Privacy Policy
We publish one policy per app. Pick the one you're using.
Lunar Defense is a device-based security app. Its job is to check whether your device and its network connection show signs of compromise, then tell you what it found and what to do about it. The analysis runs on your device, and the results stay on your device.
This policy explains exactly what that means: what we process locally, the few specific things that do leave your device and why, and what we never touch.
Our approach: on-device first
When you run a sweep, the security checks and the AI model that weighs them run entirely on your device. Your scan results (the findings, the verdict, and the device and network signals we examine to produce them) are computed locally and are never transmitted to us or stored off your device — with one exception, which only happens when you choose it: if you email our support team from inside the app, the message you send contains your findings, because that is the point of it. That path is described below, and nothing is sent until you read the email and send it yourself.
There is no account to create, no profile, and no login.
What we process on your device (and never send)
To assess your device's security, the app inspects local security-relevant signals, such as:
- Signs that the operating system has been jailbroken or otherwise tampered with, or that unauthorized code is running alongside the app.
- Whether anything is attached to or monitoring the app.
- Your network and connection configuration (for example whether a proxy or VPN is present, and whether the secure connection to our service holds).
- Whether the Wi-Fi network you're on adds encryption of its own. The app reads the network's security type only. It never reads the network's name, and it never reads your location.
Two features work on content you hand them directly, and both are also entirely local:
- Check a Link. When you paste a suspicious message in, it is analyzed by Apple's on-device intelligence, on your own device. The message text is never uploaded, never stored on our servers, and never seen by us.
- QR link safety. When you point the camera at a QR code, the code is read and the link it points to is evaluated on your device. This feature makes no network calls at all — not to us, not to anyone. No photo or video is recorded or kept.
All of this is read, analyzed, and turned into a verdict on your device. None of it, and none of the resulting findings, is transmitted to us or retained anywhere off your device.
Permissions the app asks for, and why
- Camera — used only while the QR scanner is open on screen, to read the code in front of it. Frames are analyzed live and discarded. Nothing is recorded, saved, or transmitted.
- Location (while using the app) — this one deserves an explanation, because it looks like more than it is. iOS will not tell an app anything about the Wi-Fi network you're joined to, including whether it's encrypted, unless that app holds location permission. That is the only reason we ask. The app never reads, stores, or transmits a coordinate, and it asks in context when you run a scan rather than at launch. Decline it and everything else works normally; the app simply reports that it couldn't check your Wi-Fi rather than guessing.
- Notifications — used to tell you a background scan found something. You can turn them off at any time in iOS Settings.
What leaves your device, and why
The app makes a small number of network connections. Apart from the last one, which happens only when you initiate it, none of them carry your scan results, findings, security posture, or personal information. They are the security mechanisms themselves, and they are limited to the following:
Confirming your device is genuine (Apple App Attest)
To verify that your device is a genuine, untampered Apple device, the app uses Apple's App Attest service and confirms the result with our server. This sends an opaque install identifier (a random ID generated on install, not your name, Apple ID, phone number, or device serial number) and Apple's cryptographic attestation material. Our server keeps a minimal per-install record (the opaque install ID, an attestation public key, and a timestamp) so the check can't be abused. It is not sent with every scan, and it contains nothing about you or what your scans found.
Verifying the connection to our service (certificate pinning)
The app sends a contentless request to our own service to confirm that no one is impersonating it or intercepting the connection. This carries no personal data and no scan data. It is the security check itself.
Background scan notifications (paid automation tier only)
If you subscribe to the automated-scanning tier, the app registers for push notifications so we can wake it to run scans in the background. This uses an Apple-issued push token, which is not personal information and is not tied to your identity. We keep a record of the wake messages we send (which token, when, and whether Apple accepted it) so we can tell whether background scanning is actually working. Those records say nothing about what a scan found.
Payments (Apple In-App Purchase)
Subscriptions are handled entirely by Apple's In-App Purchase system. We never receive or see your payment details. We only receive your subscription status from Apple so the app can unlock paid features.
Asking us for help (only if you send it)
If you tap "Get help," the app writes a draft email for you containing your latest verdict and findings, so support can understand what you're looking at. It opens in your own mail app. You read it, edit it if you want to, and send it — or don't. Nothing is transmitted unless you send it yourself. This is the one path by which your findings can reach us, and it exists only because you chose it.
