Lune Synth Privacy Policy
Effective date: August 13, 2026
1. Scope
This Privacy Policy explains how Griffin Kwan Rutherford, an individual doing business as Coherascent Labs ("we," "us," or "our"), collects, uses, discloses, and retains personal information through the Lune Synth website, waitlist, mobile applications, beta programs, and related services (collectively, the "Service").
It does not govern a third-party site or service that has its own privacy policy. A separate school or enterprise agreement may provide additional or different terms for an organization-managed deployment.
2. Key Commitments
- We use learning content to provide and improve the study experience, not to sell behavioral advertising profiles.
- We do not sell personal information or share it for cross-context behavioral advertising.
- Product analytics are first-party. We do not use a third-party analytics, attribution, or advertising SDK.
- We do not use private learning submissions to train a general-purpose AI model without express permission.
- During the initial beta, direct accounts and the general waitlist are not intended for independent use by children under 13, and we ask that children under 13 not sign up on their own.
- AI feedback is processed by service providers and may be reviewed by a limited number of authorized people when support, safety, or quality review requires it.
- We retain personal information only while it is reasonably needed for the Service, security, support, disputes, or legal obligations.
3. Information We Collect
Information You Provide
| Category | Examples |
|---|---|
| Waitlist and contact information | Email address, signup date, referral or campaign information, beta-interest responses, and communication preferences. |
| Account information | Name, email address, username, profile image, authentication identifiers, age or eligibility confirmations, and account settings. |
| Learning submissions | Photos and scans of handwritten work, typed answers, edited voice transcripts, prompts, questions, notes, homework, course documents, syllabi, reading guides, and related metadata. |
| Voice information | A voice recording sent for transcription, the resulting transcript, and corrections you make before grading. We use voice to transcribe the requested response, not to identify you. |
| Progress information | Scores, feedback, rubric results, recognized steps, practice history, streaks, skill progress, missions, quiz activity, achievements, medals, and study preferences. |
| Support and research information | Messages, bug reports, survey answers, interview notes, grading disputes, and any content you choose to include. |
| Transaction information | Subscription tier, purchase status, renewal date, discount eligibility, transaction identifier, and limited billing metadata. Payment processors handle complete payment-card details. |
| School-provided information | Roster, class, educator, assignment, and education-record information when a school uses an approved organization-managed version of the Service. |
Please avoid placing sensitive personal information in a learning submission when it is not needed. Do not upload Social Security numbers, financial account credentials, medical records, or another person's confidential records through the general consumer Service.
Information Collected Automatically
When you use the Service, we may collect:
- IP address and approximate region derived from it;
- device type, operating system, app version, language, and time zone;
- authentication, network, request, crash, and security logs;
- pages or screens viewed and feature interactions;
- submission mode, image count, processing status, response time, and error information; and
- cookie, local-storage, or similar identifiers needed for sign-in, preferences, waitlist operation, fraud prevention, or analytics.
Product analytics are first-party. The app emits a fixed, predefined set of product events — such as screen views, missions started, completed, or abandoned, answers submitted, grading completed or failed, tutor sessions opened, and API failures — to our own API, where they are stored in our own database. We do not use a third-party analytics, attribution, or advertising SDK, and we do not send these events to an ad network.
Crash and performance reports for beta builds come from Apple TestFlight and the Google Play Console rather than from a third-party crash SDK. See Section 3, "Information From Other Sources."
The mobile app stores preferences, progress, and cached study information locally on your device. Progress also syncs to our servers so it can survive reinstall and appear across devices.
We do not collect precise geolocation, address-book contacts, or biometric identifiers through the general Service. Handwriting and voice are processed as learning content, not for biometric identification.
Information From Other Sources
We may receive information from:
- Apple, Google, or another login provider;
- Apple TestFlight and Google Play testing tracks, which provide tester email addresses, install and session counts, tester feedback and screenshots, and crash and performance reports for beta builds;
- app stores and payment processors;
- a school, educator, parent, or organization that authorizes access;
- referral partners or beta recruiters; and
- service providers that help us detect abuse, operate infrastructure, or understand Service reliability.
4. How We Use Information
We use personal information to:
- operate accounts, authentication, the waitlist, and beta access;
- upload, transcribe, parse, grade, and return feedback on learning work;
- generate study paths, missions, quizzes, hints, audio, and practice;
- calculate and sync progress, streaks, achievements, and recommendations;
- provide support, investigate grading issues, and respond to requests;
- monitor reliability, prevent fraud and abuse, and protect users;
- evaluate and improve grading quality, prompts, rubrics, and user experience;
- administer subscriptions, beta benefits, and the Pro discount;
- send service messages and, with any consent required by law, product or beta updates;
- comply with law and enforce our agreements; and
- create aggregated or deidentified insights that do not reasonably identify a person.
Where applicable law requires a legal basis, our bases may include performing a contract, consent, legitimate interests in operating and securing the Service, and compliance with legal obligations.
