Consent to processing of health and intimate-life data
The short version
- What data: your cycle, symptoms, Apple Health measurements, intimacy markers, and whatever you write about how you feel to the Lunar Oracle.
- Where it goes: cycle data to our server; to Google's language model (Gemini), exactly what is listed in section 3.
- What we never do: no advertising, no ad-targeting profiles, no selling, no passing it to anyone for their own purposes.
- It is voluntary. Declining any optional part does not lock the feature you paid for.
- You can withdraw at any time, inside the app, with the same gesture that gave consent: in the web app this already works, and in the iPhone app it arrives with the next build — a withdrawal made in the web app closes the Oracle there too. Details in section 7.
1. What this consent covers
| Category | Specifically |
|---|---|
| Cycle | cycle start date, cycle length, menstruation duration, cycle markers and events, delays, the tracker pause (its moment and whether you set it yourself from the delay check-in), cycle history and the derived analytics you see in the app |
| Apple Health (iPhone) | menstrual flow, sleep, heart rate variability, resting heart rate, wrist temperature during sleep, cycle symptoms |
| Intimate life | the intimacy markers you tap in the calendar |
| Oracle conversation | what you write about your body, your state and your feelings. You write it yourself, and that is the service — but in law it is health data too |
The list above is what the app reads from Apple Health. It will be identical in the system permission prompt, the Privacy Policy and here — once the iOS build that requests permission for all six types ships.
On the consent screen before the Oracle the list is a different, shorter one: five signals, without menstrual flow — sleep, heart rate variability, resting heart rate, wrist temperature during sleep, cycle symptoms. The difference is deliberate, not editorial. That checkbox governs one thing: whether a signal travels together with your message to the Oracle. Those five are computed on the phone itself and are not stored by us, so switching them off means nothing travels at all. Menstrual flow takes a separate route: it syncs with the calendar and is stored on our server as a cycle event — the tracker itself is built from it, and an unchecked box would not remove it from there. Promising that kind of control through the checkbox would be untrue, so it is not offered there; the real levers are named in section 7 — read access is revoked in the iPhone's settings, and stored cycle events are removed when you delete your data.
About the tracker pause — and what we do not ask. When the tracker is paused, we record the moment of the pause and, if you paused it yourself from the delay check-in (the message about a delay that carries a "pause the tracker" button), that fact too: a pause you chose and a pause the automation sets on its own after 180 days without a mark must not be confused. Why there is no cycle we neither ask nor store — not pregnancy, not menopause, not treatment. The origin of the pause is derived from the delay you had already marked and is covered by this consent together with the rest of your cycle data. The question we ask after you cancel a subscription is outside this consent: none of its options says anything about your body — see section 2.2 of the Privacy Policy.
2. Why we process it
- to keep your cycle calendar and show where in it you are;
- so the morning recommendation matches your phase instead of being generic;
- so the Lunar Oracle answers you, and not a woman in the abstract;
- so that body signals from Apple Health help you understand your own state better;
- so that a tracker pause you chose yourself is not confused with one set by the automation.
And nothing else. None of these categories is used for advertising, marketing, profiling, or behavioural analysis in anyone's commercial interest.
3. Who this data is shared with
We name the recipient plainly rather than calling it a "technology partner".
Google (Gemini) — the language model that writes the texts. It receives:
- for the morning recommendation — your cycle day and length, the phase and its description, any recorded delay, and the day's lunar data;
- for the Lunar Oracle — the text of your message, recent turns of the conversation and the memory digest from your device, your name, age, city, cycle position and history, Apple Health body signals (if you granted access), intimacy markers for yesterday and today, derived natal chart values, and the text of today's recommendation.
The full list, and what Google does with what it receives, is in sections 5 and 7 of the Privacy Policy. In short: under the paid-tier terms Google does not use this data to improve its products, but it logs it for a limited period to detect abuse and may cache it in any country where it has facilities. This is a cross-border transfer, and consent to it is asked for separately.
Where this data does not go: nothing listed in section 1 is sent to advertising or analytics services (AppsFlyer, Google Analytics, Meta, Google Ads).
What is recorded about the consent itself. Every tap — grant and withdrawal alike — is stored as its own row: the consent scope, the action, the version of the text you saw, the surface, the language, the time, and your IP address. The IP is part of the evidence that it was you who consented, and when. That row outlives account deletion, but on deletion both the account number and the IP are scrubbed from it: what remains is "someone consented to scope X of version Y at time T".
