Privacy policy
This policy explains how The Dreamer, listed on the App Store as Dream Journal: Dream AI, handles your personal information. It covers the iPhone app, its cloud services, this website, and support requests.
Your journal can contain personal information. Cloud features process journal content and recordings; optional AI features send relevant content to an AI service. Purchases are handled by Apple and RevenueCat. Production app builds use Sentry and Amplitude for diagnostics and usage information. This website has no advertising or analytics scripts.
1. Who is responsible for your information?
LEVITES TECH LTD, company number 17059524, 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ, is the controller of personal information processed to provide The Dreamer. Contact founder@levites.app for privacy questions or requests. Our registered address is also available in the official company register.
2. What information do we process, and why?
| Information | Purpose |
|---|---|
| Dream entries, titles, dates, reflections, moods, tags, transcripts and generated summaries | Save, organise, search, sync, export and display your personal journal. |
| Voice recordings, duration and associated entry identifiers | Keep and play recordings and, when requested, transcribe them. |
| Guest/account identifiers, optional email address, sign-in verification and session information | Keep journals associated with the correct account, authenticate requests and recover an email-linked journal. |
| Purchase identifiers, subscription status, product and transaction information | Verify premium access and restore purchases. Apple processes payment details; the app does not ask for your full card number. |
| Device/app information, network information, errors, crash diagnostics and usage information | Operate and secure the service, diagnose faults and understand app use. Third-party SDKs may assign device or installation identifiers. |
| Your support email, correspondence and attachments you choose to provide | Answer questions, resolve issues, handle privacy requests and maintain a record of the response. |
You provide journal content and support information directly. Some device, session, purchase and network information is generated automatically by the app, its service providers or ordinary network requests. Website requests reach Cloudflare, which processes request and network information to deliver and protect the site.
3. AI transcription and summaries
When you request a cloud transcription or AI summary, the relevant recording, transcript or written entry is sent to the service used by that version of the app. The current backend sends requested recordings to Cloudflare Workers AI Whisper Large v3 Turbo for transcription and requested written entries or transcripts to OpenAI GPT-6 Luna for summaries and journal metadata. Journal data and saved recordings remain stored on Cloudflare. Previous backend versions used OpenAI GPT-Transcribe or Cloudflare Workers AI; earlier app releases may use OpenAI for AI processing and Supabase for cloud storage. The provider used depends on the installed release and backend configuration.
AI output can be incomplete or inaccurate. It is intended for personal reflection, not diagnosis, prediction or a definitive dream interpretation. Avoid including other people’s private information or sensitive details you do not want processed. You can stop requesting AI processing and delete saved entries. Removing microphone permission stops future voice capture; it does not delete recordings you have already saved.
OpenAI describes how it handles API inputs and outputs in its API data-use documentation. Cloudflare describes its handling of Workers AI inputs and outputs in its Workers AI data-use documentation. We do not promise that all historical releases use the same provider, retention settings or infrastructure.
4. Permissions and your choices
- Microphone: used for recordings you choose to make. Change access in iOS Settings.
- Notifications: used for optional dream reminders. Turn reminders off in the app or revoke notification permission in iOS Settings.
- Email recovery: adding an email is optional in versions that support guest journaling. A guest identity can still be associated with cloud journal data.
- Export and sharing: exports create a readable copy. When you choose a destination in the share sheet, that destination receives the information you share.
The app does not require contacts, precise location or photo-library access for its core dream-journaling features. Device backups and exported copies are managed separately from our cloud journal.
5. Our purposes and legal bases
Where UK or European data-protection law applies, we process information needed to provide the journal, accounts, requested cloud features and purchases to perform our contract with you. We rely on legitimate interests for proportionate service security, fault diagnosis and support administration, and legal obligations where a record must be kept by law. Where consent is required for an optional feature, sensitive information or a particular form of analytics, that processing requires consent; consent can be withdrawn for future processing.
Dream entries may reveal health, beliefs or other sensitive information. You do not need to include such details to use a journal. Contact us if you want to understand or restrict processing of sensitive information you have already provided. Withdrawal does not affect processing that was lawful before withdrawal.