5. AI Processing And Human Review
Lune Synth sends relevant portions of a submission and its learning context to AI service providers to perform functions such as visual interpretation, transcription, structured grading, tutoring, study-material generation, and text-to-speech. The data sent may include handwriting, images, typed text, voice, transcripts, question context, and rubric instructions.
We use business and API products whose provider terms do not use API inputs and outputs to train general-purpose models by default. We do not opt private User Content into provider model training without express user or organization permission.
AI providers may temporarily retain limited request data for abuse detection, security, and legal compliance unless a reduced-retention configuration applies. Provider practices can change, so we review material vendor changes and update this policy when needed.
Authorized Coherascent personnel or contractors may review limited submissions and results when needed to:
- answer a support request or grading dispute;
- investigate abuse, safety, or security;
- validate rubric behavior and grading quality; or
- comply with law.
We limit this access by role and purpose. Product quality review uses deidentified, minimized, or expressly consented content whenever practical.
6. How We Disclose Information
We may disclose personal information to the following recipients:
| Recipient | Purpose |
|---|---|
| Infrastructure providers | Authentication, databases, private object storage, hosting, networking, logs, and backups. We use Supabase and Railway. |
| AI providers | Vision, transcription, grading, tutoring, generation, and text-to-speech. We use OpenAI API services. |
| Platform providers | Apple, Google, Expo/EAS, app distribution, sign-in, notifications, and platform services. This includes beta distribution through Apple TestFlight and Google Play testing tracks, which return tester, install, feedback, and crash information to us. |
| Payment providers | Subscription checkout, payment confirmation, fraud prevention, refunds, and tax handling. |
| Schools or organizations | Account, assignment, progress, and result information for an approved organization-managed deployment, according to the applicable agreement and authorization. |
| Professional advisers | Lawyers, auditors, insurers, and consultants who need the information to provide services and are subject to confidentiality duties. |
| Authorities and affected parties | When reasonably necessary to comply with law, protect rights or safety, investigate misuse, or address a security incident. |
| Transaction parties | As part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality protections. |
Service providers may use personal information only to perform services for us or as otherwise permitted by their contracts and applicable law.
We do not disclose personal information to a third-party analytics, attribution, crash-reporting, or advertising provider. Product analytics are collected and stored by us, as described in Section 3.
7. No Sale Or Behavioral Advertising
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising, and we do not use third-party ad networks in the controlled beta.
If this practice changes, we will update this policy, provide legally required notice and choices, and apply heightened protections to minors. We will not use personal information from an under-13 learner for behavioral advertising.
8. Retention
We retain information only for as long as reasonably necessary for the purposes described in this policy, including support, security, legal, and dispute needs. During the beta, we apply the following approach:
| Information | Retention approach |
|---|---|
| Waitlist information | Until you withdraw, the waitlist program ends, or the information is no longer needed for beta recruitment and related communications. |
| Account and profile information | While the account is active and for a limited period afterward to complete deletion, resolve disputes, prevent abuse, and meet legal obligations. |
| Original handwritten scans and images | Stored with submission history while needed to provide grading, account history, support, dispute resolution, security, and quality review. They are deleted in response to a verified deletion request, subject to legal and security exceptions. |
| Typed answers and reviewed voice transcripts | Stored with the submission and grading history while needed to provide account history, progress, regrading, and support. |
| Raw voice audio | Received for transcription and not written by Lune Synth to a durable account record. Our transcription provider may temporarily process or retain request data under its applicable business terms. |
| Grading results and progress | Retained while the account is active so users can review results and maintain learning history, then deleted or deidentified subject to backup, legal, and security needs. |
| Security, audit, and transaction records | Retained for a period appropriate to fraud prevention, incident response, accounting, tax, and legal obligations. |
A retention hold is removed when its purpose ends. Deletion from active systems may take time to propagate through backups. We may retain aggregated or deidentified information that cannot reasonably be linked to you.
9. Children And Teen Users
During the initial beta, the general waitlist and direct-to-consumer Service are not intended for independent use by children under 13; we ask that a child under 13 not create an account or join the waitlist on their own, and we do not knowingly collect their personal information through those flows. This is a current product and consent-control policy, not a permanent exclusion of younger learners. The phrase "Pre-K through PhD" describes the range of learning material the product aims to support; it does not change current account-age requirements.
An under-13 learner may use Lune Synth only through a separate experience that we expressly designate as parent-managed or verified school-managed. Before collecting a child's personal information in that experience, we will provide the required notice and obtain verifiable parental consent unless a lawful school authorization applies.
A parent or guardian may contact us to ask whether we hold a child's information, review or correct it, withdraw consent, or request deletion. We may verify the requester's identity and relationship to the child.
Users ages 13 through 17 must have parent or guardian permission where required by law. We do not sell or share minors' personal information for behavioral advertising.
