COOKIE POLICY

Last Updated: February 6, 2026

Effective Date: February 6, 2026

lluna ("we", "us", "our", "Company") uses cookies and similar tracking technologies on our website located at lluna.app (the "Website", "Platform") to ensure functionality, enhance user experience, and maintain security. The present Cookie Policy explains what cookies are, which cookies we use, why we use them, and how you can manage your cookie preferences.

By using our Website, you acknowledge that you have read and understood our use of cookies as described herein. Where required by law, we will obtain your explicit consent before deploying non-essential cookies.

1. WHAT ARE COOKIES

Cookies are small text files that websites place on your device (computer, smartphone, tablet, or other electronic device) when you visit them. Cookies contain information that is transferred to your device's hard drive and stored by your web browser. They enable websites to recognize your device, remember your preferences, and provide certain functionality.

Cookies serve various purposes, ranging from essential technical functions that make websites work properly to optional features that enhance user experience or enable analytics. Some cookies are deleted when you close your browser (session cookies), while others remain on your device for a specified period or until you manually delete them (persistent cookies).

Similar technologies such as web beacons, pixels, and local storage may also be used alongside cookies. Throughout the present Policy, the term "cookies" encompasses these related technologies unless otherwise specified.

2. LEGAL BASIS FOR USING COOKIES

Our use of cookies is governed by Swedish and European Union legislation, specifically:

  • The Swedish Electronic Communications Act (ECA) (Chapter 6, Section 18), which implements the EU ePrivacy Directive and requires that users be informed about cookies and consent to their use.
  • The General Data Protection Regulation (GDPR) (EU) 2016/679, which classifies cookies that can identify users (directly or indirectly) as personal data subject to data protection requirements.

The Swedish Post and Telecom Authority (PTS) supervises compliance with the ECA, while the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, "IMY") oversees GDPR compliance.

According to Swedish law, cookies may be stored on your device only if:

  • You have been informed about the purpose of the cookies; and
  • You have provided explicit consent to their use.

Consent is not required for cookies that are strictly necessary for transmitting electronic communications or providing a service you have explicitly requested.

3. TYPES OF COOKIES WE USE

We categorize cookies based on their purpose and function. Different categories have different legal requirements regarding consent.

3.1 Strictly Necessary Cookies

Purpose: These cookies are essential for the Website to function properly and cannot be disabled without severely affecting your ability to use the Platform.

Legal Basis: No consent required, as these cookies are necessary to provide the service you have explicitly requested.

Examples of Strictly Necessary Cookies:

  • Authentication Cookies: Verify your identity when you log into your account and maintain your logged-in status as you navigate between pages.
  • Security Cookies: Detect authentication abuse, prevent fraudulent use of login credentials, and protect user data from unauthorized access.
  • Session Management Cookies: Remember your actions and preferences during a single browsing session, such as items added to your workspace or settings adjusted during your visit.
  • Load Balancing Cookies: Distribute user traffic across our servers to maintain optimal performance and prevent service disruptions.
  • User Interface Customization Cookies: Remember your display preferences, language selection, and accessibility settings to ensure consistent functionality.

These cookies typically expire when you close your browser or after a short period necessary for security purposes.

3.2 Functional Cookies

Purpose: These cookies enhance your user experience by remembering your choices and preferences across multiple sessions, making the Website more convenient and personalized.

Legal Basis: Explicit opt-in consent required before deployment.

Examples of Functional Cookies:

  • Preference Cookies: Store your language preferences, theme selections (if applicable), and interface customization choices.
  • Content Display Cookies: Remember which features or tools you use most frequently to provide quicker access.
  • Auto-Save Preferences: Maintain your document auto-save settings and workspace organization preferences.

While functional cookies improve convenience, the Website remains accessible without them, though some personalized features may not be available.

3.3 Analytics and Performance Cookies

Purpose: These cookies collect information about how visitors use the Website, including which pages are visited most often, how long users spend on pages, error messages received, and navigation patterns.

Legal Basis: Explicit opt-in consent required before deployment.

