Privacy
Luna reads your search data to tell you what to fix. This page says exactly what that means: what is collected, what is never collected, who else can see it, and how to get rid of it.
Last updated 9 September 2026
The short version
- Luna reads your connected accounts, and only ever reads them.
- Luna never asks for your customers’ personal data. The Shopify permissions Luna requests exclude orders and customers entirely.
- Your data is never sold, and is never used to train anyone’s models.
- Disconnecting deletes the stored access token rather than marking it unused.
- Analytics run only if you agree to them, and the choice is a real one — declining costs you nothing.
What Luna collects
Three kinds of thing, and nothing else.
| What | Why | Where it comes from |
|---|---|---|
| Account details | To sign you in and to know which organization you belong to | Your name and email, from you or from Google sign-in |
| Your sites and their pages | To audit them and score technical health, content health and AI readiness | Luna's crawler, reading your site the way a search engine would |
| Search and analytics figures | To show impressions, clicks, position and traffic beside the findings | Google Search Console and Google Analytics, read-only, once you connect them |
| Your product catalogue | To audit product and collection pages for search and AI visibility | Shopify, read-only, once you install the app |
| Answer-engine replies | To measure whether AI assistants mention your brand | Questions Luna asks answer engines about your category — never about you personally |
What Luna never collects
Luna is a search tool, so it has no use for the data most breaches are made of, and asks for none of it.
- No customer records. The Shopify permissions Luna requests are
read_products,read_content,read_themesandread_online_store_pages. Orders, customers and payment data are not among them, and Luna could not read them if it tried. - No card details. Payment is handled by Stripe. Luna never sees a card number.
- No write access. Every connection Luna holds today is read-only. Nothing Luna does can change your site, your store or your Google account.
- No tracking across other websites. Luna sets no advertising cookies and runs no ad network code.
Who else sees it
Luna runs on other people’s infrastructure, and being specific about which is part of the answer. These are every third party that can hold your data.
| Who | What they hold | Why |
|---|---|---|
| Supabase | Your account, sites, audits and findings | The application database and sign-in |
| Vercel | Requests to the application, and its logs | Hosting |
| Nothing new — Luna reads what you already have | Search Console and Analytics figures | |
| Shopify | Nothing new — Luna reads your existing catalogue | Product and collection data |
| Stripe | Your billing details | Subscriptions and payment |
| Answer engines, through one provider | The questions Luna asks about your category, and your brand name | Measuring whether AI assistants mention you |
The answer engines are asked questions a customer might ask — “what is the best running shoe for flat feet” — together with the brand name Luna is looking for. They are not sent your analytics, your customers, or anything from your store.
How it is protected
Access tokens for your connected accounts are encrypted before they are stored, with a key held in the application environment and never written to the database — so a copy of the database is not a copy of your Google account. Every table that belongs to a customer is isolated at the database level, not merely filtered by the application.
The longer version, including what an attacker would have to do, is on the security page.
Analytics, and your choice about them
Luna uses product analytics to see which features are used and where people get stuck, and an in-app widget so you can send feedback without leaving the page. Both are loaded only if you accept them. If you decline, they are never loaded at all — not loaded and silenced, but never fetched.
Analytics never record what your audits found, what your traffic is, or anything from your connected accounts. You can change your mind at any time from the footer of any page.
How long it is kept, and how to delete it
Your data is kept while your account is open. Disconnecting an integration deletes the stored token immediately. Closing your account deletes the organization and everything belonging to it — sites, audits, findings, reports and answers — within 30 days, apart from records Luna is required to keep for tax and accounting.
To ask for a copy of your data or its deletion, write to privacy@gambix.io. We answer within 30 days.
Your rights
Depending on where you live, you may have the right to see the data held about you, correct it, take it elsewhere, or have it deleted. Luna applies these to everyone rather than checking your address first. Use the address above, and say what you want — you do not need to cite a regulation to be taken seriously.
Changes
If this policy changes in a way that affects what is collected or who sees it, we will say so in the product before the change takes effect, not merely edit this page and update the date.