WooMoon Health Data Consent

Consent to processing of health and intimate-life data

Last updated: 2026-09-03  ·  Русская версия

This is a separate consent covering special categories of personal data — health data and data about your sex life. It is not buried in the terms of service and it is not implied: without an explicit action from you, we do not process this data.

The short version

1. What this consent covers

CategorySpecifically
Cycle cycle start date, cycle length, menstruation duration, cycle markers and events, delays, the tracker pause (its moment and whether you set it yourself from the delay check-in), cycle history and the derived analytics you see in the app
Apple Health (iPhone) menstrual flow, sleep, heart rate variability, resting heart rate, wrist temperature during sleep, cycle symptoms
Intimate life the intimacy markers you tap in the calendar
Oracle conversation what you write about your body, your state and your feelings. You write it yourself, and that is the service — but in law it is health data too

The list above is what the app reads from Apple Health. It will be identical in the system permission prompt, the Privacy Policy and here — once the iOS build that requests permission for all six types ships.

On the consent screen before the Oracle the list is a different, shorter one: five signals, without menstrual flow — sleep, heart rate variability, resting heart rate, wrist temperature during sleep, cycle symptoms. The difference is deliberate, not editorial. That checkbox governs one thing: whether a signal travels together with your message to the Oracle. Those five are computed on the phone itself and are not stored by us, so switching them off means nothing travels at all. Menstrual flow takes a separate route: it syncs with the calendar and is stored on our server as a cycle event — the tracker itself is built from it, and an unchecked box would not remove it from there. Promising that kind of control through the checkbox would be untrue, so it is not offered there; the real levers are named in section 7 — read access is revoked in the iPhone's settings, and stored cycle events are removed when you delete your data.

About the tracker pause — and what we do not ask. When the tracker is paused, we record the moment of the pause and, if you paused it yourself from the delay check-in (the message about a delay that carries a "pause the tracker" button), that fact too: a pause you chose and a pause the automation sets on its own after 180 days without a mark must not be confused. Why there is no cycle we neither ask nor store — not pregnancy, not menopause, not treatment. The origin of the pause is derived from the delay you had already marked and is covered by this consent together with the rest of your cycle data. The question we ask after you cancel a subscription is outside this consent: none of its options says anything about your body — see section 2.2 of the Privacy Policy.

2. Why we process it

And nothing else. None of these categories is used for advertising, marketing, profiling, or behavioural analysis in anyone's commercial interest.

3. Who this data is shared with

We name the recipient plainly rather than calling it a "technology partner".

Google (Gemini) — the language model that writes the texts. It receives:

The full list, and what Google does with what it receives, is in sections 5 and 7 of the Privacy Policy. In short: under the paid-tier terms Google does not use this data to improve its products, but it logs it for a limited period to detect abuse and may cache it in any country where it has facilities. This is a cross-border transfer, and consent to it is asked for separately.

Where this data does not go: nothing listed in section 1 is sent to advertising or analytics services (AppsFlyer, Google Analytics, Meta, Google Ads).

What is recorded about the consent itself. Every tap — grant and withdrawal alike — is stored as its own row: the consent scope, the action, the version of the text you saw, the surface, the language, the time, and your IP address. The IP is part of the evidence that it was you who consented, and when. That row outlives account deletion, but on deletion both the account number and the IP are scrubbed from it: what remains is "someone consented to scope X of version Y at time T".

Rows come from wherever the consent screen has already been turned on — section 6. And plainly, about what does not reach that journal: "the screen was shown" and "she closed it without accepting" are neither consent nor its refusal, they are never written there, and they do not affect your access. But they do not vanish either: we record them as an ordinary product analytics row tied to your account, like other events in the app, so we can see whether the screen reads clearly. Not one of your ticks and not one of your words is in that row: only which areas the screen displayed, and which version of the text. It is erased along with your account.

4. Where this data is stored

One caveat, without which the line above would read wider than it is: every message passes through our server — it assembles the context, calls the model and returns the reply. In that moment the server sees and processes the text; it does not save it. "On your device only" is about storage. The fact that a message was sent (when, from which surface, never its text) we do record in our event log.

5. This is voluntary

Consent is split into parts, and they are not equal.

Without this there is no conversation. For the Oracle to answer, your message has to reach the model and come back as a reply — and it has to leave the country to do so. That is not "access to your data", that is the service itself. Declining here means "I do not want to use the Oracle"; everything else — cycle, calendar, moon, recommendations — keeps working as before.

What is optional — and it is exactly three layers, no more. Cycle data in the conversation's context, Apple Health signals, intimacy markers. The Oracle works without each of these three — it will simply know less about you. Declining any of them locks neither the feature you paid for nor anything else.

What that choice does not cover. Alongside your message, the model also receives what has no switch of its own: your name, city, age in years and the derived natal-chart values. Today you cannot decline those separately and keep using the Oracle. The full contents of the transfer are in section 5 of the Privacy Policy.

No consent box is pre-ticked. There is no "accept all" button.

6. How consent is given

Consent is given by a distinct affirmative action: before your first conversation with the Lunar Oracle a separate screen rises, where the required and optional parts are separated and listed by name. No box is pre-ticked. We record what you ticked, when, and which version of the text you saw.

Where that screen already exists. In the web app — it arrives with this revision, but for the first few days it does not rise yet: some browsers still hold an older version of the app that does not contain it at all, and turning it on immediately would close the Oracle in front of someone with no way to answer. Through that period the Oracle works exactly as it did yesterday. We turn the screen on once the new version has spread — and from that moment no "I accept" means no conversation; there is no in-between state of "shown but lets you through". In the iPhone app the screen is not there yet — it arrives with the next build through the App Store.

About registration, separately and honestly. Dedicated consent checkboxes at registration are shown only in the English-language versions: the Telegram bot, the web app and the iPhone app. The Russian-language surfaces have no such step at all — and we will not invoke a consent that was never given: until the consent screen ships, the basis for that audience is this document and the fact that she came to the Oracle and paid for it herself.

7. Withdrawal

In the web app, withdrawal works — as of this revision, and it works from day one, whether or not the consent screen has been turned on. Settings → "Consents": the same place where you gave it. Each of the five areas has its own switch. The three optional ones go off silently, in one gesture, with no persuasion. Either of the two required ones we will ask about again — not to talk you out of it, but because switching it off closes the Oracle, and that is worth seeing before rather than after.

And it takes effect everywhere, not only where you tapped it. Consent lives on the server, so withdrawing in the web app closes the Oracle on the iPhone too — including the build that has no consent screen yet.

The iPhone app has no withdrawal screen of its own yet: it arrives with the next build. Until then you can withdraw through the web app, with the same effect — or, for withdrawal wholesale, delete your data with the delete button (what it does and does not do is in section 12 of the Privacy Policy). Apple Health access is revocable independently of us, at the system level: Settings → Privacy & Security → Health → WooMoon.

What will happen after withdrawal:

An honest caveat: what you can withdraw is future transmission. What has already gone to the model cannot be recalled — that is true of any service, and we will not pretend otherwise.

Withdrawing consent is not the same as deleting your account. If you want the latter, the app has a delete-my-data button; what it does and does not do is in section 12 of the Privacy Policy.

8. Legal basis

For the Russian audience: Art. 10 of Federal Law 152-FZ — processing of special categories of personal data (health, intimate life) with the data subject's consent; Art. 12 — cross-border transfer.

Questions?

Support: @lunnaya_care

Privacy Policy  ·  Terms of Service  ·  Русская версия