Eluna.

Eluna โ€” Privacy Policy and Terms of Use

Effective: 28 August 2026
Applies to: every Eluna application (listed below), on Android and iOS
Publisher and data controller: Serhii Vakulenchyk (“Eluna”, “we”)
Contact: support@eluna-apps.com

The short version

Eluna has no accounts and no servers. There is no sign-up, no profile, and no database of ours anywhere with your name on it. What you write down in an Eluna app โ€” your cycle, your books, your watch history, what you pay for every month โ€” is stored in a database on your own phone, and we cannot read it, because there is nowhere for us to read it from.

That is not the whole story, and the rest of this page is the rest of the story. An app that has to tell you when the next episode airs must ask somebody. An app that converts today's exchange rate must fetch one. Every one of those requests goes directly from your phone to that service โ€” never through a server of ours โ€” and every one of them is listed below, with how to stop it where stopping it is possible.

The apps differ, and this policy does not pretend otherwise: what leaves the device is spelled out per app, and the annex at the end is the summary.

The apps this covers

AppIDWhat it does
Eluna Cyclecom.eluna.cycleMenstrual-cycle and symptom tracker
Eluna Readercom.eluna.readerE-book reader for books you own
Eluna Screencom.eluna.screenTV, film and anime tracker
Eluna Mediacom.eluna.mediaOn-device video, audio, image and GIF converter
Eluna Subscom.eluna.subsSubscription and recurring-payment tracker
Eluna Budgetcom.eluna.budgetExpense tracker with budgets, envelopes and goals
Eluna Kitchencom.eluna.kitchenRecipe book with computed nutrition, food diary and goals

Apps released later are covered by this policy from the day they ship, and the annex is updated with them.

What we never do

  • No account. No sign-up, no sign-in, no user id of ours, no profile of you.
  • No analytics. None of these apps contains an analytics SDK. We do not measure what you tap, read, watch, or log.
  • No crash reporting. No Sentry, no Crashlytics. A crash is written to a log on your device and stays there.
  • No data brokers. We do not sell, rent or share your data. There is no mechanism by which we could.
  • Almost no advertising left, and never personalized. Every app on this page is now ad-free except Eluna Cycle on Android, which still carries the banner described below until its next update reaches Google Play. Where that banner appears it is requested as non-personalized: never chosen from a profile of you or of what you have done in the app.
  • No profiling of the contents. No Eluna app sends what you wrote anywhere for analysis. Not your symptoms, not your notes, not your diary.

What stays on your device

Everything you enter. Concretely, per app:

  • Eluna Cycle โ€” period and cycle dates, basal temperature, symptoms (including intimate ones), moods, medications, notes, and your app PIN. Stored in a local SQLite database; the more sensitive fields (notes, intensities, temperature, sexual activity, exact times) are encrypted with a key held in the device keystore. If you turn cloud sync on, a sealed copy of that history also lives in your own iCloud or Drive โ€” see Cloud backup below.
  • Eluna Reader โ€” the book files you import, their covers, your reading position, highlights, notes, bookmarks, reading statistics, looked-up words, and a full-text index of your books. All local.
  • Eluna Screen โ€” what you track, what you have watched and when, your diary entries, ratings, notes, goals, collections, and any photos you attach to a diary entry.
  • Eluna Media โ€” the files you convert and the files it produces, plus the queue and the history of past jobs. The originals never leave the app, and the results are written where you tell the app to write them.
  • Eluna Subs โ€” your subscriptions, prices, billing dates, payment methods as you label them, categories and notes. The database is encrypted with SQLCipher (AES-256); the key is generated on the device and kept in the Android Keystore or the iOS Keychain, never in the database, the preferences or an export.
  • Eluna Budget โ€” your accounts, transactions and their splits, categories, payees, tags, budgets and envelopes, goals, debts, recurring rules, reconciliations and receipt attachments. The database is encrypted with SQLCipher (AES-256); the key is generated on the device and kept in the Android Keystore or the iOS Keychain, never in the database, the preferences or an export. There is no bank connection and no aggregator: figures are typed in, imported from a statement you pick, or read from a receipt photo on the device.
  • Eluna Kitchen โ€” what you eat and when (the food diary, with portions and grams), your weight entries, what is in your pantry, your shopping list, your meal plan, the recipes you write yourself, your favourites, and any barcodes you add by hand. Height, weight, sex, age and activity level, if you enter them, are used to compute your daily targets and stay on the device.

