LunasAI, LLC operates Lunas, a clinical evidence retrieval product. This describes what we collect, where it goes, and what leaves our systems.
Questions, conversation history and uploaded document text are processed by language models running on Amazon Bedrock, inside our AWS account and under our Business Associate Agreement with AWS. Two paths sit outside this — web search and Library summaries — and both are named on the HIPAA page rather than left for you to discover.
This is worth stating precisely, because it is stronger than a policy commitment.Your questions, your conversations and your uploaded documents reach only Bedrock. The client that carries them is constructed so that there is no code path to any other model provider — not a setting that defaults to safe, not an environment flag, but the absence of an alternative. It cannot be switched off by configuration, by a per-user setting, or by an operator, because there is nothing to switch it to.
A property enforced by the absence of a code path is a different kind of assurance from one enforced by a policy: a policy can be changed quietly, and this cannot be changed at all without deleting and rewriting the code that carries your text. We would rather you could check it than take our word for it — which is also why those three things are named individually rather than covered by a phrase like "all your data". Anything not on that list is named as an exception on the HIPAA page.
Uploaded documents are converted into search vectors on our own machines, using a model that runs locally. Uploaded text is never sent to a third-party embedding service. The resulting vectors and text chunks are stored in a vector database we host ourselves, inside our private network — not a managed third-party search service.
There is no Sentry, no Datadog, no PostHog, no Segment, no Mixpanel, no Google Analytics, no session recording and no advertising pixel anywhere in this product. The only third-party script the site loads is Google's sign-in client, which is there to sign you in.
We mention this plainly rather than leaving it as an absence in a list. In a clinical product it is a meaningful difference: your questions are not being replayed, profiled, or shared with a measurement vendor, because no such vendor exists in our stack.
The logged-out question box is protected against automated abuse by Cloudflare Turnstile. To do that, Cloudflare receives the visitor's IP address and signals about how the page was interacted with. This happens before anyone creates an account or agrees to anything, and it is the only place we collect information about people who are not our users. It exists to keep an open, free-to-try surface from being consumed by bots. It is not used to identify you, is not joined to any account, and is not used for advertising.
We keep your account and its contents until you ask us to delete them. Nothing is purged on a schedule — your uploads, collections, conversations and generated documents have no expiry, and they survive a subscription lapsing. That is a deliberate commitment: if a trial or subscription ends, access stops and the work stays, so subscribing later restores everything as you left it.
Anonymous conversations from the logged-out box are the one exception: they are deleted on a schedule, because they belong to no account.
You can delete your account from Settings. It happens immediately, there is no grace period, and we cannot restore it afterwards — not on request, and not by support. Your profile, uploads, collections, conversations and generated documents are destroyed.
Three things survive, and we would rather name them than let you find out.
You can come back. Signing in again with the same Google or Apple account gives you a working account. What you do not get back is your data, a second free trial, or your old handle until the 90 days have passed.
If you would rather we deleted it for you, or you want a copy of something first, write to support@lunasai.health.
Whether you may put patient information into Lunas depends on whether we have a Business Associate Agreement with you or your organisation. That is covered on the HIPAA page. Please read it before uploading anything containing patient data.