Legal
Privacy Policy
Somery (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains what information we collect when you use the Somery iOS app, how we use it, who we share it with, and your rights regarding that information.
1. Information We Collect
Account information. You can create an account with an email address and password, or sign in with Google or Sign in with Apple. When you use Google or Apple to sign in, those providers share a verified email address (and, for Sign in with Apple, an identity token used only to verify your identity) with us — we do not receive your Google or Apple password.
Dream journal entries. The text you write for each dream, together with any rating, mood, sleep quality, dream type, and moon phase you attach to that entry.
Profile & preferences. During onboarding you may share details such as gender, age range, zodiac sign, goals, and how you’d describe your dream recall, mood, or dream patterns. We use these to personalise your AI interpretations (see Section 3) — they’re optional and can be changed at any time from your profile in the app.
HealthKit sleep data (optional). If you grant permission, Somery can read sleep duration and sleep stages from Apple HealthKit, to show you sleep stats inside the app. This permission is entirely optional, can be revoked at any time in iOS Settings, we never write data back to HealthKit, and — unlike the sleep quality you enter yourself in a journal entry — this HealthKit data is never sent to our AI provider or to any other third party (see Section 3).
Push notification token. If you enable reminders or other notifications, we register your device with Apple Push Notification service (APNs) and store the resulting device token, linked to your account, so we can deliver notifications. You can disable notifications at any time in iOS Settings.
Apple Watch companion app (optional). If you use the Somery Watch app, dream entries and images are synced between your iPhone and Apple Watch using Apple’s WatchConnectivity framework, directly between your own devices. This sync does not pass through Somery’s servers.
Usage analytics. We use Mixpanel and Firebase Analytics to collect analytics about how features are used. These events are linked to your account (not anonymous) — your Mixpanel profile includes your email address and display name — so we can understand usage patterns, but analytics events do not contain the content of your dream entries. Analytics is on by default; you can turn it off at any time in the app under Settings → Privacy Settings → Share Usage Analytics, which stops Mixpanel and Firebase from receiving further events from your device.
Voice input (optional). If you use voice input, Somery uses
Apple’s speech recognition (SFSpeechRecognizer) to transcribe your
speech to text. This transcription is processed server-side by Apple. The audio
itself is not stored by Somery and is never sent to Somery’s backend — only the
resulting text is.
Subscription status. Purchases are handled entirely by Apple’s App Store and StoreKit (see the Terms of Service). We receive your subscription status and entitlements from Apple so the app can unlock the features you paid for — we never receive or store your card details.
2. How We Use Your Information
- To provide and personalise the dream journaling experience.
- To generate AI interpretations, answers, recaps, and visualisations of your dreams (see Section 3).
- To sync your data across your devices and keep it backed up.
- To deliver reminders and other notifications you’ve enabled.
- To improve the app through account-linked usage analytics.
- To communicate with you about your account when necessary.
3. AI Processing
Somery uses OpenAI, via Supabase Edge Functions, for every AI-generated feature in the app:
- Dream interpretation — sends your dream text, rating, chosen interpretation style, and (if provided) a follow-up question, together with your profile & preferences and this entry’s context (mood, sleep quality, dream type, moon phase).
- Follow-up questions about a dream — sends your question, the dream text, the prior interpretation, and that entry’s context.
- Monthly / period recaps — sends an aggregate of tags and patterns from your dreams over the period (emotions, themes, moods, dream types) — not the full text of every entry.
- Dream recall prompts — sends the recall questions and answers you provide.
- Dream visualisations (images) — sends your dream text, rating, and profile to OpenAI’s image API to generate an image.
Your HealthKit sleep data is never included in any of the AI requests above. It is used only for local, on-device features (such as sleep stats in the app).
OpenAI does not retain your content after generating a response, other than a short-term abuse-monitoring window (per OpenAI’s policy, typically up to 30 days) that is outside our control, and does not use content submitted through its API to train its models, per OpenAI’s API data usage policy. We do not use your dream content to train our own models either.
Generated images are stored locally on your device and are not transmitted to any other third-party image service.
4. Data Storage
Server-backed with local cache. Once you’re signed in, your profile and dream data are stored on Supabase (PostgreSQL) and kept in a local SwiftData cache on your device for fast, offline-friendly access. All server-side data is protected with row-level security so only your account can access your records.
Before you sign in, anything you create is stored only in the local SwiftData cache on your device.
5. Data Sharing
We do not sell your personal information to third parties. We share data only with the following service providers, and only to the extent necessary to operate the app:
- Supabase — hosts your account, dream journal, profile, subscription/credit status, and your push notification device token.
- OpenAI — receives the dream text and context described in Section 3 to generate interpretations, answers, recaps, and images. Never receives your HealthKit data.
- Google / Apple — receive your sign-in request if you choose those providers; share back a verified email (and, for Apple, an identity token).
- Apple (App Store / StoreKit) — processes your subscription purchase and shares your entitlement status back to us. Apple handles all payment details directly.
- Apple (APNs) — receives your device push token to deliver notifications; does not receive journal content.
- Mixpanel & Firebase — receive account-linked usage analytics events, including your email and display name, unless you opt out (see Section 1).
Each provider is bound by their own privacy policy and applicable data protection laws.
6. Your Rights
You can access or export your dream data at any time from the Data section of your profile in the app. You can delete your account at any time from the same place. When you do, we call our server to delete your account and all associated records (dreams, interpretations, questions, images, profile, and your push token), and the app then wipes your local database, generated images, and any pending sync data from your device. If you signed in with Apple, we also revoke that Sign in with Apple authorization as part of deletion.
If you are located in the European Economic Area (EEA) or United Kingdom, you have additional rights under the GDPR, including the right to data portability, rectification, and to lodge a complaint with a supervisory authority.
7. Children’s Privacy
Somery is rated 12+ on the App Store, and — separately — you must be at least 13 years old to create an account (see the Terms of Service). We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will delete it promptly.
8. Data Retention
Supabase. We retain your account and dream data for as long as your account is active. If you delete your account, this data is permanently removed from our servers immediately (see Section 6).
OpenAI. OpenAI does not retain the content of your requests beyond its short-term abuse-monitoring window (see Section 3) — independent of whether your Somery account still exists.
Mixpanel & Firebase. Account-linked analytics events may be retained for up to 24 months, or until you opt out and request deletion by contacting us.
9. Security
We use industry-standard measures to protect your data, including encryption in transit (TLS) and at rest, and row-level security in our database. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the “Last updated” date at the top of this page whenever we do, and we’ll take reasonable steps to bring material changes to your attention — for example, through an in-app notice — in addition to updating this page. Continued use of the app after changes are posted constitutes acceptance of the revised policy.
11. Contact Us
If you have questions or requests regarding this Privacy Policy — including data access, export, deletion, or analytics opt-out requests — please contact us at support@lunora.space.