LunaStat Privacy Policy
Version 0.7 (2026-08-20, counsel-approved). Not yet in force.
Provider: Medresearch LLC, Nashville, Tennessee, U.S.A.
The bright line (this never changes)
LunaStat is designed so that your datasets, analyses, results, and any Protected Health Information (PHI) or patient data you work with remain on your device and are not transmitted to Medresearch during ordinary operation. LunaStat performs all statistical computation locally, on your computer. This is a core design guarantee, not a setting. The only things that can reach Medresearch are the limited technical exchanges described in Section 1, the optional features described there (each off by default and under your control), and messages you choose to write to us.
Two different kinds of information appear in this policy, and we never blur them:
- Your work, which stays on your device: datasets, data tables, analyses, results, figures, files, and any PHI. We do not receive it.
- Limited personal and technical information we may receive to operate the product: account information, license information, the machine identifier described below, software and operating- system versions, optional analytics and diagnostics if you turn them on, and messages you choose to send us. Some of this is personal data even though it includes none of your datasets or PHI (an email address or a persistent identifier is personal data), and this policy treats it that way.
1. Information we may collect (none of it includes your datasets or PHI)
a. Account information. If you create a LunaStat account or purchase a paid plan, we collect the information needed to establish and manage it, such as your name, email address, organization, and billing details (payment processing is handled by a third-party payment provider; we do not store full card numbers). We use this to provide the Software, manage your license, and communicate with you about your purchase.
b. License and update data. The Software validates your license and can check for updates. These exchanges transmit only limited technical information: license identifiers, the current software version, your operating system, processor architecture, and a machine identifier used to bind a paid license to your device (each license covers a limited number of machines). The machine identifier is a random value the Software creates for this installation; it is not derived from your hardware and does not itself encode information about your computer or your identity. Because it is a persistent identifier unique to your installation, it may be personal data under laws such as the GDPR and CCPA, and we treat it accordingly: in our systems it is stored with your license record (that is how machine limits are enforced), it is included when we answer access or deletion requests, and it is deleted on the schedule in Section 7. You can reset the identifier at any time in the Software's settings; a reset detaches the old identifier, which then ages out and is deleted on that same schedule. Like virtually all internet services, the servers that answer these exchanges also record ordinary request logs, which include IP addresses; we keep those logs briefly (Section 7), use them only to operate and protect the service, and do not use them to profile you. These exchanges never transmit your datasets, results, or PHI.
c. Product analytics (opt-in). If you choose to turn on product analytics (off by default), we collect limited information about how the Software is used, such as which features are opened, aggregate usage counts, and non-content error indicators, to understand and improve the product. Analytics events never include your datasets, variable values, results, file contents, or any PHI. You can turn analytics off at any time in the Software's settings.
d. Error and crash reports (opt-in). To help us find and fix defects, you can choose to turn on error reporting (off by default). When enabled, the Software sends a diagnostic report when it encounters an error, such as the software version, the operating system, and a technical description of the fault. Error reports are designed to exclude your dataset content and PHI. Because a fault's technical details can, in rare cases, incidentally include fragments of the data being processed, reports are filtered to remove data content before transmission, and the Software shows you what a report contains so you can review it before enabling reporting.
e. Opt-in telemetry. You may choose to share additional usage and diagnostic information that includes none of your datasets or PHI, to help us improve LunaStat. This telemetry is off by default and only collected if you turn it on; you can turn it off at any time.
f. Support communications. If you contact us for support, we receive the information you choose to send us (such as your message, contact details, and the software/OS version). Please do not include PHI, patient identifiers, or dataset content in support requests; you should not transmit that information to us through any channel.
g. Course feedback (optional). The Software's built-in training course lets you send us a short written comment about a lesson if you choose to. This is optional and off by default: you decide whether to write anything and whether to press Send; skipping it never affects your use of the course. When you do send a comment, we receive only the text you wrote together with non-content context identifying which lesson it concerns and the software version. The feedback payload is built from a fixed list of those fields and carries no name, account, license, or machine identifier, and we do not intentionally associate course feedback with your account or license. Because this is a free-text box, please do not include any PHI, patient identifiers, or dataset content in it. The box displays this reminder. We use course feedback solely to improve the training content.
2. What we never collect
- Your datasets, data tables, variable values, or file contents.
- Your analyses, statistical results, figures, or generated text derived from your data.
- Any Protected Health Information or patient-identifiable information.
- Keystroke logs, automatic or surveillance screen capture, or content-monitoring data of any kind.
3. Your choices and controls
- Analytics: off by default; opt in or out at any time in the Software's settings.
- Telemetry: off by default; opt in or out at any time.
- Error reporting: off by default and opt-in; reports are filtered to exclude data content, and the Software shows you what a report contains before you enable reporting.
- Course feedback: optional and off by default; you choose whether to send each comment; it carries no name, account, license, or machine identity, and we do not intentionally associate it with you.
- Machine identifier: resettable at any time in the Software's settings.
- Updates: you can control update checks in the Software's settings.
- Account: you may access, correct, export, or delete your account information by contacting us; see Section 7.
4. How we use and share information; our service providers
We use the information described in Section 1 to operate, secure, support, and improve the Software and to manage your license. We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising. We disclose it only to the service providers below, who process it on our behalf or as independently regulated businesses, and as required by law. The automated data flows we send providers (license validation, update checks, and analytics if you enable them) are built from closed lists of technical fields and contain no dataset content by construction, consistent with the bright line above. Messages you yourself write to us (support requests, course feedback) travel through our email provider the way any email does, which is one more reason not to put PHI in them; if PHI reaches us in error that way, we delete it on discovery (Section 7).
