DREAMERIE

Privacy Policy

Last updated: 2026-08-18  ·  Version: 1

In one sentence: Dreamerie is a sleep-audio app that collects only the data we need to make it work, never sells or shares anything, and keeps your health data on your device unless you separately agree to share it.

What we collect and why

A random device identifier. When you first open the app, your phone generates a random ID and stores it in the iOS Keychain. This ID is sent with requests to our server so we can group your activity together. It has nothing to do with your real-world identity. You can reset it at any time from Settings → Clear all my data (see “Deleting your data” below). Note that deleting and reinstalling the app does not reset it. iOS keeps Keychain entries across reinstalls, so the app gets the same ID back.

Usage events. As you use the app, starting a podcast, adding a show, setting a sleep timer, we record what happened and when. We use this to understand what works and to improve the product. We do not record the contents of your screen.

Your podcast searches. When you search for a podcast, we record the words you searched, along with your random device ID and the time. We use this to run the search, protect the service from abuse, and improve results. We also look at what people search for and add in aggregate, across everyone and never tied to you personally, to help us decide which podcasts to add to our library. We do not tie searches to your real-world identity.

The shows you add. When you add a podcast to "My Shows," we store that choice on our server so your library is there when you come back.

Basic technical info. To diagnose problems and keep the app fast, we record technical details such as your device model, iOS version, and how long the app takes to launch, along with crash information. This is not tied to your real-world identity.

That's it. We do not collect your name, email, phone number, location, contacts, photos, microphone, or camera. We do not use any advertising identifier. We do not track you across other apps or websites.

Podcasts you play

Dreamerie plays podcasts from publicly available RSS feeds. When you play a third-party podcast, the audio streams directly from the podcast publisher's own servers, not from us. As with any podcast app, that means the publisher (and whoever hosts or serves ads in their feed) can see your device's IP address and that the episode was requested. We do not control, receive, or store that information. We do not edit episodes and we do not remove or replace the ads inside them; we only adjust playback loudness for a consistent, sleep-friendly volume.

Health data

By default, your health data never leaves your phone. If you grant permission, the app reads your heart rate, heart-rate variability, respiratory rate, blood oxygen, and sleep stages from the iOS Health app. On your device, it learns from your sleep history when you tend to fall asleep, so the Auto sleep timer can end audio at the right time. For almost everyone, this happens entirely on your device. We don't receive it, store it, or see it.

Research participants only. During this test period, some people choose to help us study sleep by sharing their overnight biometric sessions. This happens only if you give explicit, informed consent in the app (Settings → Sleep research), a screen that describes exactly what is shared before you agree. That agreement, recorded with the version of the disclosure you saw, is what authorizes the upload; nothing leaves your phone until you give it. Only then are the vitals listed above uploaded to our server (in the United States), where we can view them to improve how the app responds to your body. You can withdraw at any time in the app (Settings → Sleep research → “Withdraw & delete my data”), which immediately stops future uploads and deletes the sessions we hold; you may also email us. Withdrawing does not change your device ID, so if the deletion can't complete right away you can simply try again when you're online.

Who else sees your data

Cloudflare hosts the audio library and cover art. They do not receive any information about you personally.

Railway hosts our server. They store the random device ID, the usage events and searches described above, and, for enrolled research participants only, the biometric sessions described above, in a database located in the United States. Forge8 LLC is a US company and our servers are in the US, so wherever you are, your data is held in the United States from the moment it leaves your phone. We apply the same protections and the same rights to everyone, no matter which country you are in.

Apple handles app distribution and, if you opt in through iOS Settings, receives anonymized crash reports to help diagnose problems. We never see those reports with any personal detail attached.

We will never sell your data to anyone, ever. We will never share your data with advertisers, data brokers, or marketers.

How long we keep data

Usage events, searches, and technical info are kept for 13 months and then automatically deleted. Biometric sessions from enrolled research participants are kept until you withdraw or ask us to delete them, and no longer than needed for the study. If you don't use the app for 12 months, all your data is erased entirely, including the random device ID.

Your rights

You can ask us to:

The fastest way to delete your data is in the app. To erase everything, use Settings → Clear all my data (see “Deleting your data” below). To stop and delete your biometric research data only, use Settings → Sleep research → “Withdraw & delete my data.” For anything else, such as a copy of your data or deletion of other data, email with the Keychain UUID shown in-app (Settings → About → Your device ID). We'll respond within 30 days.

Your data is tied to a random device ID rather than your name, so we treat it as pseudonymous personal data and honor these rights on that basis. We don't refuse a request on the grounds that the data is “anonymous.”

You have these rights wherever you are. We don't do geographic branching. We treat everyone to the strictest standard (GDPR).

If you think we've handled your data badly, you can complain to a regulator. In the UK that's the Information Commissioner's Office, at ico.org.uk. In the EU it's the data protection authority in the country where you live. You're welcome to come to us first and give us the chance to put it right, but you don't have to.

Deleting your data

You can erase your data at any time from Settings → Clear all my data. This clears everything Dreamerie has stored on your device, deletes any health data we hold about you on our servers, and gives your app a new anonymous device ID so your future use can't be connected to your past use.

If your device is offline when you do this, the erase on your phone still happens straight away. We keep your old device ID on your phone, and nothing else, so the app can finish deleting your server-side health data the next time it connects. That ID is used for nothing but the deletion, is kept for at most 30 days, and is removed as soon as the deletion succeeds. If it hasn't succeeded within 30 days, we delete the ID from your phone; any remaining data is then removed on our normal retention schedule.

Children

Dreamerie is rated 13+ on the App Store. That rating is there because you can search and play podcasts from public directories that we don't individually screen. We pick what goes into our own library carefully, but a third-party feed can change at any time and we can't guarantee what's inside every episode, so please treat it as best effort rather than a promise.

The app isn't designed for children, and we don't knowingly collect data from anyone under 13. If you believe we have, email and we'll erase it.

Changes to this policy

When this policy changes in a material way, we'll update the "Last updated" date and raise the version number above. We don't quietly change our privacy posture.

Who we are

Dreamerie is made by Forge8 LLC, a company registered in the United States. Forge8 LLC decides what data this app collects and why, which makes it the data controller for everything described in this policy.

Contact