Uninstalling an app deletes all of it. That is the flip side of local-first, and it is stated again under Your responsibility below.

What leaves your device

Each item below is a direct call from your phone to that service, so that service sees your IP address. None of it passes through a server of ours.

1. Advertising โ€” Eluna Cycle on Android only

Eluna went ad-free. The advertising SDK, its consent flow and the advertising identifier were removed outright: from Eluna Screen in version 1.0.4, and from Eluna Cycle in the build now on the App Store. Eluna Reader, Eluna Media, Eluna Subs, Eluna Budget and Eluna Kitchen have never shipped an ad and contain no advertising code at all. The apps are funded by optional tips instead, described under Purchases below.

One copy in the wild is still behind: Eluna Cycle on Google Play. Its ad-free build exists and is on the App Store, but the Android release is held up, so the version you can install from Play today still carries the banner described in the rest of this section. When that update ships, this section goes with it. Check Settings โ†’ About for the version you have.

Where that banner appears it is a single one. Never an interstitial, never a rewarded video.

It does not appear at all:

  • during the first two weeks after you install the app;
  • ever again, once you bought the one-time “remove ads” purchase โ€” which is no longer sold, because the ads are going away for everyone.

When it does appear, it is served by Google AdMob, which receives your IP address, your device model and OS, and your device's advertising identifier. Ads are requested as non-personalized: they are never chosen from a profile of you or of what you have done in the app. AdMob still uses the identifier for frequency capping and fraud prevention, and that is why consent matters where the law requires it.

In the EEA, the UK and Switzerland, an app that shows one asks first. Google's consent form is shown before the advertising SDK is started, and if you decline it is never started at all โ€” no ad request, no identifier, no ad. You can change your answer at any time from the app's settings, under Ad privacy. Outside those regions no form is required and none is shown.

Google's handling of this data is described at policies.google.com/technologies/partner-sites.

Legal basis: consent (Art. 6(1)(a)) where required; otherwise our legitimate interest in funding a free app (Art. 6(1)(f)).

2. Purchases โ€” tips, in every app

Handled entirely by Google Play Billing or the Apple App Store. They tell the app whether the purchase exists; we never see your payment details, your card, or your name. No third-party purchase-validation service is used โ€” no RevenueCat, no receipt server of ours.

There is nothing to unlock in any Eluna app. Every purchase is a tip, of a few sizes, and it buys no feature: the app is the same before and after. Not tipping costs you nothing and hides nothing. Older versions of Eluna Cycle and Eluna Screen sold a “remove ads” purchase instead; it is no longer offered, and if you bought it there is nothing left for it to do โ€” the ads are being removed for everyone.

3. Catalogues and reference data โ€” Eluna Screen, Eluna Reader, Eluna Subs, Eluna Kitchen

Eluna Screen queries the public catalogues it needs to know anything about a show at all: TMDB, TVmaze, Kitsu, Shikimori and Simkl. They receive the request (a search term, a show id) and your IP address. This cannot be switched off โ€” without it the app knows nothing about any title.

One more is asked only when you open a series: Wikidata (query.wikidata.org) is what tells the app that a show has spin-offs, or that films were made from it โ€” no catalogue above records that. It receives the show’s public IMDb id and your IP address, and nothing else. Wikidata’s data is published under CC0 (public domain).

Optionally, and on by default, an English synopsis can be sent to translated.net (MyMemory) to be translated into your language. The text is public โ€” it came from the catalogues above โ€” but translated.net sees your IP address alongside it. Turning Translate descriptions off stops this completely, and the app then simply shows you the original English text; there is no on-device translator.

Eluna Reader talks to a catalogue only when you open one: the OPDS catalogues (Project Gutenberg, ManyBooks, or any you add yourself) receive your searches and, if the catalogue requires a login, the credentials you gave it. Two lookup features are off by default and, when you switch them on and use them, send the text you selected in your book:

  • the dictionary lookup sends the selected word to en.wiktionary.org;
  • the translation sends the selected passage (up to 500 characters) to MyMemory.

These are the only channels in any Eluna app through which the content of your own file leaves the device, they are opt-in, and they are per-tap.

OCR language models are downloaded from GitHub when you enable a language; the OCR itself runs on the device.

Eluna Subs and Eluna Budget fetch exchange rates so that amounts billed in other currencies can be totalled in yours. The request goes to open.er-api.com, or to cdn.jsdelivr.net if that is unreachable; it asks for the whole rate table and sends nothing about you โ€” not which currencies you use, not what you pay. Those services see your IP address and nothing else. If you never refresh the rates, the app never makes the call.

