This notice explains what Turn Byte LLC does with personal data when you use the Lunahra (“the Service”). Turn Byte LLC is the controller of that data. You can reach us at info@turn-byte.com.
The Service handles information about a person’s health and religious practice. Both are special category data under Article 9 of the GDPR, and the whole Service is built on that footing: as little is collected as the Service can work with, nothing is sold or shared for advertising, and no profiling or automated decision-making is carried out.
You can use this without giving us anything
The Service runs in local mode by default. In local mode your dates, settings and lists are held in your browser’s storage on your own device and are never transmitted to us. We cannot read them, restore them, or produce them if asked. Clearing your browser data deletes them.
Creating an account is what moves data to our servers, and it is entirely your choice. It buys you synchronisation across devices, reminders, and the ability to share a read-only link with a rav.
What we hold when you have an account
- Account details — email address, password (stored only as a bcrypt hash), and any name, phone number and address you enter.
- Calendar entries — the type, date, time and onah of each entry, any note you write, and the location the entry was recorded at. This is health data.
- Settings — your shitos, language, location and reminder preferences, your mikvah lists, and your rav’s contact details if you enter them. Your choice of shitos reveals religious belief.
- Share and setup links — a random token, and the rav’s email address where you created a link for one.
- Push subscriptions — the endpoint your browser gives us, if you turn on push reminders.
We do not use analytics, advertising, or third-party trackers, and we set no cookies beyond the one that keeps you signed in.
Why we are allowed to hold it
For the special category data — your entries and your shitos — our lawful basis is your explicit consent under Article 9(2)(a), given when you create an account. For the ordinary account data, it is the performance of our contract with you under Article 6(1)(b). You may withdraw consent at any time by deleting your account, which deletes the data with it; withdrawal does not affect anything done before it.
Reminders and email
Reminder emails and push messages are deliberately contentless: they say a date on your calendar is coming and nothing else, so that a notification on a lock screen or a subject line in an inbox discloses nothing.
Where you ask us to send a question to your rav, we send it to the address saved in your settings and to no other. Where a rav locks your settings, the code that unlocks them is sent only to his address.
Where it is kept, and for how long
Data is stored on servers in the European Union. We keep your account data for as long as your account exists. Deleting your account deletes your entries, settings, links and push subscriptions; backups are overwritten on a rolling basis within 30 days. Individual entries you delete are removed immediately.
Who else sees it
Nobody, unless you send it. We use processors for hosting and for sending email, bound by data processing agreements and located in the European Union or covered by an adequacy decision. A share link you create is readable by whoever holds it — that is what it is for — and you can revoke it at any time. We do not sell data, and we would resist any request to disclose it that was not backed by valid legal process.
Your rights
- Access — a copy of everything we hold about you.
- Rectification — correction of anything wrong.
- Erasure — deletion of your account and its data.
- Portability — your data in a machine-readable form; the export is on the share page.
- Restriction and objection — limits on what we do with it.
- Withdrawal of consent, at any time.
- Complaint to a supervisory authority in your country of residence, work, or where you think something went wrong.
Write to info@turn-byte.com to exercise any of these. We answer within one month.
Security
Traffic is encrypted in transit. Passwords are hashed with bcrypt and never stored in a readable form. Unlock codes are hashed and expire after thirty minutes. Share and setup tokens are 192 bits of randomness. No system is perfect, and we will tell you and the relevant authority without undue delay if a breach affects you.
Children
The Service is not directed at children and accounts are for adults.
Changes
If we change this notice in a way that matters we will say so in the app before the change takes effect. The version and date are at the top of this page.