10. School And Education Records
Data collected through an ordinary consumer account is governed by this Privacy Policy and is not automatically an education record under the Family Educational Rights and Privacy Act ("FERPA").
If a school authorizes Lune Synth under a written agreement, the school controls the education records covered by that agreement. We will act only for the authorized educational purpose, under the school's direct control where required, and will not use those records for behavioral advertising or an unrelated commercial profile.
Students and parents should direct FERPA requests to the school first. The school is responsible for deciding whether and how access, correction, disclosure, and deletion rights apply, and we will assist as required by the agreement and law.
We will not launch school-directed use for children under 13 without completing the necessary contract, authorization, security, retention, parent-rights, and data-governance controls.
11. Your Choices And Privacy Rights
Depending on where you live, you may have the right to:
- know whether we process your personal information;
- access and obtain a portable copy of it;
- correct inaccurate information;
- delete information;
- withdraw consent where processing relies on consent;
- opt out of targeted advertising, sale, or certain profiling;
- restrict or object to certain processing; and
- appeal our decision on a privacy request.
If you have a Lune Synth account, you can delete it from inside the app, without contacting us first. Deleting your account removes your profile, learning submissions, and progress from our active systems, subject to the retention exceptions described in Section 8 and to the time it takes deletion to propagate through backups.
If you use Lune Synth as a guest, in-app deletion is not available directly, because a guest session has no account credential to authenticate the request against. You have two ways to delete anyway:
- Add an email address and password in the app to convert the guest session into an account. Your missions, progress, and streak carry over, and you can then delete the account using the step above. This is the reliable route, because it gives your existing data an identity we can verify you own.
- Uninstall the app. A guest session cannot be recovered without the device it was created on.
If neither option is workable, email us using the method below. We may need information that identifies the session, and without an account we may be unable to locate guest data you cannot help us identify.
You may unsubscribe from promotional email through the link in the message. Essential account, security, transaction, and beta-operation messages may continue while you use the Service.
To exercise a privacy right, email griffin@lunesynth.com with the subject "Privacy Request." Describe the request and the account or email address involved. We may ask for information needed to verify identity, authority, or residency. An authorized agent may submit a request where law permits, but we may require proof of authorization or direct confirmation.
We will not discriminate against you for exercising a privacy right. If we deny a request, you may appeal by replying with the subject "Privacy Appeal." You may also contact your state attorney general or privacy regulator.
Some information may be exempt from a request, including information we must retain for security, fraud prevention, legal claims, taxes, or another legal obligation.
Do Not Track And Global Privacy Control
Some browsers offer a "Do Not Track" (DNT) signal. Because there is no common industry standard for how to interpret DNT, we do not currently respond to DNT signals. Where applicable law requires, we treat a recognized browser- or device-level opt-out preference signal, such as the Global Privacy Control (GPC), as a request to opt out of any "sale" or "sharing" of personal information for that browser or device. As described in Section 7, we do not sell personal information or share it for cross-context behavioral advertising.
12. Additional U.S. State Disclosures
For residents of states with comprehensive privacy laws, the categories of personal information we collect, their sources, purposes, recipients, and retention approach are described above.
Under those laws, these categories include identifiers, account credentials, internet or device activity, commercial information, audio or visual information, educational information, inferences about learning progress, and User Content that may reveal sensitive information.
We use sensitive personal information only to provide, secure, and improve the requested Service; authenticate users; process authorized payments; and comply with law. We do not use it to infer characteristics for advertising.
During the 12 months before this policy's effective date, we did not sell personal information or share it for cross-context behavioral advertising. We do not have actual knowledge that we sold or shared personal information of users under 16.
California and Colorado residents may use the request and appeal methods in Section 11. California residents may also request information about categories collected, disclosed, sold, or shared where the California Consumer Privacy Act applies. Colorado residents may appeal a denied request and contact the Colorado Attorney General if the appeal is denied.
13. Security
We use administrative, technical, and organizational safeguards designed to protect personal information. These include encrypted transport, managed authentication, private object storage, short-lived signed file access, role-based authorization, access logging, secrets management, and production access controls.
No system is completely secure. You are responsible for protecting your credentials and device. Notify griffin@lunesynth.com promptly if you believe an account or the Service has been compromised.
If a data breach requires notice, we will notify affected people and regulators as required by law.
14. International Use
The initial beta and general waitlist are operated from the United States and may be offered to participants in more than one country. Availability and some features or legal terms can vary by region depending on where you are located.
Our systems and providers may process information in the United States and other countries whose laws may differ from those where you live.
15. Changes To This Policy
We may update this Privacy Policy as the Service, vendors, or law changes. We will post the updated version with a new effective date. If a change materially affects how we use previously collected personal information, we will provide additional notice or obtain consent when required.
16. Contact
Privacy questions and requests may be sent to:
Griffin Kwan Rutherford
Coherascent Labs, a Tano Holdings brand
Security reports may be sent to griffin@lunesynth.com.