What we never collect
We do not collect, transmit, sell, or share your personal data. In particular, the app does not collect:
- Contacts, photos, messages, or call history
- The text of anything you check with the phishing checker, or the links behind the QR codes you scan
- Browsing history or the contents of your network traffic
- Your location or your movements (see "Permissions" above for why the app asks for location access anyway)
- A list of the other apps installed on your device
- Advertising identifiers or device identifiers tied to your real-world identity
- Your name, email address, or phone number
There are no third-party trackers, no analytics SDKs, and no advertising networks in the app.
No selling, no sharing
We do not sell, rent, trade, or share any information with advertisers, data brokers, other companies, or governments. The only third party involved is Apple (for device attestation, push notifications, and payments, as described above), which acts under Apple's own privacy terms.
Data retention
We do not store your scan results or personal data, so there is nothing for us to retain about your activity. The only records we keep are the minimal, non-personal anti-abuse and operational records described in "What leaves your device": the opaque install attestation record, and, for subscribers, a push token plus the log of wake messages sent to it. You can end these by uninstalling the app and, for subscriptions, canceling through Apple. If you emailed support, that message lives in our support mailbox like any other email; ask us and we'll delete it.
Security
Analysis runs inside Apple's app sandbox using on-device machine-learning frameworks. The limited network connections we do make are protected by certificate pinning to prevent impersonation or interception.
Children's privacy
Lunar Defense is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from children.
Your choices
- Use the free, manual-scan tier with no subscription.
- Decline camera or location access and keep using everything else.
- Turn off notifications at any time in iOS Settings.
- Cancel a subscription through your Apple account.
- Uninstall the app to remove it and stop all activity.
Changes to this policy
If we change how the app handles data, we will update this policy and revise the effective date above.
Contact
Questions about this policy? Get in touch.
Lunar Defense Managed is a device-based security app. Your IT or security provider deployed it to you and holds its license. It checks whether your device and its network connection show signs of compromise, tells you what it found in plain language, and keeps a tamper-evident record of what it found over time so a technician can help you when something goes wrong. The analysis runs on your device, and the record stays on your device.
This policy is written for you, the person holding the device. It explains what stays local, the few specific things that leave your device, and — the question that matters most here — exactly what your provider can and cannot see.
Three parties, so it's clear who does what
You hold the device and everything the app finds. Your provider — the IT or security company that gave you the activation code — holds the license and decides who gets a seat. Lunar Defense LLC makes the app and runs the licensing service the code checks against. Your provider decides who receives a code and may label your seat in their console; we hold those seat records on their instruction. Neither we nor your provider receives your scan results.
Our approach: on-device first
When a sweep runs, the security checks and the AI model that weighs them run entirely on your device. Your scan results — the findings, the verdict, and the device and network signals we examine to produce them — are computed locally and are never transmitted to us or to your provider. The security record the app keeps is written to your device and stays there.
There is no account, no login, and no password. There is one activation code, typed once.
What we process on your device (and never send)
To assess your device's security, the app inspects local security-relevant signals, such as:
- Signs that the operating system has been jailbroken or otherwise tampered with, or that unauthorized code is running alongside the app.
- Whether anything is attached to or monitoring the app.
- Your network and connection configuration (for example whether a proxy or VPN is present, and whether the secure connection to our service holds).
- Whether the Wi-Fi network you're on adds encryption of its own. The app reads the network's security type only. It never reads the network's name, and it never reads your location.
Two features work on content you hand them directly, and both are also entirely local:
- Check a Link. When you paste a suspicious message in, it is analyzed by Apple's on-device intelligence, on your own device. The message text is never uploaded, never stored on our servers, never seen by us, and never written into your security record.
- QR link safety. When you point the camera at a QR code, the code is read and the link it points to is evaluated on your device. This feature makes no network calls at all. No photo or video is recorded or kept.
All of this is read, analyzed, and turned into a verdict on your device.
Permissions the app asks for, and why
- Camera — used only while the QR scanner is open on screen, to read the code in front of it. Frames are analyzed live and discarded. Nothing is recorded, saved, or transmitted.
