Privacy Policy
Last updated: September 3, 2026
Dreamcore is a dream journal. By its nature, the content you entrust to it — your dreams, your voice, your reflections — is deeply personal. This policy explains what data we process, why, and what rights you have. The short version: your dreams are private by default, we don't sell your data, and you can export or delete everything at any time.
1. Controller
The controller responsible for data processing in connection with the Dreamcore app and this website is:
Mareike Haug
8048 Zürich, Switzerland
Email: info@dreamcore-app.com
We have not appointed a data protection officer. Privacy enquiries and requests under this policy go to the address above.
2. What data we process
Dreamcore is for people aged 16 and over (see our Terms of Service). We do not knowingly process data from children below that age; if you believe a child has created an account, contact us and we will delete it.
Account data
When you sign up we process your email address (magic-link sign-in) or, if you use Sign in with Apple or Google, the identifier and email your provider shares with us. Your profile may additionally include a display name, username, bio, and profile photo — all optional and provided by you.
Dream content
The core of the app: dream texts you write, voice recordings you make, tags, moods, and related notes. Dream content can reveal sensitive aspects of your inner life (for example emotional or health-related information, Art. 9 GDPR). We process it solely to provide the journal and the features you actively use, on the basis of your explicit consent — never for advertising, profiling, or sale. Voice recordings are only ever visible and audible to you.
AI features
AI processing only happens if you switch on "Allow AI analysis of my dreams" — asked during onboarding, changeable at any time in Settings. While it is off, nothing you write or record is sent for AI processing. Every AI request is made server-side by our backend; the app never contacts the AI provider directly.
The provider is Google, through its Gemini models. What is sent depends on the feature you use:
- Transcription — the audio file of the voice recording you made for that dream.
- Analysis and interpretation — that dream's title and text, whether you marked it as lucid or as a bad dream or nightmare, and your chosen interpretation style.
- Dream images — that dream's title, text and themes, to produce a scene description, which is then used as the prompt for the image itself.
- Dream reports — aggregated figures for the period (number of dreams, themes, recurring people you tagged, emotion and sentiment counts, lucid and nightmare counts), not the text of your dreams.
- Guided plan check-ins — the plan and step you are on, your rating and the note you wrote, and for your recent dreams their title, sentiment and themes, not their text.
Your name, email address, username, profile photo and account identifiers are never sent with any of this, and no dream is sent that you have not requested processing for. The generated result is stored with your dream.
Google acts as our processor here, bound by a data processing agreement to a level of protection equivalent to the one described in this policy, and its terms do not permit your content to be used to train its models. Processing may take place outside the EU/EEA — see section 4 for the transfer safeguards.
Social features
If you choose to share a dream to the feed, the shared content, your profile, and interactions on it (likes, comments, follows) are visible to the audience you selected. Nothing is shared without an explicit action by you.
Purchases
Subscriptions are processed by Apple (App Store) or Google (Google Play). We use RevenueCat to manage subscription status. We receive pseudonymous transaction data (e.g. subscription tier and expiry) — never your payment details.
Notifications and technical data
If you enable reminders or social notifications, we store a push token for your device (delivered via Expo Push, Apple Push Notification service, and Google Firebase Cloud Messaging). Our infrastructure additionally processes technical data that is strictly necessary to operate the service, such as IP addresses in server logs. If the app crashes or hits an error, a diagnostic report — device model, operating system, app version and the technical context of the error — is sent to our error-monitoring provider Sentry (hosting region: EU) so we can fix it. We do not attach your account identity to those reports.
3. Purposes and legal bases
- Providing the app (account, journal, sync, purchases): Art. 6(1)(b) GDPR — performance of contract.
- Processing dream content, including AI features: Art. 6(1)(a) and Art. 9(2)(a) GDPR — your explicit consent, revocable at any time.
- Notifications: Art. 6(1)(a) GDPR — consent via system permission, revocable in settings.
- Security and abuse prevention (e.g. server logs, content moderation of shared dreams): Art. 6(1)(f) GDPR — legitimate interest in a safe, functioning service.
The AI features analyse and describe your dreams. They make no automated decisions that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR), and we do not profile you in that sense.
4. Processors and recipients
We use the following processors under data processing agreements:
- Supabase — database, authentication, and file storage (hosting region: EU (Ireland, eu-west-1)).
- Google — AI processing (Gemini), Sign in with Google, push delivery (Firebase Cloud Messaging).
- Apple — Sign in with Apple, push delivery (APNs), App Store purchases.
- RevenueCat — subscription management.
- Expo — push notification delivery.
- Sentry — crash and error reporting (hosting region: EU).
- Resend — delivery of account emails (sign-in links).
- Strato — email hosting for our contact address (info@dreamcore-app.com) and DNS.
Some of these providers process data in countries outside the EU/EEA (in particular the USA). Where that happens, transfers are safeguarded by the EU Commission's adequacy decision for the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses. We do not sell personal data and do not share it with advertisers.
5. Retention and deletion
Your data is retained for as long as your account exists. You can delete individual dreams at any time, and you can delete your entire account directly in the app (Settings → Account). Account deletion permanently removes your profile, dreams, recordings, images, and social activity from our systems; residual copies in encrypted backups are purged on a rolling basis within 30 days. Legal retention obligations (e.g. for purchase records) remain unaffected.
6. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15) — the app includes a built-in data export,
- rectification (Art. 16) and erasure (Art. 17),
- restriction of processing (Art. 18),
- data portability (Art. 20),
- object to processing based on legitimate interest (Art. 21),
- withdraw any consent at any time with effect for the future (Art. 7(3)),
- lodge a complaint with a supervisory authority (Art. 77) — for example the data protection authority of your German federal state or your place of residence.
To exercise your rights, use the tools in the app or contact us at info@dreamcore-app.com.
7. This website
This website is a static page. It sets no cookies and uses no analytics or tracking. Fonts are served from our own server, so your browser contacts no third party to render this page. Web server logs (IP address, time, requested page) are processed by our hosting provider Fly.io for delivery and security (Art. 6(1)(f) GDPR).
8. Changes
We will update this policy when the app or legal requirements change. The current version is always available at this address; material changes will be announced in the app.