Privacy Policy
The short version
- Your dream entries are yours. We don't sell them, we don't advertise against them, and we don't share them with anyone except the service providers listed below that are needed to run the app.
- To generate your insights, the text of your dreams is sent to specialist AI providers we contract with. They process it only to return an analysis, and are not permitted to use it to train their models.
- Your data is encrypted in transit and at rest, and access rules mean no other user can read your entries. It is not end-to-end encrypted — see Security for exactly what that means.
- You can delete your account and everything in it from inside the app at any time.
- Dream journals are deeply personal, so we treat all of your dream content as sensitive information.
1. Who we are
Dremr is operated by Moonshine Labs LLC, a Florida limited liability company ("Moonshine Labs", "we", "us"). For the purposes of the UK and EU General Data Protection Regulation, we are the data controller for the personal data described in this policy.
You can reach us about anything in this policy at support@moonshinelabs.app.
2. What we collect
We collect only what the app needs to work. There are no advertising SDKs, no analytics trackers and no third-party tracking libraries in Dremr.
| Category | What it is | Where it comes from |
|---|---|---|
| Account data | Your email address and a securely hashed password, plus the date your account was created. | You, at sign-up |
| Dream content | The dream entries you write or dictate, their dates and titles, any tags, notes, corrections and starred status. | You, in the app |
| Voice input | When you use the microphone button, the audio is sent to a speech-to-text provider and converted to text. We do not store the recording — only the transcribed text is saved to your journal. | You, with your permission — iOS asks before the microphone is ever used |
| People and places you name | The names or labels you give to people and places that appear in your dreams, and any category or relationship you assign them. | You, in the app |
| Derived insights | Emotions, symbols, themes, patterns and connections our analysis produces from your entries, and any feedback you give on them. | Generated by us from your content |
| Technical data | App version, device type, error and crash diagnostics, and the IP address our hosting provider sees when your app connects. | Automatically, when you use the app |
What we do not collect
We do not collect your location, contacts, photo library, health data from Apple Health, or any advertising identifier. We do not track you across other apps or websites, so Dremr never shows the iOS App Tracking Transparency prompt.
3. Sensitive information
A dream journal can reveal a great deal about a person — health and mental health, relationships, sexuality, religious or philosophical belief, and the people in your life. We therefore treat all dream content, voice input and derived insights as sensitive personal information, whether or not a particular entry happens to contain anything of that nature.
If you are in the UK or the European Economic Area, some of this may be "special category data" under Article 9 of the GDPR. We process it on the basis of your explicit consent, which you give when you create your account and which you can withdraw at any time by deleting your account.
About other people in your dreams. When you name someone in an entry, you are recording information about them as well as about yourself. Please only enter what you are comfortable recording, and avoid entering other people's contact details, medical information or identification numbers. You remain responsible for what you choose to write.
4. How we use it
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Storing and showing you your dream journal | Performance of our contract with you |
| Generating analysis, insights and patterns from your entries | Your explicit consent (Art. 9(2)(a)) |
| Creating and securing your account, and preventing abuse | Performance of our contract; our legitimate interest in keeping the service secure |
| Fixing bugs and keeping the app working | Our legitimate interest in maintaining a functioning product |
| Responding to you when you contact support | Performance of our contract; our legitimate interest in supporting users |
| Complying with the law and responding to lawful requests | Compliance with a legal obligation |
We do not use your dream content to train our own models, sell or rent it, share it with data brokers, use it for advertising or profiling that produces legal effects, or read it for any purpose other than those above.
5. AI processing
Dremr's insights are produced by large language models. When you save a dream, its text — and, where relevant, the labels you have given people and places in it — is transmitted over an encrypted connection to one or more specialist AI providers we contract with, which return the analysis you then see in the app.
Our providers process your entries only to return an analysis, and are not permitted to use them for their own purposes, including training their own models. A provider may retain content briefly for abuse monitoring before deleting it.
If you are a Dremr user and would like to know which providers process your entries, contact us at support@moonshinelabs.app.
Insights are generated automatically and can be wrong, incomplete or simply odd. They are offered for reflection and self-understanding, not as fact and not as advice — see the Terms of Service. No decision with a legal or similarly significant effect on you is made automatically.
