Skip to document

Demure AI LLC · Dreamy mobile app

Privacy Policy

What Dreamy collects, why it is used, which providers receive it, and the choices available to your family.

Draft updated 12 September 2026 · Not yet effective

01Who we are

Demure AI LLC, Hong Kong (DEMURE AI, “we”, “us”, or “our”), provides Dreamy. We are responsible for the personal data we collect and use to operate the service. This policy covers the Dreamy mobile app on Android and iOS and the connected services used to create, store, and play stories.

Dreamy is intended to be operated by adults. Children may read and listen with an adult; they are not permitted to create their own accounts or operate the service independently. The Terms & Conditions explain the rules for use.

Demure AI LLC
Hong Kong
valeriy.kuznetsovdev@gmail.com
Business mailing address: to be confirmed before publication.

02Data we collect

  • Account and device information: an account or guest identifier, an app/device identifier, account creation and activity dates, and, if you register, your name, email, and authentication information. Guest use is linked to identifiers; it is not necessarily anonymous.
  • Child and character details: the name or nickname, age or age group, gender, appearance, interests, character descriptions, and other details you choose to provide. Character customization can include skin tone or race/ethnicity-related descriptions. Please use a nickname and provide only what is needed for the story.
  • Photos and derived descriptions: reference photos you select, generated portraits, and appearance descriptions extracted from photos, such as hair color, eye color, and skin tone. These help create illustrations that resemble the selected character.
  • Audio: recordings you submit for spoken story ideas or an optional parent voice, transcriptions, voice identifiers and voice models, and generated narration. Live voice features, where offered, also process session audio and session metadata.
  • Story content and activity: prompts, settings, themes, lessons, emotional focus, language, generated text and media, choices, favorites, likes, reading completions, dates, durations, and streaks.
  • Purchases: app user and transaction identifiers, products, receipts or purchase tokens, subscription status, renewals, cancellations, and entitlement information. Apple or Google handles payment details for store purchases; Dreamy does not receive your full payment-card number from those purchases.
  • Technical and usage data: device and app version, operating system, network information such as IP address, event timestamps, screens and actions, diagnostics, crashes, notification identifiers, and session replay data where enabled.
  • Support and reports: messages you send us and content reports, including the affected story and reason for the report.

Photos, microphone access, and parent voice creation are optional. If you do not supply a photo or recording, the associated feature cannot use it. Account/device identifiers and the information needed to fulfill a story request are necessary for those services. Do not submit identification documents, precise addresses, medical records, or other sensitive information that a story does not need.

03Why we use data

We use data to authenticate you, personalize and generate stories, keep characters and pictures consistent, create narration and sound, maintain your library, restore purchases, deliver notifications, respond to support requests, investigate reports, and operate and protect the service.

We also use usage and diagnostic information to understand which features work, investigate failures, and improve the app. Support investigations may require access to the story, prompt, or media concerned. Information sent through advertising or measurement SDKs is described below; these uses must be considered separately from story generation.

04Children and adult responsibility

An adult must manage the account, purchases, uploads, and story creation. Only submit information about a child if you are their parent or legal guardian, or have the necessary permission. Supervise use and review each story before sharing it with a child.

Child names, photos, appearance details, and voices can be personal data even when an adult submits them. An adults-only account rule does not remove our obligations for this data. Use fictional characters or nicknames when possible. The parent voice feature is intended for an adult’s authorized voice, not for cloning a child’s voice.

A parent or guardian may ask about the information held about their child, request correction or deletion, or withdraw consent where consent applies. We may need to verify authority before providing access. If you believe a child has independently provided data, contact us so we can investigate and take appropriate action.

05AI, photos, and voice processing

Dreamy sends the content needed for a requested feature to external AI providers. Story requests can include names, character descriptions, age settings, interests, prompts, and previous story context. Photo-based character creation sends selected photos for appearance analysis and illustration generation. Audio features can send recordings, transcripts, or story text.

For an optional parent voice, ElevenLabs receives the submitted recording and voice label to create a reusable voice model. That voice can then be used to narrate stories. Use only your own adult voice or a voice you have express permission to use. Removing a voice does not erase narration already generated with it.

AI providers may retain inputs, outputs, and service logs under their applicable service terms, account settings, and legal obligations. Their rules for model improvement and human review differ. This draft does not promise zero retention or that every provider excludes all data from training; the release-specific arrangements must be confirmed before this policy becomes effective.

A device permission to access photos or the microphone is separate from permission to send personal data to an AI provider. Read the feature disclosure before you submit data. AI content can contain errors and must not be treated as medical, psychological, or other professional advice.

06Providers and recipients

The reviewed app and backend include the following services. A provider receives the data needed for its function; availability can depend on platform, feature, or the configured generation route. Links below explain the providers’ practices and do not replace our responsibilities.