Our current providers:
- Paddle (merchant of record): processes your checkout and payment as the seller of record under its own buyer terms and privacy policy; passes us limited transaction and entitlement information.
- Zoho (email): carries our business mail, including license-key delivery and support correspondence.
- Cloudflare (website hosting and network services): serves the LunaStat website and sits in front of our licensing service; like any network provider it processes request metadata, including IP addresses, to deliver traffic.
No analytics or error-reporting vendor is engaged today (those features are off by default and not yet enabled). Before any new provider receives personal data, we will add it to this list and update this policy. This list is our current service-provider register; material changes to it are material changes to this policy. Our email provider, like any email service, keeps standard mail logs of messages it carries.
5. HIPAA and your obligations
LunaStat's architecture is described above: your datasets, results, and PHI stay on your device, and Medresearch does not receive them in the ordinary operation of the Software. You must not transmit PHI to Medresearch through any channel, including support requests, feedback, or email. Whether laws such as HIPAA apply to any party, and in what role, depends on the facts of your use and on those laws; Medresearch makes no representation about your regulatory obligations. You remain responsible for handling the data on your device in compliance with HIPAA and your institution's policies, including securing your machine and files.
6. The LunaStat website
The LunaStat website (lunastat.app) is informational. It does not use advertising or cross-site tracking cookies and does not build advertising profiles. If a page-analytics or strictly-necessary cookie is ever used, it will be limited to operating the site and disclosed here; the website never receives your datasets, results, or PHI (those exist only in the desktop Software, on your device). The website is served by Cloudflare, which processes ordinary web-request logs, including IP addresses, to deliver and protect the site.
7. Legal bases, retention, your rights, transfers, security, children, changes, and contact
Who is responsible. Medresearch LLC (Nashville, Tennessee, U.S.A.) is the controller of the personal data described in Section 1. We have not appointed a data protection officer; the contact below reaches the people responsible.
Legal bases (GDPR / UK GDPR). Where these laws apply, our legal bases are: performance of a contract for account and license administration and for the license and update exchanges that make the Software work (Section 1a–b) and for support you request (1f); legitimate interests for service security, abuse and fraud prevention, and the short-lived request logs described above (1b); your consent for optional analytics, telemetry, and error reporting (1c–e), which you may withdraw at any time in the Software's settings with effect for the future; your consent, given by choosing to press Send, for course feedback (1g); legitimate interests for the ordinary web-request logs involved in serving the website (Section 6); and legal obligation for tax, accounting, and similar records.
How long we keep information. Account information: while your account is active, deleted within 90 days of account deletion or a verified deletion request, except records we must keep for tax, accounting, or legal compliance (kept 7 years; the merchant of record holds the primary transaction records under its own rules). License and activation records, including machine identifiers: the license term plus 12 months, then deleted; a reset identifier ages out on the same schedule. Server request logs (including IP addresses): deleted on a 90-day rolling basis. Optional analytics: 24 months, then deleted or irreversibly aggregated. Optional error reports: deleted when the defect is resolved, and no later than 12 months after receipt. Support communications: 24 months after the matter closes; any PHI received in error is deleted on discovery. Course feedback: 24 months.
Your rights. Subject to applicable law, you may request access to, rectification of, erasure of, or a portable copy of your personal data; restriction of or objection to processing based on legitimate interests; and you may withdraw any consent at any time with effect for the future. We honor these rights for all users, wherever located. To make a request, contact [email protected]; we will verify the request by reasonable means appropriate to it (for example, confirming control of the email address associated with your purchase) and respond within the time applicable law requires. If you are in the EU, EEA, or UK, you also have the right to lodge a complaint with your supervisory authority. We do not make automated decisions about you that have legal or similarly significant effects, and we do not use your personal data for profiling. We will never discriminate against you for exercising a privacy right.
What deletion means. If you ask us to delete your account, we delete your account information and detach and delete machine identifiers on the schedule above. What remains afterward is exactly the records described in that schedule: tax and accounting records the law requires us to keep, license and activation records for the license term plus 12 months (fraud prevention and reactivation disputes), and short-lived security logs until they roll off. The merchant of record keeps its own transaction records as an independent seller under its own policy.
California. We do not sell personal information and we do not share it for cross-context behavioral advertising, and we have not done so. We collect only the categories described in Section 1, for the purposes stated there, retained as stated above. California residents may exercise the access, correction, deletion, and portability rights above through the same contact, with the same verification, and without discrimination.
Where your information is processed. Medresearch is a U.S. company; the information in Section 1 is processed in the United States (and by the providers in Section 4 under their own safeguards). If you use LunaStat from the EU, EEA, UK, or elsewhere, your Section 1 information is transferred to the United States; where the law requires a transfer mechanism for such transfers, we will implement the appropriate safeguard and describe it here.
Security. We use reasonable administrative and technical safeguards for the information we hold. No method of transmission or storage is perfectly secure.
Children. The Software is a professional tool and is not directed to children.
Changes. We will update this policy and its version date as our practices change, and reflect material changes in the Software's release notes. A material change affecting an existing paid term will not apply to your current paid term without your affirmative acceptance where the law requires it.
Contact: Medresearch LLC · 4004B Woodmont Blvd · Nashville, TN 37205, U.S.A. · [email protected].
