Privacy Policy

Last updated: November 2025

1. Introduction

This Privacy Policy describes how DreamStorm ("we", "us", or "our") collects, uses, stores, and protects your personal information when you use our spiritual insight platform ("Service"), including our DreamStorm meditation generation features. We are committed to protecting your privacy and handling your data responsibly.

2. Information We Collect

2.1 Personal Information You Provide

Account Information:

  • Email address (for account creation and communication)
  • Password (encrypted and stored securely via Supabase Auth)

Birth and Identity Information:

  • Full name (first name, last name)
  • Birth date (essential for all calculations)
  • Birth time (optional, for enhanced accuracy)
  • Birth location (city, country, or coordinates)

Optional Personality Information:

  • MBTI personality type
  • Enneagram type

2.2 Information We Automatically Collect

  • Technical Data: IP address (for rate limiting and security)
  • Usage Data: Pages visited, features used, API requests made
  • Device Information: Browser type, device type, operating system
  • Timestamps: Account creation, last login, report generation times

2.3 Generated Content

  • Calculated spiritual insights and reports
  • AI-generated interpretations and analyses
  • Cached calculation results for performance
  • Report metadata and generation history

2.4 Voice Recordings and Biometric Data (DreamStorm)

🎙️ Voice Cloning Feature

If you use our DreamStorm meditation feature, you may record your voice to create personalized guided meditation audio.

What We Collect:

  • A 1-5 second audio recording of your voice in WebM format
  • Voice profile ID generated by our AI partner (Cartesia)
  • Voice name you assign to the profile
  • Timestamp of recording creation

How We Use It:

  • Generate personalized meditation narration using your voice
  • Store voice profile securely in our encrypted database
  • Process voice data through Cartesia's AI voice cloning service

Legal Basis (GDPR):

  • Your explicit consent (Article 6(1)(a))
  • Processing necessary to provide requested services (Article 6(1)(b))

⚖️ Illinois Residents (BIPA Compliance)

Under the Illinois Biometric Information Privacy Act (BIPA):

  • Purpose: We collect your voice recording solely to create personalized meditation audio
  • Retention: Voice profiles are stored until you delete your account or request deletion
  • No Sale: We will never sell, lease, or trade your biometric data
  • Consent: We obtain explicit written consent before collecting voice data
  • Deletion: Voice data is permanently deleted within 30 days of your request or account deletion
  • Security: We implement industry-standard security measures to protect biometric data

Special Category Data (GDPR Article 9):

Voice recordings may qualify as biometric data. We process this data with your explicit consent and implement additional security measures including:

  • Encryption at rest and in transit
  • Access restricted to authorized personnel only
  • Regular security audits
  • Secure deletion upon request

Third-Party Processing:

  • Voice recordings are processed by Cartesia, Inc. (https://cartesia.ai)
  • Cartesia uses voice data solely to generate voice profiles
  • Cartesia does not retain voice audio after processing (typically < 1 hour)
  • Cartesia privacy policy: https://cartesia.ai/privacy

Your Rights:

  • Review your voice profile metadata at any time
  • Delete your voice profile from Settings → DreamStorm → Voice Profile
  • Revoke consent (this will disable personalized meditation audio)
  • Request a copy of your voice data (may not be available if already processed)

Data Retention:

  • Voice profile metadata: Stored until account deletion or manual deletion
  • Voice audio recordings: Not stored after Cartesia processing
  • Generated meditation audio: Stored indefinitely unless you delete meditations

Cross-Border Transfers:

Cartesia processes voice data on servers located in the United States. If you are in the EU/UK, this constitutes a cross-border data transfer. We rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Your explicit consent for transfer

2.5 User-Generated Content (DreamStorm)

Dream Descriptions:

  • You may submit written descriptions of your dreams or goals
  • These descriptions are stored in our database
  • Used to generate personalized meditation scripts via AI
  • Retained until you delete your account or meditation
  • NOT shared with third parties except AI processing services

Image Uploads:

  • You may upload personal photos to DreamStorm (max 8 MB)
  • Images are stored privately in Supabase Storage
  • Used for AI-powered image enhancement and generation
  • Images are NOT publicly accessible
  • You retain all ownership rights to uploaded images
  • We may process images through third-party AI services (see Section 4)

3. How We Use Your Information

3.1 Core Service Functions

  • Generate personalized spiritual insights and reports
  • Calculate astrological positions, numerology, and other spiritual systems
  • Create and maintain your user account
  • Store and retrieve your personalized reports
  • Cache calculations to improve performance and user experience
  • Generate personalized guided meditations from your dreams and goals
  • Create meditation audio using your cloned voice (if you opt-in)
  • Enhance and process uploaded images for meditation visuals