Convex
Authentication, database, file storage, backend functions, and service logs. Processes account/device identifiers, profiles, prompts, uploaded files, generated content, and activity records.
OpenAI
Story and prompt processing, character planning, photo appearance analysis, and live voice features where offered. Receives the relevant text, images, or voice-session data.
Google Gemini API and fal.ai
Illustration generation, photo-based portraits, and picture-discovery processing. Receives image prompts, story context, reference pictures, or generated images. fal.ai may route processing to hosted model services.
ElevenLabs
Narration, character voices, speech transcription, parent voice models, music, and sound effects. Receives relevant text, recordings, voice labels, and voice identifiers.
RevenueCat, Apple, and Google Play
Purchase processing and subscription entitlements. RevenueCat receives the app user identifier and store purchase information. The stores also process data under their own terms and privacy notices.
PostHog
Android product analytics and session replay, including event and screen data, identifiers, device information, and a representation of app sessions. See the next section for the limits of masking.
Google Firebase Crashlytics
Android crash and diagnostic reporting in release builds, including app/device details and crash information. Firebase Analytics collection is disabled in the reviewed Android configuration.
OneSignal
Android push-notification services, including notification subscription identifiers, device details, and notification delivery or engagement information.
Meta / Facebook SDK
The Android app initializes the Facebook SDK and includes app-event logging for measurement. Events and device or network information can be processed according to SDK configuration. Advertising identifiers, attribution, and consent settings require release verification.

Additional selectable or older generation paths include Anthropic for character planning, and Leonardo.Ai or Replicate for images. If those paths are used, they receive the associated prompt and reference data. External avatar or sample-media hosts, including DiceBear, Unsplash, and Google-hosted audio, receive normal network request information when their resources load.

We may also disclose relevant information to professional advisers, authorities where legally required, or a successor in a business transaction, subject to applicable law and appropriate protections.

07Analytics and session replay

The reviewed Android build enables PostHog session replay with image and text-input masking configured. Masking is a protective measure, not a guarantee that all displayed content or event properties are removed. Session data may include screen content, interactions, technical information, and identifiers. The iOS analytics integration may differ.

We have not verified a universal in-app analytics opt-out in the reviewed build. Turning off notifications or microphone access does not turn off analytics or remove data already collected. The final release must document available consent and withdrawal controls before this policy becomes effective.

The reviewed Android app removes the advertising-ID permission and disables Google ad-personalization signals. Those settings alone do not establish that all SDK processing is outside legal definitions of advertising-related “sharing” or tracking. The final policy must reflect the verified Meta and other SDK configuration.

08Story visibility and sharing

Do not assume all created stories are private. In the reviewed version, ordinary generated stories can be public by default and available to other users. Story Fort stories are created with a private flag. Public stories may include personalized text and generated media, which can reveal information supplied about a child.

Shared or downloaded media can be copied by recipients. Removing content from your library cannot recall copies others have already saved. Avoid real identifying details in content that may be public. Visibility controls and access to stored media must be verified for the released version.

09Permissions and your choices

You can choose whether to supply reference photos, record your voice, or use a parent voice. Your device settings control microphone and notification permissions. Photo selection gives the app access to the items you select; the app does not need your entire photo library for a character reference.

You can stop optional uploads, use fictional details, and manage purchases through the store. Revoking a device permission stops future access covered by that permission; it does not automatically erase copies already submitted. Signing out or uninstalling the app also does not necessarily delete backend data.

10Retention and deletion

Data remains in the service to support accounts, saved characters, stories, purchases, and requested features. Retention must be limited to the time needed for those purposes, resolving requests or disputes, security, and applicable legal duties. Exact limits for uploaded photos, recordings, logs, session replays, and backups still need to be set and verified before publication.

In the reviewed build, deleting a story removes story records and associated database entries, but does not show complete deletion of all stored media or provider copies. Removing a parent voice attempts to remove the provider voice and clears the profile reference; it does not currently demonstrate deletion of every stored recording. A complete account-deletion process has not yet been verified.

A deletion request should cover the account, child/character profiles, uploads, generated files, voice models, and relevant provider records. Limited records may need to be retained for legal obligations or security; the reason and applicable retention must be explained. Backups and files copied outside the service may follow separate deletion cycles.

Deleting an account does not cancel an Apple or Google subscription. Cancel it separately through the store to stop renewal.

11Your rights and requests

Depending on the law that applies, you may have rights to access and correct data, obtain a copy, request deletion, restrict or object to processing, and withdraw consent. Withdrawal does not affect processing that was lawful before withdrawal. Some rights have legal exceptions.

Contact Demure AI LLC using the details in this policy. Explain the request and provide the account email or an app identifier if available. Do not send passwords, full payment-card details, or identity documents unless a secure verification process specifically requires them. We may verify your identity or parental authority and will respond within the applicable legal period.

In Hong Kong, you may contact the Office of the Privacy Commissioner for Personal Data. Where other privacy laws apply, you may also complain to the relevant authority in your country. Send privacy requests to valeriy.kuznetsovdev@gmail.com. Our business mailing address will be added before final publication.

12Legal grounds and international processing

Demure AI LLC is based in Hong Kong. Providers may process information in the United States and other countries where they and their service providers operate. Data-protection rules can differ between countries. The release review must confirm processing locations, provider contracts, and any legally required transfer safeguards; this draft does not claim a specific hosting region or executed transfer agreement.

Where GDPR or similar law applies, the relevant legal basis depends on the purpose: performance of the adult’s service contract for necessary account and service operations; legal obligations for required records; legitimate interests for proportionate security and service administration; and consent for processing that requires it. These grounds are not interchangeable. The basis for child personalization data, optional photo/voice features, analytics, and advertising-related processing must be assessed separately and explained at collection.

13Security and policy changes

We use service access controls and secure connections to help protect information. No service can guarantee absolute security. Keep account credentials secure and avoid including unnecessary personal information in prompts or public stories.

We may update this policy when the app, providers, or legal requirements change. The effective version will carry an updated date. Material changes will be communicated as required by law, with new consent where required. A policy update is not a substitute for obtaining that consent.