Two further things in that app are yours to trigger. Importing a subscription from a screenshot reads the picture on the device; the recognition models are downloaded once from GitHub for the language you pick, and the screenshot itself is never uploaded anywhere. And the Manage button opens the provider's own cancellation page in your browser โ€” from that point you are on Netflix's or Spotify's site, under their privacy policy, not ours.

Eluna Media asks nobody anything. It contains no network code: no catalogue, no rates, no model download, no update check. Conversion runs entirely on your phone, and the only address in the whole app is the link to this page.

Eluna Kitchen asks no catalogue about your food. Its recipes and its food table ship inside the app and are read on the device; nothing you eat, weigh or plan is ever sent anywhere. The app downloads two kinds of file from GitHub, and both are plain public downloads that carry nothing of yours: the interface translation for the language you chose, and โ€” only if you ask for it โ€” the barcode pack for a country you pick, so that scanning a package works with no connection at all. Scanning itself is local: the camera reads the code on the device and looks it up in the pack you already downloaded.

4. App updates โ€” Eluna Cycle

Eluna Cycle checks for a code update from Expo's update service (u.expo.dev) on each launch. That request carries the platform, the app's runtime version and your IP address. It carries none of your data. The same app downloads its knowledge-base language packs from GitHub on demand, which tells GitHub your IP and which language you asked for.

5. Cloud backup โ€” Eluna Cycle, Eluna Screen, Eluna Reader, Eluna Subs, Eluna Budget, Eluna Kitchen

Each offers an end-to-end encrypted backup: the library is packaged and encrypted on your phone with a key derived from a password only you know, and the sealed file is placed in your own Google Drive (in the app's hidden appDataFolder, from which the app can see none of your other files) or, on iOS, your own iCloud container.

Google and Apple hold the file. They cannot read it. Neither can we โ€” the key never leaves your device and is stored nowhere, including by us. That also means we cannot recover it for you, which is why the app shows a one-time recovery code when you turn the feature on.

Signing in to Google hands the app your name, email address and profile photo โ€” that is how Google sign-in works, and Google says so in its own consent dialog. Of these the app uses only the email address, and only to show you which account the backup went to. It stays on the device. iCloud needs no sign-in at all and gives the app no account details.

Eluna Reader additionally supports WebDAV and KOSync servers that you choose and configure. Those are your servers; what the app sends them (reading progress, statistics, a backup archive) goes to you, not to us.

Eluna Subs syncs the same way, and it is how the same subscriptions appear on a second device: the encrypted vault travels through your Drive or iCloud, and the password that opens it is set by you on the first device and typed again on the second. It is never sent anywhere, so a forgotten one cannot be recovered by us or by anyone.

Eluna Kitchen syncs the same sealed vault through your own iCloud, and it is off until you turn it on. The payload โ€” your food diary, weight entries, pantry, plan, shopping list and your own recipes โ€” is gzipped and sealed with AES-GCM on the device; the key that opens it is derived from your password with Argon2id and never leaves the phone, which is why a forgotten password cannot be recovered by us or by anyone. A recovery code is offered at setup for exactly that reason.

Eluna Cycle now offers this too, and it deserves saying plainly, because what travels is health data. The feature is off until you switch it on. When you do, the app asks for a password, derives the key from it on the device with Argon2id, seals your cycle history into a vault and puts that file in your own iCloud container (iOS) or the hidden appDataFolder of your own Google Drive (Android). Apple and Google hold a file they cannot read. Neither can we: the password is never sent anywhere, and the one-time recovery code shown when you turn the feature on is the only other way in โ€” we cannot reset either.

The version of Eluna Cycle on Google Play is older than this feature and does not offer it at all. On that build, nothing about your cycle leaves the phone except by the support email below or a backup file you export yourself.

6. Support emails โ€” every app

If you write to support from inside an app, the app can attach diagnostic information. It is shown to you, in the draft, before you send it, and you send it yourself from your own mail app.

In Eluna Cycle that diagnostic bundle is not neutral: with the consent toggle on, it can include your cycle history and the last 30 days of logged symptoms, which are health data of the most sensitive kind. The toggle is off by default and you can send the email without it. Read the draft before you send it โ€” this is the one place where health data can leave your phone, and it leaves it because you pressed send.