Current Status: We currently do not deploy analytics cookies such as Google Analytics or similar third-party analytics tools. Should we decide to implement analytics functionality in the future, we will update the present Policy and obtain your explicit consent through our cookie consent mechanism before deploying such cookies.

If analytics cookies are introduced, they would be used solely to improve Website performance, identify technical issues, and enhance user experience. Data collected would be aggregated and anonymized where possible.

3.4 Marketing and Targeting Cookies

Purpose: These cookies track your browsing activity across websites to build a profile of your interests and display relevant advertisements.

Legal Basis: Explicit opt-in consent required before deployment.

Current Status: We currently do not use marketing or targeting cookies, including Facebook Pixel or similar advertising technologies. We do not engage in behavioral advertising or share your data with advertising networks.

Should our practices change in the future, we will update the present Policy and implement a robust consent mechanism before deploying any marketing cookies.

4. THIRD-PARTY COOKIES AND SERVICES

While we minimize the use of third-party cookies, certain essential services integrated into the Platform may set their own cookies.

4.1 Payment Processing

Stripe, our payment processor, may set cookies necessary to complete payment transactions securely. These cookies are essential for subscription management and are covered under strictly necessary cookies. Stripe's use of cookies is governed by their privacy policy and terms of service.

4.2 Service Infrastructure

The Platform is hosted using Netlify, which may employ cookies necessary for technical infrastructure and service delivery. These are classified as strictly necessary for Platform operation.

4.3 AI Service Providers

Our AI service providers (OpenAI API, DeepSeek AI, Anthropic API, and Google Gemini API) process data transmitted from the Platform but do not directly set cookies on your device through our Website. Any data processing by these services is described in our Privacy Policy.

We do not control third-party cookies and cannot access data stored in them. Third-party cookie usage is subject to the respective provider's privacy policies. We recommend reviewing these policies to understand how your data is processed.

5. HOW WE OBTAIN YOUR CONSENT

In accordance with Swedish law and GDPR requirements, we obtain your consent for non-essential cookies through a clear and compliant mechanism.

5.1 Cookie Consent Banner

When you first visit our Website, you will be presented with a cookie consent banner that:

  • Clearly explains that we use cookies
  • Describes the types of cookies and their purposes
  • Provides separate options for different cookie categories
  • Requires active, affirmative consent through explicit action
  • Presents "Accept" and "Reject" options equally without visual bias
  • Links to the present Cookie Policy for detailed information.

5.2 Consent Requirements

Your consent must meet the following legal standards:

Freely Given: You must have genuine choice without coercion or negative consequences for refusing consent. You can access our Website and use essential features even if you decline non-essential cookies.

Specific and Granular: You can consent to specific cookie categories while rejecting others. We do not force an "all or nothing" choice.

Informed: We provide clear, comprehensive information about what data each cookie category collects, why we collect it, and how long cookies remain active.

Unambiguous: Consent requires a clear affirmative action, such as clicking an "Accept" button. We do not use pre-ticked checkboxes, implied consent through continued browsing, or other ambiguous methods.

Easily Withdrawable: You can withdraw or modify your consent at any time with the same ease as granting it.

5.3 Prohibited Practices

In compliance with Swedish Authority for Privacy Protection (IMY) enforcement guidance and Court of Justice of the European Union (CJEU) rulings, we do not employ the following practices:

  • Pre-checked consent boxes
  • Cookie walls that block Website access without consent to non-essential cookies
  • Visual manipulation where "Accept" buttons are prominently displayed while "Reject" options are hidden or styled as inconspicuous text
  • Friction by design where accepting requires one click but rejecting requires multiple steps
  • Coercive or misleading language that pressures users into consenting
  • Consent inferred from scrolling, continued browsing, or closing the banner.

5.4 Consent Documentation

We document your consent choices and maintain records for a minimum of five (5) years as required by Swedish data protection authorities. Documentation includes the date and time of consent, the specific cookies you consented to, and the consent mechanism version.

5.5 Consent Renewal

Cookie consent expires after twelve (12) months, at which point you will be asked to renew your preferences. Additionally, if you clear your browser cookies or use a different device or browser, you will need to provide consent again.

