top of page

Privacy Policy

Last Updated: June 12, 2026

This Privacy Policy explains how Lunar Moth Studios ("Lunar Moth Studios," "we," "us," or "our") collects, uses, discloses, stores, and protects information in connection with our website, forms, scheduling pages, Operational Review calls, consulting services, software services, AI agent systems, automations, prototypes, workflows, and related offerings.

This Privacy Policy applies to Lunar Moth Studios' current website, services, and business offerings focused on operational software, AI agent systems, automation, data workflows, and related business services.

By using our website, submitting information, booking a call, communicating with us, or using our services, you acknowledge that you have read and understand this Privacy Policy. If you do not agree with this Privacy Policy, do not use our website or services.

1. Important AI and Data Privacy Notice

AI agents and automation systems are not private, safe, or risk-free by default. Building, evaluating, configuring, testing, or operating AI agents may involve processing prompts, instructions, files, screenshots, workflow descriptions, logs, business records, API responses, database fields, system outputs, model responses, tool calls, and other information.

Depending on the project, AI-agent-related data may be processed by Lunar Moth Studios, third-party AI model providers, cloud providers, automation platforms, analytics tools, logging tools, data stores, integration platforms, communication tools, repository providers, or other service providers. AI systems can also create new privacy and security risks, including unintended data disclosure, excessive data collection, prompt leakage, retrieval of the wrong information, unauthorized tool use, logging of sensitive data, or disclosure through third-party systems.

Do not submit sensitive, regulated, confidential, or highly personal information through our website forms, scheduling tools, email, or general intake process unless we have expressly agreed in writing to receive and handle that information. If a project requires sensitive data, credentials, production access, personal information, customer data, employee data, or regulated information, we should define the applicable access, privacy, security, retention, and data-processing requirements in a separate written agreement before work begins.

2. Information We Collect

We may collect the following categories of information:

Information You Provide Directly

This includes information you submit through our website, forms, scheduling tools, email, calls, documents, messages, invoices, proposals, or other communications, such as:

  • Name

  • Email address

  • Phone number

  • Job title or role

  • Company name

  • Website or social profile

  • Business address or billing information

  • Operation type

  • Estimated budget

  • Timeline

  • Project goals

  • Workflow descriptions

  • System descriptions

  • Reporting pain points

  • Technical requirements

  • Messages, notes, or attachments you choose to provide

Business and Operational Information

When you request an Operational Review call or engage us for services, you may provide business or operational information, such as:

  • Reports, dashboards, spreadsheets, or samples

  • Workflow diagrams or written workflow descriptions

  • Vendor, asset, facility, portfolio, or operational context

  • Data-source descriptions

  • Software stack information

  • Tooling, integration, API, or database context

  • Process bottlenecks, handoffs, approval flows, and recurring reporting needs

  • Screenshots, documents, call notes, or examples

AI-Agent and Technical Data

If we help evaluate, design, prototype, build, test, or support AI agents, automations, workflows, or software systems, we may process technical information such as:

  • Prompts, system instructions, model inputs, and model outputs

  • Tool-call logs and API responses

  • Agent traces, evaluation records, test cases, and debug logs

  • Code, scripts, configuration files, prompt templates, and workflow definitions

  • Sample datasets, database schemas, field names, metadata, and documentation

  • Integration credentials or access details, if separately authorized

  • Files, screenshots, exports, or records used to test or validate workflows

  • Error logs, runtime logs, deployment logs, monitoring data, and usage information

Website and Device Information

When you visit our website or interact with online services, we may automatically collect limited technical information, such as:

  • IP address

  • Browser type

  • Device type

  • Operating system

  • Referring URLs

  • Pages visited

  • Time and date of visit

  • Cookie identifiers

  • Approximate location derived from IP address

  • Form interaction or analytics events

Our website may be hosted or supported by third-party platforms such as website builders, hosting providers, analytics providers, scheduling tools, or form processors. Those providers may collect information according to their own privacy policies and settings.

Payment and Transaction Information

If you purchase services or pay invoices, payment processors or billing providers may process payment-related information. We generally do not directly store full payment card numbers. Payment processing is handled by third-party providers subject to their own terms and privacy policies.

Communications

If you contact us, we may collect and retain the content of your messages, email address, attachments, call notes, scheduling history, and related communications.

3. Information We Do Not Want Through General Intake

Unless we expressly agree in writing, do not provide us with:

  • Protected health information

  • Payment card numbers

  • Social Security numbers or government identification numbers

  • Consumer credit, lending, housing, insurance, benefits, or eligibility data

  • Children's data

  • Biometric data

  • Precise geolocation data

  • Criminal history data

  • Union membership, political, religious, or highly sensitive demographic data

  • Highly sensitive employee, customer, tenant, patient, or consumer records

  • Trade secrets or third-party confidential information you are not authorized to share

  • Production credentials, passwords, API keys, private keys, tokens, or secrets through unsecured channels

If you provide this information without prior written approval, you do so at your own risk, and you remain responsible for all legal, contractual, privacy, security, and regulatory obligations related to that information.

