your organization's knowledge belongs to your organization. We store and process it to run the service, and for nothing else.
- We do not train AI models on your content, and we do not sell it.
- Your account and content live in the European Union. To answer a question, relevant excerpts are sent to AI providers in the United States. That is the part people most often want to know, and the part we will not hide.
- Inside the service there is no third-party analytics or advertising software. The website uses analytics and advertising cookies from Google, Meta and TikTok, and only if you accept them in the cookie banner.
- Ask us anything at hannes@luna-labs.io.
Who is responsible
Luna Labs is the trading name of Luna Learning Labs AB, a Swedish company (organization number 559532-5290) with its registered office at Skanstorget 10C, 411 22 Göteborg, Sweden. It is run by its two founders, Hannes Hård af Segerstad and Wilma Deleryd.
For the personal data your organization chooses to put into Luna Labs, your organization is the data controller and Luna Labs is the processor: we handle it on your instructions. For account data and the data we need to run and bill the service, we are the controller.
Data protection questions go to hannes@luna-labs.io. There is no separate data protection officer; a company of two does not need a department to answer an email.
What we collect
Account and organization data. Your name, work email address, your profile picture from Google if you sign in with Google, your role in the organization, your job title if you fill it in, the organization's name and size, and who invited whom.
The knowledge your organization curates. Documents you upload, paste or import, the text extracted from them, answers given in mapping interviews, drafts and proposals awaiting review, and the folder structure and tags around all of it. This is the company brain, and it is whatever your organization decides to put in it.
Search indexes derived from that knowledge. Documents are split into passages and each passage is turned into a numeric embedding so that questions can find the right material. The passage text is stored alongside the embedding.
Connected sources. If your organization connects Google Drive, Microsoft SharePoint or OneDrive, we store which folder or site is connected and when it was last scanned, and we copy the files you choose (or the files in the folder you chose) into Luna Labs so they can be reviewed and mapped. For Microsoft connections we store the access credentials needed to rescan, encrypted at rest. For Google Drive imports the access token is used for that import and is not stored in our database.
Usage data. Which AI tool made a request to our MCP server, when it was first and last used, and how many requests it has made; and technical event records used to keep the service working and to understand what people actually use.
Session and security data. Active sessions with IP address, browser, operating system and device name, so that you can see where you are signed in and revoke a session you do not recognise.
Prompt history from the older clients. People still using the Luna Chrome extension or the macOS app to improve prompts have the original prompt, the improved version and the analysis stored so they can look them up again. See retention in section 07.
Inside the service at app.luna-labs.io we run no third-party analytics, advertising or tracking software: no Google Analytics, no Meta pixel, no session-recording tool. The only cookies and local storage the service uses hold your sign-in session. The marketing cookies above exist on the public website only and never see your organization's content.
The website. luna-labs.io uses cookies and pixels from Google Analytics, Google Ads, Meta and TikTok to measure how people find the site and to show Luna Labs ads to people who have visited it. None of them are set until you accept them in the cookie banner, and you can change your mind at any time through the cookie settings link in the footer. What each one collects and how long it lasts is listed in the Cookie Policy. If you leave your email address or a message in a form on the website, we use it to get back to you.
Why we process it, and on what legal basis
- To run the service you asked for (storing your knowledge, answering questions, serving connected AI tools, sending account email). Legal basis: performance of a contract.
- To keep the service secure and working (session records, rate limits, error diagnosis, abuse prevention). Legal basis: our legitimate interest in a service that stays up and is not abused.
- To understand how the product is used so we can improve it, using our own first-party event data. Legal basis: legitimate interest.
- To know that a new customer has arrived. When an organization is created we post its name, team size and the creator's email address to our own internal Slack channel so the founders can welcome them. Legal basis: legitimate interest.
- To get back to people who asked us to. An email address or message left in a form on the website is used only to contact that person about Luna Labs. Legal basis: consent, which you withdraw by replying and saying so.
- To measure the website and advertise Luna Labs. Analytics and advertising cookies on luna-labs.io tell us which pages work, where visitors come from, and let us show ads to people who have visited. Legal basis: your consent, given in the cookie banner and withdrawable at any time.
- To meet legal obligations, such as bookkeeping for invoices. Legal basis: legal obligation.
We do not use your content for marketing, we do not build profiles for advertising, and we do not make automated decisions with legal effects about you.
Where your data lives
The database, file storage and backend functions run on Supabase in the European Union (Ireland, AWS region eu-west-1). The web app is delivered by Vercel. Files you upload or import are kept in private storage that is only reachable through our backend, never by a public link.
One thing crosses a border, and we would rather say it plainly than bury it: to generate an answer, an analysis, an interview question or an embedding, the relevant text is sent to AI providers whose APIs run in the United States. That is unavoidable for a product built on today's large language models. Those transfers rely on the providers' standard contractual clauses. The material sent is the excerpt needed for the request, not your whole knowledge base.
The website's analytics and advertising providers (Google, Meta, TikTok) also process data outside the EU, mainly in the United States. Those transfers rely on the EU-US Data Privacy Framework and standard contractual clauses, and they happen only after you have accepted the relevant cookies.
Who else processes your data
These are the only companies that handle data on our behalf.
For the service:
- Supabase (database, authentication, file storage, backend functions). Hosted in the EU. Also sends account email such as invitations and password resets.
