Lune

Privacy Policy

Last updated 28 July 2026

Lune is a fairy-tale app for children, used under a parent's account. A parent signs in with Apple or Google, creates up to five child profiles — a first name and an emoji — and Lune records which stories each child has finished so it can show read counts and suggest the branch they haven't taken yet.

That is the whole of it. There is no analytics, no advertising, no tracking, and nothing identifying a child is ever sent to anyone else. Deleting the account erases everything, permanently, in one step.

1. Who is responsible for your data

Lune is published by Ahmet Fazlı Cengiz, an individual based in Türkiye. Under the GDPR they are the data controller for everything described here.

Ahmet Fazlı Cengiz
Namık Kemal Mahallesi, Orta Sokak No: 10, Kat: 2 Daire: 8
Ümraniye, İstanbul
Türkiye

Contact for any privacy question or request: taleodevacc@gmail.com.

2. Children

Lune is made for children, but it is not operated with children. Only an adult can hold an account. Children never sign in, never have an account of their own, and cannot type anything that leaves the device — there is no chat, no comments, no uploads and no user-generated content of any kind.

Two pieces of children's personal data exist in Lune, both created by the parent or by the child's use of the app: a child's first name on their profile, and the record of which stories that profile has finished. Both are described in full below. Everything else a profile holds is an emoji chosen from a fixed list.

Lune deliberately does not ask for a child's date of birth, age, photograph, email address, phone number, location or gender, and has no way to collect them.

Anything that spends money or opens a link outside the app sits behind a parental gate — a challenge a young child cannot pass.

3. What Lune collects

3.1 The parent's account

Sign-in runs entirely through Apple's or Google's own OAuth flow. Lune never sees, receives or stores a password, and never asks for one.

Email addressFrom Apple or Google. Identifies the account and is the only way back into it. If you use Apple's Hide My Email, we only ever receive the private relay address.
Provider identityThe identifier and basic sign-in metadata Apple or Google returns.
TimestampsWhen the account was created and last signed in, for session management.

3.2 Child profiles

First nameTyped by the parent. This is children's personal data and we treat it as the most sensitive field in the app.
AvatarA reference to one of a fixed set of emoji. Not an upload, not an image of the child.
Created atWhen the profile was made.

A maximum of five profiles per account.

3.3 Reads

When a child finishes a story, Lune records which profile read it, which story it was, the choices made in order, and when. This is behavioural data about a child, so we want to be plain about what it is for.

It is used for exactly two things, both inside the app: showing how many times a story has been read, and suggesting the branch a child hasn't taken yet. It is never sent anywhere else, never combined with data from other families, and never used for advertising or for any recommendation beyond that one screen. The record is only ever added to — it is never edited, and it is deleted only when the profile is.

3.4 Kept on the device only

These never leave the phone or tablet and are listed only so the picture is complete: which profile is currently selected, whether interface sounds are on, the chosen theme, the sign-in tokens that keep the parent signed in, and story media cached for offline and smooth playback.

4. Why Lune is allowed to hold it (legal bases)

Account and profilesPerformance of our contract with the parent — without them there is no app to provide.
ReadsPerformance of that contract: read counts and "try the other branch" are features the parent signed up for. A parent who does not want them can delete the profile, which deletes the reads with it.
SubscriptionsPerformance of contract, and our legal obligation to keep billing records.
Crash reportsOur legitimate interest in an app that works, weighed against a report that carries no identity at all — see §5.1.

5. Who else receives data

Lune uses four service providers and the two app stores. None of them are advertisers, and none of them receive a child's name.

5.1 Sentry — crash reporting

Hosted in the European Union. When something breaks, Sentry receives a report describing what broke: the story and block involved, the kind of block, whether playback was interrupted, the route pattern, the stack trace, and the device model, operating system and app version its SDK collects by default.

A crash report says what broke, never who it broke for. The following are stripped in our own code before anything is sent, not merely by policy: the child's profile name and id, the parent's email address and user id, the IP address (blanked on every report), the text of any story, media addresses, the subscription status, and the interaction breadcrumbs that would otherwise record the label of whatever was tapped — because on the profile picker, that label is a child's name.

5.2 RevenueCat — subscriptions

Receives an anonymous identifier that it generates itself, together with the purchase receipt, subscription status, and the device and country information its SDK collects. We do not give RevenueCat your email address, your Lune account id, or anything at all from a child's profile, so it holds nothing that can be linked back to a person by us or by them.

Payment is handled entirely by Apple and Google. Lune never sees card details, and no payment information ever reaches our database.

5.3 Cloudflare — delivering stories

Every image, animation and narration file is served from Cloudflare. These requests carry no account, no profile and no identifier — only the name of the file being fetched. As an unavoidable part of serving any file over the internet, Cloudflare receives the request's IP address and browser/app user agent.

5.4 Supabase — database and sign-in

Holds the account, the profiles and the reads, in a project located in the European Union (Frankfurt, Germany). Supabase receives request IP addresses as ordinary API traffic, and its authentication service records the IP address of sign-in events in a security audit log that is rotated on a short schedule.

5.5 Apple and Google

Sign-in and, if you subscribe, billing. Their own privacy policies govern what they do with that.

6. What Lune does not do

For a children's app these absences are the point, so they are worth stating outright:

7. Where your data is and when it crosses a border

The account, the profiles and the reads are stored in the European Union (Frankfurt). Crash reports are stored in the European Union. The controller is in Türkiye, so viewing or acting on data means a transfer out of the EEA; RevenueCat and Cloudflare also process data outside the EEA. Those transfers rely on the European Commission's Standard Contractual Clauses in our agreements with each provider, together with the technical measures described above — most importantly that no third party ever receives a child's name.

8. How long it is kept, and how to erase it

The account, the profiles and the reads are kept for as long as the account exists, and no longer.

Deletion is real and it is immediate. In the app, Settings → Delete my account, behind the parental gate and a confirmation, permanently erases the parent's account, every child profile on it and every read belonging to those profiles, in a single operation. There is no soft delete, no deactivation and no retention window. You can also ask us to do it by email — see the support page.

Two honest caveats:

9. Your rights

As the parent and account holder you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to you in a portable form. You exercise these on your own behalf and on behalf of your children.

Email taleodevacc@gmail.com and we will respond within one month. There is no charge. If you would rather not wait, deletion is available immediately in the app.

If you are in the EEA or the UK and think we have handled your data badly, you can complain to your national data protection authority. If you are in Türkiye, the equivalent rights under KVKK Article 11 apply and the authority is the KVKK.

10. Security

Everything travels over encrypted connections and is encrypted at rest by our providers. Database access is restricted row by row, so an account can only ever reach its own profiles and reads. Nobody signs in with a password, so there is no password of yours for anyone to steal.

11. Changes to this policy

If we change how Lune handles data we will update this page and move the date at the top. If a change is significant we will say so in the app before it takes effect.

12. Contact

taleodevacc@gmail.com — or the Help & Support page. Please do not include a child's name or any other detail about a child in your message; we do not need it to help you.