1. Information We Collect
DreamScript collects only the minimum data necessary to provide its services:
- Dream journal entries you record in the app (stored locally on your device by default)
- If Cloud Sync is enabled: a protected account identifier and your encrypted dream data
- Subscription status used only to unlock plan features
2. Information We Do NOT Collect
- Your phone number, precise location, contacts, or full photo library
- Device location
- Contacts or photo library contents
Health & Sleep Data (HealthKit / Health Connect)
If you grant permission in Settings, the following applies:
- Scope: We read health data only with your permission. On iOS, this may include sleep records, REM and other sleep stages, heart rate rhythm summaries, and heart rate variability (HRV). On Android, Health Connect access is limited to sleep records and sleep stages.
- Purpose: Health data is used for in-app dream journaling, sleep trends, and optional monthly insight reports. It is never used for advertising, user profiling, or any commercial purpose.
- Storage & sync: Raw HealthKit / Health Connect records remain on your device and are not uploaded as raw records. Derived summaries, such as sleep duration, REM duration, sleep efficiency, and iOS heart rate / HRV summaries, may be used in monthly insight reports. If Cloud Sync is enabled, those summaries may be included in end-to-end encrypted reports/backups; the server stores only ciphertext it cannot decrypt.
- Third-party sharing: Health summaries may be sent to the interpretation service only when you request a monthly insight report. Health data is never shared with advertisers or analytics providers.
- Revoking access: You can revoke permission at any time via Settings → Privacy & Security → Health (iOS) or Settings → Apps → DreamScript → Permissions (Android).
3. Third-Party Services
- Dream Interpretation and Exploration: Requested interpretation, guided exploration, and monthly insights may send relevant dream text or summaries over HTTPS to external providers. Opening the dream dictionary may send a short excerpt of your latest dream and candidate symbols to rank dream clues; local ordering remains if the service is unavailable. Providers may retain limited request or abuse-prevention records under their published terms; DreamScript does not use this content to train its own models.
- Cloudflare (Cloud Sync): Account data and dream backups are stored in Cloudflare D1 using end-to-end encryption. Decryption keys reside only in your device's secure enclave; we cannot access your dream content.
- RevenueCat (Subscription Management): Processes purchase history, subscription status, and an app user identifier. After Cloud Sync sign-in, that identifier may be linked to the cloud account.
- Image Generation: Dream illustrations are generated via an external platform. Only a descriptive text prompt is transmitted — your raw dream text is never sent.
- Error Diagnostics: Our Cloudflare Worker and, when enabled, Sentry may receive bounded error messages, stacks, steps, screen or navigation context, app/device information, network address, and a pseudonymous device identifier. Dream, email, and health content are not intentionally added.
- Voice Input: If you use voice input, the operating system's Apple or Google speech service processes audio under its platform terms. DreamScript stores the resulting transcript, not the original recording.
- Anonymous Resonance Pool: If you opt in, selected symbols and emotions plus a hashed device identifier may be retained for up to 365 days and shown only after at least 10 similar contributions.
- Support: Feedback submitted through Google Forms is processed by Google under its terms.
- First-Party Usage Metrics: To improve first-dream capture, voice, exploration, and subscription flows, the app sends event names, app version, language, platform, plan, and a separate random identifier to our Cloudflare Worker. The identifier is hashed again and daily aggregate records are retained for 91 days. These metrics never contain dream text, titles, email, health data, error messages, or advertising identifiers, and are not shared with third-party analytics services.
4. How We Use Your Data
Data is used for app functionality, security, support, subscriptions, and consented product metrics. It is never sold or used for personalized advertising. Only Cloud Sync data is end-to-end encrypted before leaving the device; requested interpretations travel over HTTPS in a form the provider can process.
5. Your Rights
- Clear all local data at any time via Settings → Storage.
- Delete your cloud account and all server data via Settings → Cloud Sync.
- Request deletion outside the app at dreamscript.app/delete-account.html. Deleting an account does not cancel an App Store or Google Play subscription, which must be cancelled with that store.
- Download a full copy of your data via Settings → Export.
- Uninstalling the app deletes all local data automatically (except iOS Keychain lock settings).
6. Children's Privacy
This app is not directed at children under 13, and we do not knowingly collect personal data from children.
7. Changes to This Policy
Material changes will be announced in app update release notes. Continued use of the app constitutes acceptance of the updated policy.
8. Contact Us
For privacy-related questions, please use the in-app feedback form: Settings → About → Feedback.