1. Who this policy applies to
This draft describes personal information handled through the Dreamloom app, website and related family services. It covers adult account holders, child profiles managed within a family account, visitors and people who contact support.
Dreamloom is operated by David Stein. References to “Dreamloom”, “we”, “us” and “our” mean that operator. The effective date will be [CONFIRM: EFFECTIVE_DATE].
2. Information we collect
Depending on the features you use, information can include:
- Adult account details: name or display name, email address, verification status and authentication/session records.
- Family profiles: profile names or nicknames, selected age bands, settings and relationships within the family account.
- Creative content: uploaded drawings or selected photos, processed images and thumbnails, creature models, names, Dreambook settings and text, and saved-world records.
- Feature activity: creation requests, completion or failure status, technical retries, sharing choices, session/device identifiers and operational usage records.
- Subscription records: Apple product and transaction identifiers, verified entitlement, renewal, expiry, refund and revocation information. Dreamloom does not receive your full payment-card number through the App Store purchase flow.
- Technical information: IP address and request logs, app/browser and operating-system information, error references and security events that the deployed service records.
- Requests and correspondence: information you send to support, consent or approval records, export requests and account-deletion requests.
3. How we collect information
We collect information when an adult registers or signs in, creates a family profile, chooses artwork, requests a creation, uses a world or book, manages a subscription, or contacts us. We also receive transaction information from Apple and technical records created when the service operates.
Please use nicknames where practical and avoid drawings or uploads containing a child’s full name, school, address, face or other identifying details unless those details are genuinely needed. A selected photo can contain more than the drawing itself; review and crop it before uploading.
Device permissions are requested when relevant to a feature. Declining camera or photo access may make that particular capture route unavailable. A device permission prompt is not, by itself, consent to every kind of server or AI processing.
4. Why we use information
We use information to operate accounts and profiles; authenticate access; interpret artwork and generate requested content; save and load creatures, worlds and books; perform content-safety checks; verify and restore subscriptions; handle support and privacy requests; diagnose faults; prevent fraud or abuse; and meet applicable legal obligations.
Any quality-improvement use must be consistent with the notice and choices actually provided. This draft does not authorise unrelated advertising, sale of family content or reuse of identifiable children’s content to train models.
5. Children’s information and parental choices
Dreamloom is designed for family use with adult-managed accounts and child profiles. A parent or guardian should manage profile information, review age selections and supervise the child’s creative experience. Sensitive account and privacy controls use the in-app Parent approval flow.
Parents can use the available creation settings to pause new AI-assisted creations and can request access, correction or deletion of family information. Pausing creation does not itself delete earlier content or cancel a subscription.
An emailed account code, a profile age selection or Apple’s payment confirmation is not represented as universal verification of parental consent. The appropriate notice, authorisation and consent process depends on where the service is offered and the information being handled.
6. Creative content, AI and family media
When you request a creature or Dreambook, the artwork and settings needed for that task may be sent to image-processing and AI providers. This can include the selected image, creature details, text prompts, selected age range, story type or learning focus. The resulting images, models, text and processing metadata can then be stored with the family account.
The reviewed build references OpenAI for text generation, content moderation and creature analysis, and withoutBG for background removal. Their involvement is not a promise that all content is anonymous or immediately deleted by the provider.
Private-media controls restrict ordinary access to authorised account, profile or paired-display contexts. Copies you deliberately export or share leave those controls. Do not share private access links or family exports publicly.
7. Subscriptions and payment information
Subscriptions are offered through Apple’s in-app purchase system when purchasing is available. Apple handles the payment method and its own Apple Account information. Dreamloom uses verified transaction and renewal information to link access to the correct Dreamloom family, restore a purchase and respond to lifecycle changes.
Cancelling an Apple subscription and deleting a Dreamloom account are different actions. A deletion request must not be assumed to cancel Apple’s future billing. See subscription help for cancellation and refund guidance.