4. How We Use Information

We may use information for the following purposes:

  • Responding to inquiries

  • Scheduling and conducting Operational Review calls

  • Evaluating whether and how we can help with operational software, AI agents, automations, or workflows

  • Preparing proposals, statements of work, estimates, invoices, or project plans

  • Providing consulting, software, AI-agent, automation, workflow, data, reporting, or implementation services

  • Creating notes, diagrams, recommendations, prototypes, code, workflows, prompts, configurations, or deliverables

  • Testing, debugging, evaluating, and improving systems related to a project

  • Communicating with you about services, scheduling, billing, updates, or support

  • Maintaining internal business records

  • Improving our website, services, processes, templates, and offerings

  • Protecting security, preventing misuse, and enforcing our Terms of Service

  • Complying with legal, regulatory, contractual, tax, accounting, or dispute-resolution obligations

We may also use de-identified, aggregated, or non-confidential learnings to improve our general methods, templates, workflows, prompts, and services, provided that we do not disclose your confidential information, personal information, or Client Materials in violation of a written agreement.

5. AI Model Providers and Third-Party AI Processing

Some services may involve third-party AI model providers or AI infrastructure providers. Depending on the project, information may be sent to or processed by those providers to generate model outputs, classify data, summarize text, retrieve information, call tools, draft content, analyze workflows, write code, or perform other AI-related tasks.

We will use commercially reasonable efforts to select appropriate tools and settings for the project, but we do not control every aspect of third-party model-provider operations, security practices, retention periods, training policies, or terms. Third-party providers may process information according to their own terms, privacy policies, data processing agreements, API settings, enterprise settings, or service configurations.

Unless expressly stated in a separate written agreement, you should assume that information provided for AI-agent design, testing, or operation may be processed by third-party services involved in the applicable workflow. Do not provide sensitive or regulated data for AI processing unless we have agreed in writing on the relevant providers, settings, security requirements, data-processing terms, and risk controls.

AI agents may also create or expose information through their actions. For example, an agent may place information into prompts, logs, tool calls, API requests, database queries, tickets, emails, chat messages, documents, spreadsheets, browser sessions, repositories, analytics systems, or other connected systems. Even when an agent is intended to use limited data, errors in configuration, retrieval, permissions, prompts, tool design, or third-party systems may cause data to be accessed, transmitted, stored, or displayed in unintended ways.

For that reason, AI agents should be designed and operated using least-privilege permissions, test data where possible, human approval gates, monitoring, logging, redaction, credential isolation, and other controls appropriate for the sensitivity of the data and the risk of the workflow. Unless otherwise agreed in writing, you are responsible for deciding what data an AI agent may access and for supervising the agent's use of that data in your environment.

6. Training and Improvement

We do not sell your personal information.

We do not intentionally use your confidential Client Materials or personal information to train a public AI model owned by Lunar Moth Studios. However, third-party AI providers may have their own training, retention, abuse-monitoring, logging, or service-improvement practices depending on the provider, account type, settings, and agreement in place.

If a project requires restricting third-party model training, limiting retention, using enterprise AI settings, using local models, or applying specific data-processing terms, those requirements must be identified before work begins and documented in writing.

7. How We Disclose Information

We may disclose information in the following circumstances:

Service Providers

We may share information with vendors and service providers who help us operate our business and provide services, such as:

  • Website hosting and website-builder platforms

  • Form and scheduling providers

  • Email and communication tools

  • Cloud hosting providers

  • AI model providers and AI infrastructure providers

  • Automation and integration platforms

  • Code repositories and development tools

  • Analytics and logging providers

  • Payment processors and billing tools

  • Document, storage, and collaboration tools

  • Professional advisors such as lawyers, accountants, or insurance providers

Project-Related Tools and Integrations

If a project involves your tools, accounts, APIs, repositories, databases, or third-party systems, information may be processed by those tools as necessary to perform the work you requested.

Legal, Safety, and Enforcement

We may disclose information if we believe it is necessary to:

  • Comply with law, legal process, or government requests

  • Enforce our Terms of Service or agreements

  • Protect our rights, property, safety, or security

  • Protect the rights, property, safety, or security of others

  • Prevent fraud, abuse, unauthorized access, or harmful activity

  • Resolve disputes or collect amounts owed

Business Transfers

If Lunar Moth Studios is involved in a merger, acquisition, financing, restructuring, sale of assets, or similar business transaction, information may be disclosed or transferred as part of that transaction, subject to appropriate confidentiality protections where applicable.

8. Cookies, Analytics, and Tracking

Our website may use cookies, pixels, local storage, analytics tools, or similar technologies to operate the website, remember preferences, understand website usage, improve performance, and measure marketing or form activity.

Depending on the website platform and tools in use, third-party providers may set cookies or collect technical information. You can control cookies through your browser settings. Disabling cookies may affect website functionality.

We do not knowingly use website data to sell personal information or for cross-context behavioral advertising unless we clearly disclose that practice and provide any legally required choices.

9. Data Retention

We retain information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide services, maintain business records, comply with legal and accounting obligations, resolve disputes, enforce agreements, protect security, and improve our services.

