Skip to content
Transparent Privacy Policy • GDPR & CCPA Compliant

Privacy Policy.

Last Updated: 2026. Luno ("Luno", "Platform", "We", "Us", or "Our") is committed to protecting your privacy. This comprehensive Privacy Policy explains our collection, use, disclosure, retention, and protection of personal data in full compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA / CPRA), and international privacy standards.

Zero Data Selling

We never sell, rent, monetize, or trade your personal information with data brokers or advertising networks under CCPA/CPRA or GDPR.

Cryptographic Security

Passwords are salted and cryptographically hashed by Supabase Auth. Sessions utilize encrypted JSON Web Tokens (JWT).

1-Click Self Deletion

Full GDPR Right to Erasure & CCPA Right to Delete. Permanently purge your profile, authentication record, and account anytime.

TOTAL DATA BREACH WAIVER & LIMITATION OF LIABILITY

MANDATORY DISCLAIMER — PLEASE READ CAREFULLY:

While Luno implements industry-standard administrative, physical, and technical safeguards, no system, transmission over the Internet, or electronic database is 100% secure or immune to sophisticated cyberattacks, zero-day vulnerabilities, or breaches.

UNDER NO CIRCUMSTANCES SHALL LUNO, ITS FOUNDERS, OPERATORS, ADMINISTRATORS, DEVELOPERS, HOSTING PROVIDERS, OR AFFILIATES BE LIABLE FOR ANY DAMAGES, LOSSES, LIABILITIES, COSTS, OR CLAIMS WHATSOEVER ARISING OUT OF OR RESULTING FROM:

  • Data Breaches & Cyberattacks: Any unauthorized access, security breach, credential stuffing, scraping, interception, ransomware attack, DDoS attack, or unauthorized extraction of user data, hashed passwords, email addresses, or database records.
  • Third-Party Service Provider Breaches: Any security vulnerability, data exposure, service outage, or incident occurring at third-party infrastructure providers (including Supabase, Resend, Vercel, Cloudflare, Discord, or web hosts).
  • User Account Compromise: Any compromise resulting from weak user passwords, password reuse across multiple websites, phishing, malware, or keyloggers on the user's personal device.
  • Loss or Corruption of Data: Any accidental deletion, database corruption, server downtime, or loss of user accounts, forum posts, bookmarks, or script configurations.

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL LUNO'S TOTAL AGGREGATE LIABILITY FOR ANY DATA BREACH, PRIVACY CLAIM, OR SYSTEM FAILURE EXCEED $0.00 USD (ZERO DOLLARS).

1. Information We Collect & Process

We collect only the minimum necessary information required to operate the Luno community, authenticate user accounts, and prevent abuse:

Email Address

Provided during account registration for authentication, email verification links, and password resets via Supabase Auth. Never sold or displayed publicly.

Cryptographic Credentials

Account passwords are never stored in plaintext. Supabase Auth stores only salted and cryptographically hashed password digests.

Public Profile & Forum Content

Username, display name, biography, avatar image URL, forum threads, replies, badges, and community reputation points.

Technical & Security Telemetry

IP addresses (hashed/masked for anti-DDoS, brute-force rate-limiting, and scam prevention), User-Agent strings, and transient server access logs.

2. European Union & UK GDPR Rights

If you reside in the European Economic Area (EEA), the United Kingdom, or Switzerland, you are entitled to specific rights under the General Data Protection Regulation (Regulation (EU) 2016/679) and UK Data Protection Act 2018:

Right of Access (Art. 15)

You have the right to obtain confirmation and a copy of all personal data held about you.

Right to Rectification (Art. 16)

You can edit, update, or correct inaccurate profile details at any time in your Settings.

Right to Erasure / Forgotten (Art. 17)

Instant, self-service 1-click deletion permanently purges your account and credentials from our database.

Right to Restrict & Object (Art. 18 & 21)

You can object to processing based on legitimate interest and withdraw consent at any time.

Right to Data Portability (Art. 20)

You may request an export of your account data in a structured, commonly used format.

Legal Bases for Processing

Processing is grounded in Contractual Necessity (account features), Consent, and Legitimate Interest (anti-abuse & security).

3. California Consumer Privacy Act (CCPA & CPRA) Disclosures

This section applies exclusively to California residents under the California Consumer Privacy Act of 2018 (CCPA) and the California Privacy Rights Act of 2020 (CPRA):

  • Right to Know & Access: You have the right to request information regarding the categories and specific pieces of personal information we have collected over the preceding 12 months, the sources of collection, and the business purposes for which it is used.
  • Right to Delete: You have the right to request the permanent deletion of personal information collected from you, which you can execute instantly in your Account Settings (Danger Zone).
  • Do Not Sell or Share My Personal Information: Luno does NOT sell personal information, nor do we share personal data for cross-context behavioral advertising. We have not sold or shared personal information in the preceding 12 months.
  • Right to Non-Discrimination: We will never deny you services, charge you different prices, or provide a different quality of service for exercising any of your CCPA/CPRA rights.
  • California “Shine the Light” Law (Civil Code § 1798.83): We do not disclose personal information to third parties for direct marketing purposes.
4. What We NEVER Collect

We are strictly dedicated to user safety and digital privacy. Under no circumstances does Luno collect, inspect, or retain:

  • ✕ No game account passwords, 2FA keys, or authentication PINs.
  • ✕ No browser session cookies or authentication tickets.
  • ✕ No personal computer files, browsing history, or private chats.
  • ✕ No credit card numbers or financial banking details.
5. Third-Party Infrastructure & Subprocessors

We partner with industry-leading enterprise service providers who maintain strict data protection and compliance standards:

Supabase Inc.
Enterprise PostgreSQL hosting, Supabase Auth user management, and encrypted Storage.
Database / Auth / Storage
Resend Technologies
Delivers transactional account confirmation emails and password recovery codes.
Transactional Email
Discord Inc.
Used for community support channels and private developer crash telemetry logs.
Community & Webhooks
6. Cookies & Local Storage

Luno uses strictly necessary browser storage mechanisms to provide core functionality:

  • Authentication Tokens: Supabase Auth stores encrypted JWT session tokens in browser localStorage so you stay logged in.
  • Consent & Preferences: Local storage keys remember your acknowledgment of platform disclaimers.
  • No Ad Tracking Cookies: We do NOT place third-party advertising cookies or cross-site tracking pixels on your device.
7. Self-Service Account Deletion (Equal Friction)

In full accordance with FTC equal-friction cancellation guidelines and GDPR Art. 17:

You may permanently delete your account at any time without needing to email support. Simply navigate to your Account Settings (Danger Zone). Deletion cascades immediately through Supabase Auth, permanently erasing your authentication credentials, email record, and profile data from our live systems.

Privacy Requests & Inquiries

For GDPR/CCPA inquiries or removal requests, contact our administration on Discord.

Join discord.gg/getluno
Review our Terms of Service•Review our Community Guidelines