Updated: 28 September 2026
This list supplements the Privacy Policy for our current services. Processing depends on use of the relevant feature, necessary permissions or an enabled service. System services, server providers and web components are not necessarily SDKs embedded in the app. There is currently no advertising SDK or WeChat sign-in SDK.
1. Apple
- Services and integration: App Store distribution, Sign in with Apple, StoreKit subscriptions and server transaction verification; Core Location / CLGeocoder reverse geocoding; WeatherKit API when configured and called.
- Information and purpose: Apple identifiers and authorized, verified emails link sign-in identities. Transactions and subscription status support payments and entitlements. Authorized location coordinates identify weather cities. WeatherKit receives queried latitude/longitude, country code and time zone for weather.
- Limits: Apple does not provide us with avatars, payment card data or Face ID biometric templates. Weather queries do not include chores, financial records or household schedules. Face ID and local notifications are handled by the OS; this does not mean biometric information is shared with family members or remote push is available.
- Apple Privacy Policy
2. Tencent Cloud
- Cloud servers and COS object storage host business services, databases and selected avatars, household logos, and images and files selected through file-upload features. Infrastructure and upload interfaces process business data, files and necessary request metadata to store and deliver the service.
- SMS server requests include phone numbers, message templates and verification or security-notification parameters for sign-in, binding, changes and account-support checks. Provider acceptance does not guarantee delivery.
- Captcha processes IP addresses, browser/device environment and verification interactions in its web component to issue short-lived proof and prevent abuse. The app does not pass phone numbers to that component.
- Integration uses cloud infrastructure, server APIs, direct object uploads and a web verification component, rather than exclusively native SDKs.
- Tencent Cloud Privacy Policy
3. Amap
- Services and integration: server Web APIs for mainland China weather-city address lookup, reverse geocoding and coordinate conversion.
- Information: city addresses or queried coordinates to identify weather locations, without account identifiers, household calendar or financial content.
- Trigger: weather locations requiring address lookup, reverse geocoding or coordinate conversion.
- Amap Privacy Policy
4. Caiyun Weather
- Service and integration: server weather API when configured and weather is requested.
- Information and purpose: catalog city coordinates or coarse location coordinates for weather queries, without account identifiers, household profiles or collaboration content.
- Caiyun Privacy Policy
5. SMTP email delivery (configuration-dependent)
- Service and integration: server SMTP sends registration, password reset, email binding/change and identity-recovery codes, and security notifications.
- Information and purpose: recipient addresses, sender information, verification/security message bodies and delivery metadata. Login passwords and household content are not sent.
- The actual provider's identity and privacy policy must be verified and disclosed before activation. When email delivery is not enabled, your address and email contents are not sent to this service.
6. WeCom and other operational webhooks (enabled subscriptions only)
- WeCom server group-bot calls send registration or first-install events to the operator's configured group for operational notifications. This is not consumer WeChat sign-in, household chat or task push.
- Registration events contain event type, time, account ID and registration source. First-install events contain event type, time, app device ID, app ID, app version, iOS version and language. These identifiers can be linked and are not anonymous statistics. Payloads do not include passwords, verification codes, phone numbers, emails or household content.
- Other custom webhooks can receive the same fields. The recipient depends on operational configuration. Its identity, purpose and data scope must be verified and disclosed, with applicable notice and consent requirements met, before activation. This clause does not authorize arbitrary external delivery.
- WeCom Privacy Policy
7. Local components and data sources
- MMKV stores preferences and cached data on the device. Our integration does not upload this local data to the component provider.
- The weather city catalog comes from GeoNames under CC BY 4.0. City selection reads the local catalog and does not send user information to GeoNames.
These are local-component and data-source disclosures, not recipients of user information.
8. Changes and contact
Providers may process information outside China under their policies. Domestic distribution and interface language do not determine processing location. Before adding SDKs or changing recipients or purposes, we will update this list and meet applicable notice, consent and cross-border requirements.
Operator: 杭州月涌星科技有限公司. Privacy and support contact: support@lunastar.top.