The short version

Your dreams are yours. On the free tier we process a dream to give you an interpretation, then we let it go: nothing is stored on our servers. On the paid plans, if you choose to save a dream to your journal, it is kept encrypted under your control and you can delete it any time. We never use your dreams to train AI models, and we never sell or share your personal data. This policy explains exactly what we collect, why, and what happens to it.

1. Who we are

Somniary is an EU-based dream interpretation service operated from the Czech Republic. As an EU operator, all data processing is subject to the General Data Protection Regulation (GDPR). We are the data controller for personal data processed through somniary.com.

For any privacy-related questions, contact us at hello@somniary.com.

2. What data we collect and why

2.1 Dream text and mood selection

What: The text you write in our dream interpreter and the mood you select.

Why: To generate your personalized dream interpretation using AI.

Legal basis: Your consent (GDPR Art. 6(1)(a)), you actively choose to submit your dream.

Sensitive data notice (GDPR Art. 9): Dream descriptions may incidentally contain special categories of personal data, such as information relating to your health, intimate life, religious beliefs, or emotional state. By submitting your dream text, you provide your explicit consent (Art. 9(2)(a)) for the processing of any such sensitive data, for the purpose of generating your personalized interpretation and, if you are on a paid plan and choose to save it, storing it in your journal (see 2.5).

Retention: On the free tier, your dream text is sent to our AI provider (Anthropic) for processing and is not stored on our servers. Once the interpretation is generated, the dream text exists only in your browser session, and when you close the tab it is gone. On the paid plans, only if you actively save a dream, it is stored encrypted in your journal until you delete it (see 2.5).

2.2 Payment information (paid plans)

What: Name, email, payment card details. Why: To process your subscription payment. Legal basis: Performance of a contract (GDPR Art. 6(1)(b)). Retention: Payment processing is handled entirely by Stripe, Inc. We do not store your full card number.

2.3 Usage analytics

What: Anonymized, aggregated data about how the public site is used (Google Analytics), and, when you arrive from one of our ads, measurement of that ad's performance. Why: To improve Somniary and to see which ads are worth running. Legal basis: In the EEA, UK and Switzerland, your consent (GDPR Art. 6(1)(a)): nothing is collected until you agree in the cookie bar, and Google Analytics runs without cookies until then. Elsewhere it runs on an opt-out basis (legitimate interest, Art. 6(1)(f)) and you can decline at any time from the cookie bar. This never applies to your dream content. Retention: Up to 26 months, non-identifiable.

2.4 Email address (if you create an account)

What: Your email address. Why: Authentication, recovery, and (with consent) updates. Legal basis: Contract (Art. 6(1)(b)) for functionality; consent (Art. 6(1)(a)) for marketing. Retention: Until you delete your account.

2.5 Dream journal (Companion and Reverie plans only)

What: If you subscribe and choose to save a dream, we store that dream: the dream text, its interpretation, any follow-up conversation and your notes, plus light metadata (the date, the moods you selected, the moon phase, and short motif tags such as "water" or "being chased" that let us build your timeline). Free use never reaches this: the free tier stays account-free and stores nothing.

Why: To give you the journal you are paying for, the recurring-motif "golden thread", the timeline, and the monthly letter.

How it is protected: The sensitive content (dream text, interpretation, conversation, notes) is encrypted at rest (AES-GCM) in our database. This is encryption at rest with a key we hold, not end-to-end encryption, so our systems can decrypt a dream to generate your letter and timeline; no human at Somniary reads your dreams. The short motif tags and the mood, date and moon-phase fields are stored in the clear so the timeline works without decrypting every entry. To create the motif tags, the dream text is sent once to our AI provider (Anthropic) for tagging and is not retained by them.

Legal basis: Performance of your subscription contract (Art. 6(1)(b)) and, because a dream may contain special-category data, your explicit consent (Art. 9(2)(a)) given when you save it. Retention: Until you delete the entry or your account, whichever comes first. You can export or delete your journal at any time from your account.

3. How your dream interpretation works

When you click " Read Your Dream", your dream text is sent from your browser to our EU-based server, forwarded to Anthropic’s Claude API for processing, and the interpretation is returned and displayed. We do not log, store, or save your dream text at any point, it exists in server memory only for the duration of the API call and is discarded immediately after.

Your dreams are never used to train AI models. Anthropic’s API usage policy explicitly states that API inputs are not used for model training. We have no access to your dream text after the interpretation is delivered, and no human at Somniary reads your dreams. This describes the free interpreter, where nothing is kept. On a paid plan, a dream you actively choose to save to your journal is stored encrypted under your control (see 2.5); we never assemble a dataset of dreams for our own use. This is by design, not by accident.

4. Cookies

Essential cookies: Minimal, required for sign-in and security, no consent needed. Analytics and ad-measurement cookies: Managed through Google Consent Mode. In the EEA, UK and Switzerland they are set only after you agree, and Google Analytics runs cookieless until then. In regions where the law does not require prior consent, analytics runs on an opt-out basis and you can decline at any time from the cookie bar. We use Google Analytics and Google Ads conversion measurement to understand visits and our own ads; we do not sell your data, run social-media pixels, or build advertising profiles from your dream content. You can change or withdraw your choice at any time:

5. Third-party services (processors)

We use a small set of processors, each only for the purpose named:

We do not sell, rent, or share your data with anyone else.

6. International data transfers

Somniary is based in the Czech Republic (EU). Some of our processors are US companies. When your dream text is sent to Anthropic (US) for interpretation or tagging, and when payments are processed by Stripe (US), these transfers are protected by Standard Contractual Clauses (SCCs). Cloudflare and Google (US) rely on the EU-US Data Privacy Framework and/or SCCs. Free interpretations are processed transiently and not stored. Your saved journal is held encrypted in our Cloudflare database; we work to keep that storage within the EU and will update this section if that changes.

7. Your rights under GDPR

As an EU/EEA resident, you have the right to: access, rectification, erasure, restriction, data portability, objection, and withdrawal of consent. Contact hello@somniary.com, we respond within 30 days. You may also lodge a complaint with the Office for Personal Data Protection (ÚOOÚ).

8. Data security

All transmission is encrypted via HTTPS/TLS. Secure infrastructure. Restricted access. Regular security reviews. For a full explanation of our technical and ethical safeguards, see Security & Ethics.

9. Children’s privacy

Somniary is not intended for children under 16. We do not knowingly collect data from children.

10. Changes to this policy

Material changes will be announced on our website at least 30 days before taking effect.

11. Contact

Email: hello@somniary.com. For the full legal contact path, see the contact page.

Operator: Mgr. Gabriela Kurková · IČO: 86970160 · Bělohorská 243/75, Praha, Břevnov, 169 00, Czech Republic (EU) · hello@somniary.com