Privacy Policy

We publish one policy per app. Pick the one you're using.

Effective date August 2026 Applies to: Lunar Defense Mobile Security, downloaded from the App Store

Lunar Defense is a device-based security app. Its job is to check whether your device and its network connection show signs of compromise, then tell you what it found and what to do about it. The analysis runs on your device, and the results stay on your device.

This policy explains exactly what that means: what we process locally, the few specific things that do leave your device and why, and what we never touch.

Our approach: on-device first

When you run a sweep, the security checks and the AI model that weighs them run entirely on your device. Your scan results (the findings, the verdict, and the device and network signals we examine to produce them) are computed locally and are never transmitted to us or stored off your device — with one exception, which only happens when you choose it: if you email our support team from inside the app, the message you send contains your findings, because that is the point of it. That path is described below, and nothing is sent until you read the email and send it yourself.

There is no account to create, no profile, and no login.

What we process on your device (and never send)

To assess your device's security, the app inspects local security-relevant signals, such as:

  • Signs that the operating system has been jailbroken or otherwise tampered with, or that unauthorized code is running alongside the app.
  • Whether anything is attached to or monitoring the app.
  • Your network and connection configuration (for example whether a proxy or VPN is present, and whether the secure connection to our service holds).
  • Whether the Wi-Fi network you're on adds encryption of its own. The app reads the network's security type only. It never reads the network's name, and it never reads your location.

Two features work on content you hand them directly, and both are also entirely local:

  • Check a Link. When you paste a suspicious message in, it is analyzed by Apple's on-device intelligence, on your own device. The message text is never uploaded, never stored on our servers, and never seen by us.
  • QR link safety. When you point the camera at a QR code, the code is read and the link it points to is evaluated on your device. This feature makes no network calls at all — not to us, not to anyone. No photo or video is recorded or kept.

All of this is read, analyzed, and turned into a verdict on your device. None of it, and none of the resulting findings, is transmitted to us or retained anywhere off your device.

Permissions the app asks for, and why

  • Camera — used only while the QR scanner is open on screen, to read the code in front of it. Frames are analyzed live and discarded. Nothing is recorded, saved, or transmitted.
  • Location (while using the app) — this one deserves an explanation, because it looks like more than it is. iOS will not tell an app anything about the Wi-Fi network you're joined to, including whether it's encrypted, unless that app holds location permission. That is the only reason we ask. The app never reads, stores, or transmits a coordinate, and it asks in context when you run a scan rather than at launch. Decline it and everything else works normally; the app simply reports that it couldn't check your Wi-Fi rather than guessing.
  • Notifications — used to tell you a background scan found something. You can turn them off at any time in iOS Settings.

What leaves your device, and why

The app makes a small number of network connections. Apart from the last one, which happens only when you initiate it, none of them carry your scan results, findings, security posture, or personal information. They are the security mechanisms themselves, and they are limited to the following:

1

Confirming your device is genuine (Apple App Attest)

To verify that your device is a genuine, untampered Apple device, the app uses Apple's App Attest service and confirms the result with our server. This sends an opaque install identifier (a random ID generated on install, not your name, Apple ID, phone number, or device serial number) and Apple's cryptographic attestation material. Our server keeps a minimal per-install record (the opaque install ID, an attestation public key, and a timestamp) so the check can't be abused. It is not sent with every scan, and it contains nothing about you or what your scans found.

2

Verifying the connection to our service (certificate pinning)

The app sends a contentless request to our own service to confirm that no one is impersonating it or intercepting the connection. This carries no personal data and no scan data. It is the security check itself.

3

Background scan notifications (paid automation tier only)

If you subscribe to the automated-scanning tier, the app registers for push notifications so we can wake it to run scans in the background. This uses an Apple-issued push token, which is not personal information and is not tied to your identity. We keep a record of the wake messages we send (which token, when, and whether Apple accepted it) so we can tell whether background scanning is actually working. Those records say nothing about what a scan found.

4

Payments (Apple In-App Purchase)

Subscriptions are handled entirely by Apple's In-App Purchase system. We never receive or see your payment details. We only receive your subscription status from Apple so the app can unlock paid features.

5

Asking us for help (only if you send it)

If you tap "Get help," the app writes a draft email for you containing your latest verdict and findings, so support can understand what you're looking at. It opens in your own mail app. You read it, edit it if you want to, and send it — or don't. Nothing is transmitted unless you send it yourself. This is the one path by which your findings can reach us, and it exists only because you chose it.

What we never collect

We do not collect, transmit, sell, or share your personal data. In particular, the app does not collect:

  • Contacts, photos, messages, or call history
  • The text of anything you check with the phishing checker, or the links behind the QR codes you scan
  • Browsing history or the contents of your network traffic
  • Your location or your movements (see "Permissions" above for why the app asks for location access anyway)
  • A list of the other apps installed on your device
  • Advertising identifiers or device identifiers tied to your real-world identity
  • Your name, email address, or phone number

There are no third-party trackers, no analytics SDKs, and no advertising networks in the app.

No selling, no sharing

We do not sell, rent, trade, or share any information with advertisers, data brokers, other companies, or governments. The only third party involved is Apple (for device attestation, push notifications, and payments, as described above), which acts under Apple's own privacy terms.

Data retention

We do not store your scan results or personal data, so there is nothing for us to retain about your activity. The only records we keep are the minimal, non-personal anti-abuse and operational records described in "What leaves your device": the opaque install attestation record, and, for subscribers, a push token plus the log of wake messages sent to it. You can end these by uninstalling the app and, for subscriptions, canceling through Apple. If you emailed support, that message lives in our support mailbox like any other email; ask us and we'll delete it.

Security

Analysis runs inside Apple's app sandbox using on-device machine-learning frameworks. The limited network connections we do make are protected by certificate pinning to prevent impersonation or interception.

Children's privacy

Lunar Defense is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from children.

Your choices

  • Use the free, manual-scan tier with no subscription.
  • Decline camera or location access and keep using everything else.
  • Turn off notifications at any time in iOS Settings.
  • Cancel a subscription through your Apple account.
  • Uninstall the app to remove it and stop all activity.

Changes to this policy

If we change how the app handles data, we will update this policy and revise the effective date above.

Contact

Questions about this policy? Get in touch.

Lunar Defense LLC

Email: support@lunardefense.co

Website: lunardefense.co