← Back to LunaStat
Preview. This document is being finalized with legal counsel and is not yet in force. It will take effect on its stated effective date at launch.

LunaStat — Privacy Policy

Provider: Medresearch LLC, Nashville, Tennessee, U.S.A.

The bright line (this never changes)

**Your datasets, your analyses, your results, and any Protected Health Information (PHI) or patient data

you work with never leave your device. Medresearch does not collect, receive, transmit, or have access to

that content.** LunaStat performs all statistical computation locally, on your computer. This is a core

design guarantee, not a setting.

Everything below describes the limited, PHI-free information LunaStat may handle to operate the

product, provide your license, and improve the Software — and the controls you have over it.

1. Information we may collect (all PHI-free)

a. Account information. If you create a LunaStat account or purchase a paid plan, we collect the

information needed to establish and manage it — such as your name, email address, organization, and

billing details (payment processing is handled by a third-party payment provider; we do not store full

card numbers). We use this to provide the Software, manage your license and subscription, and communicate

with you about your account.

b. License and update data. The Software validates your license and can check for updates. These

exchanges transmit only technical information — such as license identifiers, the current software version,

your operating system, and processor architecture — and never your datasets, results, or PHI.

c. Product analytics (PHI-free). We may collect information about how the Software is used — for

example, which features are opened, aggregate usage counts, and non-content error indicators — to

understand and improve the product. **Analytics events never include your datasets, variable values,

results, file contents, or any PHI.** Where technically feasible you will be able to opt out of

non-essential analytics.

d. Error and crash reports. To find and fix defects, the Software may send diagnostic reports when it

encounters an error — for example, the software version, the operating system, and a technical description

of the fault. Error reports are designed to exclude your dataset content and PHI. Because a fault's

technical details can, in rare cases, incidentally include fragments of the data being processed, error

reporting that could carry such fragments is opt-in, and reports are filtered to remove data content

before transmission.

e. Opt-in telemetry. You may choose to share additional, PHI-free usage and diagnostic information to

help us improve LunaStat. This telemetry is off by default and only collected if you turn it on; you

can turn it off at any time.

f. Support communications. If you contact us for support, we receive the information you choose to send

us (such as your message, contact details, and the software/OS version). **Please do not include PHI,

patient identifiers, or dataset content in support requests** — you should not transmit that information to

us through any channel.

2. What we never collect

3. Your choices and controls

Section 7.

4. How we use and share information

We use the PHI-free information above to operate, secure, support, and improve the Software and to manage

your license. We do not sell your personal information. We share it only with service providers who

process it on our behalf (for example, payment processing, error-reporting, and analytics infrastructure)

under contracts that limit their use of it, and as required by law. Any such providers are selected and

configured so that no PHI or dataset content is ever exposed to them — consistent with the bright line

above.

5. HIPAA and your obligations

The Software is designed so that your datasets, results, and PHI are not received, processed, transmitted,

or stored by Medresearch in the ordinary operation of the Software. Provided you do not transmit PHI to

Medresearch (for example, by including PHI in a voluntary support request), Medresearch does not receive

PHI and therefore does not function as a "business associate" (as defined under HIPAA) under the intended

operation of the Software. You must not transmit PHI to Medresearch through any channel. You remain

responsible for handling the data on your device in compliance with HIPAA and your institution's policies,

including securing your machine and files.

6. The LunaStat website

The LunaStat website (lunastat.app) is informational. It does not use advertising or cross-site

tracking cookies and does not build advertising profiles. If a page-analytics or strictly-necessary cookie

is ever used, it will be limited to operating the site and disclosed here; the website never receives your

datasets, results, or PHI (those exist only in the desktop Software, on your device).

7. Retention, security, international users, children, changes, and contact

tax, and accounting purposes; analytics and telemetry are retained only as long as needed for the

purposes described above.

hold. No method of transmission or storage is perfectly secure.

controller of that PHI-free personal data and honor applicable rights, including access, correction,

deletion, portability, and objection. We do not sell or "share" personal information as those terms are

defined under U.S. state privacy laws.

material changes in the Software's release notes.