Introduction

At Oneira, we take your privacy seriously. This Privacy Policy explains how we collect, use, and protect your personal information when you use our dream journal application.

Information We Collect

We collect information you provide directly: account information (email, name), dream entries and content, mood selections, and app preferences. We also collect usage data: app interactions, feature usage statistics, and device information for troubleshooting.

How We Use Your Information

We use your information to: provide and improve our services, personalize your experience, generate dream statistics and insights, send important notifications about your account, and develop new features based on usage patterns.

Data Storage

Your data is securely stored on encrypted servers. Dream content is stored privately and is only accessible by you. We use industry-standard security measures to protect your information from unauthorized access.

Information Sharing

We do not sell your personal information. We may share data with: service providers who assist in operating our app (under strict confidentiality agreements), and legal authorities when required by law.

Security

We implement appropriate technical and organizational measures to protect your data, including encryption in transit and at rest, regular security audits, and access controls. However, no method of transmission over the internet is 100% secure.

NightLock Encryption

Oneira offers an optional security feature called NightLock that provides end-to-end encryption for your dream entries. When you enable NightLock, you create a personal 6-digit PIN that is used to generate a unique encryption key. This key encrypts all your dream content (text, mood selections, tags, and AI analyses) before it leaves your device.

Your NightLock PIN is never stored on our servers in any form — not as plain text, not as a hash, and not in any recoverable format. We use a zero-knowledge architecture, which means that only you can decrypt your dreams. Even Oneira staff cannot access your encrypted dream content.

The encryption process works as follows: your 6-digit PIN is combined with a unique salt value tied to your account to derive a strong cryptographic key using industry-standard key derivation. This derived key is then used to encrypt and decrypt your dream data using AES-256 encryption.

Because we never store your PIN, it is impossible for us to recover your data if you forget your PIN. There is no "forgot PIN" option, no recovery email, and no backdoor. If you lose your PIN and switch to a new device, your previously encrypted dreams will be permanently inaccessible. We strongly recommend that you write down your NightLock PIN and store it in a safe place.

You can change your NightLock PIN at any time from the Profile menu. When you change your PIN, all your existing dreams are re-encrypted with the new key. This process happens entirely on your device.

Important: Your NightLock PIN cannot be recovered by Oneira under any circumstances. If you forget your PIN and need to access your dreams on a new device, your encrypted data will be permanently lost. Please store your PIN securely.

Your Rights

You have the right to: access your personal data, correct inaccurate data, delete your account and data, export your dream entries, and opt out of marketing communications. Contact us to exercise these rights.

Third-Party Services

We use the following third-party services to operate and improve our app: Supabase (authentication and cloud database), RevenueCat (subscription and payment management), OpenAI API (AI-powered dream analysis), Apple Speech Framework (on-device voice-to-text conversion). These services may process certain data on our behalf under strict privacy and security agreements. We encourage you to review their respective privacy policies.

Subscription & Payment Data

Oneira offers auto-renewable subscriptions (monthly and yearly plans) through the Apple App Store and Google Play Store. All payment transactions are processed directly by Apple or Google. We do not collect, store, or have access to your credit card number, bank account details, or other financial information. We only receive a confirmation of your subscription status (active, expired, or in trial) through our payment partner RevenueCat to enable premium features.

Auto-Renewable Subscriptions

Oneira Premium is available as an auto-renewable subscription with Monthly and Yearly plans. Prices vary by region and are clearly displayed in the app and on the subscription purchase screen before you confirm. A 3-day free trial is included with both plans for new subscribers. Payment is charged to your Apple ID or Google Play account upon confirmation of purchase. Subscriptions automatically renew unless canceled at least 24 hours before the end of the current period. You can manage or cancel your subscription at any time through your device's subscription settings (iOS: Settings > Apple ID > Subscriptions; Android: Google Play Store > Subscriptions). No cancellation fee applies. Any unused portion of a free trial will be forfeited upon purchasing a subscription.

Children's Privacy

Oneira is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, please contact us immediately.

Changes to Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy in the app and updating the "Last updated" date.

Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at privacy@oneirapp.com