Lunara works without an account, without ads, and without sending your cycle data anywhere. The app does not request the Android internet permission, so it has no general-purpose way to send data off your device at all. Below is exactly what the small number of connected features do — and don't do.
Period dates, flow, symptoms, mood, energy/sleep/stress/pain ratings, notes, birth-control schedule, temperature and cervical-mucus readings, ovulation-test results, pregnancy/postpartum/ perimenopause tracking, visit-prep questions, and app settings are stored in a local database on your device only. We never receive this data — there is no server, no account, and no analytics or crash-reporting SDK in the app.
| Permission | Why | Notes |
|---|---|---|
| Notifications | Local reminders: predicted period, daily check-in, pill/ring/patch/shot reminders, PMS heads-up (Pro) | Only requested if you turn on a reminder. Generated entirely on-device. |
| Health Connect (read/write menstruation data) | Share period/flow data with other health apps you choose, and pull their data in | On-device only, over inter-process communication — no network connection. You control access in Health Connect's own settings and can revoke it anytime. |
| Biometric | Optional app lock so cycle data stays private on a shared device | Handled by Android; Lunara only receives a yes/no unlock result, never your biometric data. |
Lunara does not request the Internet or network-state permissions — they are explicitly removed from the app, including from any library that might otherwise add them.
These are the only ways any Lunara data can reach somewhere other than your device's own storage. Every one is a choice you make.
Changes the app's icon, name, and notification wording on your home screen. It's a display choice made on your device — it does not change what is stored or send anything anywhere new.
Lunara is not directed at children and does not knowingly collect information from children — in part because it does not collect information from anyone.
Delete data anytime from within the app, delete a backup file from wherever you saved it, revoke Health Connect access in its own settings, revoke notification permission in Android Settings, or uninstall the app to remove its local database entirely.
If a future version changes how data is handled — for example, an optional cloud-sync feature is scaffolded but not enabled in this release — this policy will be updated before that version ships.