- Location (while using the app) — this one deserves an explanation, because it looks like more than it is. iOS will not tell an app anything about the Wi-Fi network you're joined to, including whether it's encrypted, unless that app holds location permission. That is the only reason we ask. The app never reads, stores, or transmits a coordinate, and it asks in context when a scan runs rather than at launch. Decline it and everything else works normally; the app simply reports that it couldn't check your Wi-Fi rather than guessing.
- Notifications — used to tell you when a background scan found something, and when the app's own security record needs attention. You can turn scan notifications off in iOS Settings.
What leaves your device, and why
The app makes a small number of network connections. Apart from the last one, which happens only when you initiate it, none of them carry your scan results, findings, security posture, or personal information. They are the licensing and security mechanisms themselves, and they are limited to the following:
Activating your license
When you enter the activation code your provider gave you, the app sends that code, an opaque install identifier (a random ID generated on install — not your name, Apple ID, phone number, or device serial number), and Apple's App Attest material proving your device is a genuine, untampered Apple device. Our server checks the attestation with Apple, claims one seat in your provider's allotment, and returns a license valid for 21 days that is cryptographically welded to that specific device. We keep a seat record (your provider's ID, the opaque install ID, the device's attestation key ID, whether the seat is active, and the dates it was activated and last renewed) and a log of each license issued to it. Nothing about you and nothing about what your scans found is part of any of that.
Keeping it current (renewal)
Your license is checked on your own device every time the app launches, with no network involved, which is why the app keeps working for up to three weeks with no connection at all. Before it expires, the app quietly renews in the background: it re-proves it's the same device and receives a fresh 21-day license. This carries the same identifiers as activation and nothing else. If your provider has released your seat, the renewal is declined and the app becomes inert when the current license expires.
Proving your security record hasn't been altered
The security record on your device is chained together so that changing an old entry breaks every entry after it. To make that provable rather than merely local, the app periodically sends us a fingerprint of the record's current end point: a 32-byte hash, a counter, and a timestamp, signed by your device. A hash is a one-way summary — it cannot be turned back into the record, and it reveals nothing about what the record says. We store those receipts so that if anyone later rewrites your history, the rewrite contradicts a receipt they never controlled. This happens no more than a few times a day.
Verifying the connection to our service (certificate pinning)
The app sends a contentless request to our own service to confirm that no one is impersonating it or intercepting the connection. This carries no personal data and no scan data. It is the security check itself.
Background scan notifications
Automatic background scanning is included with your provider's license, so the app registers for push notifications and we wake it periodically to run a scan. This uses an Apple-issued push token, which is not personal information and is not tied to your identity. We keep a record of the wake messages we send (which token, when, and whether Apple accepted it) so we can tell whether background scanning is actually working. Those records say nothing about what a scan found. The push itself carries no content — it only tells the app to wake up.
Asking for help (only if you send it)
If you tap "Get help," the app writes a draft email for you containing your latest verdict and findings, so support can understand what you're looking at. It opens in your own mail app; nothing is transmitted unless you read it and send it yourself. Separately, "Copy Support Info" puts a short diagnostic summary on your clipboard — your app version, install ID, provider, and seat, so a technician can find your license. Nothing is sent; you decide where to paste it. These are the only paths by which your findings can reach us, and both require you to act.
Your security record, and who can see it
The app keeps a running record of what it found on your device over time, so that a technician helping you has real history to work from instead of guesswork. Because that record is about you, it is worth being precise about what it holds, where it lives, and who can reach it.
- It records changes, not activity. A scan that finds nothing writes nothing. An entry is written when a finding appears, gets worse, or clears — plus one heartbeat a day, so that a quiet stretch is provably quiet rather than a silent failure. In normal use that's a handful of entries a day at most.
- It records the verdict, never the content. The message you checked, the full web address behind a QR code, and the AI's written explanation of either are all treated as content and none of them are ever written into the record. What goes in is the verdict itself, and for a link, the registered domain it points at. This is enforced by how the record is written, not by a policy someone has to remember to follow.
- It lives on your device, encrypted. The record is encrypted at rest with a key held in your device's Secure Enclave, and it is excluded from device backups.
