Privacy
A dream journal holds unusually personal material. This explains plainly what we collect, who else sees it, and what you can ask us to do with it.
Last updated [DATE — set when first published]
This is a draft. It is not in force and does not yet bind anyone. Passages shown in square brackets are not yet filled in, including the contact address, and the document is awaiting review. Nobody is being asked to agree to it in this state.
Who is responsible
DreamSynse is operated by [YOUR FULL LEGAL NAME], a sole trader, of [TRADING ADDRESS]. That means the data controller for everything described here is a person rather than a company, and [YOUR FULL LEGAL NAME] is registered with the Information Commissioner's Office under [ICO REGISTRATION NUMBER].
For anything in this policy, including a request to see or delete your data, write to privacy@dreamsynse.com.
What we collect
Your account. Your email address, and a display name and timezone if you set one. We do not ask for your real name, date of birth, address, or phone number, and you should not put them in a dream entry either.
What you write. The text of your dreams, any titles and tags, your later reflections on them, the ratings you record for mood on waking, sleep quality and vividness, whether you marked an entry as a nightmare, lucid or recurring, and any life events you choose to log.
Voice recordings. If you record a dream rather than typing it, the audio is stored so you can play it back, and kept alongside the transcript rather than deleted after transcription.
Technical and usage data. A record of how many times you have used features that cost us money to run — transcription minutes and generated readings — so we can apply the limits described in our terms. We do not use analytics, advertising, or tracking software of any kind, and there are no third-party trackers on this site.
Dreams can be sensitive, and the law treats them that way
Dreams are not neutral text. What you write may reveal — directly or by implication — your health, your mental health, your sex life, your religious or philosophical beliefs, or your politics. Under UK data protection law these are “special category” data and need a stronger legal basis than ordinary information.
We rely on your explicit consent to process what you write. You give that consent by creating an account and recording entries, you can withdraw it at any time by deleting your entries or your account, and withdrawing it does not affect anything we did before you withdrew it.
For the rest — your email address, your subscription, the usage counts — our basis is performance of our contract with you, and our legitimate interest in keeping the service secure and preventing abuse.
Your dreams are sent to an AI provider
This is the disclosure that matters most, so it has its own section rather than a line in a list.
When you ask for readings of a dream, and when the app matches your entry against its list of motifs or runs its safety check, the text of that dream is sent to Anthropic, which operates the language model the app uses. Anthropic processes it in order to return a result to us. If you record audio, that audio is sent to a speech-to-text provider to be turned into text.
These providers act as our processors: they handle your material on our instructions and are not permitted to use it for their own purposes. Both are based in the United States, so your data is transferred outside the UK under the safeguards described below.
If you would rather no dream of yours ever left our systems, do not request readings, and type your entries rather than recording them. Your journal, search and export all work without any of that.
Who else is involved
We use a small number of suppliers to run the service:
- Supabase — the database, sign-in system and file storage where your entries and recordings are held.
- Vercel — hosting for the website itself.
- Anthropic — the language model that produces readings, matches motifs, and runs the safety check.
- A speech-to-text provider — converts voice recordings to text, when you use voice capture.
- Stripe — takes payment if you subscribe. We never see or store your card details.
- An email provider — sends your sign-in links.
We do not sell your data, we do not share it for advertising, and we do not use what you write to train anyone's models.
We would disclose information if the law required us to, and we would tell you unless we were legally prevented from doing so.
Transfers outside the UK
Some of the suppliers above are based in the United States. Where your data is transferred outside the UK, we rely on the UK International Data Transfer Agreement or the Addendum to the European Commission's Standard Contractual Clauses, together with the suppliers' own security measures.
How long we keep it
We keep what you write for as long as your account exists, because that is the point of the product: a journal you can read back in five years is only useful if it is still there.
When you delete an entry it is removed from our database. When you delete your account, your entries, recordings, reflections and readings are deleted with it. Backups may retain copies for a short period before they are overwritten in the ordinary course.
We keep records of payments for as long as tax and accounting law requires, currently six years. These contain your email address and the amounts paid — never anything you wrote.
What you can ask us to do
Under UK data protection law you have the right to:
- see the personal data we hold about you;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to how we use it;
- receive your data in a portable form;
- withdraw your consent at any time.
You do not need to ask us for a copy: the export in your settings gives you everything you have written, in Markdown and JSON, at any time. It is free permanently, including if you stop subscribing — leaving with your own journal should never require anyone's permission.
For anything else, write to privacy@dreamsynse.com and we will respond within one month. If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk, though we would rather you told us first so we can put it right.
Security
Entries are stored in a database where access rules are enforced per row, so one account cannot read another's material even if the application had a bug. Voice recordings sit in private storage that is similarly scoped to their owner. Traffic is encrypted in transit, and data is encrypted at rest by our hosting providers.
No system is perfectly secure, and we will not pretend otherwise. If a breach affected your rights we would tell you and the Information Commissioner's Office promptly.
Cookies
We set one cookie, which keeps you signed in. It is strictly necessary for the service to work, so it does not require consent, and there is no cookie banner because there is nothing to consent to.
There are no analytics cookies, no advertising cookies, and no third-party tracking of any kind.
Age
DreamSynse is not for under-16s. We do not knowingly collect data from children, and if we learn that we have, we will delete it. If you believe a child has created an account, write to privacy@dreamsynse.com.
Changes
If we change this policy in a way that materially affects you, we will email you rather than quietly updating the page. The date at the top always reflects the current version.