Privacy Policy
LAST UPDATED September 2026
1. Overview
Lunichor is local-first. Your game is indexed on your own machine, and the index, project memory, and checkpoints stay on your disk. This policy explains what leaves your machine, where it goes, and what we store.
2. What we collect
Account identity. When you link accounts we receive your Discord user ID and username, and your Roblox user ID and username through OAuth. We never receive your Discord or Roblox passwords.
Workspace data. Conversations, prompts, and settings tied to your account, stored in our database so your work persists.
Project data. The full game index stays on your device. When the agent works, relevant code excerpts are included in prompts sent to the AI model provider. That is the only path game code takes off your machine.
Usage and billing data. Token usage logs and balance records. Payment card details are handled entirely by Stripe; we never see or store them.
Technical data. IP addresses are processed transiently for rate limiting and abuse prevention. The website runs no analytics and no third-party trackers.
3. How we use it
To provide the service, authenticate you, enforce account linking, process payments, prevent abuse and alt-farming, and improve reliability. We do not sell your data and do not use your game code to train models.
4. Third parties that process data
Supabase (authentication and database), Stripe (payments), Discord and Roblox (OAuth), and third-party AI model providers (prompt content while the agent works). Each processes only what it needs under its own privacy policy.
5. Retention and deletion
Account data is kept while your account is active. You may request export or deletion of your account data at any time through the Discord or the contact address in the app. Local data (index, memory, checkpoints) is deleted by removing the app's data folder on your PC. You can unlink Discord or Roblox from those platforms' own settings, which stops future data from flowing.
6. Security
Provider and billing credentials live in server environment variables only. Traffic is encrypted with TLS. Account-link sessions are single-use and expire in ten minutes. Studio commands require the connected plugin to match your linked Roblox identity. No method is perfect, but this is the standard we hold ourselves to.
7. Children
The service is not directed at children under 13, and we do not knowingly collect data from them. Discord and Roblox each set their own minimum ages, which also apply.
8. International processing
Our providers may process data in other countries. Where required, transfers rely on the providers' own safeguards.
9. Changes and contact
We may update this policy; material changes are announced in the app or on this page with a new date. Privacy questions: contact us through the Lunichor Discord or the address listed in the app.
