Privacy Policy
This Privacy Policy explains how FemoraAI (“we”, “us”) collects, uses, and protects your information when you use Luna, a proactive AI assistant. We built Luna on one rule: nothing moves without you. Your privacy follows the same principle.
1. Information we collect
- Account information — your name, email, and authentication details when you sign up.
- Connected data — content from services you choose to connect (such as email and calendar), accessed only with your authorization to provide Luna’s features.
- Usage data — how you interact with Luna, used to operate and improve the service.
- Billing data — handled by our payment processors; we do not store full card numbers.
2. How we use your information
- To provide Luna: surface what matters, and take actions you approve.
- To maintain memory and context that make Luna more useful to you over time.
- To secure, operate, debug, and improve the service.
- To communicate with you about your account and important updates.
3. What we do not do
We do not sell your personal data. We do not use the content of your connected accounts to train third-party foundation models. Luna acts on the outside world only with your approval or within routines you explicitly enable.
4. How we share
We share data only with service providers that help us run Luna (for example, cloud hosting, AI model providers that process requests, and payment processors), under contracts that require them to protect it. We may disclose information if required by law or to protect users and the service.
5. Google user data and Limited Use
If you connect a Google account, Luna requests only the narrowest permissions its features need. We request exactly these scopes, and nothing else:
- Gmail (gmail.modify) — to read the messages you ask Luna about, prepare draft replies you review before anything is sent, and organise your inbox by applying or removing labels and archiving. Luna never sends email on its own; a draft becomes a sent message only when you send it.
- Google Calendar (calendar.events) — to read events on your primary calendar so Luna can brief you and protect your time, and to create, update, or cancel events at your request. This permission does not give Luna access to your calendar sharing settings or other people's calendars.
- Your calendar list (calendar.calendarlist.readonly) — to see which calendars you are subscribed to, so Luna knows which ones should count as “busy” when it schedules and can tell you which calendar an event came from. It reads the list only, never the contents of those calendars.
- Availability (calendar.events.freebusy) — to check whether someone you are scheduling with is free before Luna proposes a time. This returns only busy time intervals — no titles, attendees, or details of anyone's meetings.
- Workspace groups (cloud-identity.groups.readonly) — if you are on Google Workspace, to see which groups you belong to, so Luna can tell colleagues apart from outside contacts and resolve requests like “schedule this with the design team”. Read-only: Luna cannot create, change, or delete any group or membership, and reads only your own memberships.
- Sign-in (openid, email, profile) — to identify your account and show your name and picture in the app.
Luna's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the features described above, which you can see in the product.
- We do not transfer Google user data to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition.
- We do not use Google user data for advertising, and we do not sell it.
- We do not use Google Workspace APIs data to develop, improve, or train generalised artificial intelligence or machine learning models. Content is sent to AI model providers only to generate your response in the moment, under contracts that prohibit them from training on it.
- We allow humans to read Google user data only with your explicit consent, to resolve a specific support issue you raise, where required by law, or on aggregated anonymised data for security and operations.
You can disconnect Google from Luna's settings at any time, and you can revoke Luna's access directly from your Google Account permissions page. When you disconnect, we stop accessing your Google data and delete the stored tokens and cached content derived from it.
6. AI processing
To answer you and take actions, Luna sends relevant context to AI model providers that process it on our behalf to generate a response. We minimize what is sent and scope every request to your account. As stated above, this content is never used to train generalised models.
7. Data retention
We keep your information for as long as your account is active or as needed to provide the service. You can delete your data or account at any time; we remove it except where we must retain limited records for legal or security reasons.
8. Security
We use encryption in transit, scoped access controls, and per-user data isolation so your information is only ever accessed on your behalf. No system is perfectly secure, but protecting your data is core to how Luna is built.
9. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to withdraw consent for connected services (disconnect them anytime). To exercise these rights, email info@femoraai.com.
10. Changes
We may update this policy as Luna evolves. If changes are material, we will let you know. Continued use after an update means you accept the revised policy.
11. Contact
Questions about your privacy? Email info@femoraai.com.