Lounar / Legal / Privacy Policy

Privacy Policy

For the Lounar AI Armor browser extension — a personal safety net that detects sensitive data in AI prompts and helps your workforce use AI safely. This policy explains what information we collect, how we use it, how we protect it, and your rights regarding your data.

Last updated
January 15, 2026
Controller
OPA Group, Inc.
Contact
help@lounar.com
Scope
Lounar AI Armor
§ 01   Introduction

Introduction

Lounar AI Armor (the "Extension") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, how we protect it, and your rights regarding your data. This policy applies to all users of the Extension, regardless of where you are located.

If you do not agree with this Privacy Policy, please do not use the Extension.

§ 02   Data we collect

What data do we collect?

2.1   Information you provide directly

  • Account / authentication data (if applicable): login credentials, email addresses, authentication tokens.
  • User input: any text, files, or information you explicitly enter into the Extension.
  • Support communication: messages sent through support channels or feedback forms.
  • Payment information (if applicable): credit card or other payment method details, processed securely through third-party payment processors.

2.2   Information collected automatically

  • Extension usage data: features used, buttons clicked, workflows initiated, and frequency of use.
  • Performance data: error reports, crashes, and performance metrics to improve stability.
  • Browser / device information: browser version, operating system, and device type.
  • Timestamps: when you use the Extension.

2.3   Information we do NOT collect

Important

We do not collect your browsing history or monitor websites you visit (unless explicitly required for Extension functionality — see Section 3).

We do not collect personal data from websites you visit.

We do not read the content of your emails, documents, or personal files unless you explicitly share them with the Extension.

We do not collect location data.

We do not collect health, financial, or other sensitive personal information unless required for Extension functionality.

§ 03   How we use your data

How do we use your data?

We use the information we collect for the following purposes:

PurposeData usedLegal basis
Providing the ExtensionUsage data, user input, device infoPerformance of contract / Legitimate interest
Improving the ExtensionUsage patterns, error reports, feedbackLegitimate interest (product improvement)
CommunicationEmail address, communication dataConsent / Contractual obligation
Security & fraud preventionUsage patterns, authentication dataLegitimate interest (security)
ComplianceAll data categories as neededLegal obligation
AnalyticsAggregated usage data (anonymized)Legitimate interest

We limit our use of data strictly to the purposes disclosed in this policy and your Extension listing on the Chrome Web Store.

§ 04   Sharing & third parties

Data sharing & third parties

4.1   Who we share data with

We only share your data with third parties when necessary:

  • Cloud storage providers — none. Purpose: securely store user data. Data shared: none.
  • Analytics services — none. Purpose: understand usage patterns. Data shared: aggregated, anonymized usage data only.
  • Payment processors — ExtensionPay, Stripe. Purpose: process payments securely. Data shared: payment information only (not stored by us).
  • Legal / law enforcement — only when required by law or to protect rights, safety, or property.

4.2   What we do NOT do

We do not

Sell your personal data to third parties.

Share data with advertising networks or data brokers.

Use your data for personalized advertising targeting.

Transfer data to other extensions, apps, or websites without your explicit consent.

Share data for credit-worthiness or lending decisions.

4.3   Data processing agreements

All third-party partners must comply with this Privacy Policy and applicable data protection laws (GDPR, CCPA, etc.). We require data processing agreements with all service providers who access personal data.

§ 05   Retention

Data retention

We retain your personal data only as long as necessary to provide the Extension functionality, comply with legal obligations, resolve disputes, and enforce agreements.

Specific retention periods

  • Account data: retained until account deletion.
  • Usage data: retained for 24 months for analytics purposes, then aggregated and anonymized.
  • Support communications: retained for 24 months after your inquiry is resolved.
  • Payment information: not retained by us; processed and retained by third-party payment processors per their policies.

You may request deletion of your data at any time (see Section 7).

§ 06   Security

Data security

We implement industry-standard security measures to protect your data:

  • Encryption in transit: all data transmitted between your browser and our servers uses HTTPS/TLS encryption.
  • Encryption at rest: sensitive data is encrypted when stored.
  • Access controls: only authorized employees with a legitimate need have access to personal data.
  • Regular security audits: we conduct periodic security reviews and vulnerability assessments.
  • Secure coding practices: we follow OWASP and industry best practices in development.
  • No hardcoded credentials: API keys, tokens, and credentials are never embedded in the Extension code.
No system is perfect

While we work diligently to protect your data, we cannot guarantee absolute security. You use the Extension at your own risk.

§ 07   Your rights

Your rights & data subject requests

7.1   Your rights (GDPR, CCPA, and similar laws)

Depending on your location, you may have the right to:

  • Access — obtain a copy of the personal data we hold about you.
  • Deletion — request erasure of your data ("right to be forgotten").
  • Correction — update or correct inaccurate data.
  • Portability — receive your data in a structured, machine-readable format.
  • Opt-out — withdraw consent for data processing at any time.
  • Restrict processing — limit how we use your data.
  • Object — oppose certain uses of your data (e.g. automated decision-making).

7.2   How to exercise your rights

To exercise any of these rights, email us at help@lounar.com with:

  • Your name and account email.
  • Clear description of your request.
  • Any relevant documentation.

