Privacy Policy
Last updated: July 27, 2026
This policy describes what data Nightwards processes, why, and how you can access or delete it.
1. Data Controller
Responsible for data processing under the Swiss Federal Act on Data Protection (revFADP) and, for users in the EU, the GDPR:
Fuat Bostanci
Alte Bernstrasse 10
5603 Staufen, Switzerland
Contact: info@dreamr.ch
This app is currently operated by a private individual. This page will be updated if it transitions to a company.
2. What Data We Process
Nightwards works without an account or login. On first launch, your device generates a random, pseudonymous device ID and stores it in your device's Keychain. This device ID – not your name or Apple ID – is the key under which any server-side data is stored.
Pseudonymous Device ID
- A random UUID, generated and stored locally in your device's Keychain
- The only link between your device and any data stored on our servers
- No name, email address, or account is attached to it
Dream Recordings & Transcripts
- During your morning dream log, you record up to 30 seconds of audio
- The recording is sent to our own backend (Railway), which forwards it to OpenAI (model whisper-1) for transcription
- The audio itself is never stored on our servers – only the resulting text (transcript) is saved
- An optional second AI step (OpenAI gpt-4o-mini) compares the transcript against your saved motifs; the response is a yes/no flag only, no further analysis
Wish Sentence
The sentence that glows on your Lock Screen is stored server-side, encrypted with AES-256-GCM, so we can send you the matching push notification.
Session Metadata
Timestamps, duration, and completion status of your evening sessions, along with lucid and motif-match flags from your dream logs, are stored under your device ID in a PostgreSQL database (Railway).
Push Tokens
For Live Activity features like the Wish Glow (WishGlow) on your Lock Screen, we store your device's push token (Apple APNs).
Purchase Status
Whether your subscription is active is managed by Apple and RevenueCat. We only see your subscription status, never payment data (see section 5).
Feedback
Via the feedback field in Settings, you can voluntarily send us a message. The feedback text is stored pseudonymously under your device ID in our database and additionally delivered to us by email (Resend, see section 5). Please don't include sensitive information in your feedback.
Analytics
PostHog (EU-hosted) collects exactly five pseudonymous events: onboarding_completed, session_completed, dream_logged, paywall_viewed, purchase_completed – no content, no names, no other personal details.
Local-only (never leaves your device)
- The SQLite database with your journal, sessions, moments, and settings
- The dream audio files themselves
- A coarse location (~1 km accuracy, checked once daily) used for sunrise and sunset times
- Screen Time / Family Controls data, if you enable App Shield (Apple's own framework)
3. What We Use the Data For
- App functionality: evening sessions, dream log, Wish Glow on the Lock Screen, night-sky view
- Transcription: turning your dream recording into text (OpenAI)
- Motif matching: optional yes/no comparison against your saved motifs (OpenAI)
- Subscription management: checking your purchase status (Apple, RevenueCat)
- Product improvement: the five pseudonymous PostHog events
- Advertising measurement: finding out which of our ads led to an install (Meta, TikTok) – only with your explicit consent
We do not sell your data and we do not build profiles for third parties. What we measure is solely whether an install came from one of our ads – see section 11. Your dream recordings, transcripts, your sentence, your name and your email address never enter it.
4. Legal Basis
For users in Switzerland, processing is based on the revFADP, in particular contract performance (Art. 31 para. 2 lit. a revFADP). For users in the EU, the GDPR applies: core functionality (sessions, dream log, transcription, subscription) relies on contract performance (Art. 6 para. 1 lit. b GDPR); pseudonymous product analytics and the secure operation of the app rely on our legitimate interest (Art. 6 para. 1 lit. f GDPR) in a working, secure app. Advertising measurement relies solely on your consent (Art. 6 para. 1 lit. a GDPR, Art. 31 para. 1 revFADP), which you give through the iOS prompt "Allow this app to track your activity across other companies' apps and websites" and can withdraw at any time.
5. Data Processors
We use the following service providers who process data on our behalf. Appropriate data processing agreements are in place with each of them.
Hosting & Database
Railway
Purpose: hosting the backend API and database.
Data: transcripts, session metadata, encrypted wish sentence, push token, device ID.
Location: USA – railway.com/legal/privacy
Transcription & Motif Matching (AI)
OpenAI
Purpose: transcribing your dream recording (model whisper-1) and optional motif matching (model gpt-4o-mini).