3.2 Platform Operations

  • Authenticate and authorize access to your account
  • Implement rate limiting to ensure fair usage
  • Monitor system performance and troubleshoot issues
  • Prevent fraud, abuse, and unauthorized access
  • Comply with legal obligations and enforce our Terms of Service

3.3 Communication

  • Send account-related notifications and updates
  • Respond to your inquiries and support requests
  • Notify you of important changes to our service or policies

4. Third-Party Services and Data Sharing

4.1 Third-Party APIs

We use external services to provide accurate calculations:

  • Divine API: Western astrology calculations (birth charts, planetary positions)
  • Human Design API: Human Design chart generation and activations
  • OpenStreetMap Nominatim: Converting birth locations to coordinates (free, open-source geocoding service)

Data shared: Birth date, time, and location coordinates (never your name or email). These services are used solely for calculations and do not store your personal data.

4.2 AI and Content Generation

We use multiple AI services for personalized content generation:

Cartesia (Voice Cloning & Text-to-Speech)

  • Purpose: Generate personalized meditation audio with your voice
  • Data shared: Voice recordings (1-5 seconds), meditation scripts (text only)
  • Data retention: Voice audio is not retained after processing; voice profiles stored until deletion
  • Privacy policy: https://cartesia.ai/privacy

Cerebras/OpenRouter (AI Text Generation)

  • Purpose: Generate meditation scripts and spiritual interpretations
  • Data shared: Dream descriptions (text only), calculated spiritual data, your first name for personalization
  • Data retention: Requests are processed and not stored by the AI service
  • Important: NO personal data (birth date, email, location) is sent to AI text services

Replicate (Image & Video Processing)

  • Purpose: Enhance image quality (upscaling) and generate video previews
  • Data shared: Uploaded images (if you use DreamStorm image features)
  • Data retention: Processing is temporary; images deleted after 24-48 hours
  • Privacy policy: https://replicate.com/privacy

Parallel Search API (Resource Search)

  • Purpose: Find relevant articles, videos, and resources related to your dreams
  • Data shared: Dream keywords only (NO personal data)
  • Data retention: Search queries are not stored

4.3 Infrastructure and Storage

  • Supabase: Database hosting, user authentication, and data storage (including meditation audio and images)
  • Vercel: Web hosting and application deployment
  • Upstash Redis: Caching and rate limiting

4.4 Payment Processing

  • Stripe: Secure payment processing for premium features

We do not store payment card information. All payment data is handled securely by Stripe.

4.5 Data We Never Share

We will never sell, rent, or share your personal information for marketing purposes or with data brokers.

5. Data Storage and Security

5.1 Data Storage Architecture

Supabase Storage Buckets (Private):

  • dreamstorm-meditations: Generated meditation audio files (MP3 format)
  • dreamstorm-meditation-thumbnails: Meditation preview images
  • vision-images: Dream images and user uploads (private, not publicly accessible)

Local Browser Storage:

  • IndexedDB: Cached meditation audio for offline playback (temporary, cleared on browser data reset)
  • LocalStorage: Voice preferences and UI settings (non-sensitive data only)

Third-Party Processing (Temporary):

  • Cartesia: Voice data processed and deleted after cloning (typically < 1 hour)
  • Replicate: Images processed and deleted after generation (24-48 hours)

5.2 Data Retention

  • Account Data: Retained as long as your account is active
  • Reports: Stored indefinitely for your access unless you request deletion
  • Cache Data: Automatically expires after 24 hours
  • Logs: Technical logs retained for 90 days for troubleshooting

🧘 DreamStorm Data Retention

  • Meditation audio: Retained until you delete the meditation or your account
  • Voice profiles: Retained until you delete them or your account
  • Dream images: Retained until you delete the dream or your account
  • Dream descriptions: Retained until you delete the meditation or your account
  • Backup copies: May persist for up to 90 days after deletion for disaster recovery

5.3 Security Measures

  • Passwords are hashed and never stored in plain text
  • API keys and sensitive credentials are encrypted
  • Rate limiting prevents abuse and unauthorized access
  • Regular security updates and monitoring
  • Access controls and authentication for all administrative functions
  • Voice data encrypted at rest and in transit
  • Images stored in private buckets with signed URL access only

6. Cookies and Tracking

6.1 Essential Cookies

We use essential cookies for:

  • User authentication and session management
  • Security and fraud prevention
  • Maintaining your preferences and settings (including voice preferences)

6.2 No Tracking or Analytics

We do not use third-party analytics, advertising cookies, or social media tracking pixels. We do not track your activity across other websites.

