privacy.
the apps and this website are two different things. the apps collect nothing at all. the website is a website, and this page says exactly what it does and what it does not.
the apps
every Cosmicore app runs on your own device. there is no sign-up and no login, no account of any kind, and no server on the other end. an app sends nothing anywhere: no telemetry, no analytics, no crash reports, no update pings, no advertising or tracking code of any sort. we cannot see, access, hand over, sell, or lose your files, because they never reach us.
your work is ordinary files in ordinary formats on your own disk. LunaLog keeps its records as JSON — in your Documents folder on desktop, in the app’s own private storage on a phone — and your photos as ordinary image files; Novelisha keeps one JSON file per book. you can open them in a text editor, copy them to another computer, or read them in twenty years without this software.
the sensitive parts, named. LunaLog is a cycle tracker with a password vault in it, and a privacy page that does not say so is not much use. it holds period dates and predictions, symptoms, moods, intimacy, and a pregnancy log; and in its logins tab, site names, usernames, and passwords. all of it sits in the plain JSON described above, and LunaLog does not encrypt any of it. nothing is transmitted, so none of it reaches us and there is no store of it here to be breached or handed over. the risk that is real is local: whoever can open that folder — or a backup, or a copy synced to another machine — can read what is in it. if you keep passwords or cycle records in LunaLog, put that folder on an encrypted disk, which your operating system can do and this app does not attempt. that is the desktop case. on the Android and iPhone apps there is no such folder to move: the files sit in the app’s own private storage, which other apps on the device cannot read, and the phone encrypts its own storage once you have a screen lock set. a backup you export yourself is an ordinary file wherever you put it, so it deserves the same care as the desktop folder above.
some apps also write a plain-text diagnostic log into their own folder, so that when something goes wrong there is something to read. it stays on your disk, it is never sent anywhere, the app keeps about two weeks of it and deletes the rest itself, and you can delete the lot whenever you like.
because it all lives on your device, backups are yours to keep. deleting a phone app takes its storage with it, the way a phone does with any app. on desktop the files stay where they are, in your Documents folder, until you delete them yourself, which is also why uninstalling never costs you your work.
the app lock is a PIN, not encryption
where an app offers a lock, it is a PIN or your device’s own unlock, and what it does is keep the app closed. it does not encrypt your files, and we never describe it as encryption. anyone with the device and a file browser can open them. if you want the files themselves protected, use your operating system’s disk encryption, which does that properly.
this matters most for the logins tab in LunaLog. a PIN in front of a file of plain-text passwords is a door, not a safe, and it should be read that way when you decide what to keep in there.
permissions the phone apps ask for
this list is what the builds actually request, app by app, rather than the catch-all a privacy page usually prints. each one is asked for when you first tap the feature that needs it, what it reaches stays on the device, and you can decline or revoke any of it in your device settings with the rest of the app still working.
the microphone. all three phone apps ask. LunaLog and Novelisha only if you record a short voice note; Narralog because recording is the whole point of it, so it asks the first time you tap record and keeps the audio as files on your device. recordings are never uploaded and never analysed, and they leave the device only if you export a file and send it somewhere yourself.
photos, reminders, and the lock — LunaLog only. LunaLog asks for your photo library so pictures can go into a journal entry, for permission to show notifications so reminders you set yourself can appear, and, if you switch the app lock on, for the fingerprint or face unlock your phone already has. the PIN remains available either way, and no biometric data is read or stored by us: the phone does the matching and answers yes or no. Novelisha and Narralog ask for none of these three, because neither has reminders and neither has a lock. Novelisha can still attach an image on Android without asking for anything, because the system photo picker hands it the one file you chose and no access to the rest.
the camera. no Android build here holds the camera permission at all. taking a photo hands off to the camera app your phone already has, and only the picture comes back. on iPhone, LunaLog and Novelisha do ask, because that is how iOS does it.
the internet permission. every Android app here lists it, and it is granted at install without a prompt. it is what lets the app load its own screens from inside itself. none of them opens a connection with it, and you can check that by running one in airplane mode.
what happens when you pay
this is the one place any information about you exists at all, so it is worth being exact.
desktop checkout is run by Paddle, who are the merchant of record — legally the seller, not a payment widget. Paddle collects what a seller has to collect: your name, email address, billing address and country, your payment details, and your IP address, which is how the right sales tax or VAT is worked out. Paddle keeps those transaction records for as long as tax law requires. its privacy notice is at paddle.com/legal/privacy.
Cosmicore never sees your card. what reaches this end is an order record: that a purchase happened, and the email address to send the download link to. no card number, no security code, nothing that could be used to charge you again. there is no account to create, so there is nothing to log into and nothing to delete.
phone apps are bought from the App Store or Google Play instead. those stores take the payment under their own privacy policies, and what Cosmicore receives from them is sales figures, not buyers.
the app itself never contacts Paddle, either store, or this site. once the file is on your machine the transaction is over.
this website
cosmicore.net is an ordinary website on ordinary hosting, and it is a different thing from the apps. nothing that happens on this site is ever fed back into an app.
there are no advertising networks here, no social pixels, and no third-party trackers. apart from the analytics described below, the site loads nothing from anyone else’s server: no remote fonts, no CDN, no embedded video, no widgets. there is no contact form, no comment section, and no mailing list, so email is the only way to reach us.
analytics. this site can run Google Analytics 4, and whether it does is a single setting. while that setting is empty, no analytics load, no consent strip appears, and this site sets no cookie at all. when it is filled in, a small strip at the bottom of the page asks first, and nothing loads until you press yes. press no and Google Analytics is never loaded on any page. either answer is remembered in one first-party cookie named cn_consent, which holds nothing but yes or no and expires after a year. if you have never been asked, nothing was ever loaded.
say yes and Google sets its own analytics cookies as well — the usual _ga pair, which tell one browser from another and nothing more. clearing your cookies clears them, and declining means they are never set. the tag is configured to anonymise addresses, and Google Analytics 4 does not store an IP address: it reads one to work out a rough location and discards it. what that produces is page counts and rough country, not who you are, and it is never joined to a purchase or to anything in an app.
server logs. the web host records the usual request log — IP address, time, page, browser — the way every web server does, to keep the site running and defend it. that is the host’s ordinary operation rather than a Cosmicore analytics system, and it has nothing to do with the apps.
checking it yourself
none of the app claims on this page have to be taken on faith. put an app behind a firewall, pull the network cable, or run it on a machine that has never been online: it behaves exactly the same, because there is nothing on the other end for it to talk to. watch it with any network monitor you like and it stays quiet.
your rights, and children
rights like access, correction, and deletion apply to data a company holds about you. Cosmicore holds none from the apps — no account, no profile, no database of users — so there is nothing to request and nothing to erase. for the purchase record, the seller is the one holding it: Paddle for desktop, the store for phone apps, each with its own process. anything you email us is deleted on request.
the apps are not directed to children under 13 and knowingly collect nothing from anyone, children included.
changes
if this page changes, the date below changes with it, and the new version replaces this one at this address.
contact
privacy questions go to hello@cosmicore.net. mail sent here is kept the way anyone keeps mail, and nothing further happens to it.
Cosmicore LLC · New Mexico · last updated September 2026.