Privacy Policy

Effective Date: July 10, 2026

This Privacy Policy explains how Dreammmer handles personal data and AI generation data when you use our image generation product.

1. Information We Collect

Account data: name, email address, authentication data, profile image when provided by an OAuth provider, session data, IP address, user agent, and account status.

Generation data: prompts, optional reference image URLs or uploaded images, generated image URLs, image generation status, credits used, model metadata, revised prompts when returned by a provider, errors, and generation history.

Billing data: plan keys, credit ledger entries, PayPal checkout and webhook data, payment and subscription status, transaction references, purchase-email status, service-delivery events, and refund, dispute, or support communications.

Support and communications data: messages you send through contact forms, support email, newsletter subscription data, and related delivery status.

Technical data: cookies, language preference, logs, IP address, device and browser information, rate-limit counters, cryptographic hashes of selected network or browser signals, security and abuse-prevention signals, and basic analytics where enabled.

2. How We Use Information

We use information to authenticate users, provide image generation, save generation history, manage credits, process payments, send account and support emails, debug failures, prevent fraud and abuse, enforce our Acceptable Use Policy, and comply with legal and payment provider obligations.

Prompts, uploaded or referenced images, and generated images may be reviewed for safety. If moderation rejects or flags content, we may block the request, withhold the output, record the safety event, and show a general policy message.

Safety controls may make automated decisions. Repeated blocked inputs, attempts to evade controls, or other serious risk signals may result in rate limits, a temporary account lock, or account termination. You may ask support to review an account restriction.

3. AI Providers, Moderation, and Storage

Dreammmer uses Volcano Engine / Doubao to generate images. Prompts and optional reference images may be sent to the model provider so the requested image can be created.

Dreammmer uses PayPal for payments and a configured moderation provider for content safety review. Prompts, uploaded or referenced images, and generated images may be sent to that moderation provider before they are accepted or delivered.

Dedicated moderation audit records contain a keyed cryptographic hash of the reviewed content, the decision, source, provider reference, and hashed request signals rather than a copy of the raw content. The underlying prompt or image may still be processed or retained separately as generation history, an upload, a provider record, or support evidence as described in this policy.

Uploaded reference images and generated media may be stored in S3-compatible storage. If configured storage is unavailable for provider results, the service may temporarily rely on the provider URL as described by the product behavior.

Dreammmer does not sell your prompts, uploads, or generated images. We do not claim that third-party providers never use data for their own purposes unless their terms or our agreement clearly supports that claim.

4. How We Share Information

We share limited data with service providers that help operate Dreammmer, including PayPal for payments, a configured moderation provider for prompt and image safety review, Volcano Engine / Doubao for generation, hosting and database providers, S3-compatible storage providers, Resend for email, optional OAuth providers such as Google, and security or analytics tools where enabled.

We may disclose information when required by law, to protect users and the service, to investigate fraud or abuse, to enforce our terms, or as part of a merger, acquisition, financing, or sale of assets.

5. Data Retention

Logged-in generation history may be retained so you can view recent generations and so we can support billing, credit, safety, abuse prevention, and debugging workflows.

Payment, subscription, credit ledger, purchase-email, delivery, download, dispute, tax, accounting, fraud-prevention, moderation, and compliance records may be retained for as long as reasonably needed to establish service delivery, investigate abuse, respond to disputes, or satisfy legal and payment-provider obligations.

If you request deletion, we will delete or anonymize eligible personal data unless we need to keep it for security, fraud prevention, accounting, dispute, legal, or compliance reasons.

6. Your Choices and Rights

You may request access, correction, deletion, or export of eligible account data by contacting support@dreammmer.com. We may need to verify your account before completing a request.

You can unsubscribe from marketing emails using the unsubscribe link where available. You can manage cookies through your browser settings and review our Cookie Policy for more information.

If your content or account is restricted by an automated safety decision, you may request a human review by emailing support@dreammmer.com from your account email and providing the relevant generation details.

7. Security

We use reasonable technical and organizational safeguards, including HTTPS, authentication controls, access restrictions, and operational monitoring. No internet service can guarantee absolute security.

8. International Processing

Dreammmer and its providers may process information in countries other than your country of residence. Data protection laws may differ by location.

9. Children's Privacy

Dreammmer is not intended for children under 18. We do not knowingly collect personal data from children under 18.

10. Contact

For privacy, support, or data protection questions, contact support@dreammmer.com or privacy@dreammmer.com.