This Privacy Policy explains how Lunary Inc. ("Lunary Cloud", "we", "us", or "our"), a corporation incorporated under the Canada Business Corporations Act, collects, uses, discloses, and protects personal information when you visit lunary.cloud, join our waitlist, contact us, or use the Lunary Cloud service (together, the "Services"). We follow the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where it applies to you, Quebec's Act respecting the protection of personal information in the private sector (Law 25).
1. Who Is Responsible
Lunary Inc. is accountable for the personal information under its control. Our Privacy Officer can be reached at legal@lunary.cloud or by mail at 174 Spadina Ave, Unit 507, Toronto, Ontario M5T 2C2, Canada. Direct access requests, corrections, complaints, and questions about this policy there.
2. Two Kinds of Data
We handle two very different things, and this policy treats them differently:
- Your account and business data: what we collect about you as our customer or visitor. Contact details, sign-in identity, billing records, support correspondence, dashboard activity, and server logs. We are the organization responsible for this information; Sections 3 to 9 are about it.
- Content inside the applications we host for you: the databases, files, workflows, and records your team puts into any application we host for you. That content is yours. We store it, back it up, and operate the servers it lives on; we do not read it, analyze it, or use it for our own purposes, and we access it only to operate the service, to help you when you ask, or as the law requires. You are responsible for the personal information you choose to put in those applications, including any consents your own use requires. Section 10 covers how we handle it.
3. Information We Collect
Information you provide
- Contact and inquiry submissions: your name, email address, and a description of what you are looking for, all of which the form requires, plus your company name if you give it.
- Waitlist signups: email address, and optionally your name, company name, and a description of the tools your team pays for today. We use this to contact you about hosting and to decide which applications to support next.
- Account information: when you sign in to the customer dashboard we receive your name, email address, and organization membership from our identity provider (WorkOS). We do not store your password; sign-in is handled by WorkOS.
- Billing information: our payment processor (Stripe) collects and stores your payment card and billing address. We never see or store full card numbers. We keep the records Stripe returns to us: the last four digits and expiry of the card on file, invoice and payment status, plan, and billing email.
- Support and service correspondence: what you send to hello@lunary.cloud or legal@lunary.cloud, and our replies.
Information collected automatically
- Server and access logs: IP address, user agent, request timestamps, and the pages or API endpoints requested, for security, abuse prevention, and operations.
- Dashboard and API activity: an append-only log of API calls that change your instances (deploy, teardown, plug and routine changes) and of API-token, team, and network exposure changes made in the dashboard, each with the time and outcome. Dashboard entries name the person who acted; API and MCP entries name the API token used. The log cannot be altered or deleted.
- Instance health and metrics: whether your hosted applications are running, their resource use, backup results, and similar operational telemetry about the servers we run for you. This is about the infrastructure, not the content inside your applications.
- Cookies: a small number of strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. We do not use advertising or third-party tracking cookies.
4. How We Use Information
- To provide, operate, secure, support, and bill the Services.
- To respond to you and to tell you about service events that affect you, such as an instance going live, a payment failing, or a renewal coming up.
- To investigate and prevent abuse, fraud, and security incidents.
- To comply with the law and to establish, exercise, or defend legal claims.
- To improve the Services, using aggregated or de-identified information where we can.
We do not sell personal information, and we do not share it with anyone for their own marketing. If we are ever party to a merger, financing, or sale of the business, personal information may be disclosed to the other party, under an agreement that limits them to using it for that transaction, requires them to protect it, and requires them to return or destroy it if the transaction does not proceed. If a transaction completes, we will tell you. The email our platform sends today is transactional and service email: invoices and payment notices, renewal and card-expiry reminders, notice that your environment or an instance's address is live, confirmation and updates for a waitlist you asked to join, and replies to what you send us. We do not send newsletters or marketing email. If we ever send commercial electronic messages we will do so only with the consent Canada's Anti-Spam Legislation (CASL) requires; every such message will identify us, give our mailing address and a way to reach us, and carry a working unsubscribe. Those contact details and that unsubscribe stay valid for at least 60 days after the message is sent, and we will honour an unsubscribe within 10 business days.
5. Who We Share It With (Sub-processors)
We use a small number of service providers to run Lunary Cloud. Each receives only what its job needs, under contractual confidentiality and security obligations. We keep this table current when the platform's configuration changes; a test fails if it names a provider the configuration does not use.
