PRIVACY MANIFESTO: At Our Dream AI, we recognize that synthetic companionship, personal storytelling, and creative roleplay involve your most private imaginations and conversations. We operate under a strict, non-negotiable principle: your private chats, character prompts, and generated media belong solely to you. We do not sell your personal data, and we NEVER use your confidential conversations to train publicly available AI models.
1. Introduction & Global Scope
This Privacy Policy (the "Policy") explains how Our Dream AI Ltd., including its subsidiaries, affiliates, and parent organizations (collectively, "Our Dream AI", "Company", "we", "us", or "our"), collects, processes, encrypts, maintains, and safeguards information obtained from users ("User", "you", or "your") across our websites (including ourdream.ai and en-ourdreamai.us), mobile web experiences, proprietary inference clusters, creator portals, and interactive services (collectively, the "Platform" or "Services").
By accessing, creating an account on, conversing with AI models within, or submitting visual prompts to the Platform, you acknowledge that you have read, understood, and consented to the operational data practices articulated within this comprehensive Privacy Policy. If you do not consent to these data processing parameters, you must cease all utilization of our Platform immediately.
2. Commitment to Absolute Privacy & Data Ethics
Traditional social networks and ad-supported tech companies view personal dialogues as behavioral commodities to be extracted, sold to advertising data brokers, and fed into surveillance advertising models. Our Dream AI rejects this paradigm.
We operate as a direct-to-consumer software service funded by premium memberships, DreamCoin compute credits, and creative licensing subscriptions. Because our business model is sustained directly by user subscriptions rather than ad networks, we have zero commercial interest in harvesting, indexing, or monetizing your personal interactions. We enforce zero third-party advertising tracking libraries on our conversational pages and live chat environments.
3. Categories of Data We Collect
We limit data collection exclusively to the technical and operational data necessary to deliver low-latency computational inference, maintain persistent episodic character memory, and fulfill billing transactions:
A. Information You Voluntarily Provide to Us
- Account Registration Identifiers: Your email address, encrypted master password hash (salted using bcrypt/Argon2), chosen display handle, and verification tokens;
- Character Customization Parameters: Text descriptions of character backstories, personality descriptors, voice style preferences, scenario settings, and conversational tone profiles authored by you;
- User Inputs & Chat Transcripts: The textual dialogue messages, creative scenario prompts, scenario roleplay instructions, and conversational choices you transmit to synthetic characters;
- Visual Generation Prompts: Descriptive image prompts, camera focal lengths, artistic style selections, and lighting directives submitted to our diffusion pipelines;
- Communications with Support: Feedback, inquiries, bug reports, and correspondence submitted via email to our support desks or legal compliance officers.
B. Automatically Collected Technical Metadata
- Session & Diagnostic Telemetry: Anonymized server latency figures, token generation rates, neural network response timestamps, and crash telemetry needed to balance server cluster load;
- Hardware & Browser Attributes: Operating system type, browser user-agent, preferred language settings, and display viewport dimensions to render responsive interfaces;
- Network Identifiers: IP addresses logged temporarily for rate limiting, distributed denial-of-service (DDoS) mitigation, and automated fraud prevention, which are systematically truncated and anonymized in diagnostic archives;
- Local Cache Tokens: Client-side storage keys that keep you authenticated between browsing sessions and maintain local theme preferences (e.g., dark mode settings).
C. Financial & Payment Verification Data
All financial transactions—including DreamCoin credit purchases and recurring VIP memberships—are processed exclusively by PCI-DSS Level 1 certified third-party payment processors (such as Stripe, Paddle, or authorized merchant providers). Our Dream AI never stores or processes raw credit card numbers, CVVs, or full bank account details on our servers. We receive only non-sensitive transaction tokens, order identifiers, and billing country metadata necessary to verify payment completion and calculate applicable value-added taxes (VAT/sales tax).
4. Zero Public Model Training Guarantee
One of the foremost concerns in modern generative artificial intelligence is the unauthorized scraping of user conversations to train public or foundational artificial intelligence models.
OUR EXPLICIT CONTRACTUAL PROMISE: Our Dream AI explicitly guarantees that no user chat transcripts, private character roleplay logs, image generation prompts, voice recordings, or customized persona backstories are ever used to train, retrain, fine-tune, or calibrate public open-source foundational models or external commercial third-party language models.
Your conversational transcripts remain strictly isolated within your private, encrypted account database partition. Fine-tuning of underlying platform models is performed solely on proprietary, ethically vetted, synthetic benchmark datasets specifically authored by Our Dream AI staff and licensed content creators.
