Privacy Policy — DreamVoice (Yume no Koe)
1. About This Policy
This Privacy Policy explains how the Operator handles user information in DreamVoice (“Service”). The Service is intended for users aged 13 or older. Users under 13 may not use the Service. If a higher age requirement applies under the applicable store age rating or local laws, that requirement applies. We do not knowingly collect information from users below the applicable age. If we learn that a user is under the applicable age, we will delete the information. Minors should use the Service with guardian consent.
2. Information Collected
The Service may collect the following:
- User input: dream text, Today's Voice text, optional titles, emotion tags, dream date / record date, and notes or answers users write for daily Dream Voice or Today's Voice questions.
- AI outputs: daily Dream Voice analysis, supportive notes, symbols, summaries/keywords, Today's Voice feedback, Today's Voice hints/snapshots and safety support flags, and Weekly Dream Letter reflections, headlines, body text, highlights, prompts, symbols, and generated results that may reference or reflect source dream entries and notes for daily questions.
- Identifiers: anonymous auth ID (e.g., Firebase Auth UID), Support ID.
- Usage/technical data: screen/interaction events, compose mode changes, filter/segment taps, favorite/share/TTS taps, title edit sheet open/save/failure events (without title text), daily question note display/input/save/delete/sync-failure events (without note text or question text), Today's Voice generation/status events, Weekly Dream Letter display/create/ready/open/delete/push-open events, crash logs, config fetches.
- Notification data: device tokens, notification permission status, and notification category settings needed to send notifications.
- Device and app information: OS version, app version, device model, language settings, Firebase Installation ID, IP address, and similar technical information.
- Apple Ads attribution information: whether an install was attributed to an ad, campaignId, adGroupId, keywordId, adId, country/region, supply placement, and similar fields. Fields such as keywordId are not collected when Apple does not return them.
- Server-stored data: user input (including dream text, Today's Voice text, and daily question notes), AI results, daily question note text, snapshots of the related question text, Today's Voice snapshots/hints/safety support metadata, character counts, timestamps, deletion/sync state, Weekly Dream Letter job state/results/source references, weekly aggregate information such as dream-entry counts, dates, emotion tags, keywords, and daily question note counts for the target week, processing state, usage counts.
- Contact info: email address, inquiry content, optional Support ID/device info/screenshots.
Safety support flags, levels, and reason categories are used only to display supplemental in-app guidance when the input may include strong distress or safety concerns. They do not constitute medical, psychological, legal, or other professional judgment.
3. How It Is Collected
- Entered by users.
- Automatically collected by the app (analytics, diagnostics).
- Issued via authentication (anonymous auth).
4. Purpose of Use
- Provide the Service (daily Dream Voice, Today's Voice, Weekly Dream Letter, display, storage, notifications).
- Store daily question notes and reflect them in Weekly Dream Letters or in each voice feature.
- Manage usage limits, provide minimum safety support notices, and prevent abuse.
- Improve quality (troubleshooting, usage understanding).
- Measure Apple Ads performance and improve advertising operations.
- Understand Weekly Dream Letter generation status, reading behavior, and notification performance.
- Respond to inquiries and verify identity when needed (e.g., to prevent impersonation).
- Legal compliance and dispute response when required.
5. Third-Party Services
The Operator uses third-party services to provide and operate the Service. Their handling of information is governed by their own policies.
- Google Firebase (authentication, database, hosting, analytics, crash reporting, etc.)
- Apple AdServices (Apple Ads attribution)
- OpenAI (AI generation)
- Google Forms (support/inquiry form)
Apple Ads Measurement
To measure Apple Ads performance, the attribution token obtained from Apple’s AdServices.framework is sent temporarily to Apple through the Service’s server. The token itself is not stored and is not written to logs or analytics. From Apple’s response, only attribution fields such as campaignId, adGroupId, and keywordId are stored on the device and recorded in Google Firebase Analytics. This process does not display the OS tracking-permission prompt.
Sending to OpenAI
To provide AI-generated features, user input such as dream text, Today's Voice text, titles, emotion tags, dates, daily question notes, daily Dream Voice outputs, Today's Voice outputs, source dream information, daily question notes and related question text needed for Weekly Dream Letter generation, references, and generated results may be sent to OpenAI.
By using AI-generated features, users agree that user input and related information necessary for generation may be sent to external AI services within the scope necessary to provide those features.
OpenAI states that API inputs and outputs are not used to train or improve its models by default. However, OpenAI may retain inputs, outputs, and related metadata for a limited period for purposes such as abuse monitoring, service operation, legal compliance, and safety. Retention and handling are governed by OpenAI’s policies and the API settings used by this Service.
6. Disclosure to Third Parties
The Operator does not provide personal information to third parties without consent, unless required by law. However, data may be sent to the above service providers within the scope necessary to provide the Service.
7. Cross-Border Transfer
Because the Service uses cloud services provided by overseas operators, including Apple, Google Firebase, OpenAI, and Google Forms, collected data may be processed or stored on servers outside your country/region, including but not limited to the United States.
8. Retention
- On-device data: kept until the user deletes it.
- Server data: in principle kept until the user deletes it.
- Daily question notes: in principle kept until the user deletes them.
- Today's Voice results, snapshots, and job data: in principle kept until the user deletes them.
- Weekly Dream Letter results and job data: in principle kept until the user deletes them.
- Inquiry data: kept as long as reasonably necessary to respond and manage support history, and deleted when no longer needed.
- Logs, backups, audit records, abuse-prevention records, legal-compliance records, and dispute-response records held by third-party services: follow each provider’s retention rules or legally required periods and may persist for a certain period.
9. User Rights and Choices
- Delete individual dreams.
- Delete Today's Voice records.
- Delete daily question notes.
- Delete Weekly Dream Letters.
- Delete account (which removes related data on device and server).
- Push notification permissions: users can enable or disable push notifications through OS notification settings or in-app settings where available.
- Currently, there is no opt-out UI for analytics or crash reporting.
If you want deletion of information submitted via the support form, please contact the Operator via the contact form. If you delete a Today's Voice record, the stored data, generated result, and related snapshot for that Today's Voice record are subject to deletion. Today's Voice is not used as a source for Weekly Dream Letter generation in v1. Even if you delete an individual dream entry or daily question note, Weekly Dream Letters already generated before deletion may still contain summaries, keywords, symbols, reflections, or text based on that entry or note. To delete derived weekly results as well, please use the Weekly Dream Letter deletion feature or the account deletion feature. Deletion mainly applies to data managed by the Service. Logs, backups, audit records, abuse-prevention records, legal-compliance records, and dispute-response records held by external services may remain for the period required by each service or applicable law. Identifiers issued through anonymous authentication may remain on the device or be restored after reinstalling the app, depending on the device and OS behavior. To delete related server-side data, please use the account deletion feature.
10. Security
The Operator takes reasonable measures to prevent unauthorized access or leakage, including:
- Encrypted communication (HTTPS)
- Access control and authentication
- On-device data protected by standard OS mechanisms
11. Incident Response
If a breach or similar incident occurs, the Operator will investigate impact, prevent recurrence, and notify when legally required or deemed necessary.
12. Changes to This Policy
This Policy may be updated; notices will be given in-app or on the web.
13. Contact
For inquiries about this Policy: https://forms.gle/9eEJhVS64nKTxdgr8