Health data โ€” Eluna Cycle and Eluna Kitchen

Everything Eluna Cycle records about your body is a special category of personal data under Art. 9 GDPR. We treat it accordingly:

  • It is stored on your device. It is not sent to us, not analysed by us, and not shared with anyone. We have no copy and no way to obtain one.
  • Predictions and insights are computed on the device. There is no AI service, no remote model, and no server involved.
  • It leaves the phone by exactly three paths, all of which you open yourself: the support email described above, a backup file you export, and โ€” if you switch cloud sync on โ€” the encrypted vault in your own iCloud or Google Drive. In that last case it travels sealed: encrypted on the device with a key derived from your password, unreadable to Apple, to Google and to us. Leave sync off and no copy exists outside the phone at all.
  • Legal basis: your explicit consent (Art. 9(2)(a)), given by entering the data and, for the support email, by ticking the box.
Eluna Cycle is not a medical device. Its predictions cannot be used as contraception and do not replace a doctor. It is a diary with arithmetic on top.

Eluna Kitchen holds health data of a different kind and treats it the same way: what you ate and when, your weight entries, and โ€” if you enter them โ€” your height, sex, age and activity level. All of it is a special category of personal data under Art. 9 GDPR, and all of it stays on the device.

  • Daily targets are computed on the device by published arithmetic โ€” the Mifflin-St Jeor or Katch-McArdle formula โ€” and calibrated against your own weight log. No remote model, no AI service, no server.
  • It leaves the phone by exactly two paths, both of which you open yourself: a backup file you export (plain JSON, so you can read it too), and โ€” if you switch sync on โ€” the sealed vault in your own iCloud. Leave sync off and no copy exists outside the phone at all.
  • Nothing about your food is sent to any catalogue. The recipes and the food table ship inside the app; barcodes are looked up in a country pack you downloaded, on the device.
  • Legal basis: your explicit consent (Art. 9(2)(a)), given by entering the data.
Eluna Kitchen is not a medical device and gives no dietary advice. The calories and targets it shows are arithmetic over the numbers you and the USDA food table supply; they do not replace a doctor or a dietitian, and no recipe in it is a treatment for anything.

Backups you make yourself

You can export your data. Where the file goes is your decision โ€” the app hands it to your system's share sheet and does not know what you pick.

What is and is not encrypted, plainly:

AppExportEncrypted?
Eluna Cycle.eluna backupYes โ€” AES-256 with a key derived from your password
Eluna CyclePDF report for a doctorOptional password protection; unencrypted if you do not set one
Eluna Screenencrypted vault fileYes โ€” same sealed vault used for cloud backup
Eluna Reader.elunabackup archiveNo. It is a ZIP. The password you set is only checked on restore โ€” it does not encrypt the archive, and anything that opens ZIPs can read it
Eluna BudgetJSON exportNo โ€” plain readable JSON, so anything can read your data back. That is the point of it: you can leave whenever you want
Eluna Budgetencrypted backupYes โ€” AES-256-GCM, key derived with PBKDF2-HMAC-SHA256 over 210,000 iterations. A separate file from the plain export, meant for a messenger or a flash drive
Eluna SubsJSON exportYes by default โ€” AES-256-GCM, key derived with PBKDF2-HMAC-SHA256 over 210,000 iterations. You can switch the password off, and then it is plain readable JSON
Eluna KitchenJSON exportNo โ€” plain readable JSON, so anything can read your data back: your diary, weights, pantry, plan, shopping list, your recipes and your own barcodes. That is the point of it โ€” you can leave whenever you want. The sealed vault used for iCloud sync is a separate thing and is encrypted

The Reader row is a fact, not a feature, and it is here because a backup you believe is encrypted and is not is worse than one you know is not.

Eluna Media has nothing of this kind: it keeps no library of yours to export. The files it produces are the output, and you already chose where they go.

Children

No Eluna app is directed to children under 13 (under 16 in the EEA), and we do not knowingly collect data from them. Only one app still shows an ad at all โ€” Eluna Cycle on Android โ€” and it is non-personalized for everyone regardless of age. If you believe a child has provided personal data through an Eluna app, write to us and we will help you delete it โ€” though in nearly every case the data is on the device and deleting the app deletes it.

Your rights

Because there is no account and no server, most of these are things you can do yourself, immediately, without asking us:

  • Access and portability โ€” export your data from the app's settings.
  • Erasure โ€” uninstall the app. If you enabled cloud backup, delete the vault as well (in the app: Cloud sync โ†’ Delete the cloud copy).
  • Withdraw consent โ€” turn off the feature that asked for it: ads consent (EEA users of Eluna Cycle on Android, in Settings), translation, cloud backup, or the support-email diagnostics.
  • Object, or complain โ€” write to support@eluna-apps.com, or to your national data-protection authority.

