Privacy policy
Last updated 27 July 2026
The short version
Your dreams, reflections, and journal entries are only readable by you and people you explicitly share them with. We store ciphertext, not your words — see our on-device and E2EE promise for how that works in practice. We don't sell data, run ads, or track you across other sites.
What this policy covers
Two things: oliminal.com in your browser, and the Oliminal Android app. They share one account system and one encryption scheme, so most of what follows is true of both — where they differ, it says so.
The Android app runs without an account at all. Installed and never signed in, it records, transcribes, and stores everything on your phone and talks to no server of ours, because there is nothing to talk to it about. Creating an account is what turns on backup, sync, and sharing, and it is the only thing that sends us anything.
What we collect
To run an account, we store the minimum needed to authenticate you and sync your data: your username, a securely hashed authentication key, and the timestamps on your entries. Entry content — dream text, journal reflections, tarot notes, and AI interpretations — is encrypted on your device before it ever reaches our servers, using a key derived from your password. We never have access to the key that would let us read it.
We ask for no email address, no phone number, and no real name.
Your voice and your recordings
The app records audio through your phone's microphone, only while you are on a recording screen and have granted the microphone permission. There is no background or always-on listening.
Transcription happens on your phone. The app runs a speech model (Whisper) locally, so your voice is never uploaded to us or to anyone else to be turned into text. The audio file stays in the app's private storage on your device.
If you have an account and sync is on, recordings are encrypted on your phone — with the same key that protects your text — and the encrypted file is uploaded so your other devices can play it. We hold an encrypted blob and cannot listen to it.
What the app stores on your phone
The app keeps its own copy of your entries, transcripts, and recordings on the device, readable by the app so it can work offline. Your account credentials and encryption key are held in Android's hardware-backed keystore.
We deliberately exclude the app's database and its audio from Google's cloud backup and device-to-device transfer. Those copies would be readable, which would hand Google content our own servers cannot read — so the app opts out and syncing to your Oliminal account is the intended backup path instead. Uninstalling the app erases everything it stored locally, and Settings has a "Clear all local data" action that does the same without uninstalling.
AI readings
AI is optional, off until you turn it on, and we run no AI service ourselves — we hold no key with any AI provider and there is no server-side AI path to relay anything through. You choose between two arrangements:
- On the device (Android only). The app downloads a Gemma model once and runs it on the phone. Your dream text never leaves the device, and no key or account is needed. The one-time download comes from Hugging Face, which — like any download — sees your IP address; it is a file fetch and carries nothing about you or your entries. The same is true of the optional additional transcription models.
- A cloud provider, with your own API key. You pick the provider — Anthropic (Claude), OpenAI, or Google Gemini — and supply that provider's key. Your device decrypts the text and sends it straight to that provider for that one request — it never passes through our servers — then encrypts the result before storing it. In this arrangement, the dream you asked about is disclosed to the provider you chose and handled under their terms, not ours; if you switch providers, later requests go to the new one and earlier ones remain disclosed to the old. Your API key is stored only on your device (browser local storage on the web, the encrypted keystore in the app); we never see or store it.
Device sync
If you pair a phone or another device, sync uses a device-specific token rather than your password. Pairing codes expire after five minutes. You can pair up to ten devices at once, and you can disconnect any of them individually — or all of them — from your settings. Changing your password or using your recovery code disconnects every device.
Permissions the app asks for
- Microphone — to record dreams and reflections. The app is unusable without it, but only for recording; you can still write entries by hand.
- Notifications — to show progress while a recording transcribes or a model downloads.
- Camera — only when you scan a pairing QR code, and only for as long as the scanner is open. No image is stored or transmitted.
- Internet — for sync, sharing, model downloads, and Claude requests, if you use them.
What we don't do
- We don't log or store entry content on our servers.
- We don't sell or share your data with third parties for advertising.
- We don't use tracking cookies or third-party analytics — on the web or in the app. The app contains no analytics or crash-reporting SDK, so it reports nothing about you to anyone, including us.
- We don't listen in the background, read your other apps, or ask for your contacts or location.
Children
Oliminal is not directed at children under 13, and we don't knowingly create accounts for them. Since we collect no email address or date of birth, we have no way to identify a user's age — if you believe a child has created an account, tell us via the contact page and we'll remove it.
Your data, your control
You can export everything from your account settings at any time. Because your entries are encrypted with a key only your devices hold, the export is produced on your device rather than by us — we could not assemble a readable copy even if you asked us to.
Deleting your account
You can delete your account from either surface, and both do exactly the same thing:
- In the app — Settings › Delete your Oliminal account.
- On the web — Settings, while signed in.
Either way you confirm with your password first. Deletion permanently removes your account, every entry and interpretation, your recordings, any shares you sent or received, and every paired device. Deleting from the app also erases the app's local copy from that phone; other phones you paired keep theirs until you clear or uninstall them, because we can no longer reach those devices to tell them anything.
It is immediate and it cannot be undone: we have no way to restore your content, because we cannot read it. Export first if you want to keep a copy.
What we keep, and for how long
- Deleting a single entry marks it as deleted so the deletion reaches your other devices. The encrypted content stays on our servers until you delete your account.
- A recording attached to a deleted entry is likewise kept until account deletion.
- If you shared an entry with someone, they keep their copy of that snapshot until you revoke the share or delete your account.
- Our web server keeps standard request logs — IP address, page, timestamp, browser — at the network layer. These never contain entry content, session cookies, or device tokens. Requests the app makes for sync are logged the same way and to the same depth: that a device synced, never what it synced.
- The app keeps a diagnostic log on your phone so you can send it to us if something breaks. It stays on the device unless you choose to share it, and it holds no entry content or credentials.
- If you joined the waiting list, we store the email address you gave us until launch. It is never connected to an account.
Questions
If you have questions about this policy, reach out via our contact page.