Privacy Policy
Last updated: [date]
Dreamcore is a dream journal. By its nature, the content you entrust to it — your dreams, your voice, your reflections — is deeply personal. This policy explains what data we process, why, and what rights you have. The short version: your dreams are private by default, we don't sell your data, and you can export or delete everything at any time.
1. Controller
The controller responsible for data processing in connection with the Dreamcore app and this website is:
[Full name / company name]
[Street address]
[Postal code, city, country]
Email: [contact email]
2. What data we process
Account data
When you sign up we process your email address (magic-link sign-in) or, if you use Sign in with Apple or Google, the identifier and email your provider shares with us. Your profile may additionally include a display name, username, bio, and profile photo — all optional and provided by you.
Dream content
The core of the app: dream texts you write, voice recordings you make, tags, moods, and related notes. Dream content can reveal sensitive aspects of your inner life (for example emotional or health-related information, Art. 9 GDPR). We process it solely to provide the journal and the features you actively use, on the basis of your explicit consent — never for advertising, profiling, or sale. Voice recordings are only ever visible and audible to you.
AI features
When you request an AI interpretation, dream image, or dream report, the relevant dream text is sent to our AI processing partner (Google — Gemini models) to generate the result. The output is stored with your dream. AI requests are made server-side through our backend; our contractual terms with the provider do not permit the use of your content to train their models.
Social features
If you choose to share a dream to the feed, the shared content, your profile, and interactions on it (likes, comments, follows) are visible to the audience you selected. Nothing is shared without an explicit action by you.
Purchases
Subscriptions are processed by Apple (App Store) or Google (Google Play). We use RevenueCat to manage subscription status. We receive pseudonymous transaction data (e.g. subscription tier and expiry) — never your payment details.
Notifications and technical data
If you enable reminders or social notifications, we store a push token for your device (delivered via Expo Push, Apple Push Notification service, and Google Firebase Cloud Messaging). Our infrastructure additionally processes technical data that is strictly necessary to operate the service, such as IP addresses in server logs.
3. Purposes and legal bases
- Providing the app (account, journal, sync, purchases): Art. 6(1)(b) GDPR — performance of contract.
- Processing dream content, including AI features: Art. 6(1)(a) and Art. 9(2)(a) GDPR — your explicit consent, revocable at any time.
- Notifications: Art. 6(1)(a) GDPR — consent via system permission, revocable in settings.
- Security and abuse prevention (e.g. server logs, content moderation of shared dreams): Art. 6(1)(f) GDPR — legitimate interest in a safe, functioning service.
4. Processors and recipients
We use the following processors under data processing agreements:
- Supabase — database, authentication, and file storage (hosting region: [region, e.g. EU/Frankfurt]).
- Google — AI processing (Gemini), Sign in with Google, push delivery (Firebase Cloud Messaging).
- Apple — Sign in with Apple, push delivery (APNs), App Store purchases.
- RevenueCat — subscription management.
- Expo — push notification delivery.
Some of these providers process data in countries outside the EU/EEA (in particular the USA). Where that happens, transfers are safeguarded by the EU Commission's adequacy decision for the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses. We do not sell personal data and do not share it with advertisers.
5. Retention and deletion
Your data is retained for as long as your account exists. You can delete individual dreams at any time, and you can delete your entire account directly in the app (Settings → Account). Account deletion permanently removes your profile, dreams, recordings, images, and social activity from our systems; residual copies in encrypted backups are purged on a rolling basis within [e.g. 30 days]. Legal retention obligations (e.g. for purchase records) remain unaffected.
6. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15) — the app includes a built-in data export,
- rectification (Art. 16) and erasure (Art. 17),
- restriction of processing (Art. 18),
- data portability (Art. 20),
- object to processing based on legitimate interest (Art. 21),
- withdraw any consent at any time with effect for the future (Art. 7(3)),
- lodge a complaint with a supervisory authority (Art. 77) — for example the data protection authority of your German federal state or your place of residence.
To exercise your rights, use the tools in the app or contact us at [contact email].
7. This website
This website is a static page. It sets no cookies and uses no analytics or tracking. Fonts are loaded from Google Fonts, which involves your browser sending your IP address to Google; web server logs (IP address, time, requested page) are processed by our hosting provider [hosting provider] for delivery and security (Art. 6(1)(f) GDPR).
8. Changes
We will update this policy when the app or legal requirements change. The current version is always available at this address; material changes will be announced in the app.