Cookie Policy
Effective Date: June 24, 2025
This Cookie Policy explains how OS Financial LLC ("Luna Money," "we," "us," or "our") uses cookies and similar tracking technologies when you use our mobile/web application and services (the "Service"). This policy should be read alongside our Privacy Policy and Terms of Service.
Your Privacy Matters: We use only essential cookies for authentication and security. We do not use tracking cookies, advertising cookies, or any cookies that compromise your privacy. All analytics are anonymized and cookie-free.
1. What Are Cookies?
Cookies are small text files stored on your device when you visit a website or use an app. They help services remember your preferences and authenticate your sessions. Cookies can be "session cookies" (deleted when you close your browser) or "persistent cookies" (remain until they expire or you delete them).
2. How We Use Cookies
Luna Money uses a minimal, privacy-focused approach to cookies. We only use strictly necessary cookies required for authentication and security. We do not use cookies for tracking, advertising, or analytics.
Essential Cookies We Use
Cookie Name | Purpose | Duration | Type |
---|
__session | Legacy authentication cookie for maintaining your login session | 24 hours | Essential |
auth_session | Primary authentication cookie for secure session management | 24 hours | Essential |
authSession | Alternative authentication cookie for compatibility | 24 hours | Essential |
Note: All our cookies are marked as HttpOnly
(inaccessible to JavaScript), Secure
(transmitted only over HTTPS), and SameSite=Strict
(protecting against CSRF attacks).
3. Authentication and Security
Our authentication system uses a hybrid approach for maximum security and compatibility:
- Bearer Token Authentication: For API calls, we use JWT tokens in Authorization headers (not stored as cookies)
- Session Cookies: For browser-based authentication, we use secure, encrypted session cookies
- Multi-Factor Authentication: When enabled, adds an extra layer without additional cookies
- Device Fingerprinting: Used for security without storing tracking cookies
4. Third-Party Services and Cookies
Services That Don't Use Cookies
The following third-party services we use do not place cookies on your device:
- Plaid: Financial data aggregation (uses secure API tokens)
- Stripe: Payment processing (tokenized, no cookies on our domain)
- Firebase: Database and authentication backend
- Sentry: Error monitoring (anonymized, no tracking cookies)
- OpenAI: AI services (API-based, no cookies)
Google Services
We use Google services with privacy-preserving configurations:
- Google Sign-In: Only during authentication flow, cookies are managed by Google on their domain
- Google Analytics: Configured with IP anonymization, no user tracking, no advertising features, and no cookies that identify individual users
- reCAPTCHA: Used only on critical forms for security, minimal cookie usage
Privacy First: We've configured all Google services to be as privacy-preserving as possible. Google Analytics is set to fully anonymize all data and does not track individual users.
5. What We Don't Do
Luna Money is committed to your privacy. We do NOT use:
- Advertising or marketing cookies
- Third-party tracking cookies
- Social media cookies
- Cross-site tracking cookies
- Behavioral profiling cookies
- Cookies that share data with advertisers
- Persistent cookies beyond 24 hours
6. Local Storage and Session Storage
In addition to cookies, we use browser local storage and session storage for:
- Caching non-sensitive data to improve app performance
- Storing user preferences (theme, layout settings)
- Temporary form data to prevent loss during navigation
- App state management for better user experience
Important: We never store sensitive financial data, passwords, or personal information in local storage. All sensitive data is encrypted and stored securely on our servers.
7. Managing Cookies
Cookie Controls
Since we only use essential cookies for authentication, disabling them will prevent you from using Luna Money. However, you can manage cookies through:
- Browser Settings: Most browsers allow you to view, delete, and block cookies. Note that blocking our authentication cookies will require you to sign in again.
- Sign Out: Signing out of Luna Money will clear your session cookies.
- Private/Incognito Mode: Browsing in private mode will delete cookies when you close the browser.
Clearing Local Storage
You can clear local storage data through your browser's developer tools or by signing out of the app, which automatically clears cached data.
8. Cookie Security
We implement industry best practices for cookie security:
- Encryption: All session data is encrypted using strong cryptographic algorithms
- Secure Flag: Cookies are only transmitted over encrypted HTTPS connections
- HttpOnly Flag: Cookies cannot be accessed by JavaScript, preventing XSS attacks
- SameSite Strict: Cookies are not sent with cross-site requests, preventing CSRF attacks
- Short Expiration: Session cookies expire after 24 hours of inactivity
- Secure Token Generation: We use cryptographically secure random token generation
9. Updates to This Policy
We may update this Cookie Policy from time to time to reflect changes in our practices or for legal requirements. We will notify you of any material changes by posting the new policy on this page and updating the "Effective Date."
We encourage you to review this Cookie Policy periodically to stay informed about how we use cookies.
10. Contact Us
If you have questions about our use of cookies or this Cookie Policy, please contact us:
OS Financial LLC
502 W 7th St Ste 100
Erie, PA 16502
Email: privacy@osfinancialfreedom.com
Support: support@osfinancialfreedom.com
11. Your Rights
Depending on your location, you may have certain rights regarding cookies:
- Right to Information: This policy provides full transparency about our cookie usage
- Right to Refuse: You can refuse cookies through browser settings (though this will prevent app usage)
- Right to Delete: You can delete cookies at any time through your browser
- Right to Complain: You can contact privacy authorities if you have concerns
© 2025 OS Financial LLC. All rights reserved.
Luna Money - Your trusted financial companion