Legal

Privacy Policy.

Last updated: May 19, 2026

TrueDream AI (“we,” “our,” or “us”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our service at truedreamguide.com.

Data We Collect

  • Account information: email address and password (stored as a bcrypt hash) when you register.
  • Dream content: the dream descriptions you submit, stored to provide and improve the service and saved as your personal history.
  • Usage data: plan type, feature usage counts, and timestamps for billing and quota enforcement.
  • Cookies and similar technologies: see our Cookie Policy.

How We Use Your Data

We use your data to operate, maintain, and improve the Service; to process subscriptions and payments (through Creem, our payment processor); to communicate with you about your account, billing, and service updates; and to comply with legal obligations.

Data Sharing

We do not sell your personal data. We may share data with:

  • Creem — payment processing (they receive billing information only, never dream content).
  • Brevo — transactional email delivery (verification, password reset).
  • OpenRouter / DeepSeek — AI interpretation generation (dream text is sent for processing; see their privacy policies for how they handle API content).
  • Law enforcement — where required by applicable law or legal process.

Data Retention

Account and dream history are retained for as long as your account exists. You may delete your account at any time by emailing [email protected], after which data is deleted within 30 days, except where we are required to retain it for legal or accounting reasons (e.g., billing records).

Your Rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or port your data. To exercise these rights, contact [email protected]. We will respond within 30 days.

Security

We implement reasonable technical and organizational measures to protect your data, including encryption in transit (TLS) and at rest, bcrypt password hashing, and access controls on our production systems.

International Transfers

Your data is processed on servers located in the United States and the European Union. By using the Service, you consent to the transfer of your data to these locations. We rely on Standard Contractual Clauses and adequacy decisions as appropriate transfer mechanisms under GDPR.

Children

The Service is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us.

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified by email (for registered users) or via the Service.

Contact

For privacy-related questions or to exercise your rights:

Email: [email protected]