LunaStat — Privacy Policy
Provider: Medresearch LLC, Nashville, Tennessee, U.S.A.
The bright line (this never changes)
**Your datasets, your analyses, your results, and any Protected Health Information (PHI) or patient data
you work with never leave your device. Medresearch does not collect, receive, transmit, or have access to
that content.** LunaStat performs all statistical computation locally, on your computer. This is a core
design guarantee, not a setting.
Everything below describes the limited, PHI-free information LunaStat may handle to operate the
product, provide your license, and improve the Software — and the controls you have over it.
1. Information we may collect (all PHI-free)
a. Account information. If you create a LunaStat account or purchase a paid plan, we collect the
information needed to establish and manage it — such as your name, email address, organization, and
billing details (payment processing is handled by a third-party payment provider; we do not store full
card numbers). We use this to provide the Software, manage your license and subscription, and communicate
with you about your account.
b. License and update data. The Software validates your license and can check for updates. These
exchanges transmit only technical information — such as license identifiers, the current software version,
your operating system, and processor architecture — and never your datasets, results, or PHI.
c. Product analytics (PHI-free). We may collect information about how the Software is used — for
example, which features are opened, aggregate usage counts, and non-content error indicators — to
understand and improve the product. **Analytics events never include your datasets, variable values,
results, file contents, or any PHI.** Where technically feasible you will be able to opt out of
non-essential analytics.
d. Error and crash reports. To find and fix defects, the Software may send diagnostic reports when it
encounters an error — for example, the software version, the operating system, and a technical description
of the fault. Error reports are designed to exclude your dataset content and PHI. Because a fault's
technical details can, in rare cases, incidentally include fragments of the data being processed, error
reporting that could carry such fragments is opt-in, and reports are filtered to remove data content
before transmission.
e. Opt-in telemetry. You may choose to share additional, PHI-free usage and diagnostic information to
help us improve LunaStat. This telemetry is off by default and only collected if you turn it on; you
can turn it off at any time.
f. Support communications. If you contact us for support, we receive the information you choose to send
us (such as your message, contact details, and the software/OS version). **Please do not include PHI,
patient identifiers, or dataset content in support requests** — you should not transmit that information to
us through any channel.
2. What we never collect
- Your datasets, data tables, variable values, or file contents.
- Your analyses, statistical results, figures, or generated text derived from your data.
- Any Protected Health Information or patient-identifiable information.
- Keystroke, screen-capture, or content-surveillance data of any kind.
3. Your choices and controls
- Analytics: opt out of non-essential analytics in the Software's settings (where available).
- Telemetry: off by default; opt in or out at any time.
- Error reporting: the content-bearing form is opt-in.
- Updates: you can control update checks in the Software's settings.
- Account: you may access, correct, export, or delete your account information by contacting us; see
Section 7.
4. How we use and share information
We use the PHI-free information above to operate, secure, support, and improve the Software and to manage
your license. We do not sell your personal information. We share it only with service providers who
process it on our behalf (for example, payment processing, error-reporting, and analytics infrastructure)
under contracts that limit their use of it, and as required by law. Any such providers are selected and
configured so that no PHI or dataset content is ever exposed to them — consistent with the bright line
above.
5. HIPAA and your obligations
The Software is designed so that your datasets, results, and PHI are not received, processed, transmitted,
or stored by Medresearch in the ordinary operation of the Software. Provided you do not transmit PHI to
Medresearch (for example, by including PHI in a voluntary support request), Medresearch does not receive
PHI and therefore does not function as a "business associate" (as defined under HIPAA) under the intended
operation of the Software. You must not transmit PHI to Medresearch through any channel. You remain
responsible for handling the data on your device in compliance with HIPAA and your institution's policies,
including securing your machine and files.
6. The LunaStat website
The LunaStat website (lunastat.app) is informational. It does not use advertising or cross-site
tracking cookies and does not build advertising profiles. If a page-analytics or strictly-necessary cookie
is ever used, it will be limited to operating the site and disclosed here; the website never receives your
datasets, results, or PHI (those exist only in the desktop Software, on your device).
7. Retention, security, international users, children, changes, and contact
- Retention: account information is retained while your account is active and as required for legal,
tax, and accounting purposes; analytics and telemetry are retained only as long as needed for the
purposes described above.
- Security: we use reasonable administrative and technical safeguards for the PHI-free information we
hold. No method of transmission or storage is perfectly secure.
- International users (GDPR / UK GDPR / CCPA): where we collect account or analytics data, we act as a
controller of that PHI-free personal data and honor applicable rights, including access, correction,
deletion, portability, and objection. We do not sell or "share" personal information as those terms are
defined under U.S. state privacy laws.
- Children: the Software is a professional tool and is not directed to children.
- Changes: we will update this policy and its version date as our practices change, and reflect
material changes in the Software's release notes.
- Contact: Medresearch LLC · 4004B Woodmont Blvd · Nashville, TN 37205, U.S.A. · privacy@lunastat.app.