8. Service providers and other disclosures
Information is shared with the providers needed to perform the requested service and with authorised people providing support, security or operational services. The following is a draft provider map, not a final list of every recipient:
| Provider / category | Purpose and relevant information |
|---|---|
| Apple | In-app purchases, transaction verification and subscription status. |
| OpenAI | Requested text/image analysis, generated book content and content-safety checks. |
| withoutBG | Image background removal using submitted artwork. |
| DigitalOcean / hosting | Application hosting, stored records/media and operational request information; confirm actual services and regions. |
| [CONFIRM: EMAIL_PROVIDER] | Delivery of sign-in/Parent codes and configured service notifications. |
| [CONFIRM: OTHER_LIVE_PROVIDERS_OR_NONE] | Confirm support, logging, crash reporting, analytics, backups and any CDN/storage recipients. |
We may also disclose information when required or authorised by law, to protect safety or security, or for another purpose specifically explained and lawfully authorised. Provider access should be restricted to the purpose and protections agreed for the service.
9. Overseas handling
Providers, support personnel or infrastructure may handle information outside Australia. The final policy must name the likely recipient countries where practicable and describe the actual service arrangements; it must not assume all family data stays in Australia.
Confirmed countries and relevant providers: [CONFIRM: PROCESSING_AND_RECIPIENT_COUNTRIES].
10. How information is held and protected
Dreamloom uses account authorisation, profile/family access checks, protected server credentials and controlled media/export access in the reviewed build. Access by staff or contractors must be limited to authorised purposes. We use reasonable safeguards appropriate to the information, but no service can promise absolute security.
Please protect your email account, sign-in codes and devices. Never send a password, sign-in code or private family export in an initial support message.
11. Retention and deletion timing
Information should be kept only as long as needed for the purposes described, taking account of the account’s use, security, legal recordkeeping, complaints and valid deletion requests. Different records can have different retention periods. The approved schedule must distinguish live storage, backups and provider-held copies.
Account, profile and creative content: [CONFIRM: ACCOUNT_CONTENT_RETENTION]
Logs, security and processing records: [CONFIRM: LOG_AND_PROCESSING_RETENTION]
Temporary exports and private download artifacts: [CONFIRM: EXPORT_EXPIRY_PERIOD]
Purchase, complaint and legally retained records: [CONFIRM: LEGAL_AND_TRANSACTION_RETENTION]
Backups and third-party copies: [CONFIRM: BACKUP_AND_PROVIDER_RETENTION]
Deletion from live storage does not necessarily remove a separately retained backup immediately. The completed policy must explain the applicable expiry, restricted access and treatment of restored backups; it must not promise instant erasure everywhere.
12. Access and correction
An adult account holder may request access to information held about them or their family, and correction of inaccurate or outdated information. Available in-app profile settings and export tools can assist, but are not the only way to make a request.
Contact david@steindavid.com or use the details in section 16. We may need a proportionate identity or authority check before releasing or changing family information. We will explain any lawful reason we cannot fulfil all or part of a request and the available complaint route.
Exported files are private. An export with missing-media warnings is not a complete media backup; check its manifest before relying on it.
13. Deletion requests and withdrawing consent
You may use the Parent area’s account-and-family deletion request flow, or contact david@steindavid.com to request deletion or discuss withdrawal of consent. A request being received is not the same as erasure being completed. We may need to confirm authority, explain any legally required retention and communicate the outcome.
Archiving a profile or item is not permanent deletion. Downloaded or externally shared copies are outside Dreamloom’s later account controls. Cancel the Apple subscription separately when future billing should stop.
14. Questions and complaints
Please contact David Stein at david@steindavid.com with enough detail to investigate, without sending unnecessary child information. We will assess the issue, seek clarification where needed and respond within the time required by applicable law. The approved support process will describe any expected acknowledgement time.
Where the Office of the Australian Information Commissioner has jurisdiction, you may raise a privacy complaint with the OAIC. Other applicable local regulators or complaint avenues remain available. You do not give up a legal complaint right by using our support process.
15. Changes to this policy
We will update the policy and its effective/updated date when information practices change. A material change will be explained through an appropriate notice. Where a new use requires a fresh choice or consent, changing this page alone does not supply that consent.
16. Contact and operator details
- Legal operator
- David Stein
- Privacy contact
- David Stein — david@steindavid.com
- Support email
- david@steindavid.com
This document is a review draft. The marked business and operational details must be completed and checked before it becomes a published Privacy Policy.
Still have a question?
Contact details