5. Legal Bases for Data Processing (GDPR & Global Frameworks)
Under the European General Data Protection Regulation (GDPR Article 6), the UK GDPR, and comparable international data privacy frameworks, Our Dream AI processes your personal data strictly under valid lawful bases:
- Performance of a Contract (Article 6(1)(b)): Processing necessary to provide you with the Services you requested—namely, executing generative inference, rendering your companion's responses, synchronizing character memory, and fulfilling virtual currency purchases;
- Legitimate Interests (Article 6(1)(f)): Processing necessary to secure our servers, detect automated scraping attacks, prevent abusive behavior violating our Terms of Service (such as illegal CSAM generation), and optimize neural pipeline efficiency;
- Legal Compliance (Article 6(1)(c)): Processing necessary to comply with statutory legal mandates, financial audit reporting, tax record retention, and valid judicial court orders;
- Explicit Consent (Article 6(1)(a)): Where you explicitly choose to opt into optional features, such as publishing your custom character persona to the public community showcase or participating in creator monetization programs.
6. AI Processing, Episodic Memory & Session Isolation
To provide characters like Aubrey, Miranda, Tracy, and your own custom companions with persistent personalities, Our Dream AI utilizes a proprietary episodic memory architecture. It operates under strict security paradigms:
- Context Window Isolation: Each user's conversational session is hosted in an isolated memory container. Characters do not have cross-account data bridges; another user's companion cannot access, read, or synthesize memories generated within your private conversations;
- Vector Embedding Vaults: Long-term memories (such as favorite books, shared fictional storylines, and past conversation highlights) are converted into high-dimensional vector embeddings stored in a dedicated, tenant-isolated vector database protected by access-control tokens;
- Episodic Flush Controls: You retain complete granular control to reset, purge, or selectively delete your companion's memory at any time. When you click "Clear History" or execute a character reset, the associated vector embeddings and conversational context tokens are marked for immediate deletion and unlinked from the neural pipeline.
7. Cookies, Local Storage & Tracking Technologies
Our Dream AI maintains a minimalist approach to browser storage. We use first-party browser cookies and modern HTML5 localStorage purely to sustain operational functionality:
- Strictly Necessary Session Tokens: Secure, HTTP-only, encrypted session cookies that authenticate your login credentials and verify user session validity across page navigations;
- Functional Preference Storage: Local storage values that store your active companion selection, dark mode theme preferences, and chosen chat model tier (e.g., Balanced vs. Genius);
- Security & Rate-Limiting Keys: Cryptographic tokens used to protect against Cross-Site Request Forgery (CSRF) and automated bot spamming.
We do not deploy third-party cross-site advertising trackers, behavioral fingerprinting scripts, or data-broker pixels. For detailed disclosures regarding cookie durations, please inspect our dedicated Cookie Policy.
8. Third-Party Disclosures & Infrastructure Subprocessors
We do not sell, rent, monetize, or lease your personal information. We transmit personal data only to trusted infrastructure subprocessors strictly bound by confidentiality and data processing agreements:
- High-Performance Cloud & GPU Providers: Tier-4 certified data centers located in the United States and the European Economic Area (such as AWS, Google Cloud Platform, and specialized GPU compute clusters) that process real-time neural inference under strict operational confidentiality agreements;
- Payment Processors: Certified merchant payment gateways that handle credit billing, fraud validation, and chargeback prevention under strict PCI-DSS Level 1 compliance;
- Law Enforcement & Legal Compliance: We will disclose user records only if legally mandated to do so by a valid, enforceable court order, subpoena, or statutory warrant issued by a court of competent jurisdiction, or in emergency situations involving imminent danger of death or severe physical harm to an individual.
9. International Data Transfers
Our Dream AI operates a global neural computing network with primary inference clusters and databases situated in the United States and European Union. If you access our Services from outside these regions, your personal data will be transferred to, stored, and processed in jurisdictions where data protection standards may differ from those of your home nation.
Whenever personal data originating from the European Economic Area (EEA), the United Kingdom, or Switzerland is transferred internationally, Our Dream AI relies upon Standard Contractual Clauses (SCCs) approved by the European Commission, UK International Data Transfer Agreements (IDTAs), and equivalent technical safeguards including end-to-end transport layer security (TLS 1.3) and AES-256 at-rest encryption.
10. Data Retention, Archival & Auto-Purging Schedules
We adhere to the privacy principle of storage limitation. We retain your information only for as long as your account remains active or as needed to provide you with the Services:
- Active Account Data: Your account profile, character backstories, image galleries, and conversational history remain retained for as long as your account is maintained in good standing;
- User-Initiated Deletions: If you delete a character, individual dialogue messages, or image renderings, the respective assets are removed from active production caches immediately and irreversibly purged from our live database clusters within twenty-four (24) hours;
- Account Termination: Upon receiving a formal account deletion request via account settings or our Data Protection Officer, your entire user profile, conversational embeddings, custom persona definitions, and virtual currency balances are permanently purged from active systems within thirty (30) days;
- Financial Records: Transaction receipts, invoice records, and tax payment documentation are retained for up to seven (7) years strictly to satisfy statutory tax, audit, and legal accounting obligations.