7. Your Privacy Rights

7.1 Access and Control

  • View Your Data: Access your profile and generated reports through your account
  • Update Information: Modify your birth information, name, or preferences
  • Download Reports: Export your personalized insights and reports
  • Delete Account: Request complete account and data deletion
  • Delete Voice Profile: Remove your voice clone from Settings → DreamStorm → Voice Profile
  • Download Meditations: Export meditation audio files (MP3 format)
  • Delete Meditations: Remove individual meditation audio and associated data

7.2 Data Subject Rights (GDPR/CCPA)

If you are in the EU, UK, or California, you have additional rights:

  • Right to Know: Request details about data collection and use
  • Right to Delete: Request deletion of your personal data (including voice data)
  • Right to Correct: Request correction of inaccurate information
  • Right to Portability: Receive your data in a portable format (JSON, MP3, PNG)
  • Right to Object: Object to certain data processing activities
  • Right to Limit Use of Sensitive Data: Opt-out of voice recording (disables personalized meditation audio)

🏛️ California Residents (CCPA/CPRA)

Voice recordings are considered "sensitive personal information" under CCPA. You have the right to:

  • Know what sensitive personal information we collect and how it's used
  • Limit the use and disclosure of your sensitive personal information
  • Delete your sensitive personal information
  • Opt-out of any "sale or sharing" (we do not sell or share your data)

7.3 Exercising Your Rights

To exercise these rights, contact us at support@dreamstorm.ai. We will respond within 30 days and may require identity verification to protect your privacy.

8. AI-Generated Content Notice

8.1 Accuracy and Reliability

  • DreamStorm uses AI to generate meditation scripts, images, and audio
  • AI-generated content may contain inaccuracies or unexpected results
  • We do not guarantee the quality, accuracy, or safety of AI outputs
  • You should review all AI-generated content before use

8.2 Content Moderation

  • We implement safety filters to prevent harmful content
  • AI services may refuse to process requests that violate their policies
  • We are not responsible for AI service availability or performance

9. Children's Privacy

Our Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that a child under 18 has provided us with personal information, we will delete such information immediately.

AI vision board features (voice cloning, image uploads) are restricted to users 18 years or older due to legal requirements under BIPA, GDPR, and COPPA regarding biometric data collection from minors.

10. International Data Transfers

Your data may be processed in countries other than your own, including the United States, where our infrastructure providers operate. We ensure appropriate safeguards are in place to protect your data in accordance with applicable privacy laws.

Third-party AI services location: Cartesia (United States), Replicate (United States). We have data processing agreements in place with all third-party services that handle your personal data.

Standard Contractual Clauses (EU/UK Users)

For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission (Commission Implementing Decision 2021/914) to ensure adequate protection when transferring personal data to the United States and other countries.

Our data processing agreements with Cartesia, Replicate, Supabase, and other processors include SCCs that:

  • Require processors to implement appropriate technical and organizational security measures
  • Grant you enforceable rights against processors
  • Provide mechanisms for data protection authorities to intervene
  • Ensure compliance with GDPR Chapter V transfer requirements

View SCCs: You may request a copy of the Standard Contractual Clauses by contacting support@dreamstorm.ai.

EU Representative (Article 27 GDPR)

📍 TODO - EU Representative Contact

For EU/EEA users, we will designate an EU representative under GDPR Article 27 as required. Contact information will be added here once appointed.

In the meantime, EU users may contact us directly at support@dreamstorm.ai for all data protection inquiries.

11. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices or applicable laws. We will notify you of significant changes via email or prominent notice on our Service. The "Last updated" date indicates when the policy was last revised.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at support@dreamstorm.ai. We are committed to addressing your privacy concerns promptly and transparently.

Key Privacy Principles

  • • We collect only the data necessary to provide our spiritual insight services
  • • Your birth information is used solely for calculations and generating your reports
  • • We never sell your personal data or use it for advertising
  • • You maintain full control over your data and can delete your account at any time
  • • All data is encrypted in transit and stored securely
  • • Voice recordings are collected with explicit consent and can be deleted at any time
  • • We comply with BIPA, GDPR, and CCPA regulations for biometric data
  • • Your uploaded images and dreams are private and never shared publicly

What's New in This Version (v2.0)

  • • Added comprehensive voice recording and biometric data disclosures (Section 2.4)
  • • Disclosed Cartesia, Replicate, Cerebras, and Parallel Search API usage (Section 4.2)
  • • Added DreamStorm-specific data retention policies (Section 5.2)
  • • Enhanced user rights for voice profile deletion and meditation data portability (Section 7)
  • • Added AI-generated content disclaimers (Section 8)
  • • Clarified BIPA compliance for Illinois residents
  • • Clarified CCPA/CPRA compliance for California residents