- Vercel (hosting and delivery of the web app and the website).
- Google (United States). The primary provider for generated answers, analyses and interview questions (Gemini models). Separately, Google is your identity provider if you choose to sign in with Google, and the source of your files if you import from Google Drive.
- OpenAI (United States). Creates the embeddings that make your knowledge searchable, and is the first fallback for generation when Google is unavailable.
- Anthropic (United States). The second fallback provider for the same generation work.
- Slack (United States). Receives the one-line new-organization notification described in section 03, in our internal workspace.
For the website, only after you accept cookies:
- Google (Google Analytics and Google Ads). Measures visits and conversions and lets us show Luna Labs ads to previous visitors. Google acts as our processor for Analytics and as its own controller for advertising.
- Meta (Meta Pixel). Measures ad results and lets us reach visitors on Facebook and Instagram. For the data the pixel collects on our site, Meta and Luna Labs are joint controllers under Meta's controller addendum; Meta is independently responsible for what it does afterwards.
- TikTok (TikTok Pixel). The same, for TikTok. For the data the pixel collects, TikTok and Luna Labs are joint controllers under TikTok's joint controller addendum.
- Formspree (United States). Receives what you type into a form on the website and forwards it to us. No consent needed; you chose to send it.
The three AI providers are used for processing only: text goes in, an answer comes back. Luna Labs never trains models on your content. We reach these providers through their business APIs, where content sent for processing is not used to train their models, and they may retain it briefly for abuse monitoring under their own terms.
If your organization connects an external source of its own (Google Drive, Microsoft SharePoint or OneDrive, Notion), data moves between Luna Labs and that provider on your instruction, under that provider's terms as well as ours. You choose what is connected and can disconnect it in the app.
The AI tools you connect through our MCP server (Claude, ChatGPT, Cursor and the like) are not our subprocessors. They are systems your organization chose, which read your knowledge because a member of your organization authorized them to. What they do with an answer is governed by their own terms.
We will tell the organization's administrators before adding a new subprocessor that handles customer content. Website cookies never handle customer content; the current list of them is kept in the Cookie Policy and in the cookie banner.
How long we keep things
- Your organization's knowledge: kept until you delete it, or until the organization's account is closed.
- Proposals and imports awaiting review: kept until they are accepted or rejected, or the account is closed.
- Account data: kept while the account is open.
- Website form submissions: kept until we have answered and the conversation is over, or until you ask us to remove yours.
- Website analytics and advertising data: Google Analytics keeps it for 14 months. Cookie lifetimes are listed in the Cookie Policy, none longer than 13 months, and we ask for your consent again after 12 months.
- Session records: kept while relevant to showing you where you are signed in, and removed with the account.
- Prompt history (extension and macOS app): 30 days. A scheduled job in our database deletes prompt-history rows 30 days after they are created. Prompts you deliberately save to your library are kept until you delete them.
- Usage events: kept while we need them to operate and improve the service. We are not going to quote a retention figure here that our systems do not actually enforce.
- Invoices and bookkeeping: kept for seven years, as Swedish law requires.
- Backups: deleted content can persist in backups for up to 30 days before it rolls off.
Who at Luna Labs can see your content
Access inside the app is enforced per organization at the database level: a member of one organization cannot read another organization's knowledge. Luna Labs staff do not get to browse your content by default. An owner or administrator in your organization can switch on time-limited support access when they want our help with something. It expires by itself after seven days and can be switched off earlier.
The honest caveat: we operate the database, so our engineers hold infrastructure-level access, exactly as the operators of any hosted service do. We use it to keep the service running, not to read your material, and we would rather write that sentence than pretend the access does not exist.
Your rights
If you are in the EU or EEA you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or hand it over in a portable format. Write to hannes@luna-labs.io and we will answer within 30 days.
Some of it you can do yourself: edit your profile, revoke a session, revoke an AI tool's access, disconnect a source, delete documents you have permission to delete, and withdraw cookie consent through the cookie settings link in the website footer. Closing an account or erasing a person entirely is done by request today, not with a button in settings.
Note that most of what you can ask us to delete belongs to your employer rather than to you. If your organization put a document into Luna Labs, we forward a deletion request about it to the organization's administrators rather than acting on it ourselves.
If you think we have handled your data badly, please tell us first. You also have the right to complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) or to the supervisory authority where you live.
Security
Traffic is encrypted in transit with TLS, and stored data is encrypted at rest by our hosting provider. Access between organizations is separated by row-level security in the database rather than by application checks alone. AI tools connect with OAuth 2.1, one authorization per person, revocable by that person or by an organization administrator. Credentials for connected Microsoft sources are encrypted with a key our database does not hold. File storage is private and only reachable through our backend.
No system is perfect. If we discover a breach affecting your personal data, we will notify the affected organizations without undue delay and, where the law requires it, the supervisory authority within 72 hours.
Children
Luna Labs is a tool for work and is not intended for anyone under 18. We do not knowingly collect data about children.
Changes to this policy
When we change this policy we update the date at the top. If a change materially affects how we handle your data, we will email the organization's administrators before it takes effect.
Contact
Email hannes@luna-labs.io for anything in this document: access requests, deletion requests, a data processing agreement, or a question you think we have not answered clearly enough here.