Legal
Privacy Policy.
How we collect, use, and protect your information.
Last updated: June 5, 2026
Scope. This Privacy Policy explains what information Daydream collects, why we collect it, and how we use it. It covers both the daydream.center website and the Daydream platform (companion chat).
1. Information we collect
Account information. When you create an account we collect your email address, a username, an age confirmation that you are 18 or older, and a hashed password. If you sign in through a third party identity provider, we receive a verified email address and a stable user ID from that provider. We do not receive your password from third party providers.
Profile information. You may add a display name, avatar, banner color, and a short about me. All of this is optional.
Conversation content. When you talk to a Daydream companion, we store the text of your messages and the AI replies so the conversation can resume across sessions and devices. Companion memories and learned preferences are stored alongside the conversation.
Onboarding and preferences. During onboarding we collect a coarse age bracket, gender, partner preference, and a small list of interests so we can tailor companion suggestions. These fields are stored in your account and you can update them at any time.
Geographic information. We use coarse country and region level data from your network connection to determine whether Daydream is available in your area. We do not log or store your IP address.
Technical data. When you load the platform we automatically receive standard information such as browser type and version, operating system, and screen size. We use this to size content correctly and to detect security issues.
Crash and error data. We use Sentry to capture application errors so we can fix bugs. Sentry receives the error stack trace, a short description, and basic device information. We do not send your conversation content or your personal profile to Sentry. Sentry only fires when something goes wrong.
Acknowledgment timestamps. We record the date and time when you accept these Terms or acknowledge the in app AI disclosure so we have a clear record of your consent.
2. Information we do not collect
- We do not run third party advertising on Daydream
- We do not sell or rent your personal information to anyone
- We do not use behavioral tracking cookies for advertising
- We do not collect biometric data, location coordinates, or contact lists
- We do not allow under 18 use, so we do not knowingly collect data from children
3. How we use your information
We use the information we collect to:
- Operate the platform: deliver messages, run companion replies, keep your account active across devices
- Maintain safety: detect abuse, enforce our acceptable use rules, respond to legal requests
- Improve the product: study how features are used, report on it in aggregate, and design better experiences
- Communicate with you: send service messages, security alerts, product updates, and waitlist invitations
- Comply with law: respond to lawful requests from regulators or courts
4. AI processing
To generate replies, your message and a limited amount of recent conversation context are sent to third-party language model providers. We choose providers whose published terms commit them, by default, not to retain your inputs or outputs and not to use API content to train their models, and we configure each request to instruct the provider not to log or retain your conversation for its own purposes. We do not sell this content and we do not use it to train our own models. A provider may briefly retain content to detect abuse or for security, under its own terms. You agree to this processing when you accept our Terms and the in-app AI notice before your first message.
If we change our model providers, or how your conversation content is processed, we will update this policy; where the change is material we will ask you to review and agree again before you continue.
5. How we share information
We do not sell your personal information. We share information only with the following categories of recipients, and only as needed:
- Service providers that we contract to run the platform: Supabase (database and authentication), Cloudflare (edge security and content delivery), Vercel (web hosting), Sentry (error reporting), and the language model providers we use to generate replies.
- Payment processors if you purchase a subscription. The processor handles card details directly; we receive a token, not your full card number.
- Law enforcement if we receive a valid legal demand and after we review it for scope and legality.
- A successor company if Daydream is acquired or merged, in which case the recipient must honor this policy.
6. Children
Daydream is for adults. We require all users to be at least 18 years old. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with information, email and we will delete the account.
7. Geographic availability
Daydream is currently available only in certain regions. We do not serve users in the European Union, European Economic Area, Switzerland, the United Kingdom, Australia, Canada, or in the U.S. states of New York, California, Utah, Texas, and Illinois. We may expand availability over time.
Because we exclude these regions from the service entirely, this policy is written for our current user base in unrestricted regions. We do not run GDPR, UK GDPR, or CCPA data sale opt out flows, because the underlying conditions for those rights do not apply to our user base.
8. Data retention
We retain your account and conversation data for as long as your account is active. If you delete your account, we delete your conversation content and profile within 30 days. We keep a minimal record of the deletion itself, plus any data we are legally required to keep, for up to one year.
Acknowledgment records (Terms acceptance, AI disclosure dismissal) are retained for as long as we may need to demonstrate consent, then anonymized.
9. Your choices and rights
You can:
- Update your account information at any time from your profile
- Delete your account at any time by emailing
- Request a copy of the personal data we hold about you
- Ask us to correct inaccurate data
We respond to requests within 30 days.
10. Security
We use industry standard measures to protect your data, including:
- encryption in transit
- encrypted database storage
- row level security policies on our database
- hashed passwords
- signed and short lived authentication tokens
- rate limits on sensitive endpoints
No system is perfectly secure. If we discover a breach affecting your personal information we will notify you in compliance with applicable law.
11. Cookies and similar technologies
We use a small number of strictly functional cookies and similar storage:
- Authentication session cookies that keep you signed in
- A preference cookie that remembers your active skin
- A signed token cookie that records the date you acknowledged the AI disclosure (used to skip the modal during the next 24 hours)
- A signed token cookie that records your Terms acceptance (used to skip the re-accept modal until the next material update)
- Cloudflare may set a short lived token cookie as part of bot protection
We do not use advertising cookies, tracking pixels, or cross site identifiers. We do not run analytics tools that profile individual users.
You can review Cloudflare’s privacy practices at cloudflare.com/privacypolicy.
12. International users
If you are accessing Daydream from outside the United States, you understand that your information will be processed in the United States. By using the service you consent to this processing. We do not serve users in regions that prohibit this transfer (see Section 7).
13. Changes to this policy
We may update this policy. When we make a material change, we will update the date at the top of this page and require you to accept the updated Terms before continuing to use the platform. Minor changes will be posted without a re-acceptance prompt.
14. Contact
Privacy questions: .
General questions: .