Rows come from wherever the consent screen has already been turned on — section 6. And plainly, about what does not reach that journal: "the screen was shown" and "she closed it without accepting" are neither consent nor its refusal, they are never written there, and they do not affect your access. But they do not vanish either: we record them as an ordinary product analytics row tied to your account, like other events in the app, so we can see whether the screen reads clearly. Not one of your ticks and not one of your words is in that row: only which areas the screen displayed, and which version of the text. It is erased along with your account.
4. Where this data is stored
- Cycle data and intimacy markers — on our server, until you delete your account.
- Apple Health measurements — nowhere. They are computed on the phone and travel with one specific question to the Oracle; no server-side copy exists.
- Oracle conversations — on your device only. We do not have them. If you erase them, they are gone for good.
One caveat, without which the line above would read wider than it is: every message passes through our server — it assembles the context, calls the model and returns the reply. In that moment the server sees and processes the text; it does not save it. "On your device only" is about storage. The fact that a message was sent (when, from which surface, never its text) we do record in our event log.
5. This is voluntary
Consent is split into parts, and they are not equal.
Without this there is no conversation. For the Oracle to answer, your message has to reach the model and come back as a reply — and it has to leave the country to do so. That is not "access to your data", that is the service itself. Declining here means "I do not want to use the Oracle"; everything else — cycle, calendar, moon, recommendations — keeps working as before.
What is optional — and it is exactly three layers, no more. Cycle data in the conversation's context, Apple Health signals, intimacy markers. The Oracle works without each of these three — it will simply know less about you. Declining any of them locks neither the feature you paid for nor anything else.
What that choice does not cover. Alongside your message, the model also receives what has no switch of its own: your name, city, age in years and the derived natal-chart values. Today you cannot decline those separately and keep using the Oracle. The full contents of the transfer are in section 5 of the Privacy Policy.
No consent box is pre-ticked. There is no "accept all" button.
6. How consent is given
Consent is given by a distinct affirmative action: before your first conversation with the Lunar Oracle a separate screen rises, where the required and optional parts are separated and listed by name. No box is pre-ticked. We record what you ticked, when, and which version of the text you saw.
Where that screen already exists. In the web app — it arrives with this revision, but for the first few days it does not rise yet: some browsers still hold an older version of the app that does not contain it at all, and turning it on immediately would close the Oracle in front of someone with no way to answer. Through that period the Oracle works exactly as it did yesterday. We turn the screen on once the new version has spread — and from that moment no "I accept" means no conversation; there is no in-between state of "shown but lets you through". In the iPhone app the screen is not there yet — it arrives with the next build through the App Store.
About registration, separately and honestly. Dedicated consent checkboxes at registration are shown only in the English-language versions: the Telegram bot, the web app and the iPhone app. The Russian-language surfaces have no such step at all — and we will not invoke a consent that was never given: until the consent screen ships, the basis for that audience is this document and the fact that she came to the Oracle and paid for it herself.
7. Withdrawal
In the web app, withdrawal works — as of this revision, and it works from day one, whether or not the consent screen has been turned on. Settings → "Consents": the same place where you gave it. Each of the five areas has its own switch. The three optional ones go off silently, in one gesture, with no persuasion. Either of the two required ones we will ask about again — not to talk you out of it, but because switching it off closes the Oracle, and that is worth seeing before rather than after.
And it takes effect everywhere, not only where you tapped it. Consent lives on the server, so withdrawing in the web app closes the Oracle on the iPhone too — including the build that has no consent screen yet.
The iPhone app has no withdrawal screen of its own yet: it arrives with the next build. Until then you can withdraw through the web app, with the same effect — or, for withdrawal wholesale, delete your data with the delete button (what it does and does not do is in section 12 of the Privacy Policy). Apple Health access is revocable independently of us, at the system level: Settings → Privacy & Security → Health → WooMoon.
What will happen after withdrawal:
- withdrawing a required part closes the Lunar Oracle — and nothing else;
- withdrawing any optional part closes nothing: from your very next message that layer is no longer assembled;
- Apple Health access can also be revoked at the system level: Settings → Privacy & Security → Health → WooMoon;
- the conversation on your device is erased by you, with "Clear conversation". We do not store it, so there is nothing on our side left to erase.
An honest caveat: what you can withdraw is future transmission. What has already gone to the model cannot be recalled — that is true of any service, and we will not pretend otherwise.
Withdrawing consent is not the same as deleting your account. If you want the latter, the app has a delete-my-data button; what it does and does not do is in section 12 of the Privacy Policy.
8. Legal basis
For the Russian audience: Art. 10 of Federal Law 152-FZ — processing of special categories of personal data (health, intimate life) with the data subject's consent; Art. 12 — cross-border transfer.