HearthboardFAMILY ORGANIZER

TRANSPARENCY BUILDS TRUST

Privacy policy

Updated: 25 September 2026

Hearthboard (月涌星-生活看板) is operated by 杭州月涌星科技有限公司. This policy covers our app and public website and the information processing involved in our current services. Availability depends on your app version. We do not sell personal information and currently use no advertising SDK.

1. Accounts, profiles and security

2. Household collaboration and personal content

Shared content is available to current household members. Check the selected household before submitting it. Leaving a household is not account deletion and does not automatically erase all shared history. Manage content you are authorized to delete, or contact us with a deletion request.

3. Weather and location

You can select a weather city manually. If you authorize location access, iOS obtains your location and uses Apple reverse geocoding to identify the city. Weather requests preferentially use a nearby catalog city's coordinates, or coordinates rounded to two decimal places. Apple reverse geocoding processes location coordinates; we do not retain raw precise GPS as location history. Your city selection stays on your device. The server temporarily caches weather rather than storing weather coordinates in the database. Configured providers may include Caiyun, Amap or Apple WeatherKit, as described in the sharing list.

4. Device permissions and local settings

You can manage permissions in system settings. Revocation stops subsequent access but does not automatically delete submitted content. Live family location, background tracking, family chat, file messages and WeChat sign-in are not currently available. New processing will be explained and required consent obtained before applicable future features are enabled.

5. Subscriptions, service security and website access

Apple handles App Store payments. We process transaction identifiers, subscription status and entitlement verification, not payment card credentials. Removing the app or deleting your account does not cancel an Apple subscription; cancel it separately in Apple's subscription settings.

To investigate sign-in, message delivery, account support and payment issues, we record login method, outcome category, recent session activity, provider request identifiers, latency and payment notification results. Diagnostic records do not contain passwords, verification codes or sent message bodies. Authorized support access to bound phone numbers, account/login emails and Apple identifiers is audited. Manual recovery still requires proof of an existing bound identity and cannot bypass verification when proof is unavailable.

The website serves static pages. Network services process IP addresses, request paths and browser request information to deliver pages and maintain security. The website currently embeds no advertising or third-party analytics trackers. Language switching uses localized URLs and does not require tracking cookies.

6. Third-party services and disclosures

See our Third-Party Information Sharing List for Apple, Tencent Cloud, Amap and Caiyun. Integrations may use system interfaces, web components or server APIs; they are not all app SDKs.

Configured SMTP services process recipient addresses and verification or security message contents. Only enabled operational subscriptions send registration or first-install events, relevant account/device identifiers, versions and language to WeCom or configured webhook recipients, without household content. Actual email providers and other webhook recipients must be identified before enabling them. This policy is not blanket authorization to disclose information to arbitrary recipients. Adding providers does not replace legally required notice or separate consent.

7. Retention, security and deletion

Account and collaboration data are retained as needed to provide the relevant service or meet legal requirements. Operational diagnostics and account security events have a 90-day retention period; closed identity-recovery support cases and administrator audit records have a 365-day period. Scheduled jobs perform expiry cleanup. Account deletion clears identity-linked diagnostics and sensitive support-case information; necessary audit facts are retained in de-identified form.

We use authentication, household/account access controls, encrypted transport, password hashing and restricted operational access. Business services use Tencent Cloud infrastructure and object storage. Apple and map providers may process information outside China under their policies, so not all processing can be described as exclusively domestic. Cross-border provision requires applicable notices, consent and legal conditions. Backups and legal retention mean deletion does not imply instantaneous removal of every media copy. Contact us about retention or deletion of specific data.

8. Your rights and minors

Manage profiles and bound identities in profile/account-security settings, and edit or delete content where you have permission. Use Settings → Account Security → Delete Account to verify identity and confirm deletion. Personal financial and historical records are removed with account deletion. Shared content follows deletion-eligibility and household rules; review the in-app notice before confirming. You may contact us to request access, a copy, correction, deletion, withdrawal of consent or an explanation of processing. Withdrawal does not affect prior lawful processing. Stopping necessary processing may make related features unavailable.

Minors should use the service under a guardian's guidance. Processing information about children under fourteen requires guardian consent. Family roles and relationship labels do not establish verified guardianship authorization. Guardians can contact us to investigate and address information submitted without consent.

9. Updates and contact

We will update this policy and notify you through in-app notices or other appropriate means of material changes, obtaining renewed consent where required.

Operator: 杭州月涌星科技有限公司. Privacy, account and support requests: support@lunastar.top. Describe your request without sending passwords or verification codes. We may need to verify your identity to protect your account.