Privacy Policy
Last updated: October 3, 2026
What we collect
When you use the contact form on this website, we collect the information you provide: your name, email address, and message. This information is sent to us via FormSubmit.co and delivered to our email. We do not store form submissions in a database.
What we do not collect
This website does not use cookies, tracking pixels, analytics services, or advertising networks. We do not collect browsing behavior, IP addresses, or device information through this website.
DreamerOS GPT (ChatGPT Store)
DreamerOS Light runs in the ChatGPT Store. When you use DreamerOS Light, your conversations are processed by OpenAI and subject to OpenAI's privacy policy. DreamerOS does not have access to your ChatGPT conversation data.
DreamerOS Pro and Elite
DreamerOS Pro and Elite are available at app.dreameros.app. When you use a paid tier, your interactions are processed through the DreamerOS gateway. Conversations are verified, and memory is stored in the DreamerOS infrastructure (not in any third-party AI provider). Elite additionally provides the B2B Trust API and exhaustive-depth verification; those calls flow through the same gateway and are covered by this policy.
The DreamerOS phone app
This section applies from the phone app's first store release. It states what the app sends, what it keeps on your device, and what it never does without you.
At sign-in, the app sends your email address and password to Supabase, the service DreamerOS uses to check who you are. While the app is open, it refreshes your session automatically, and each refresh sends your refresh token to Supabase. When you sign out, the app sends your access token to Supabase to end the session.
When you send a chat message, the app sends the message text, and the conversation ID once the conversation has one. When you file a report on an AI answer, the app sends the answer ID and the reason, plus the conversation ID when there is one. When you save a session handoff, the app sends the summary, the next actions, the open questions, the engine name, and the phone platform. When you delete your account in the app, it sends the phone platform. The phone platform is iOS or Android. Each of these requests carries your session token, so the gateway knows the request is yours.
Outside these calls, the app carries no analytics tool, no ad tool, and no crash-reporting tool.
Your session stays on your device. DreamerOS encrypts it. The key is kept in the phone's own protected key storage: the iOS Keychain on iPhone, and Keystore-backed encrypted storage on Android. The encrypted session sits in app storage. A flag that marks your first run also stays on your device. This flag is not encrypted. If you pick a starter prompt before sign-in, the app holds it on your device until chat reads it once, then removes it.
The phone app has no ability to send a message, move a meeting, or spend money on its own. It sends network requests to two services only: Supabase, for sign-in, session refresh, and sign-out; and the DreamerOS service, for everything else listed in this section. One screen's Open on the web button opens app.dreameros.app in your phone's browser instead. That happens outside the app, and the app sends no data to that address.
Every AI answer gets a Report control once the DreamerOS service has recorded that answer. An answer with no recorded ID yet cannot be reported, and the app tells you so until the ID arrives.
You can delete your account two ways. In the app, open Settings, then Delete account, and type DELETE to confirm. On the web, dreameros.app/delete-account ships in that same release. At that moment, the DreamerOS service ends your sign-in and revokes your connected services at once. It also records a removal date for what remains. It returns the number of days until that date. When it returns no number, the app uses 30 days. The app tells you your remaining data is marked for removal after that many days.
The app needs your email, your password, and your chat text to work. A report, a handoff, and a starter prompt are optional. Your data links to your account. The DreamerOS service address is fixed in the app and uses HTTPS. The Supabase project address is set when DreamerOS builds the app. The app itself sends network requests only to those two addresses. Supabase handles session management on DreamerOS's behalf.
Questions about the phone app? Email hello@thedreamerai.com.
Data sharing
We do not sell, rent, or share your personal information with third parties for marketing purposes. Form submissions are processed through FormSubmit.co - see their privacy policy for details on how they handle data in transit.
Your rights
You can request deletion of any personal information we hold by emailing hello@thedreamerai.com. We will respond within 30 days.
Contact
If you have questions about this privacy policy, email us at hello@thedreamerai.com.