Data: audio (only during transcription, not stored), transcript text.
Location: USA – openai.com/privacy
Subscription Management
RevenueCat
Purpose: managing subscription status and App Store purchases.
Data: device ID, purchase receipts, subscription status – no payment data.
Location: USA – revenuecat.com/privacy
Product Analytics
PostHog (EU)
Purpose: pseudonymous product analytics to improve the app.
Data: device ID, the five defined event names (see section 2).
Location: EU – no transfer to the US – posthog.com/privacy
Advertising Measurement (only with your consent)
Neither service below receives any dream recordings, transcripts, your sentence, your name or your email address. Without your consent to the iOS tracking prompt, your device's advertising identifier is not read (see section 11).
Meta Platforms Ireland Limited
Purpose: recognising whether an install came from one of our Meta ads.
Data: app launch, "onboarding completed", "paywall viewed"; advertising identifier (IDFA) only where consent was granted. We deliberately do not send purchase events.
Location: Ireland, processing also in the US – facebook.com/privacy/policy
TikTok Technology Limited
Purpose: recognising whether an install came from one of our TikTok ads.
Data: app launch, "onboarding completed", "paywall viewed" and "purchase completed" with amount, currency and product identifier; advertising identifier only where consent was granted.
Location: Ireland, processing also outside the EU – tiktok.com/legal/privacy-policy
Feedback Delivery (Email)
Resend
Purpose: delivering your feedback to us by email.
Data: feedback text, truncated device ID, app version.
Location: USA – resend.com/legal/privacy-policy
Purchase Handling & Push Delivery
Apple
Purpose: processing App Store purchases, delivering push notifications (APNs).
Data: purchase/subscription status, push token.
6. International Data Transfers
OpenAI, RevenueCat, Railway, and Resend process data in the US – a country without a level of data protection recognized as adequate by Switzerland. Transfers rely on Standard Contractual Clauses (SCCs) or, where the provider participates, the Swiss-U.S. Data Privacy Framework. PostHog is hosted exclusively in the EU – no international transfer occurs there. Meta Platforms Ireland and TikTok Technology Limited are based in Ireland but also process the advertising measurement data outside the EU, on the basis of their Standard Contractual Clauses. This transfer only happens if you consented to the tracking prompt.
7. Retention Period
- Audio: never stored on our servers – processed only during transcription, then discarded
- Transcripts, session metadata, wish sentence, push token: until you delete them (see section 9)
- Feedback: until deletion – removed along with "Delete my data"; the copy additionally delivered to our email inbox is deleted manually when you request it
- Local data on your device: remains until you delete it or uninstall the app
8. Your Rights
You have the right to:
- Access the data stored under your device ID
- Correct inaccurate data
- Delete your data (see section 9)
- Restrict processing
- Port your data (export on request)
- Object to processing
- Complain to a supervisory authority (see section 12)
For requests, contact info@dreamr.ch. Since we don't have accounts or logins, we may ask for a few extra details in email requests (e.g. approximate usage period, device type) to help us locate your data.
9. Deleting Your Data
In the app, go to Settings → "Delete my data" to delete, with one tap, all data stored on our servers under your device ID as well as all local data on your device. You can also request deletion by emailing info@dreamr.ch.
10. Security
Transmission is encrypted (TLS). The wish sentence is additionally encrypted server-side with AES-256-GCM. Your device ID is kept securely in your device's Keychain.
11. Cookies and Advertising Measurement
This website uses no cookies, no trackers, and no analytics.
Inside the app there are two separate things. First, the pseudonymous product analytics via PostHog in the EU (see sections 2 and 5) – unrelated to advertising. Second, advertising measurement via Meta and TikTok: it answers whether an install came from one of our ads.
For that, iOS asks you once after onboarding ("App Tracking Transparency"). Without your consent your device's advertising identifier (IDFA) is neither read nor transmitted. Attribution then runs only through Apple's SKAdNetwork, which works without reference to an individual person. You can change your answer at any time: iOS Settings → Privacy & Security → Tracking.
12. Right to Complain
Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1, CH-3003 Bern, Switzerland
www.edoeb.admin.ch
Users in the EU may additionally contact the competent data protection authority in their country of residence.
13. Changes
Changes to this policy will be reflected on this page with an updated date. Last updated: July 27, 2026.