Lunis Privacy Policy
Effective 2026-10-08
Lunis is an AI note-taking assistant you use through a Telegram bot.
This page explains what data it stores, who processes it and where, how
long it is kept, and how you export or delete it.
What we collect
- Your Telegram user ID — the only identifier we ask for.
We do not ask for your name, e-mail, or phone number. If you pay by
card, Stripe collects your card and billing details on its own
pages; we store only its reference ids (see Payment metadata).
- Messages you send the bot — text messages and voice notes.
Voice notes are transcribed on our own server; the audio file is
deleted as soon as your note has been saved and is never stored.
- Your notes and todos — the cleaned-up content the assistant
produces from your messages, the original text or transcript it was
made from, plus tags, titles, and due dates.
- Settings — your timezone, briefing times, and AI
preferences (language, answer style).
- Usage metadata — daily AI-message counts and per-request
token and cost figures, used for quotas and cost accounting. These
records contain no message content.
- Payment metadata — if you subscribe: your plan, its expiry,
and a pseudonymous payment audit record keyed by your Telegram ID:
the payment provider's reference ids, amounts, currency, status and
billing period. Never your name, e-mail, address or card number —
Stripe and Telegram hold those under their own policies.
- Acquisition tag — if you reached the bot through a link
that carried one, the tag in that link (for example which page or
post you came from). It is used only to see which channels bring
people to Lunis.
- Server logs — request paths, status codes, timings, error
types and Telegram IDs, kept for operations and debugging — never
message text, never the query part of a web request. Logs are
rotated and deleted within 30 days.
- Dashboard session cookie — if you open the web dashboard, a
signed cookie (
lunis_dash) keeps you signed in for 30
days; it holds your Telegram ID and an expiry time, nothing else,
and Sign out clears it. The operator's admin page uses a
similar cookie (lunis_admin, 24 hours). Both are
strictly necessary; there are no tracking or advertising cookies.
- Feedback messages — feedback is sent only through the web
form at /feedback (the bot's
/feedback command just opens it; text typed after the
command in chat is not forwarded anywhere). It is not saved as a note
and is not stored in the database. The form is open to anyone:
the topic, your message, and any contact details you choose to type
(name, reply e-mail, Telegram username) are e-mailed to the
operator's mailbox at support@hilunis.com — so they pass through that
mailbox's e-mail provider — or, if e-mail is unavailable, delivered
as a Telegram message to the operator. Nothing from the form is
stored by Lunis. Your IP address is held in memory only briefly to
limit abuse, and is never logged or forwarded.
- Operator notices — when you first message the bot and when
you subscribe, the operator receives an e-mail containing your
Telegram ID, the acquisition tag and the payment route — never any
content — so sign-ups and subscriptions can be counted.
Who processes your data, and where
- Anthropic (United States) — your messages, and — when you
ask a question or receive a briefing — the stored notes and todos
the assistant looks up for it, are sent to the Anthropic API to
clean up notes, answer questions, and write briefings. When you
ask a general question, the assistant may also run a web search
through Anthropic's search tool; it is instructed to put no more of
your note content into a search query than the question strictly
needs. Anthropic does not use API data to train its models by
default.
- Telegram — carries every message between you and the bot,
and handles Telegram Stars payments under its own privacy policy.
- Stripe (United States) — processes card payments if you
choose that route and holds your billing details under its own
privacy policy.
- Our hosting provider — the server and database run on a
virtual private server at Hetzner Online GmbH, Germany.
- The mailbox provider behind support@hilunis.com — receives
feedback-form messages and the operator notices described above.
International transfers. Lunis is operated from Singapore.
Anthropic and Stripe process data in the United States, and the hosting
provider in the country named above; each does so under its own
data-processing terms and safeguards, which we have accepted. By using
Lunis you consent to these transfers. If you are in the EU or UK, the
providers' standard data-processing terms cover them.
We do not sell your data, share it with advertisers, or use it to
train AI models.
How long we keep it
- Notes and todos — until you delete them. Deleted items go to
your trash and are purged for good after 30 days (or immediately
with
/trash empty).
- Your account — until you delete it (see below). Deleting
your account removes all notes, todos (including trash), usage
history, and settings immediately, and asks Stripe to delete your
customer record. Pseudonymous billing records — provider reference
ids, amounts and dates, no name and no content — are kept for
five years for accounting and dispute handling, with your Telegram
ID removed from them at deletion; AI-usage figures are likewise kept
without any link to you. Cancelling or letting a Pro subscription
lapse never deletes anything: your notes and todos stay, and the
account simply continues on the Free plan until you delete it.
- Inactive accounts — if you have not messaged the bot or
opened the dashboard for 365 days, we send you a warning in
Telegram and delete the account, with everything in it, 30 days
later unless you send any message first. Any message resets the
clock. This never applies while you have an active Pro
subscription.
- Backups — encrypted database backups (encrypted before they
are written, with the key held off the server) are kept for up to
30 days and then destroyed; deleted data may persist in a backup
until that window lapses.
- Server logs — deleted within 30 days.
Your rights
- Export — send
/export to the bot at any time to
download all of your notes and todos as a JSON file.
- Delete — send
/deleteaccount to the bot to
permanently erase your account and all its data. The bot asks you
to confirm twice; the deletion is immediate and irreversible.
- Access and correction — e-mail us for a copy of anything we
hold about you beyond the export (settings, usage and billing
records), or to have it corrected. We answer within 30 days.
- Complain — if you are unhappy with how we handle your data,
you can complain to Singapore's Personal Data Protection Commission
(PDPC) or, if you are in the EU or UK, to your local
data-protection authority.
Children
Lunis is not directed at children. You must be at least 16 to use it
(see the Terms). We do not knowingly keep an
account for anyone younger — e-mail us and we will delete it.
Security and breaches
Data travels over TLS, backups are encrypted at rest, and the server
accepts key-based logins only. If a data breach is likely to cause you
significant harm, we will notify you, and the PDPC within three days of
establishing it (and, where EU or UK law applies, the relevant authority
within 72 hours). We disclose data to authorities only when legally
compelled, and tell you unless the law forbids it.
Contact
Lunis is operated by Lunis (sole proprietor, Singapore), who is the data
controller for everything described on this page and its designated
data protection officer.
For privacy requests — access, correction, deletion, or questions about
this policy — e-mail
support@hilunis.com, use the
feedback form, or send
/feedback to the bot, which opens that form. E-mail and the
form work even after you have deleted your account.
We may update this policy as Lunis changes; the effective
date above always reflects the current version, and material changes are
announced in the bot before they take effect.