Privacy policy
Last updated 2026
The short version
Your dreams, reflections, and journal entries are only readable by you and people you explicitly share them with. We store ciphertext, not your words — see our on-device and E2EE promise for how that works in practice. We don't sell data, run ads, or track you across other sites.
What we collect
To run an account, we store the minimum needed to authenticate you and sync your data: your username, a securely hashed authentication key, and the timestamps on your entries. Entry content — dream text, journal reflections, tarot notes, and AI interpretations — is encrypted on your device before it ever reaches our servers, using a key derived from your password. We never have access to the key that would let us read it.
AI readings
AI readings run entirely in your browser, using your own Anthropic API key. Your device decrypts the text and sends it straight to Anthropic for that one request — it never passes through our servers — then encrypts the result before storing it. Your API key is kept only in your browser's local storage; we never see or store it.
Device sync
If you pair a phone or another device, sync uses a device-specific token rather than your password. Pairing codes expire after five minutes, and pairing a new device retires the old one.
What we don't do
- We don't log or store entry content on our servers.
- We don't sell or share your data with third parties for advertising.
- We don't use tracking cookies or third-party analytics.
Your data, your control
You can export or delete your entries at any time from your account settings. Deleted entries are removed from our systems.
Questions
If you have questions about this policy, reach out via our contact page.