Privacy Policy
Last updated: 2026-09-10. App: Dreams Come True.
The short, honest version: your dreams are yours. Your journal lives on your device. We see as little as technically possible, and we sell nothing about you.
Who is responsible
Dreams Come True is operated by its developer, an individual software developer (the "operator" — and, where data-protection law uses the term, the data controller for the little data that reaches us). Contact for everything, including privacy requests: support@dreamparser.com.
What stays on your device
- Your dream journal: dream text, readings, moods, dream images, settings — stored locally on your phone. A generated dream image is saved as a file inside the journal's own storage on your device; we keep no copy of it anywhere. Deleting the app (or using "Delete all my data" in Settings) removes these journal files. The security-key exception is described below.
- Your voice: speech is transcribed on this device. The app specifically requests your operating system's on-device speech recognition, so your audio is never uploaded — not to us, and not to anyone else. If a phone cannot transcribe locally, we offer you the setting to turn on, or typing; we never quietly fall back to sending your voice somewhere. A reading uses text only after you choose to share it with AI. You can save a dream without requesting a reading.
- Dictation is a system setting of your iPhone, governed by Apple's terms. Inside Dreams Come True, speech recognition runs on your iPhone only.
- Because your journal is stored on your phone, it may be included in your device's own backups (for example iCloud or a computer backup) if you have those enabled. Those backups are controlled by you and your operating system — not by us — and you can exclude this app from them in your device settings.
What reaches our servers, and why
- Dream text, transiently: after you grant reading permission and request a reading, your dream text and any optional mood, lucidity, recurring-dream marker, sleep-quality, dream-vividness, sleep-interruption, recall, intention and reading-lens details you add are sent to our server and forwarded to our AI provider (Anthropic) to generate the reading. We do not store your dream text on our servers, and it is not used to train AI models. Our AI provider may retain the request and response briefly under its own policy (Anthropic's standard API retention is up to 30 days for trust-and-safety purposes) before deletion.
- Weekly reflection summaries (Pro), with separate permission: the weekly reflection sends your AI provider only compact per-night summaries computed on your device — dates, symbol words, mood labels and motifs — never your dream text. All the numbers you see are calculated on your device; the provider only writes the short reflection.
- Dream images (Pro), with separate permission: the image prompt (mood + symbol words, never your dream text) is sent to Cloudflare Workers AI, which generates the image; Cloudflare states customer content is not used to train models. The finished image is returned straight to your phone and saved only there, inside your journal — we do not store it on any server. Only readings created by our own server can be illustrated (each carries a signed receipt), and image requests are configured so the routing layer logs technical metrics only — not the prompt or the image. Your export contains the image itself, so a restored journal keeps its pictures.
- Usage and security records: Apple App Attest verifies that requests come from our iPhone app. We store the public verification key and replay counters, short-lived verification challenges, keyed pseudonyms for installation and purchase identities, allowance periods, request status, token counts and estimated AI cost. These records contain no dream text, reading, image, audio or private notes. IP addresses are transformed into keyed pseudonyms for challenge rate limits. This information protects the service and manages free, trial and paid allowances.
- Subscription records: RevenueCat supplies an anonymous app-user identifier and Apple purchase information, including product, transaction, purchase and expiry data. We store keyed transaction identifiers and service dates so restoring a purchase restores the same allowance.
- Technical logs: we log timings and bounded error categories. We exclude journal content, provider keys, verification proofs and raw purchase records.
A note on sensitivity: dreams can touch on health, emotions, beliefs, and other intimate topics. That is exactly why the journal stays on your device, why processing is transient, and why you alone choose what to write or speak. Sending a dream for a reading is always your action, never automatic.
Subscriptions
Purchases are processed by Apple and managed through RevenueCat (our subscription infrastructure). We receive subscription status, never payment details.
Analytics (PostHog)
You can choose “Help improve the app” in Settings & privacy. Until you turn it on, the app sends no product-analytics events. You can turn it off at any time; events from before consent are not replayed.
With your permission, PostHog (hosted in the United States) receives limited usage events, such as a screen being opened, a dream being saved, or a purchase flow being completed, with an installation identifier. Dream text, audio, notes, interpretations and crisis classifications are excluded. The identifier is pseudonymous rather than a promise of complete anonymity. Deleting your journal and settings withdraws consent for future analytics; previously sent events follow provider retention. We do not use these events for advertising.
