Privacy Policy
September 9, 2026 · September 9, 2026
This page describes the data Lunidex processes according to the features actually enabled. It is not personalized legal advice.
You can browse the Pokédex and TCG catalog without an account. Features that save a personal workspace use an account session and Neon synchronization when configured.
1. Account and personal data
Data controller: Esteban Deloge, a non-professional publisher of Lunidex. For data questions, use contact@lunidex.app.
Creating an account is optional for public pages. When an account is created, Neon Auth processes the email address, session identifiers and, if provided, a name or username. Google or GitHub sign-in may be available depending on the service configuration; the selected provider participates in that authentication flow.
When signed in, your personal workspace may synchronize with Neon the data you choose to use: favorites, caught Pokémon, teams, comparisons, progress, quiz data, TCG collection and lists, saved searches, settings and related features. Public profiles, friends, price alerts, battle rooms and notifications are processed only if you use those features.
If you enable a public profile, your handle, display name, avatar, membership date and selected progress counters may appear in the public directory. Accepted friends can see only the collection or deck information enabled in your sharing settings.
Lunidex does not sell this data or use it for personalized advertising. Passwords are managed by the authentication service and are not stored in Lunidex code.
2. Purposes and legal bases
| Processing | Legal basis |
|---|---|
| Account, authentication and synchronization | Performance of the requested service and pre-contractual steps when you create an account (GDPR Article 6(1)(b)). |
| Contact requests | Legitimate interest in answering your request; legal obligation when you exercise a right (GDPR Article 6(1)(f) or 6(1)(c)). |
| Vercel audience measurement, Sentry performance, and Neon/PostHog product measurement | Separate prior consent for optional measurement, which can be withdrawn at any time (GDPR Article 6(1)(a)). |
| Security, abuse prevention and availability | Legitimate interest in securing and maintaining the service (GDPR Article 6(1)(f)). |
| Push notifications | Consent given when enabling the feature and permission from your browser or device. |
3. Browser storage
Your browser keeps elements needed for the experience: the selected language (primedex-lang cookie), consent choices (primedex-consent-v2 localStorage and the PostHog consent gate cookie), measurement session markers, and a local cache of public PokéAPI/TCGdex responses. These caches are not your synchronized personal workspace.
The application shell also uses technical local storage. Syncable personal data is sourced from the account and the user-state API when you are signed in; it is not presented as a durable anonymous collection on this device.
4. Measurement, logs and technical data
Vercel Web Analytics, Speed Insights and Sentry browser tracing or Session Replay load only after your separate audience and performance consent. Replay masks text and inputs, blocks marked areas, and excludes network headers and bodies. Neon and PostHog product measurement is also optional: when allowed, Lunidex sends Neon predefined TCG events for aggregated counters, and PostHog normalized pageviews, explicit product events, errors and performance data with limited properties. After authentication, PostHog may use the stable technical account identifier to connect the anonymous session to the account; email, name and secrets are not sent, and identity is reset at logout.
Lunidex also uses Sentry for error and availability monitoring. The SDK does not send personal data by default, and Lunidex removes URL query parameters, cookies, headers and request bodies before sending. You may also voluntarily send Sentry a message describing a problem from the footer and choose to attach a screenshot; this form asks for neither a name nor an email address, and a screenshot is never captured automatically. Infrastructure and abuse protection may process technical request information such as IP address, URL, timestamp and response code. The contact route validates, rate-limits and forwards messages through Resend but does not store or log message content in Lunidex.
5. Services, recipients and transfers
Neon provides authentication and application data when those variables are configured. Vercel hosts and distributes the application. Sentry receives technical error events and, with consent, performance and privacy-protected replay data. PostHog receives the consented product measurement described above. Resend receives the information required to send contact messages (email address, name, subject and content). PokéAPI, TCGdex and image hosts provide public data requested by the application. Each provider may process technical data under its own terms.
Resend, Sentry, PostHog and Vercel may process data in the United States or other countries according to their configuration. Transfers rely on the safeguards published by the providers, including applicable data processing agreements and transfer mechanisms. See https://resend.com/legal/dpa, https://sentry.io/legal/dpa/, https://posthog.com/privacy and https://vercel.com/legal/dpa.
Lunidex does not deploy advertising pixels, sell data or create advertising profiles. Authentication cookies are managed by Neon Auth; their name and lifetime may depend on the provider configuration.
6. Retention periods
| Category | Period |
|---|---|
| Account, profile and synchronized workspace data | Until account deletion or the end of the relationship, followed by deletion of application data through the account procedure. |
| Neon and PostHog product measurement | Neon aggregated daily counters are retained for 90 days; PostHog data follows the retention configured in the PostHog project. |
| Contact messages | Not stored in the Lunidex database; Resend may process and retain the message according to its terms and retention policy. |
| Technical and security logs | According to the periods configured by Vercel, Neon and other infrastructure providers, limited to what is needed for security and operation. |
7. Your rights and contact
You may request access to your data, rectification, erasure, restriction of processing, portability where applicable, or object to processing based on legitimate interests. You may withdraw consent at any time, without affecting processing already carried out.
You can refuse or withdraw Vercel, Sentry, Neon and PostHog measurement separately through the consent banner or the Manage preferences button in the footer. Withdrawal prevents the affected integrations from capturing new data and clears the local measurement markers handled by the application.
To exercise a right, email contact@lunidex.app or use the account procedure provided by the application. A reasonable verification may be needed before changing or deleting account-linked data.
You may also lodge a complaint with the CNIL: https://www.cnil.fr/.
Measurement
With your choices, Vercel Web Analytics and Speed Insights measure audience and performance. Optional Neon and PostHog product measurement sends predefined TCG events, normalized page views, and limited error/performance context. An authenticated technical account ID may continue an anonymous PostHog session; email, names and secrets are excluded. Replay is consent-gated, sampled and masked. You can withdraw at any time.
This legal document is primarily drafted in French and English. The French version prevails in case of discrepancy, subject to the mandatory provisions of your country of residence.
