Privacy Policy
Privacy Policy Details
Last Updated: March 3, 2026
Introduction
Lunar is an AI-powered tax document processing platform operated by QuantumLoop Labs LLC ("we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at lunar.tax, use our web application, or install our desktop agent (collectively, the "Service").
We understand the sensitivity of the data you entrust to us — including tax forms, Social Security Numbers (SSNs), Employer Identification Numbers (EINs), and other financial information. Protecting that data is foundational to everything we build. Please read this policy carefully. By using the Service, you agree to the practices described herein.
Information We Collect
Account Information
When you create an account or join our waitlist, we collect:
- Full name and work email address
- Firm name and firm size
- Current tax software in use
- Password (stored in hashed form; we never store plaintext passwords)
Tax Documents and Financial Data
When you use Lunar to process tax documents, we receive and store:
- Uploaded tax form images and PDFs (W-2, 1099-INT, 1099-DIV, 1099-NEC, 1099-R, 1098, and other supported forms)
- Extracted data fields, including names, addresses, SSNs, EINs, income amounts, and other tax-related values
- Review notes, corrections, and approval status entered by your team
- Export records and integration logs
Usage Data
We automatically collect certain information when you use the Service:
- IP address, browser type, operating system, and device information
- Pages visited, features used, and actions taken within the application
- Date and time of access, session duration, and referring URLs
- Error logs and performance metrics (with all sensitive data such as SSNs and EINs scrubbed)
Cookies and Similar Technologies
We use cookies and similar tracking technologies to maintain your session, remember your preferences, and analyze usage patterns. See the Cookies and Tracking section below for details.
How We Use Your Information
Service Delivery
- Process, extract, and classify data from uploaded tax documents using our AI extraction engine
- Present extracted data for review and correction in our web interface
- Export approved data into your tax preparation software via our desktop agent
- Manage your account, authenticate your sessions, and enforce access controls
Service Improvement
- Improve the accuracy and performance of our AI extraction models
- Analyze usage patterns to improve the user experience
- Diagnose technical issues and monitor system health
- Develop new features and capabilities
Communication
- Send transactional emails (account verification, password resets, export confirmations)
- Notify you of service updates, maintenance windows, and security incidents
- Respond to your support requests and inquiries
- Send product announcements and feature updates (you may opt out at any time)
Data Security
We take the security of your data extremely seriously. Lunar is built with security-first architecture designed for the unique sensitivity of tax and financial data.
Encryption
- Encryption at rest: All sensitive data — including names, SSNs, EINs, and extracted tax field values — is encrypted using AES-256-GCM before being stored in our database.
- Per-firm encryption keys: Each firm receives its own unique encryption key, managed through enterprise-grade key management infrastructure. A breach of one key cannot expose another firm's data.
- Encryption in transit: All data transmitted between your browser, our servers, and the desktop agent is encrypted using TLS 1.2 or higher.
Access Controls
- Row-level security: Database-level policies enforce strict tenant isolation, ensuring that one firm can never access another firm's data, even in the event of an application-level vulnerability.
- Role-based access: Within each firm, access is controlled by user roles (Admin, Preparer, Reviewer), each with specific permissions.
- Audit logging: All access to sensitive data is logged for accountability and compliance.
Compliance
- Lunar is designed to meet the requirements of IRS Publication 4557 (Safeguarding Taxpayer Data).
- We are actively pursuing SOC 2 Type II certification to independently verify our security controls.
- We follow GLBA (Gramm-Leach-Bliley Act) safeguard requirements applicable to financial data processors.
- SSNs and EINs are scrubbed from all application logs, error reports, and analytics.
Data Sharing and Disclosure
We do not sell your personal information or your clients' data. We never have and never will.
We may share information only in the following limited circumstances:
Service Providers
We work with a limited number of trusted third-party service providers who assist us in operating the Service (e.g., cloud hosting, email delivery, error monitoring). These providers are contractually obligated to protect your data and may only use it to perform services on our behalf.
Legal Requirements
We may disclose your information if required to do so by law, regulation, legal process, or governmental request, including to comply with a subpoena, court order, or similar legal mechanism.
Business Transfers
In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website of any change in ownership or use of your personal information.
With Your Consent
We may share your information for any other purpose with your explicit consent.
Data Retention
We retain your data for as long as your account is active or as needed to provide you the Service. Specifically:
- Account data: Retained for the life of your account and deleted within 30 days of account closure.
- Tax documents and extracted data: Retained until you delete them or close your account. You may delete individual documents and their associated data at any time from within the application.
- Usage and analytics data: Retained in anonymized form for up to 24 months for product improvement purposes.
- Backup data: Encrypted backups are retained for up to 90 days and then permanently destroyed.
Upon request, we will delete your personal data within 30 days, except where we are required by law to retain it (e.g., for tax compliance or legal obligations).
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request that we correct inaccurate or incomplete data.
- Deletion: Request that we delete your personal data, subject to legal retention requirements.
- Data portability: Request your data in a structured, commonly used, machine-readable format.
- Restriction: Request that we restrict processing of your data in certain circumstances.
- Objection: Object to our processing of your data for direct marketing purposes.
- Withdrawal of consent: Where processing is based on consent, withdraw your consent at any time.
To exercise any of these rights, contact us at support@lunar.tax. We will respond to your request within 30 days.
Cookies and Tracking
We use the following types of cookies and tracking technologies:
Essential Cookies
Required for the Service to function. These cookies manage your authenticated session, enforce security controls, and remember your preferences. You cannot opt out of essential cookies.
Analytics Cookies
Help us understand how visitors interact with our website and application. We use this data to improve the user experience. Analytics data is aggregated and does not include sensitive information such as SSNs or EINs.
Managing Cookies
You can control cookies through your browser settings. Most browsers allow you to block or delete cookies. Please note that disabling essential cookies may prevent you from using certain features of the Service.
Children's Privacy
Lunar is a business-to-business service designed for use by accounting professionals and tax preparers. The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal data from a child under 18, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at support@lunar.tax.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make changes:
- We will update the "Last Updated" date at the top of this page.
- For material changes, we will notify you by email and/or a prominent notice within the Service at least 30 days before the changes take effect.
- Your continued use of the Service after the effective date of the revised policy constitutes your acceptance of the changes.
Contact Us
If you have questions about this Privacy Policy, want to exercise your data rights, or have concerns about how we handle your information, please contact us:
- Email: support@lunar.tax
- Company: QuantumLoop Labs LLC
- Website: lunar.tax