11. Your Statutory Privacy Rights (GDPR / UK GDPR / Global)
Regardless of your geographical location, Our Dream AI extends universal privacy rights to all registered members. Subject to local statutory exemptions, you hold the right to:
- Right of Access (Article 15 GDPR): Request a structured, machine-readable export of all personal data, character prompts, and profile records we maintain about you;
- Right to Rectification (Article 16 GDPR): Request immediate correction of inaccurate, outdated, or incomplete profile records;
- Right to Erasure / "Right to Be Forgotten" (Article 17 GDPR): Demand the total and permanent deletion of your account, transcripts, and embeddings;
- Right to Restriction of Processing (Article 18 GDPR): Request that we restrict active processing of your data while a formal dispute regarding accuracy or legality is investigated;
- Right to Data Portability (Article 20 GDPR): Receive your character specifications, written prompts, and dialogue logs in a portable JSON/CSV format;
- Right to Object (Article 21 GDPR): Object to any processing founded on legitimate interests;
- Right to Lodge a Complaint: Lodge a formal grievance with your local data protection supervisory authority (e.g., the CNIL in France, the BfDI in Germany, or the ICO in the United Kingdom).
To exercise any of these rights, transmit a formal Data Subject Access Request (DSAR) to our privacy team at [email protected]. We respond to all verified requests within thirty (30) calendar days without fee.
12. California & US State Privacy Disclosures (CCPA / CPRA)
This section provides supplementary disclosures required by the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, the "CCPA/CPRA"), alongside state privacy legislation in Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and Texas (TDPSA):
- No Sale or Sharing of Personal Data: Our Dream AI has not sold or shared (for cross-context behavioral advertising) any personal information of consumers in the preceding twelve (12) months;
- Notice of Sensitive Personal Information: We do not collect or process sensitive personal information for the purpose of inferring characteristics about consumers;
- Non-Discrimination Guarantee: We will never deny you services, charge you different rates, provide a disparate quality of generative inference, or penalize you in any manner for exercising your statutory CCPA rights;
- Authorized Agent: You may designate an authorized agent registered with the California Secretary of State to submit CCPA requests on your behalf, provided written power of attorney verification is submitted.
13. Strict 18+ Adult Standard & Children's Privacy
Our Dream AI provides mature, unconstrained creative roleplay, emotionally nuanced artificial companions, and adult synthetic media. The Platform is strictly prohibited to any individual under the age of eighteen (18) years (or the age of legal majority in their local jurisdiction).
We do not knowingly solicit, collect, or store personal data from children under the age of 18 in accordance with the Children's Online Privacy Protection Act (COPPA), the UK Age Appropriate Design Code, and European child protection legislation. If we determine that an account is operated by, or that data has been collected from, an individual under 18 years of age, we will immediately and permanently terminate the account and purge all associated records from our servers without prior warning.
If you suspect or have reason to believe that a minor has submitted personal information or gained access to our Platform, please notify our Trust & Safety Division immediately at [email protected].
14. Security Safeguards, Policy Updates & Contact Information
A. Technical & Organizational Security
We implement industry-standard cryptographic and architectural defenses designed to prevent unauthorized access, accidental alteration, or catastrophic destruction of your personal data:
- All network communications between your client device and our edge servers are encrypted using modern Transport Layer Security protocols (TLS 1.3);
- Persistent databases, vector embedding vaults, and disk volumes are secured utilizing AES-256 bit hardware-level encryption at rest;
- Administrative access to backend infrastructure is constrained by strict role-based access control (RBAC), mandatory hardware multi-factor authentication (MFA), and automated intrusion detection monitoring.
B. Modifications to this Privacy Policy
We may periodically amend, modify, or update this Privacy Policy to reflect advancements in our generative architectures, newly integrated neural capabilities, or evolving legal frameworks. When material alterations occur, we will update the "Last Revised" date at the top of this page and issue an in-app banner alert to registered users. Your continued use of the Platform after modified terms are posted signifies your acknowledgment and acceptance of the revised privacy practices.
C. Data Protection Officer & Contact Inquiries
For regulatory inquiries, Data Subject Access Requests (DSARs), or general questions regarding our privacy architecture, please contact our Data Protection Officer and Legal Bureau:
Our Dream AI Legal & Data Privacy Bureau
Attn: Data Protection Officer (DPO)
Website: https://en-ourdreamai.us/
Direct Privacy Inquiries: [email protected]
Trust & Safety Division: [email protected]
General Support: [email protected]
Address: 100 Montgomery St, Suite 1800, San Francisco, CA 94104, USA