- It doesn't grow forever. Entries are kept for up to a year, or sooner if the record reaches its size limit. When old entries are dropped, the record says so rather than quietly closing the gap.
- It is not sent to us or to your provider. There is no upload, no export, and no dashboard anywhere that shows it. The only thing that ever leaves your device is the fingerprint described above, which is a hash and cannot be read back into the record.
- Showing it is your action, and it is logged. A technician sees this record only when you open the technician view on your own device, typically while sharing your screen on a support call. When that view is opened, the app writes a permanent entry into your own record saying that it was shown and how much of it was shown. That entry cannot be removed without breaking the chain — which is the point.
One honest limit: the technician view is protected by your device passcode and Face ID, the same as the rest of your device. Anyone who can unlock your device can open it. Treat it the way you'd treat your Photos app.
What your provider can and can't see
They can see, in their licensing console:
- That a seat exists, and the opaque install ID it's bound to
- When it was activated and when it last renewed
- Whether it's still active or has been released
- A label they typed themselves, which may be a name like "Jane's device." Your device never sends this; your provider writes it, so it is their record to correct or remove.
They cannot see, from anywhere:
- Your scan verdicts, findings, or security record
- Messages you check, links you scan, or websites you visit
- Your location, your contacts, your photos, or your apps
- Anything at all in real time. There is no fleet dashboard, no monitoring feed, and no export path. This product is a one-tap check and a record you can show someone — it is not remote monitoring.
Where your provider is responsible. They decide who receives an activation code and can release a seat at any time, which makes the app inert once the current license expires (up to 21 days later, since a released seat is enforced at the next renewal rather than instantly). They choose whether to label your seat and what to write there. If you want to know why the app is on your device, who at your provider can see your seat, or how to have it removed, ask them first — those are their decisions, not ours. If they need our help, we'll work with them.
What we never collect
We do not collect, transmit, sell, or share your personal data. In particular, the app does not collect:
- Contacts, photos, messages, or call history
- The text of anything you check with the phishing checker, or the links behind the QR codes you scan
- Browsing history or the contents of your network traffic
- Your location or your movements (see "Permissions" above for why the app asks for location access anyway)
- A list of the other apps installed on your device
- Advertising identifiers or device identifiers tied to your real-world identity
- Your name, email address, or phone number
There are no third-party trackers, no analytics SDKs, and no advertising networks in the app. There is no advertising or upselling of any kind: there is nothing to sell you in the app, because your provider holds the license.
No selling, no sharing
We do not sell, rent, trade, or share any information with advertisers, data brokers, other companies, or governments. The only third party involved is Apple (for device attestation and push notifications, as described above), which acts under Apple's own privacy terms. Your provider sees only the seat records described above, because those records exist to administer the license they bought.
Data retention
We do not store your scan results, your security record, or personal data. What we hold is the minimum needed to run the license and prove the record hasn't been altered:
- Your seat record and the log of licenses issued to it, kept while your provider's account is active
- The install attestation record (opaque install ID, an attestation public key, timestamps)
- The record fingerprints described above, which are append-only by design — they would be worthless as evidence if we could edit them
- Your push token and the log of wake messages sent to it
On your device, the security record is capped as described above and is deleted with the app. Uninstalling removes the app and its record from your device; ask your provider to release your seat so it returns to their pool. If you emailed support, that message lives in our support mailbox like any other email; ask us and we'll delete it.
Security
Analysis runs inside Apple's app sandbox using on-device machine-learning frameworks. Your security record is encrypted with a key bound to your device's Secure Enclave and excluded from backups. Every network connection the app makes is protected by certificate pinning to prevent impersonation or interception, and the licensing calls are additionally signed by your device's hardware-backed attestation key.
Children's privacy
Lunar Defense Managed is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from children.
Your choices
- Decline camera or location access and keep using everything else.
- Turn off scan notifications at any time in iOS Settings.
- Decide for yourself whether to show the technician view on a support call.
- Uninstall the app to remove it and its record from your device, and ask your provider to release your seat.
Changes to this policy
If we change how the app handles data, we will update this policy and revise the effective date above.
Contact
For questions about why the app is on your device, who holds your seat, or having it removed, contact your IT or security provider first. For questions about this policy or how the app handles data, get in touch with us directly.