Skip to content
Legal

Privacy

Last updated 26 September 2026. The short version: we collect as little as the service needs, we don't sell anything, and there are no trackers on this site.

The open-source library

The lightmoon package runs on your servers and sends nothing to us. Two optional features contact third parties when you turn them on: the breached-password check sends the first five characters of a SHA-1 hash to the Pwned Passwords API, and threat feeds download public IP lists. Neither sends data to LightMoon.

Your account

When you create an account we store your email address, your name if you give one, a salted PBKDF2 hash of your password (never the password), your plan, and the sessions you are signed in with, including each session's browser user agent. If you subscribe, Stripe holds your payment details; we store only the Stripe customer and subscription IDs.

Data your instances send

When you connect an instance with lightmoon/cloud, it sends, for blocked, challenged and monitored requests only:

  • time, request ID, action, reason, HTTP status and method
  • host and path, without the query string
  • IDs of the rules that matched, the attack score and the bot score
  • the client's country and IP address truncated to its /24 (IPv4) or /48 (IPv6) network
  • a short message describing the decision

Bans also send the banned network (the full IPv4 address, or the /64 for IPv6) so that your other instances can apply the ban. Request bodies, headers, cookies, query strings and matched snippets are never sent. Each instance also reports its LightMoon version, runtime and a random instance ID.

You decide what your instances protect, so you are the controller of this data and we process it on your behalf. Tell your users about it in your own privacy notice if it applies to them.

How long we keep it

Events are deleted automatically after your plan's history period: 3 days on Hobby, 30 on Pro and 90 on Business. Hourly totals used for charts are kept for up to 400 days. Expired sessions, password-reset links and bans are deleted within minutes. When you delete a project, its events are deleted with it; when you delete your account, everything tied to it is deleted.

Cookies

The marketing pages set no cookies. The dashboard sets one session cookie to keep you signed in, and the LightMoon browser check that protects the dashboard sets its own cookie to remember a verified browser. Both are strictly necessary. We use no analytics, advertising or third-party scripts.

Who processes data for us

  • Cloudflare hosts the site, the dashboard and its database.
  • Stripe processes payments for paid plans.
  • Contabo hosts the mail server that sends the email confirming your address when you sign up, and password-reset emails if you ask for one. It receives your email address and the message, nothing else.

Your rights

You can see, export or delete your data from the dashboard, and you can delete your account at any time from Account settings. For anything else, including access, correction or objection requests, email privacy@lightmoon.org.