01
Data controller
The data controller is Gabriele Cogni, operating under the name Project Lunas.
projectlunas@tutamail.comPrivacy
A plain-language account of what projectlunas.org processes, why it is needed and how long it is kept.
Effective 15 August 2026. This notice covers projectlunas.org and the contact paths published on it.
Scope at a glance
Project Lunas does not operate public user accounts, a newsletter or advertising profiles. A restricted account area is available only to authorized Project Lunas operators. The site is hosted on Cloudflare Pages, reads public repository data from GitHub and uses Supabase to receive and manage commission enquiries, community project submissions and voluntary team applications.
01
The data controller is Gabriele Cogni, operating under the name Project Lunas.
projectlunas@tutamail.com02
When the site is visited, Cloudflare may process technical information required to deliver and protect it, including IP address, requested URL, date and time, routing information, system configuration and security signals.
The site asks GitHub's public API for information about the LunasProject repositories. The request is made by the visitor's browser, so GitHub may receive technical request information such as the IP address, device details and request time. The site only displays public repository information.
When a visitor submits a commission enquiry, community project or team application, the site sends the fields shown in that form to Project Lunas. These may include the sender's name or handle, email address, project requirements, authorization statements, skills, a project link and an optional portfolio link. The email fallback remains available as a separate contact method.
To limit automated abuse, the submission service creates a one-way keyed fingerprint from the connecting IP address. The raw address is not stored in the Project Lunas submissions database; the fingerprint is used only for rate limiting and is deleted automatically after 24 hours. Hosting providers may separately process technical logs under their own retention settings.
The forms use Cloudflare Turnstile to distinguish legitimate interactions from automated abuse. Cloudflare receives the technical and interaction signals needed to perform this security check; Project Lunas validates the short-lived result on the server and does not use it for advertising or profiling.
Please do not send special-category data, confidential credentials or personal data about third parties unless it is strictly necessary and lawful to do so.
For each accepted form, a transactional notification containing only the submission type and reference code is sent to the Project Lunas mailbox. Names, reply addresses and complete form contents remain in Supabase and are not copied into the notification.
A receipt is also sent to the address entered in the form. It contains the sender's name or handle, request type, reference code and expected response time. If Project Lunas responds from the internal workspace, Resend processes the destination address, subject and response text needed to deliver that message.
The internal request workspace uses Supabase Auth. For authorized operators this may process the designated email address, authentication method, session identifiers, hashed temporary-code challenges and security or audit events. Temporary codes are single-use, expire after 10 minutes and are not stored in readable form. Network addresses associated with second-factor checks are stored only as one-way keyed fingerprints in the internal log.
03
04
Data may be processed through the following services:
GitHub and Discord links lead to external platforms governed by their own terms and privacy notices. Cloudflare and GitHub may process data outside the European Economic Area using the safeguards described in their respective privacy documentation.
05
Data may be removed earlier when it is no longer needed and no legal reason requires its retention.
06
Project Lunas does not currently use Google Analytics, advertising trackers or profiling cookies. The Projects page uses the browser's local storage to cache public GitHub repository data and a timestamp for up to 15 minutes. The restricted operator area also uses browser storage required by Supabase to maintain and refresh an authenticated session, plus the opaque identifier of an in-progress temporary-code challenge. Public visitors do not receive an operator session. The repository cache is used only to improve performance, does not identify the visitor and is removed when it expires.
No non-essential analytics or advertising technology is currently active. If that changes, this notice and any required consent controls will be updated before the technology is enabled.
07
Where the GDPR applies, you may request access, correction, deletion, restriction or portability of your personal data, and may object to processing in the cases provided by law. Where a processing activity relies on consent, consent may be withdrawn at any time without affecting earlier lawful processing.
Send a request to projectlunas@tutamail.com. You may also lodge a complaint with the Italian Data Protection Authority or another competent supervisory authority.
08
Reasonable technical and organisational measures are used to protect the site and communications. Form submissions pass through a server-side function; database tables use row-level security and are not directly writable or readable by public visitors. No internet transmission can be guaranteed to be completely secure, so sensitive credentials should never be submitted.
This notice may be updated when the site, its providers or its processing activities change. The effective date at the top of the page identifies the current version.