6. Service providers and sharing
Service providers process information for the functions below. They are required to protect personal information under applicable law and their contractual obligations, and we require protection consistent with this policy. Their own policies explain their processing practices.
- Cloudflare: website/API hosting, journal database, private recording storage, authentication-email delivery and network protection.
- RevenueCat: subscription and entitlement management using account/purchase identifiers and purchase information.
- Apple: App Store distribution, payment processing, subscriptions, refunds and device services you choose to use.
- Sentry: production-app crash and error diagnostics, which may include device, network and contextual information.
- Amplitude: production-app usage analytics, including device/installation identifiers and usage information supported by its SDK.
- OpenAI: requested recording transcription and AI summaries using the relevant recording, written entry or transcript.
- Supabase: storage and account functions in earlier releases. Historical cloud records are not automatically imported or erased by installing a newer release.
- Email providers: process correspondence and delivery information when you contact support or receive an authentication message.
Journal content is not published as a public feed. We do not sell dream entries or use them to serve personalised advertising. Information may be disclosed when necessary to comply with law, address security or fraud, protect rights, or transfer the service in a business transaction subject to appropriate safeguards.
7. International processing and security
Our providers operate internationally, and information may be processed outside your country, including in the United States. Where required, transfers are subject to an adequacy decision or appropriate contractual safeguards. Contact us for information about safeguards relevant to your request.
The current backend uses encrypted HTTPS connections, authenticated journal access and private audio storage. Access controls reduce unauthorised access; they are not a promise of end-to-end encryption. Neither a device nor a cloud service can be guaranteed completely secure. Keep your device protected and do not share sign-in codes.
8. Retention and deletion
Journal and account information remains available for the service until you delete it or request removal, subject to technical and legal retention needs. We do not impose a universal automatic expiry on journal entries. In the current backend, entry deletion removes readable content and retains a minimal deletion marker to prevent an interrupted sync from recreating it. Account deletion removes the account and associated active database records; recording files enter a cleanup queue that retries failed removals.
Recordings pending cleanup, service-provider backups, security records, support correspondence and purchase/accounting records may remain for the time needed to complete deletion, resolve an issue, protect the service, or satisfy legal requirements. Not all providers use the same retention period. Contact us for the retention details relevant to your data; we do not promise immediate deletion of every provider-held record.
Deleting the app alone does not delete cloud data or cancel subscriptions. Exports, device backups and copies you shared elsewhere are outside the cloud deletion process. See account and data deletion for the current app steps and help with earlier versions or guest journals.
9. Your privacy rights
Depending on your location and circumstances, you may request access, correction, erasure, restriction, portability, or object to processing. You may also withdraw consent where processing relies on it. Contact founder@levites.app, describe your request and identify the account email if you have one. We may need proportionate verification of ownership before releasing or deleting information. Do not send passwords, verification codes or unnecessary journal content.
Your right to object
You can object to processing based on legitimate interests, including relevant usage analysis. Contact us at the email above and tell us which processing you object to; we assess the request under applicable law.
We handle requests within applicable statutory time limits, normally within one month for UK GDPR requests, with any permitted extension explained. If you are in the UK, you can complain to the Information Commissioner’s Office; elsewhere you may contact your local data-protection authority. These rights are subject to the conditions and exceptions in applicable law.
AI summaries do not make decisions about you with legal or similarly significant effects. Providing an email is optional for guest capture in supported versions; account recovery requires an email. Cloud features need the content and identifiers necessary to fulfil the request.
10. Children and age requirements
The service is a general-purpose personal journal and is not designed specifically for children. Follow the age rating shown in your local App Store and any legal requirements for parental authorisation. If you believe a child’s information was collected without required authorisation, contact us so we can investigate and take appropriate action.
11. Website storage and external links
This marketing website does not load analytics, advertising or tracking scripts and does not provide a journal login or collect dreams through a form. Cloudflare may process technical request information to deliver and protect it. The app uses device storage and session credentials for journal/authentication functions. Visiting the App Store, provider policies or another external service is governed by that service’s policies.
12. Changes and contact
This policy is effective from 8 October 2026. We publish updates here with a new date and provide further notice where required for a material change. For privacy questions, contact founder@levites.app or write to LEVITES TECH LTD, company number 17059524, 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.