6. HOW TO MANAGE AND DELETE COOKIES

You have multiple options for managing cookies on our Website.

6.1 Cookie Preference Center

You can access our cookie preference center at any time through [insert location, e.g., footer link, account settings]. The preference center allows you to:

  • View which cookie categories are active
  • Enable or disable non-essential cookie categories
  • Withdraw previously granted consent
  • Review detailed information about each cookie type.

Changes to your cookie preferences take effect immediately and apply to your future browsing sessions.

6.2 Browser Settings

Most web browsers allow you to control cookies through their settings. You can typically:

  • Block all cookies
  • Block third-party cookies only
  • Delete cookies after each browsing session
  • Receive notifications when websites attempt to set cookies
  • View and delete individual cookies.

Instructions for managing cookies vary by browser. Consult your browser's help documentation for specific guidance:

  • Google Chrome: Settings > Privacy and Security > Cookies and other site data
  • Mozilla Firefox: Options > Privacy & Security > Cookies and Site Data
  • Safari: Preferences > Privacy > Cookies and website data
  • Microsoft Edge: Settings > Cookies and site permissions > Cookies and site data
  • Opera: Settings > Privacy & Security > Cookies.

6.3 Mobile Device Settings

Mobile devices offer cookie management options through browser settings similar to desktop browsers. Additionally, you can reset your advertising identifier or limit ad tracking through device privacy settings.

6.4 Third-Party Opt-Out Tools

For third-party advertising cookies (not currently used by lluna), you can opt out through industry tools such as the European Interactive Digital Advertising Alliance (EDAA) at www.youronlinechoices.eu.

6.5 Consequences of Disabling Cookies

Disabling strictly necessary cookies will prevent you from accessing certain essential features of the Website, including:

  • Logging into your account
  • Maintaining your session while navigating between pages
  • Saving documents and accessing your workspace
  • Processing payments for subscriptions.

Disabling functional cookies may reduce convenience but will not prevent you from using core Platform features.

7. COOKIES AND PERSONAL DATA

Many cookies collect information that constitutes personal data under GDPR, particularly when they can identify you directly or indirectly. Such cookies are subject to data protection requirements detailed in our Privacy Policy.

When cookies process personal data, we:

  • Implement appropriate security measures to protect cookie data
  • Limit data collection to what is necessary for specified purposes
  • Retain cookie data only for as long as needed
  • Provide you with rights of access, rectification, erasure, and objection regarding cookie data.

For comprehensive information about how we process personal data, including data collected through cookies, please refer to our Privacy Policy.

8. CHILDREN'S PRIVACY

Sweden has set the digital age of consent at thirteen (13) years. Users under thirteen (13) years of age require verifiable parental or guardian consent before we can deploy cookies that process personal data.

If you are under thirteen (13), please ensure a parent or guardian reviews the present Policy and provides consent on your behalf. We encourage parents and guardians to monitor their children's online activities and educate them about safe internet practices.

9. CHANGES TO THIS COOKIE POLICY

We may update the present Cookie Policy periodically to reflect changes in our cookie practices, legal requirements, or Website functionality. Material changes will be communicated through email notification or prominent notice on the Website at least thirty (30) days before taking effect.

The "Last Updated" date at the beginning of the present Policy indicates when changes were most recently made. We encourage you to review the Policy periodically to stay informed about our cookie practices.

Continued use of the Website after changes become effective constitutes acceptance of the updated Policy. If you do not agree with modifications, you should adjust your cookie preferences or discontinue use of the Website.

10. CONTACT INFORMATION

If you have questions, concerns, or complaints regarding our use of cookies or the present Cookie Policy, please contact us:

Email: info@lluna.app

Data Protection Authority: Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY)

Website: www.imy.se

Telephone: +46 8 657 61 00.

We will respond to cookie-related inquiries within five (5) business days.

By continuing to use our Website, you acknowledge that you have read and understood our Cookie Policy and consent to our use of strictly necessary cookies. For non-essential cookies, we will obtain your explicit consent through our cookie consent mechanism.