We will respond within 30 days (or as required by applicable law). Some requests may take longer depending on complexity.

7.3   Withdrawal of consent

If you previously consented to data processing, you may withdraw consent at any time. Withdrawal does not affect the legality of processing prior to withdrawal.

§ 08   Regional compliance

Regional privacy compliance

8.1   GDPR (European Union)

If you're in the EU, additional rights apply:

  • We process data based on your consent, contract performance, or legitimate interests.
  • You have enhanced rights regarding data processing.
  • We comply with data protection impact assessment (DPIA) requirements for sensitive processing.
  • We have a Data Protection Officer (DPO) if required. Contact: help@lounar.com.

8.2   CCPA / CPRA (California)

If you're a California resident:

  • You have the right to know what personal data is collected, used, shared, or sold.
  • You have the right to delete personal data collected from you.
  • You have the right to opt out of "sales" or "sharing" of personal data (we do not sell or share your data).
  • You have the right to correct inaccurate personal data.
  • You have the right to limit use of your sensitive personal information.

California residents may submit requests to help@lounar.com.

Do Not Sell My Personal Information

We do not sell personal data. This statement confirms compliance with CCPA.

8.3   Other U.S. state laws

We comply with emerging state privacy laws including:

  • Virginia (VCDPA)
  • Colorado (CPA)
  • Connecticut (CTDPA)
  • Utah (UCPA)
  • Montana (MCDPA)
  • Illinois (BIPA)
§ 09   Children's privacy

Children's privacy

The Extension is not intended for users under the age of 13 (or the applicable minimum age of digital consent in your jurisdiction). We do not knowingly collect personal data from children under 13.

If we discover we've collected data from a child under 13, we will delete it immediately. If you believe we've collected data from a child under 13, please contact us at help@lounar.com.

§ 10   Cookies & tracking

Cookies & tracking technologies

10.1   Local storage

The Extension may use browser storage (localStorage, sessionStorage, IndexedDB) to save your preferences, settings, and session data for functionality. This data is stored locally on your device and is not transmitted to our servers unless you explicitly sync your settings.

10.2   Third-party scripts

If the Extension loads third-party scripts or resources (e.g. libraries, fonts), those third parties may use cookies or tracking technologies per their own privacy policies.

10.3   No cookies for tracking

We do not use cookies or tracking pixels for behavioral tracking, analytics, or advertising purposes.

§ 11   International transfers

Data transfers & international processing

If you access the Extension from outside the United States, your data may be transferred to, stored in, and processed in countries other than your country of residence. These countries may have data protection laws different from your country.

By using the Extension, you consent to the transfer of your data internationally. We will take appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs) for EU–US transfers.
  • Adequacy decisions where applicable.
  • Your explicit consent when required.
§ 12   Third-party links

Third-party links & services

The Extension may contain links to third-party websites or services. We are not responsible for their privacy practices. This Privacy Policy applies only to the Extension; third-party sites have their own privacy policies.

When you leave the Extension and visit a third-party site:

  • Your data is governed by their privacy policy, not ours.
  • We recommend reviewing their privacy policies before providing personal data.
§ 13   Changes

Changes to this Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our data practices, new legal requirements, technology improvements, and user feedback.

We will notify you of material changes by

  • Posting the updated policy in the Extension with a new "Last Updated" date.
  • Sending you an email (if you've provided contact information).
  • Requiring your consent before material changes take effect (where required by law).

Your continued use of the Extension after changes constitutes acceptance of the updated Privacy Policy.

§ 14   Contact

Contact us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Data controller
OPA Group, Inc.

We will respond to inquiries within 30 days.

Data protection authority

If you believe we've violated your privacy rights, you may lodge a complaint with your local data protection authority:

  • EU: your local Data Protection Authority.
  • California: California Attorney General or CPRA enforcement agencies.
  • Other regions: contact your local privacy regulator.
§ 15   Compliance

Compliance statement

Google API user data policy

We certify that the use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

This Extension complies with:

  • Chrome Web Store Developer Program Policies.
  • GDPR — EU General Data Protection Regulation.
  • CCPA / CPRA — California Consumer Privacy Act.
  • COPPA — Children's Online Privacy Protection Act.
  • Other applicable privacy laws.
APX A   Data reference

Appendix A · Data processing quick reference

Data type How collected Purpose Retention Sharing
Account email User input Authentication, support Until account deletion No
Usage analytics Automatic Product improvement 6 months, then anonymized Analytics provider only
Error logs Automatic Debugging, security 90 days Internal only
User settings Local storage Preserve preferences Until deletion Not shared
Payment info User input Transaction processing Payment processor (not us) Payment processor only
APX B   Glossary

Appendix B · Glossary

TermDefinition
Personal dataInformation that identifies or could identify an individual.
ProcessingAny operation on data — collecting, using, storing, transferring, deleting.
Data subjectThe individual whose data is processed.
Data controllerThe entity deciding how and why data is processed (us).
Data processorThird party processing data on behalf of the controller.
ConsentFreely given, specific, informed, and unambiguous agreement to data processing.
Legitimate interestA legal basis for processing based on balancing interests.
GDPREU regulation on data protection.
CCPACalifornia consumer privacy law.
↑Back to top