Privacy Policy
Lunet is built so that we never need your data. Here’s the short version, then every detail.
In plain language
- We don’t collect personal data. There’s no account, no ads, no analytics and no tracking.
- Your scans stay on your device. History, your codes and your designs are stored only on your iPhone or iPad.
- Lunet goes online only for three things — checking a link, looking up a product, and adding a pass to Apple Wallet — and sends only what that feature needs.
- We don’t sell or share anything, because we don’t have it.
1. Who we are
Lunet (“the app”) is developed and published by Rodrigo Valle Pinto, an independent developer (“we”, “us”). This policy covers the Lunet app for iPhone and iPad and this website, lunet.vallepinto.com. Questions: rovapin (at) gmail (dot) com.
2. What stays on your device
Everything you do in Lunet is stored in the app’s private storage on your device and is never sent to us:
- History — the content of codes you scan or create, their type and format, the date, and whether you pinned them.
- Places — only if you turn on Remember where I scanned: the place name and location of each scan.
- Your codes and designs — codes you keep on Home and styles you create in the Studio.
- Settings — your preferences.
This data is included in your device backups (iCloud Backup or a computer backup) under Apple’s terms, like any app’s data. You can delete individual scans, clear History, or remove all of it by deleting the app. When you export History as CSV, the file goes wherever you choose to send it.
3. When Lunet goes online
Scanning, creating codes, the Studio and History work fully offline. Lunet connects to the internet only in these cases:
a) Link check (“Deep check”)
When you scan a link and Deep check is on (you can turn it off in Lunet › Settings › Safety), Lunet:
- contacts the link’s own server — and each server it redirects to — to find the final destination, without cookies and without saving anything; and
- asks the public RDAP domain registry (through the rdap.org directory) for the domain’s registration date. Only the domain name is sent, for example example.com.
Nothing is sent to us. As with visiting any website, those servers receive your IP address and the request, and they are operated by third parties under their own policies. The lookalike, homograph and @-trick checks run entirely on your device.
b) Product lookup
When you scan a product barcode, Lunet sends only the barcode number to the open databases Open Food Facts and Open Products Facts (world.openfoodfacts.org, world.openproductsfacts.org), run by the non-profit Open Food Facts, to show the product’s name, brand and picture. Their servers receive your IP address as part of the connection; see openfoodfacts.org for their policy.
c) Add to Apple Wallet
Only when you tap Add to Apple Wallet, Lunet sends the pass details shown on screen (such as passenger name, flight, date, seat and booking reference) over an encrypted connection to Lunet’s pass-signing service, which runs on Cloudflare. The service signs the pass and sends it straight back. Pass contents are processed in memory only and are never stored or logged.
To prevent abuse, the service uses Apple’s App Attest to confirm requests come from a genuine copy of Lunet. For this it keeps:
- an anonymous cryptographic key created by your device for Lunet, with a request counter and timestamps — it doesn’t identify you and isn’t linked to your Apple Account; and
- hourly rate-limit counters keyed by a truncated one-way hash of your IP address, deleted automatically within two hours.
Like any hosting provider, Cloudflare processes standard technical data (such as IP addresses) transiently to deliver and protect the service, under its own privacy policy. We don’t use it to identify anyone.
d) Apple services and other apps
If you turn on Remember where I scanned, iOS may send the location to Apple to find a place name (reverse geocoding), under Apple’s privacy policy. When you choose to open a link, join a Wi-Fi network, open Maps or save a contact or event, that action is handed to iOS or the app you chose.
4. Permissions
| Permission | Why |
|---|---|
| Camera | To read codes. The camera feed is processed on your device in real time and is never recorded or uploaded. |
| Photos | Add-only access, to save codes you create. To scan an image, you pick it in the system photo picker — Lunet sees only the image you choose. |
| Location | Optional, only for Remember where I scanned. Stored on your device with your History. |
| Face ID | Optional, to lock History. iOS performs the check; Lunet only learns whether it succeeded and never receives biometric data. |
| Contacts, Calendar | Lunet doesn’t read your contacts or calendars. When you save a contact or event, iOS shows its own screen for you to confirm. |
You can change any permission at any time in Settings › Apps › Lunet.
5. What we don’t do
- No accounts, sign-in or profiles.
- No advertising, and no advertising identifier.
- No analytics or third-party SDKs that collect data.
- No tracking across apps or websites, and no data brokers.
- No sale or sharing of personal information.
If you choose to share crash reports and analytics with app developers in iOS Settings, Apple may provide us with anonymous crash reports, under Apple’s privacy policy. We use them only to fix bugs.
6. Children
Lunet is a general-audience utility and isn’t directed at children under 13 (or the minimum age in your country). Because Lunet doesn’t collect personal information from anyone, it doesn’t knowingly collect it from children. If you believe a child has sent us personal information by email, contact us and we will delete it.
7. Your rights
Depending on where you live — including under the GDPR (EU/UK), the CCPA/CPRA (California) and Mexico’s LFPDPPP — you may have rights to access, correct, delete or object to the processing of your personal data. Because we don’t hold personal data about you, your History and other data are already under your control on your device. For the transient processing described in section 3(c), the legal bases are performing the service you asked for and our legitimate interest in preventing abuse. If you email us, we use your message only to reply and delete it when it’s no longer needed. You can contact us about any request, and you may also complain to your local data protection authority.
8. Security and transfers
All network connections use HTTPS. The pass-signing service accepts only attested requests from Lunet and keeps nothing beyond what’s described above. Cloudflare operates a global network, so the transient processing in section 3(c) may happen in a data center outside your country.
9. This website
lunet.vallepinto.com uses no cookies, no analytics and no third-party scripts or fonts. It’s served by Cloudflare, which processes IP addresses transiently to deliver and protect it.
10. Changes
If this policy changes, we’ll update this page and the effective date above. If a change affects how data is handled, we’ll also mention it in the app’s release notes before it takes effect.
11. Contact
Questions about privacy? Write to rovapin (at) gmail (dot) com.
