1. Who operates DreamTruth
DreamTruth is a dream reading and interpretation service operated by Logan Pendragon Forge. This policy covers this application, its accounts, personalization, readings, and sharing features. It does not cover other Forge projects or linked services. For privacy questions or requests, use the Forge contact page and identify DreamTruth. Do not send your password or API key in a message.
2. Information you provide
- Account information: email address, display name, a password hash, account and login timestamps, and the version of the registration terms accepted. Your password is not stored as readable text.
- Dream records: the dream, waking-life context, personal associations, optional personal information for that dream, spiritual-lens and personalization choices, generated interpretations, later corrections, and previous interpretation versions.
- Saved personalization: the optional background you enter on the Personalization page. You choose the content and may edit or delete it.
- OpenAI API key: a key you authorize DreamTruth to use to check Astra access and request readings through your OpenAI account.
- Share records: an interpretation snapshot, an encrypted share token, a token hash used to find the snapshot, and its creation time.
Dreams and personal context may reveal sensitive information about health, relationships, religion, sexuality, or other parts of your life. Providing this is optional. Enter only information you want processed for this purpose. Use nicknames and avoid unnecessary identifying details about other people. Do not enter passwords, payment-card numbers, identity-document numbers, or confidential information you are not entitled to share.
3. How your information is used
DreamTruth uses information to authenticate you, provide and save readings, apply the dream framework to your own context, revise an interpretation when you add information, maintain your history, operate optional sharing, and protect the service from abuse. Saved personalization is included when the reading's “Use my saved personalization” option is enabled. Dream-specific information and corrections take priority. Follow-ups use that reading's saved inputs, earlier corrections, prior interpretation, and your current saved personalization if enabled for that reading.
Saving or editing personalization alone does not call the AI. Removing it stops its inclusion as a saved profile in subsequent requests. An earlier reading or share snapshot can still contain information or conclusions derived from it; delete those records separately if you want them removed. DreamTruth does not sell personal information, provide dream text to advertisers, or use your readings to train its own model.
4. What goes to OpenAI
When you request a reading or revision, the server sends the relevant dream inputs, selected personalization, prior corrections and interpretation when applicable, and framework instructions to OpenAI. Your key is used for API authentication. Your email, password, and account display name are not added to the reading prompt unless you put them in submitted text yourself. Requests use GPT-6 Astra and disable optional response storage with store: false.
That setting is not a promise of zero retention. OpenAI states that API content is not used for model training by default unless you opt in, and that abuse-monitoring logs may retain content for up to 30 days, with exceptions. Other processing, including prompt caching, and your OpenAI organization settings may affect retention. See OpenAI's API data controls. Deleting data from DreamTruth does not automatically delete data already processed under OpenAI's rules. OpenAI bills API usage to your account.
5. Privacy and optional sharing
Readings are private to your account by default. Creating a share link allows anyone who obtains that link to view an interpretation snapshot without logging in. The shared response excludes your email and separate raw dream, context, association, and personalization fields. The interpretation itself may repeat personal details from those inputs, so review it before sharing.
Later revisions do not silently update a snapshot. Turn sharing off and create a new link if you want to share a newer version. Turning off sharing or deleting the reading disables the live link. It cannot recall screenshots, downloads, or other copies someone has made. Share links are unlisted, and pages request that search engines not index them; this is not a guarantee against discovery or redistribution.
6. Storage, hosting, and security
Dream text, context, personal associations, per-dream personal information, saved personalization, interpretations, follow-ups, and API keys are encrypted in application storage. Reading titles, account details, timestamps, and usage metadata are not all encrypted fields. This is server-side encryption, not end-to-end encryption: the application must decrypt relevant content to provide the service. Authorized administration, recovery, or troubleshooting may involve access where necessary. No system can guarantee absolute security.
The hosting infrastructure processes requests and may record IP addresses, requested URLs, browser information, errors, and timestamps. The application uses session cookies to keep you logged in and hashed identifiers and timestamps for rate limits. Google Fonts requests used by the design can expose connection information to Google. Google Analytics measures visits and reader-link clicks on public information pages. It may use analytics cookies and connection information. Analytics is not loaded on the reader, personalization, API-key, shared-reading, or admin pages. We do not send dream text, account identifiers, API keys, or URL query strings and fragments to Analytics, and advertising personalization is disabled. The site administrator can view account names, email addresses, registration dates, and last-login dates in an account directory. Your browser extensions and external sites have their own practices.
7. Retention and deletion
Account data and saved content remain in the live application until you delete them or the operator removes them for a service, security, or legal reason. You can use these controls at any time while logged in:
- API key: remove your stored key on the API key page.
- Personalization: edit it, save it blank, or use Delete saved personalization.
- One reading: open it from My readings and use Delete this reading. Its revisions and share link are removed too.
- All readings: use Your information on Personalization and confirm your password.
- Your account: use Delete my account and information, with your current password. This removes the account, saved key, profile, readings, revisions, and share records from the live application.
These controls permanently remove active application records; they are not a recoverable trash. Backups made for recovery can contain earlier copies and are separate from the live database. They may remain until replaced or removed and are not used to generate readings. There is currently no guaranteed automatic backup-erasure deadline. Contact the operator if you need a request reviewed for backup copies, access logs, or data you cannot remove through your account. Necessary security or legally required records may be retained. Application rate-limit records are eligible for periodic cleanup after seven days; web-server logs follow hosting retention practices. Provider-held data and copies held by people you shared with are outside these controls.
8. Your choices and requests
You can browse public pages without an account, leave personalization blank, exclude it for a reading, omit optional context, turn off sharing, and delete information as described above. You may contact the operator to request access, correction, an export, deletion, or help with an inaccessible account. We may need to verify account ownership. Depending on your location, additional rights may apply, including objections or complaints to a relevant privacy authority. Applicable legal rights are not waived by using this service. Processing may occur outside your country through the hosting provider and OpenAI.
9. Adults only and policy changes
DreamTruth is for people aged 18 or older. Do not create an account or submit personal information if you are under 18. Contact the operator if you believe an underage person has submitted information. Changes to this policy will be published here with an updated version and effective date, and important product changes appear in the changelog. If a new use requires consent under applicable law, it will require that consent before proceeding.