How we
handle your dreams.
Last updated · April 2026
his is the privacy notice. It is written in plain English, on purpose.
Dream content is unusually personal data. We treat it accordingly. What follows is the full account of what we collect, how we use it, who can see it, and what you can do about all of it.
Who is responsible
DreamTracker (dreamtracker.org) is operated by Ari Horesh, an independent studio based in Pavia, Italy. The data controller for the purposes of the GDPR is:
Ari Horesh
Pavia, Italy
P.IVA IT02865360180
privacy@dreamtracker.org
What we collect
Account data. Email, name (optional), authentication method (email + password, Google, or Apple), and the timestamps of your sessions. Nothing else from third-party providers.
Dream content. Whatever you type, record, or photograph: titles, body text, audio files, journal photos, tags, mood, color, and the lucid/nightmare/sleep-paralysis flags you set.
Derived data. A mathematical fingerprint of each dream (used to group similar entries), the motifs and themes we pull from your text, your mood timeline, and your monthly reports. The technical name for the fingerprint is a vector embedding; it cannot be read as text.
Usage data. Quota counters (e.g., how many voice recordings you've made this month), basic event logs needed for the product to function. We do not collect mouse-movement heatmaps, session replays, or anything similar.
Billing data. Stripe stores your card details and tax information; we never see them. We store your Stripe customer ID, current plan, seat usage, and subscription status.
How we use it
Strictly to operate the product you signed up for: storing your journal, transcribing audio, running pattern analysis on your own data, sending you account emails (welcome, billing, password reset), and processing payments via Stripe.
We send aggregate, anonymised health metrics (e.g., total active users, error rates) to ourselves via Vercel Analytics and Sentry. None of this includes dream content.
What we do not do
We do not train any AI model on your data. We do not sell, rent, or share your data with advertisers. We do not show your dreams to anyone, including your therapist, without your explicit per-dream consent. We do not show your dreams to other users, ever.
How long we keep it
For as long as your account exists. If you delete your account, we cascade-delete all your dream content, audio files, embeddings, and analyses within 30 days, and write an audit-log entry confirming the deletion. Account-level audit logs themselves are retained for 12 months for security and compliance purposes.
Your rights
Under GDPR (and equivalent regulations in your jurisdiction):
- Export. Download your full data as JSON or PDF anytime from settings.
- Delete. Permanently remove your account and all data with one click.
- Correct. Edit or remove individual dreams, tags, and personal info.
- Object. Withdraw consent for analytics or specific processing.
- Portability. Take your data to another tool — your export includes everything.
Subprocessors
We use a small number of carefully chosen subprocessors. All are GDPR-aligned with appropriate Data Processing Agreements in place.
- Vercel (US/EU) — hosting, build, edge functions.
- Neon (EU region) — Postgres database, including pgvector.
- Vercel Blob — private storage for audio and journal photos.
- Stripe — billing and payment processing.
- Resend — transactional email delivery.
- Vercel AI Gateway — routes inference to Anthropic, OpenAI, xAI, and Google. Inference providers are governed by their respective enterprise data agreements; none of them train on our customers' data.
- Sentry — error monitoring (no dream content ever sent).
Cookies
We use essential cookies only by default — session authentication and theme preference. Analytics cookies are opt-in via the cookie banner. We do not use advertising cookies.
Children
DreamTracker is intended for users aged 16 and older. We do not knowingly collect data from anyone under 16. If you believe a minor has signed up, please email us and we'll remove the account and all associated data.
Therapist data handling
When you are linked to a therapist, the therapist sees only the dreams you have explicitly chosen to share (default: all; you can opt out per dream). Audio recordings are never visible to therapists. Therapist notes are private to the therapist and never visible to clients. Either party can revoke the relationship at any time, freeing the seat and removing the therapist's access.
Changes
If we materially change this notice, we'll email you and post the change-log here. We won't silently expand what we do with your data.
Contact
Privacy questions, data requests, complaints, or curiosities: privacy@dreamtracker.org.
Data controller
Ari Horesh · Pavia, Italy · P.IVA IT02865360180