Security at Lunarmates

Minimum data — No AI processing — No selling

Your personal data security is our top priority. We understand that cycle data is highly intimate health information — and we treat it accordingly. This page explains how we protect your data technically, legally, and organisationally.

If you believe you have found a security vulnerability, please report it responsibly to [email protected].


Legal compliance

Lunarmates is committed to ensuring the security and protection of personal data in accordance with the EU General Data Protection Regulation (GDPR), the Danish Data Protection Act, and all applicable data protection law. Our lead supervisory authority is Datatilsynet (datatilsynet.dk).


Infrastructure and hosting

Lunarmates runs on a dedicated server hosted by Hetzner Online GmbH, located in Helsinki, Finland — within the European Union. Hetzner is an EU-based company operating under EU law and GDPR. All data at rest remains within the EU at all times.

We do not use cloud infrastructure from US-based hyperscalers such as AWS, Google Cloud, or Azure for our application or database. Your data does not leave the EU: our application and database run exclusively on Hetzner's server in Helsinki, Finland. This applies to data at rest. Cloudflare, our CDN and reverse proxy provider, sits in front of this server and may process traffic in transit through its global network — see Third-party providers below for details.


Encryption

All data in transit between your device and our server is encrypted using TLS (Transport Layer Security). HTTPS is enforced for all connections — unencrypted HTTP is not permitted.

All data at rest on our server is encrypted. Passwords are hashed using bcrypt and are never stored in plain text. We do not store payment card data — we do not currently offer paid subscriptions.


Application security

Lunarmates is built on Ruby on Rails 8, which follows strict security defaults including:

  • CSRF (Cross-Site Request Forgery) protection on all forms
  • Secure, HttpOnly, SameSite session cookies
  • Parameterised database queries preventing SQL injection
  • Content Security Policy headers
  • Automatic security patch tracking via Rails security advisories

We apply security patches promptly and follow Rails security best practices as a matter of routine.


Data minimisation as a security principle

The most secure data is data that was never collected. Lunarmates is deliberately designed to collect the minimum necessary to provide the service:

  • We collect one intimate health data point from women: the period start date. Nothing more.
  • We do not collect names, phone numbers, precise location, symptoms, mood, sexual activity, or pregnancy intentions.
  • Men's personal notes are private by default and never shared without the user's explicit action.
  • Server access logs are retained for a maximum of 30 days and then automatically purged.
  • We do not use any third-party crash-reporting or analytics SDK in the Android app. Our backend maintains a small number of first-party error log entries — six log statements across the codebase, as of this writing — that record only internal record identifiers and the technical exception type. They never include health data, account credentials, or message content.

Collecting less means there is less to protect — and less that could be exposed.


No AI. By design.

Lunarmates does not use artificial intelligence, machine learning models, or large language models to process your data, generate relationship advice or suggestions, or provide any form of health guidance.

This is a deliberate design choice, not a technical limitation.

AI models — including the most capable ones available today — are known to hallucinate: to generate confident-sounding outputs that are factually incorrect. Applying such models to intimate health data, or to something as nuanced as a relationship between two people, carries real risks of harm. We believe this would be both unethical and unwise.

We also hold a deeper conviction: women are not a dataset to be modelled. The complexity, mystery, and individuality of a woman's experience cannot and should not be reduced to an AI output. Lunarmates exists to help men pay closer attention — not to replace that attention with an algorithm.

Cycle phase forecasts on Lunarmates are generated by straightforward statistical calculation from period start dates you log. No AI is involved at any stage.


Third-party providers

We use a small number of trusted third-party providers, each chosen for their EU compliance and minimal data exposure:

Hetzner Online GmbH — server hosting, Helsinki, Finland. EU-based, GDPR-compliant. Hetzner has access to the physical server but not to application data.

Brevo (Sendinblue SAS) — transactional email and push notification delivery, Paris, France. EU-based, GDPR-compliant. Brevo processes email addresses and push tokens only — no health data.

Browser push services — push notifications are delivered via your browser's built-in infrastructure (Google FCM for Chrome, Mozilla's push service for Firefox, Apple APNs for Safari). We send only notification text — no health data is included in any push payload.

Cloudflare, Inc. — CDN, reverse proxy, and Web Analytics, United States-headquartered. Cloudflare sits in front of our Hetzner server and secures and accelerates traffic to lunarmates.com; as part of its global network it may process traffic in transit at data centers outside the EU. Standard Contractual Clauses under Cloudflare's Data Processing Agreement cover this. Cloudflare does not have access to application data or your health data.

Google OAuth — if you choose to sign in with Google, your email address is received from Google to authenticate your account. No health data is shared with Google. This is optional — you may also register with an email address and password.

We use Cloudflare Web Analytics, a first-party, cookie-free analytics tool that measures aggregate traffic (visits, page views, load time) without tracking individuals across sites. We do not use Google Analytics, Facebook Pixel, advertising trackers, or any cross-site or third-party ad-tech analytics service.


Access controls

Access to production data is strictly limited to authorised personnel only. We operate on a principle of least privilege — no one has access to data beyond what is necessary for their role.


Incident response and breach notification

In the event of a personal data breach, we will:

  • Notify Datatilsynet within 72 hours of becoming aware of the breach, in accordance with GDPR Art. 33
  • Notify affected users without undue delay where the breach poses a high risk to their rights and freedoms, in accordance with GDPR Art. 34
  • Document all incidents internally in accordance with our records of processing obligations under GDPR Art. 30

Responsible vulnerability disclosure

If you discover a security vulnerability in Lunarmates, we ask that you report it to us responsibly before disclosing it publicly. Please email [email protected] with:

  • A description of the vulnerability
  • Steps to reproduce it
  • The potential impact

We will acknowledge your report within 5 business days and work to resolve confirmed vulnerabilities promptly. We will not take legal action against researchers who act in good faith and follow this process.


Contact

For security questions, vulnerability reports, or concerns:

[email protected]

For data protection and privacy questions:

[email protected]

Mattrix ApS Bymidten 65, 1tv 3500 Værløse Denmark