Retention periods vary depending on the type of information and context. For example:

  • Inquiry and form information may be retained for business follow-up and recordkeeping.

  • Project materials may be retained during the engagement and for a reasonable period afterward.

  • Billing and transaction records may be retained as required for tax, accounting, and legal obligations.

  • Logs and technical records may be retained for troubleshooting, security, and service improvement.

  • Information subject to a written agreement may be retained or deleted according to that agreement.

If you want us to delete certain information, contact us. We will honor deletion requests where required by law and where we are able to do so, subject to legal, contractual, security, accounting, backup, and legitimate business limitations.

10. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, disclosure, alteration, and destruction. These safeguards may include access controls, limited access, secure communication methods, vendor review, password management, and other security practices appropriate to the nature of the information and project.

No method of transmission, storage, software development, AI processing, or electronic communication is completely secure. AI-agent work can create additional security risks because agents may interact with tools, APIs, files, databases, communications, and third-party systems. You are responsible for controlling access to your systems, rotating credentials, limiting permissions, maintaining backups, reviewing logs, revoking access when work ends, and supervising any system you deploy.

If we become aware of a security incident affecting personal information for which we are legally responsible, we will take steps required by applicable law.

11. Your Responsibilities

You are responsible for:

  • Providing accurate information.

  • Avoiding unnecessary sensitive data disclosures.

  • Obtaining required permissions before sharing data with us.

  • Ensuring your use of our services complies with laws, contracts, internal policies, and third-party rights.

  • Reviewing and approving any third-party tools, AI providers, and integrations used for your project.

  • Maintaining backups of systems and data.

  • Managing credentials, access controls, and user permissions.

  • Reviewing AI outputs before relying on them.

  • Supervising any AI agents, automations, workflows, or software systems used in your business.

12. International Data Transfers

We are based in the United States. If you access our website or services from outside the United States, your information may be processed in the United States or other countries where we or our service providers operate. Those countries may have privacy laws different from those in your jurisdiction.

Where required, we will use appropriate safeguards for international transfers, such as contractual protections or other legally recognized mechanisms.

13. Privacy Rights

Depending on your location and applicable law, you may have rights regarding your personal information, such as the right to:

  • Know or access the personal information we collect about you.

  • Request correction of inaccurate information.

  • Request deletion of personal information.

  • Request a copy of your information.

  • Object to or restrict certain processing.

  • Withdraw consent where processing is based on consent.

  • Opt out of certain sales, sharing, targeted advertising, or profiling where applicable.

  • Not be discriminated against for exercising privacy rights.

These rights may be subject to exceptions and limitations. To exercise privacy rights, contact us at mike@lunarmothstudios.com. We may need to verify your identity and authority before responding.

14. California Privacy Notice

If California privacy law applies to our handling of your personal information, California residents may have rights to know, access, correct, delete, and opt out of certain uses of personal information, and the right not to be discriminated against for exercising those rights.

We do not sell personal information in the ordinary meaning of the word "sell." We do not knowingly sell or share personal information of individuals under 16. If our use of cookies, analytics, advertising tools, or other technologies is considered a "sale" or "sharing" under California law, we will provide legally required notices and opt-out mechanisms.

In the preceding 12 months, we may have collected the categories of personal information described in this Privacy Policy, including identifiers, professional or employment-related information, commercial information, internet or electronic network activity information, geolocation derived from IP address, and inferences related to business needs or service interest. We collect and disclose those categories for the purposes described in this Privacy Policy.

15. GDPR / UK GDPR Notice

If the GDPR or UK GDPR applies, Lunar Moth Studios may act as a data controller for information collected through our website, forms, scheduling tools, communications, billing, and business development activities.

For certain client projects, our role may depend on the nature of the work. We may act as an independent controller, processor, service provider, contractor, or subprocessor depending on the data, systems, instructions, and written agreement in place. If a project requires processing personal data on your behalf, additional data processing terms may be required before work begins.

Our legal bases for processing may include:

  • Performance of a contract or taking steps before entering into a contract.

  • Legitimate interests, such as responding to inquiries, improving services, protecting security, and operating our business.

  • Consent, where required.

  • Compliance with legal obligations.

Where GDPR or UK GDPR applies, you may have rights to access, rectify, erase, restrict, object to processing, data portability, withdraw consent, and lodge a complaint with a supervisory authority.

16. Children's Privacy

Our website and services are intended for adults and business users. We do not knowingly collect personal information from children under 13, and our services are not directed to children. If you believe a child has provided personal information to us, contact us and we will take appropriate steps as required by law.

17. Third-Party Links and Services

Our website or communications may link to third-party websites, platforms, tools, or services. We are not responsible for the privacy practices, content, security, or policies of third parties. You should review the privacy policies of any third-party services you use.

18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The updated version will be posted with a new "Last Updated" date. Your continued use of our website or services after an updated Privacy Policy is posted means you acknowledge the updated policy.

If we make material changes to how we use personal information, we will provide notice as required by law.

19. Contact Us

If you have questions about this Privacy Policy or want to exercise privacy rights, contact us at:

mike@lunarmothstudios.com

Lunar Moth Studios

bottom of page