Crash reports (Sentry)
If the app crashes or hits an error, a technical crash report is sent to Sentry: the error type, code locations, and app version. Error messages and arbitrary error names are omitted; only a bounded error category, scrubbed code locations and a fatal-error flag are included. We do not attach journal content. Reports are keyed to the anonymous device identifier only.
Our service providers
| Provider | What it does | What it can see |
|---|---|---|
| Anthropic (US) | generates readings and weekly reflections | the transient reading request described above |
| Cloudflare (US + global edge) | image generation and allowance database | transient image prompts; content-free usage/security/purchase records |
| Apple | distribution, payment, on-device speech | per Apple's own terms |
| RevenueCat (US) | subscription status | anonymous app-user ID + purchase state |
| PostHog (US) | anonymous product analytics | fixed event names + anonymous ID |
| Sentry (US) | crash reports | scrubbed technical errors + anonymous ID |
| Expo EAS Hosting / Cloudflare | run our backend at the network edge | the transient requests in flight |
We do not sell personal information, and we do not share it for cross-context behavioral advertising. There are no third-party ad networks or tracking SDKs in the app.
International transfers
The providers above process data in the United States and at global network edges. Where transfer rules such as the GDPR apply, transfers rely on the providers' published safeguards (such as standard contractual clauses or Data Privacy Framework participation, as applicable).
How long anything is kept
- On your device: until you delete it — it's yours.
- Reading/reflection requests: not stored by us; up to ~30 days at the AI provider, then deleted.
- Dream images: exist only on your device — we hold no copy to retain or delete. Image prompts are processed transiently; we do not promise a specific provider-side deletion timeframe.
- Analytics and crash events: anonymous, retained under the providers' standard retention.
- Usage and security records are retained for service operation and abuse prevention. The operator removes request records older than 90 days and expired challenges during routine maintenance. Purchase-period records remain while needed to provide and restore subscriptions; retained verification keys and accounting records are not erased by deleting the local journal. Contact us for requests concerning these records. These are operational retention targets, not a claim that provider backups vanish immediately.
Your rights
Your saved journal is local; the individual AI requests you authorize are processed as described above. The controls below let you manage both local data and future sharing. Where data-protection law (such as the GDPR, UK GDPR, or the CCPA/CPRA) grants you rights — access, correction, deletion, portability, objection, restriction, or the right to complain to your supervisory authority — you can exercise them by emailing support@dreamparser.com; we will pass provider-side requests (for example, deletion of a transient request record) to the relevant provider. We do not discriminate against you for exercising rights. California residents: we do not sell or share personal information as those terms are defined in the CPRA.
Your controls
- AI sharing: separate reading, weekly-reflection and image permissions can be withdrawn in Settings & privacy. Withdrawal stops future requests for that purpose; it cannot recall data already processed.
- Transfer: export your journal before changing phones, then import that file on the new iPhone. Automatic restoration depends on your own device-backup settings.
- Export: Settings → "Export my journal" gives you your dreams, readings, and images as one JSON file — and tells you plainly if any image could not be included or the file has grown past what a one-file import can take back.
- Delete: Settings → "Delete all my data" erases your journal, your dream-image files, your app preferences, any scheduled reminders, and every cached copy: the export file, any journal you imported, and the app's image render caches. If some part of that can't be removed, the app says so rather than claiming a clean wipe. Deleting your journal does not cancel an Apple subscription or erase the security and purchase records described above. The installation verification key is retained on this device for abuse prevention. We do not keep a server copy of your journal or generated images. Content already sent to our AI or image providers ages out under their retention policies described above.
Security
Traffic to our backend is encrypted in transit; provider keys live server-side only; the backend holds an allowance and security database, separate from the journal stored on your device. No method of transmission or storage is perfectly secure, and we cannot promise absolute security; our design choice is to minimize what exists to protect.
Children
The app is not directed at children under 13, and we do not knowingly process their data. If you believe a child has used the app, use "Delete all my data" on the device, and contact us with any concern.
Changes to this policy
When this policy changes, the "Last updated" date changes at this URL; material changes will be visible here before they take effect.
Contact
This website
This site sets no cookies and requires no account. If our privacy-respecting page analytics are enabled, the site records a small set of named events (such as a page view) with no personal data, and honors your browser’s “Do Not Track” and Global Privacy Control signals. The optional launch-notification form stores exactly one thing: the email address you choose to give us, used once, to tell you the app is out.