Privacy Policy.
Last Updated: 2026. Luno ("Luno", "Platform", "We", "Us", or "Our") is committed to protecting your privacy. This comprehensive Privacy Policy explains our collection, use, disclosure, retention, and protection of personal data in full compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA / CPRA), and international privacy standards.
We never sell, rent, monetize, or trade your personal information with data brokers or advertising networks under CCPA/CPRA or GDPR.
Passwords are salted and cryptographically hashed by Supabase Auth. Sessions utilize encrypted JSON Web Tokens (JWT).
Full GDPR Right to Erasure & CCPA Right to Delete. Permanently purge your profile, authentication record, and account anytime.
MANDATORY DISCLAIMER — PLEASE READ CAREFULLY:
While Luno implements industry-standard administrative, physical, and technical safeguards, no system, transmission over the Internet, or electronic database is 100% secure or immune to sophisticated cyberattacks, zero-day vulnerabilities, or breaches.
UNDER NO CIRCUMSTANCES SHALL LUNO, ITS FOUNDERS, OPERATORS, ADMINISTRATORS, DEVELOPERS, HOSTING PROVIDERS, OR AFFILIATES BE LIABLE FOR ANY DAMAGES, LOSSES, LIABILITIES, COSTS, OR CLAIMS WHATSOEVER ARISING OUT OF OR RESULTING FROM:
- Data Breaches & Cyberattacks: Any unauthorized access, security breach, credential stuffing, scraping, interception, ransomware attack, DDoS attack, or unauthorized extraction of user data, hashed passwords, email addresses, or database records.
- Third-Party Service Provider Breaches: Any security vulnerability, data exposure, service outage, or incident occurring at third-party infrastructure providers (including Supabase, Resend, Vercel, Cloudflare, Discord, or web hosts).
- User Account Compromise: Any compromise resulting from weak user passwords, password reuse across multiple websites, phishing, malware, or keyloggers on the user's personal device.
- Loss or Corruption of Data: Any accidental deletion, database corruption, server downtime, or loss of user accounts, forum posts, bookmarks, or script configurations.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL LUNO'S TOTAL AGGREGATE LIABILITY FOR ANY DATA BREACH, PRIVACY CLAIM, OR SYSTEM FAILURE EXCEED $0.00 USD (ZERO DOLLARS).
We collect only the minimum necessary information required to operate the Luno community, authenticate user accounts, and prevent abuse:
Provided during account registration for authentication, email verification links, and password resets via Supabase Auth. Never sold or displayed publicly.
Account passwords are never stored in plaintext. Supabase Auth stores only salted and cryptographically hashed password digests.
Username, display name, biography, avatar image URL, forum threads, replies, badges, and community reputation points.
IP addresses (hashed/masked for anti-DDoS, brute-force rate-limiting, and scam prevention), User-Agent strings, and transient server access logs.
If you reside in the European Economic Area (EEA), the United Kingdom, or Switzerland, you are entitled to specific rights under the General Data Protection Regulation (Regulation (EU) 2016/679) and UK Data Protection Act 2018:
You have the right to obtain confirmation and a copy of all personal data held about you.
You can edit, update, or correct inaccurate profile details at any time in your Settings.
Instant, self-service 1-click deletion permanently purges your account and credentials from our database.
You can object to processing based on legitimate interest and withdraw consent at any time.
You may request an export of your account data in a structured, commonly used format.
Processing is grounded in Contractual Necessity (account features), Consent, and Legitimate Interest (anti-abuse & security).
This section applies exclusively to California residents under the California Consumer Privacy Act of 2018 (CCPA) and the California Privacy Rights Act of 2020 (CPRA):
- Right to Know & Access: You have the right to request information regarding the categories and specific pieces of personal information we have collected over the preceding 12 months, the sources of collection, and the business purposes for which it is used.
- Right to Delete: You have the right to request the permanent deletion of personal information collected from you, which you can execute instantly in your Account Settings (Danger Zone).
- Do Not Sell or Share My Personal Information: Luno does NOT sell personal information, nor do we share personal data for cross-context behavioral advertising. We have not sold or shared personal information in the preceding 12 months.
- Right to Non-Discrimination: We will never deny you services, charge you different prices, or provide a different quality of service for exercising any of your CCPA/CPRA rights.
- California “Shine the Light” Law (Civil Code § 1798.83): We do not disclose personal information to third parties for direct marketing purposes.
We are strictly dedicated to user safety and digital privacy. Under no circumstances does Luno collect, inspect, or retain:
- ✕ No game account passwords, 2FA keys, or authentication PINs.
- ✕ No browser session cookies or authentication tickets.
- ✕ No personal computer files, browsing history, or private chats.
- ✕ No credit card numbers or financial banking details.
We partner with industry-leading enterprise service providers who maintain strict data protection and compliance standards:
Luno uses strictly necessary browser storage mechanisms to provide core functionality:
- Authentication Tokens: Supabase Auth stores encrypted JWT session tokens in browser
localStorageso you stay logged in. - Consent & Preferences: Local storage keys remember your acknowledgment of platform disclaimers.
- No Ad Tracking Cookies: We do NOT place third-party advertising cookies or cross-site tracking pixels on your device.
In full accordance with FTC equal-friction cancellation guidelines and GDPR Art. 17:
You may permanently delete your account at any time without needing to email support. Simply navigate to your Account Settings (Danger Zone). Deletion cascades immediately through Supabase Auth, permanently erasing your authentication credentials, email record, and profile data from our live systems.
Privacy Requests & Inquiries
For GDPR/CCPA inquiries or removal requests, contact our administration on Discord.