6. Who we share it with
We share personal data only with the service providers we need to run Dremr. Each is bound by contract to process it only on our instructions.
| Provider | What they do for us | What they receive |
|---|---|---|
| Google LLC (Firebase Authentication, Cloud Firestore, Cloud Functions) | Hosts your account and your journal, and runs our backend | All of the data in section 2 |
| AI service providers (large language model and speech-to-text APIs) | Generate the analysis of your entries, and convert dictated audio to text | Dream text and related labels, sent per analysis; and dictated audio, sent for transcription and not retained by us |
We may also disclose personal data where we are legally required to — to comply with a valid court order, subpoena or other lawful request, to enforce our Terms, or to protect the rights or safety of our users or the public. If a business transfer such as a merger or acquisition ever occurs, your data may transfer with the business, and we will tell you before it becomes subject to a different privacy policy.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act and comparable US state privacy laws. We have never done so.
7. Security
We protect your data with:
- Encryption in transit. All connections between the app and our servers use TLS; the app refuses unencrypted connections.
- Encryption at rest. Your entries are encrypted on our hosting provider's storage.
- Per-user access rules. Server-side rules enforce that only your authenticated account can read or write your entries. No other user can reach them.
- Limited internal access. Access to production data is restricted to the personnel who need it to operate and support the service, protected by multi-factor authentication.
Dremr is not end-to-end encrypted. We want to be precise about this, because it matters. Your entries are encrypted while travelling and while stored, but we hold the keys — which is what allows the app to analyse your dreams and search across them. That means our systems, and authorised personnel, are technically capable of accessing your content, and that we can be compelled to produce it by valid legal process. Any claim you may have seen that Dremr is end-to-end encrypted was inaccurate and has been corrected.
No system is perfectly secure. If a breach affects your personal data, we will notify the relevant supervisory authority within 72 hours where the law requires it, and we will notify you without undue delay where the breach is likely to present a high risk to you.
8. Retention & deletion
We keep your entries for as long as your account exists, because the point of a dream journal is that it is there when you come back to it. You are in control of that:
- Delete a single entry at any time in the app. It is removed immediately, along with the derived insights attached to it.
- Delete your entire account from Profile → Delete Account. This permanently removes your entries, derived insights, the people and places you recorded, and your login. It cannot be undone.
- Or just ask us. Email support@moonshinelabs.app and we will delete your account within 30 days.
Deleted data is purged from our encrypted backups within 90 days. We may retain a minimal record of the deletion itself, and anything the law requires us to keep, for as long as we are required to keep it.
9. Your rights
Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, or export it in a portable format. To exercise any right, email support@moonshinelabs.app from the address on your account. We will not charge you, and we will not treat you differently for asking.
If you are in the UK or the EEA
You have the right to access, rectification, erasure, restriction of processing, data portability, and objection to processing based on our legitimate interests. Where we rely on your consent, you may withdraw it at any time without affecting processing that already happened. You also have the right to lodge a complaint with your local data protection authority — in the UK, the Information Commissioner's Office at ico.org.uk.
If you are in California or another US state with a privacy law
You have the right to know what personal information we collect and how we use and disclose it, to request its deletion, to request correction, to obtain a portable copy, and to limit the use of sensitive personal information. We use sensitive personal information only to provide the service you asked for, which is a use that does not require a separate limitation right — but you may still tell us to stop, and we will, by closing your account. We do not sell or share personal information, so there is nothing to opt out of. If we deny a request, you may appeal by replying to our decision.
We will verify your request using the email address associated with your account. An authorised agent may act for you with written permission.
10. International transfers
We operate from the United States, and our providers store and process data there. If you use Dremr from the UK or the EEA, your personal data will be transferred outside your country. We rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) with our providers to protect it, together with the technical measures described in section 7. Ask us at any time for a copy of the safeguards in place.
11. Children
Dremr is not intended for children or teenagers. You must be at least 18 years old to create an account, and we ask for your date of birth at sign-up to confirm this. We use it to check your age at that moment and then discard it — we store only the fact that your age was verified. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has created an account, email support@moonshinelabs.app and we will delete the account and its contents promptly.
12. Changes to this policy
If we change this policy we will update the date at the top of this page. If the change is material — for example, a new category of data, a new provider receiving your dream content, or a new purpose — we will tell you in the app before it takes effect, and where the law requires it we will ask for your consent again.
13. Contact us
Questions, requests or complaints about privacy:
support@moonshinelabs.app
Moonshine Labs LLC, Florida, United States