We hold no personal data about you on any server. We cannot look you up, and a request to us to delete “your data” has nothing on our side to act on. That is a property of the design, not an evasion of the question.

Retention: we retain nothing, because we receive nothing. Data lives on your device until you delete it. If you emailed support, that email sits in our mailbox until we delete it; we delete support correspondence within 12 months.

Changes

If this policy changes materially, the effective date at the top changes with it, and the in-app privacy screen links here โ€” so the version you are reading is the current one.


Terms of Use

License. Downloading an Eluna app grants you a personal, non-exclusive, non-transferable licence to use it. You may not resell it, or redistribute a modified build of it.

The apps change. Features, interfaces, forecasting and reading engines are improved over time. We do not promise that any particular feature will exist forever, and we do not promise the apps are free of defects.

Your data is your responsibility. These apps are local-first: your data lives on your device and nowhere else unless you say otherwise. If you delete an app without exporting your data, or you lose the device, the data is gone, and we cannot recover it โ€” we never had it. Where an app offers a backup, use it. Where a backup is protected by a password only you know, a forgotten password cannot be reset by anyone, including us; that is what the one-time recovery code is for, and it is worth writing down.

Health disclaimer (Eluna Cycle). Not a medical device. Not contraception. Not a diagnosis. Not a substitute for a doctor. Decisions you make on the basis of what the app shows you are yours.

Automated insights. Any insight, summary, forecast or suggestion an Eluna app produces is informational. It is computed by arithmetic on the device, it can be wrong, and it is not advice.

Content you bring. Eluna Reader opens books you supply, and Eluna Media converts files you supply. Whether you have the right to a given file โ€” to read it, to convert it, to keep the result โ€” is between you and whoever holds its copyright; Eluna hosts no content, provides no library of copyrighted works, and neither app removes or circumvents any copy protection.

Liability. To the extent the law allows, we are not liable for data loss caused by device failure, OS updates, uninstalling an app, or a lost password. Nothing here limits liability that cannot be limited by law, and nothing here affects your statutory rights as a consumer.

Purchases and refunds are handled by Google Play or the Apple App Store under their terms; refund requests go to them, not to us.

Annex โ€” what each app actually does

Eluna CycleEluna ReaderEluna ScreenEluna MediaEluna SubsEluna BudgetEluna Kitchen
Account / loginnonenonenonenonenonenonenone
Our serversnonenonenonenonenonenonenone
Analytics / crash SDKnonenonenonenonenonenonenone
Sensitive categoryhealthreading habitsviewing habitsthe files you convertwhat you pay forwhat you earn and spendhealth โ€” what you eat and your weight
Local encryptionpartial (sensitive fields)app files; secrets in keystorenone (device storage)none (device storage)whole database โ€” SQLCipher AES-256whole database โ€” SQLCipher AES-256none (device storage)
Ads (AdMob, non-personalized)removed on iOS; still on Google Play until the pending updateneverremoved in 1.0.4; yes beforenevernevernevernever
EEA consent form (UMP), SDK off until answeredonly where the banner is leftโ€”only before 1.0.4โ€”โ€”โ€”โ€”
In-app purchasetips, unlock nothingtips, unlock nothingtips, unlock nothingtips, unlock nothingtips, unlock nothingtips, unlock nothingtips, unlock nothing
Talks to cataloguesโ€”OPDS, Wiktionary, MyMemory (opt-in)TMDB, TVmaze, Kitsu, Shikimori, Simkl, Wikidatanothing โ€” no network codeexchange rates; OCR models from GitHubexchange rates onlyno catalogue; downloads translation and optional barcode packs from GitHub
Sends anything you wroteonly via support email, opt-inselected text, opt-in per tapโ€”โ€”โ€”only via support email, opt-inโ€”
Update check on launchExpo (u.expo.dev)โ€”โ€”โ€”โ€”โ€”โ€”
Cloud backupiCloud / Drive (E2E), opt-in โ€” not in the Play build yetDrive (E2E), WebDAV/KOSync (yours)Drive / iCloud (E2E)โ€”Drive / iCloud (E2E)Drive / iCloud (E2E)iCloud (E2E), opt-in
Encrypted exportyesno โ€” plain ZIPyesnothing to exportyes by defaultoptional โ€” plain JSON, plus a separate encrypted file