Privacy Policy
Effective 9 August 2026 · Last updated 9 August 2026
Dreamify creates a personalized bedtime story for a child every night. This policy explains what we collect, why, and what you can do about it. It is written for the parent or legal guardian who sets the app up. Dreamify is bought and configured by an adult, and is not directed to children for account creation or purchases.
1. Who we are
Dreamify is operated by Osman Kantarcıoğlu (“we”, “us”). For any privacy question or request, write to osmankantarcioglu@hotmail.com. Where the GDPR applies, we act as the data controller for the data described below.
2. What we collect
| Data | Why we have it |
|---|---|
| Story profile: the nickname or first name you choose for the stories, age group, story language, how the story should refer to the child, interests, favorite animal, a comfort toy (optional, free text), preferred settings, values, topics to avoid, a current support topic, story style, length, narrator voice and background sound. | These are the ingredients of the story. Without them every story would be generic. Providing a nickname instead of a real name is fine and is what we recommend. |
| Bedtime and reminder preference: the time you pick, and whether you want a reminder. | To schedule the local notification you asked for. The reminder is scheduled on the device. |
| Account identifier: an anonymous account created for your device. No email address, password, phone number or social login. | To attach your profile, stories and subscription to something, and to keep your library across app restarts. |
| Generated content: the story text, the narration audio and the story artwork, plus the date each story was made. | So you can replay stories, and so we can apply the “one new story per day” allowance. |
| Subscription status: whether a subscription is active, its type and renewal date, and a purchase identifier from RevenueCat. | To unlock the app for paying users and to restore purchases on a new device. |
| Consent records: that you accepted this policy and agreed to create the child profile, with a timestamp. | To be able to show that consent was given, as data-protection law requires. |
| Basic technical data: device time-zone offset, app language, and ordinary server logs (IP address, timestamp, error traces) kept by our hosting provider. | The time-zone offset makes the daily allowance roll over at your local midnight. Logs are for security and debugging. |
We do not collect: full names, home or email addresses, phone numbers, photos, videos, voice recordings of your child, contacts, precise location, advertising identifiers, or browsing behaviour outside the app.
3. Why we are allowed to process it (GDPR)
- Performance of a contract: creating, storing and playing the stories you subscribed for, and running the account.
- Consent: for the child profile details, which you give explicitly during setup, and for reminder notifications. You can withdraw consent at any time by deleting the profile or turning reminders off.
- Legitimate interests: keeping the service secure, preventing abuse of the daily allowance, and fixing faults.
- Legal obligation: keeping records of purchases where tax or consumer law requires it.
4. Children
Dreamify is designed for a parent or guardian to use with a child. Account setup, purchases, external links and permission prompts sit behind a parental gate. The child profile is created by the adult, on the basis of the adult's consent, and holds only the story ingredients listed above: a nickname and an age group, not identifying details.
We do not knowingly collect personal information directly from a child, we do not show ads or in-app promotions to children, and we do not use children's data for profiling or marketing. If you believe a child has provided us with information beyond what is described here, email us and we will delete it.
5. Who else sees the data
We use a small number of processors, each of which receives only what it needs to do its job. None of them are permitted to use your data for their own purposes, and none of them are given the account identifier together with a real-world identity.
| Provider | What it receives |
|---|---|
| Supabase (database, storage, authentication, serverless functions) | Everything described in section 2, as our hosting backend. |
| OpenAI and Anthropic (story text and narration audio) | The story ingredients (nickname, age group, language, interests, style, length and similar) needed to write and narrate the story. Providers are used through their API, and API inputs are not used to train their models. |
| fal.ai (story artwork) | A visual description of the scene. No child data or nickname. |
| RevenueCat (subscription management) | Purchase and entitlement data, and an anonymous app user identifier. |
| Apple and Google (payments and app distribution) | They process the payment themselves. We never see your card details. |
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
6. Where data is stored, and international transfers
Data is stored on infrastructure operated by Supabase, and processed by the providers above, which may be located outside your country, including in the United States. Where data leaves the European Economic Area or the United Kingdom, transfers rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard.
7. How long we keep it
- Profile and stories: until you delete them, or until the account has been inactive for 24 months, whichever comes first.
- Consent records and purchase records: for as long as required to defend a legal claim or to satisfy tax obligations (typically up to 10 years for purchase records).
- Server logs: a short rolling window, normally under 30 days.
Deleting your data in the app removes the profile, preferences and stories. Backups are overwritten on their own cycle, normally within 30 days.
8. Your rights
You can ask us to give you a copy of the data, correct it, delete it, restrict or object to processing, or receive it in a portable format. You can also withdraw consent at any time, which does not affect processing that already happened.
The fastest route is the app itself: Parents → Download or delete data. You can also email osmankantarcioglu@hotmail.com; we answer within 30 days. If you are in the EEA or the UK you may complain to your local data-protection authority; in Türkiye, to the Kişisel Verileri Koruma Kurumu (KVKK).
9. Security
Traffic is encrypted in transit (TLS). Data is stored with per-account access rules so one account cannot read another's stories, and story media is served through short-lived signed links. No system is perfectly secure; if a breach ever affects your data, we will notify you and the relevant authority as the law requires.
10. Changes to this policy
If we change this policy we will update the date at the top, and for a significant change we will tell you in the app before it takes effect.
11. Contact
Osman Kantarcıoğlu · osmankantarcioglu@hotmail.com