Short version. Dreamloom is designed so your dream text never leaves your phone. Interpretation runs entirely on-device with a local Gemma model. Your journal is stored in an encrypted local database. Network use is narrow and explicit: a one-time model download, ads (AdMob), and opt-out crash and usage analytics. There is no account system and no cloud sync of dream content.
1. Who we are
Dreamloom is an Android application developed and published by Charles Hartmann ("we", "us"). This Privacy Policy explains how the Dreamloom app handles information when you install or use it. It does not cover any other software, websites, or services.
2. What data Dreamloom handles
Dreamloom is built around the principle that your dream content is the most personal thing in the app, and it should never leave your device. The categories of data Dreamloom handles are:
- Dream content (local only). Text you type, voice you record, and AI-generated interpretations (title, symbols, meaning, intention). Stored only on your device, in an encrypted database.
- Audio recordings (local only, transient). If you use voice capture, audio is transcribed on-device and used to populate the text entry. Audio files live in app-internal storage and are subject to the in-app deletion controls.
- App preferences. Theme, opt-in choices for analytics and crash reporting, reminder settings, ad-frequency state. Stored locally via Android DataStore.
- Diagnostic data (opt-out). Anonymous counts and event flags for product analytics and crash reports, if the matching opt-out is left enabled. Never includes dream text, titles, symbols, audio, or user identifiers.
- Advertising data. Standard data sent by Google Mobile Ads (AdMob) and its mediation partners (Meta Audience Network, AppLovin) when ads are shown. This includes a resettable Android Advertising ID, coarse signals about the device, and consent state from the User Messaging Platform (UMP). It does not include your dream text.
- Network requests for the local AI model. The first time you use Dreamloom, the app downloads a Gemma model file (~2.6 GB) from a public host. This is a standard HTTPS request and we do not log dream content over it.
3. Android permissions
- Microphone — only when you start a voice capture. Audio is transcribed on-device.
- Internet & network state — for the model download, ads, and (opt-out) analytics.
- Post notifications — for optional dream reminders and the weekly insight notification.
- AD_ID — required by Google Mobile Ads to show ads.
4. On-device processing
All dream interpretation runs locally on your device using Gemma via LiteRT-LM. The model file is stored in your app's private internal storage. No dream text, voice audio, or interpretation output is sent to any server controlled by us or by Google's Gemini API as part of interpretation.
Backend acceleration is selected automatically (NPU → GPU → CPU). All execution stays on the device.
5. When the app uses the network
Dreamloom contacts the network only in these specific situations:
- Initial model download. An HTTPS request to a public host (and configured fallback mirrors) to fetch the Gemma model. Verified by SHA-256 before being used.
- Ads. Requests to Google Mobile Ads (AdMob) and its mediation partners to load and display ads.
- Consent (UMP). A request to Google's User Messaging Platform to determine and record your ad-personalization consent state, where applicable.
- Crash & analytics (opt-out). If left enabled, anonymous events and crash reports go to Firebase Analytics, Crashlytics, and Performance Monitoring (Google).
No other network calls are made by the app.
6. Ads
Dreamloom is free, and shows ads via Google Mobile Ads (AdMob), with mediation partners Meta Audience Network and AppLovin. Ad formats used in the app include app-open ads, interstitials, rewarded ads, and native ads.
We use Google's User Messaging Platform (UMP) to handle consent in regions that require it (such as the EEA, UK, and Switzerland). You can change your consent choice at any time from in-app settings or device-level controls.
Ads do not see your dream content. Dream text is never used as an input to ad targeting. Ad-frequency caps are applied locally to keep ads out of the way of journaling.
Google's privacy policy for Mobile Ads is at policies.google.com/technologies/ads. Mediation partner policies: Meta, AppLovin.
7. Analytics & crash reporting
If left enabled, Dreamloom uses Firebase Analytics, Crashlytics, and Performance Monitoring to understand how the app is used and to investigate crashes. Events are limited to the schema documented in the project's INSTRUCTIONS.md — counts and coarse flags only — and never include dream text, titles, symbols, audio, or user identifiers.
You can disable analytics and crash reporting from Settings → Privacy. The change applies on the next process start as well as immediately for new events.
8. Storage, encryption & retention
- Encrypted at rest. Your dream entries and interpretations are stored in a Room database wrapped in SQLCipher. The passphrase is held in the Android Keystore and accessed via EncryptedSharedPreferences.
- App-internal storage. Audio recordings, the Gemma model file, and small caches live in your app's private storage area, not on shared storage.
- Retention. Dream entries persist on your device until you delete them or uninstall the app. There is no remote copy.
- Wipe & reset. The Settings screen offers a "Wipe Data" action that closes the model engine, deletes the encrypted database, removes the model file, clears preferences, and clears the Keystore-backed passphrase before restarting the process.
9. Sharing & third parties
We do not sell your data. We do not share your dream content with anyone. The third parties that may receive non-content data, only when their respective feature is in use, are:
- Google (AdMob, Firebase Analytics, Crashlytics, Performance, UMP) — see Google's privacy policy.
- Meta Audience Network — only when serving an ad mediated to Meta.
- AppLovin — only when serving an ad mediated to AppLovin.
- The host that serves the Gemma model file — only during the initial model download.
10. Children
Dreamloom is not directed to children under 13, and we do not knowingly collect data from children under 13. If you believe a child has used the app and you would like the local journal removed, simply uninstall the app or use the in-app "Wipe Data" action.
11. Your rights & controls
Because Dreamloom keeps dream content on your device only, the most important controls are local:
- Delete an entry — long-press in the Atlas, then Delete.
- Wipe the journal — Settings → "Wipe Data".
- Opt out of analytics & crash reporting — Settings → Privacy.
- Manage ad consent — Settings → Privacy (UMP).
- Uninstall — removes all local data, including the encrypted database and model file.
If you are in the EEA, UK, Switzerland, California, or another jurisdiction with applicable rights (access, deletion, correction, portability, objection), you can exercise those rights for any data we control by contacting us at the address below. Note that, by design, we do not hold a copy of your dream content.
12. Changes to this policy
If this policy changes materially, we will update the "Last updated" date at the top and, where appropriate, surface the change in the app or in release notes.
13. Contact
Questions about this policy? Email charles.h.hartmann1@gmail.com or open an issue at github.com/chartmann1590/dreamloom/issues.