| Provider | Purpose | Location | What it handles |
|---|---|---|---|
| FullHost (Pretecs Networks Inc.) | Virtual machines and object storage that run and back up your hosted applications | Canada | Your hosted applications and their backups |
| Stripe, Inc. | Payments, invoicing, and the billing portal | United States | Billing contact, payment card, invoices |
| WorkOS, Inc. | Sign-in and organization membership for the dashboard | United States | Name, email, organization, sign-in events |
| Amazon Web Services (SES), via Resend | Delivering the email we send you | United States | Recipient address and the message |
| Cloudflare, Inc. | Publishing our public DNS records only | Global anycast | Hostname-to-address records; no customer traffic or content passes through it |
| Tailscale Inc. | Coordinating the private management network between our control plane and your servers | United States / Canada | Device identity and connection metadata; the traffic itself is encrypted end to end between our own machines |
| GitHub, Inc. | Source control and the automation that deploys our infrastructure | United States | Our code and deployment credentials, your service configuration, and your application secrets as ciphertext; no hosted application content |
| Fastmail Pty Ltd | Our own email inboxes | United States / Australia | Correspondence you send us |
6. Where It Is Stored
All customer workloads, hosted application content, and backups run on Canadian-owned infrastructure in Canadian data centres. Public DNS records are published via a global anycast network with Canadian points of presence; no customer traffic passes through it. Some account, billing, and email information is processed in the United States by the providers listed above, which means it may be accessible to authorities there under United States law. If you are in Quebec, Law 25 requires us, before personal information is communicated outside the province or held there on our behalf, to assess its sensitivity, the purposes it will be used for, the protection measures that will apply to it including contractual ones, and the law of the place it is going, and to proceed only under a written agreement. We carry out that assessment before we add or change a provider in the table above.
7. How Long We Keep It
- Account and billing records: for the life of your account and for at least 6 years after the end of the tax year they relate to, the floor Canadian tax law sets for financial records. We keep them longer where the law requires it, for example while a tax objection or appeal is unresolved.
- Inquiry and waitlist submissions: up to 24 months after our last contact, or until you ask us to remove you. Reply to any of our emails or write to hello@lunary.cloud.
- Server and access logs and instance metrics: our central log and metrics stores, and the per-server HTTP access logs that record IP address, user agent, URL, and time, all keep 30 days. They are kept longer only if needed to investigate a specific incident.
- Audit trail of dashboard and API actions: for the life of your account, because it is the record of who did what to your instances.
- Your hosted content and backups: governed by Section 10 and by the Terms of Service.
8. How We Protect It
Access to our control plane is limited to named staff over an authenticated private network. Credentials we generate for your applications and any deploy secrets you give us are stored encrypted (AES-256-GCM) in our control-plane database; the running copy on your server is a file readable only by the service account. All traffic to lunary.cloud and to your hosted applications is served over HTTPS. Each customer's applications run on a virtual server used only by that customer; we do not place two customers' applications on the same server. No method of storage or transmission is perfectly secure, and we cannot promise absolute security.
If a breach happens. If we learn of a breach of security safeguards involving your personal information that creates a real risk of significant harm, we will notify your account's primary contact and its billing contact by email without undue delay, and our target is within 72 hours of confirming it, with what we know, what we are doing, and what you can do. This is carried out by our staff, not by the platform. We will report to the Office of the Privacy Commissioner of Canada as PIPEDA requires and keep the records it requires.
9. Your Rights
You may ask what personal information we hold about you, ask us to correct it, withdraw consent to uses that depend on consent, and ask us to delete it where we are not required to keep it. Withdrawing consent to the processing your account depends on means we can no longer operate the Services for you, so we would treat it as a request to close the account. If you are in Quebec you may also ask us for the account information you gave us in a structured, commonly used technological format, and we will provide it unless doing so raises serious practical difficulties. Write to legal@lunary.cloud; we respond within 30 days as PIPEDA provides, and we will tell you if we need longer and why. If you are not satisfied with our response you may complain to the Office of the Privacy Commissioner of Canada or, in Quebec, to the Commission d'accès à l'information.
10. Content Inside Your Hosted Applications
For the content your team puts into the applications we host, you decide what is collected and why, and we act on your instructions. In practice:
- Every application with a database is given a daily database backup when it is created, stored off the server it came from. You can change or turn off that schedule, and snapshot file volumes on a schedule you set; the dashboard shows what is scheduled and when it last succeeded. Backups can be downloaded at any time from the dashboard or the API.
- We do not read, mine, or use it for any purpose of our own. Our staff access it only to operate the service, to help you when you ask, or where the law requires. Changes our staff make from our console, their downloads of your backups, and their access to your gated applications are all written to your audit log, and logins to your server are recorded in system logs. We cannot record what someone does inside your application once they are signed into it as one of your users.
- When you delete an application, its data and backups are kept for at least 30 days so you can restore it under the same name or download them, unless you chose to purge its data when deleting it. After that window they are deleted automatically. If you ask us to close your account we do the same for every application on it. Backups above your plan's retention allowance are deleted on a rolling basis before that.
- If we receive a legal demand for it, our practice is to notify your billing contact before we respond unless the demand or the law forbids notice; this is handled by a person, not by the platform, and we keep a written record of each request we act on.
This Section and Section 4 of the Terms are our processor commitments, and they already form part of your agreement with us. If your own compliance work needs them addressed in a signed document, write to legal@lunary.cloud.
11. Children
The Services are for businesses and are not directed to anyone under 18. We do not knowingly collect personal information from children.
12. Changes to This Policy
When we change this policy we update the effective date above. For material changes we also email the billing contact on your account at least 30 days before they take effect.
13. Contact
Lunary Inc.
Attn: Privacy Officer
174 Spadina Ave, Unit 507, Toronto, Ontario M5T 2C2, Canada
legal@lunary.cloud
Questions? Email legal@lunary.cloud.