LunarShell
ConceptPlans
/
Download

Privacy

Core data stays local.

Updated October 1, 2026

LunarShell for Mac

Notes, preferences, system readings, and thermal history are stored locally on your Mac. LunarShell does not use this local data for advertising. Purchase and entitlement information needed to manage LunarShell AI access may be processed for billing and service delivery.

Max and Lifetime personal API keys

Personal AI API keys are stored in this Mac’s Keychain and are not sent to LunarShell’s billing servers. Chat, connected actions, document review, Module Creator and AI vocabulary generation send the key and required request context directly to the selected provider, whose billing and privacy terms apply. Personal-key requests do not use Lunar Credits. Voice uses the matching OpenAI or xAI key, including delegated Voice 3 reasoning. Missing or disabled keys use managed AI; failed personal-key requests do not fall back to credits.

Optional usage and reliability sharing

The General setting ‘Share usage and reliability summaries’ is off by default. Only if you enable it, we share daily approximate module-visible and mouse-active minutes, interaction and expansion counts, launches, basic error categories, and a count of previous runs without a clean exit. Visibility is not attention; active minutes are a sampled mouse-interaction measure. Summaries include app version and macOS major version. Unclean exits can include force quits and power loss, not just crashes.

These summaries exclude prompts, documents, notes, filenames or paths, audio, screens, typed content, location, account or billing IDs, raw logs, and crash dumps. We use no tracking SDK, advertising, or session replay. A fresh random report ID each day avoids a persistent analytics identity. Summaries go over HTTPS to LunarShell's own endpoint, processed using Vercel and Supabase.

You can preview and clear unsent summaries in Settings. Unsent data stays on your Mac for up to seven previous days and is cleared when sharing is turned off. Received metrics are immediately added to daily totals, not stored as individual reports. Scheduled cleanup removes deduplication IDs within nine days, daily-changing IP-derived abuse-prevention hashes within two days, and aggregate totals within 91 days; backup retention is separate. Hosting providers may process ordinary connection information such as IP addresses and timestamps for delivery and security. Once combined, a particular person's contribution cannot be identified and selectively removed from those totals.

AI connections

With managed AI on Free, Pro, Max, and Lifetime, prompts, relevant conversation context, and responses are processed by LunarShell's managed service and OpenAI. Max and Lifetime support personal API keys for the workflows described above. Pro and Max use weekly Lunar Credits. Managed Voice requires Pro, Max, or Lifetime with sufficient credits and uses a metered relay through OpenAI, with xAI as a connection-time fallback. Voice audio and relevant conversation context are processed by the selected provider. Message dictation remains available.

Optional external assistant connections (MCP)

MCP access is off by default. If you enable it in Settings with verified Max or Lifetime access, a connected external assistant can read supported module data and change media, notes, tasks and settings. Tool results and image/video previews you separately approve for transmission are sent to that assistant, whose privacy terms apply. Local connections use a private socket on your Mac; remote connections use a separately configured tunnel. Personal API keys are not exposed through this connection. Disabling access revokes connections and pending operations; completed changes remain.

Documents and personal facts

Document filing, text extraction, and scan OCR run locally. Before AI analysis or PDF filling, you review and approve the actual recipient, extracted text, and any personal facts selected for filling. Original PDFs and images are not uploaded. Form filling is off by default and produces a reviewable draft while preserving the original. The document archive and personal facts are separate from AI Chat history and memory.

Local AI workspace

Conversations, summaries, optional structured memory, and explicitly saved user memory persist on your Mac. Relevant context may be included in AI requests. Reset AI History removes conversations and structured memory while preserving User Memory.md and project files.

Dictation and local audio

Chat dictation uses Apple's on-device recognition where the Mac and language support it; otherwise Apple's speech service may process the audio. LunarShell does not save dictation audio. Vocabulary Study uses existing Bilingual News recordings. On playback, the app sends the selected card and clip identifiers to LunarShell and downloads the recording from Amazon S3 using a temporary URL. Audio is held briefly in memory and is not cached to disk. The visualizer analyzes system output without creating recorded files. The recorder saves authorized system output and selected inputs as local WAV files and never uploads recordings.

Optional game multiplayer

Starfall Arena online duels share controls, fighter choices and match state with one invited opponent through the existing game relay, only after you create or accept an invitation. Invitations expire after two hours. No profile images, user files, microphone audio or chat are transmitted. Solo and same-Mac matches make no game network requests.

Solo game progress stays on your Mac and makes no game network requests. Only when you create or accept a Team up invitation, game terrain, positions, equipment, combat/loot state and actions pass through a Cloudflare relay to your friend. The relay does not persist gameplay; it retains invitation credentials for up to two hours and temporarily keeps IP-derived hashes and counters to limit room creation. Cloudflare may process ordinary connection information for delivery and security. Keep invitation links private. Ending the host session disconnects the shared session.

Dune Rally friend races use the same invitation and relay service. Only when you create or accept an invitation, vehicle setups, course seed, controls, positions, race state, your chosen username and optional profile thumbnail are shared among up to six invited participants. Imported images are normalized into small thumbnails without metadata. Computer opponents and same-Mac races make no game network requests.

Other provider requests

When enabled, weather and tide features contact the provider identified in the app. In Japan, that may include the Japan Meteorological Agency. Hourly forecasts in Japan and weather outside Japan use Apple Weather. Tide predictions may use JMA or NOAA CO-OPS. Moon calculations run locally.

Wind maps use NOAA GFS data and Apple maps; earthquakes use JMA or USGS. The Star Map is offline. X and flight tracking connect directly to X and aviationstack using your credentials in Keychain. Podcast searches go to Apple, while feeds, artwork, and audio come directly from publishers. Optional Apple Calendar access uses EventKit; your selected calendar provider handles any onward synchronization.

Software updates

By default, LunarShell checks a signed update feed on moonstat.io at launch and about once per day. Downloads begin when you click UPDATE. After verification, LunarShell saves workspace state and restarts. Our hosting provider may process ordinary request information such as IP address, app version, and timestamps for delivery and security. LunarShell disables Sparkle system profiling. Automatic checks can be changed in General settings.

Website and store

Our hosting and security providers may process ordinary request information such as IP address, browser type, and timestamps for delivery, reliability, and abuse prevention. We do not add behavioral analytics in this version of the site.

Payments and orders

Stripe processes LunarShell AI subscriptions. For LunarShell Managed Payments purchases, Link acts as merchant of record and manages tax calculation, transaction support, and refunds. Stripe receives the payment and contact information needed for checkout. We do not receive full card details.

Contact

For privacy questions, email contact@moonstat.io.

LunarShell

Everyday information and tools for your desktop. Mac software designed in Tokyo.

ExploreConceptPlans
StoreCommercial disclosureTermsPrivacy
Tokyo, Japan© 2026 LunarShell