Privacy Policy
Last updated: July 13, 2026
Who this policy covers
This policy applies to Daydream Together at daydreamtogether.com (“Daydream Together,” “we,” or “us”). The service is intended only for people who are at least 18 years old. Questions and privacy requests can be sent to hunter@willisma.com.
Information we handle
Account and sign-in information
Google sign-in provides your Google account identifier, name, email address, email-verification status, and profile picture. We use the identifier—not your email address—as the stable key for your Daydream Together account. We never receive your Google password.
Stories and shared play
We store the worlds and characters you create, actions and prompts you submit, AI-generated narration, dice and game state, journals, maps, and related campaign history so that stories can continue. A campaign is visible to its owner and to accounts that the owner pairs with or invites. Pairing records, campaign invite codes, partner names, date-night settings, and shared-play presence are used to make two-screen play work.
Usage, billing, and support
For owner-only financial reporting, signature-verified Stripe webhooks produce a limited ledger of invoice amounts, refund changes, currency, timestamps, and one-way keyed Stripe deduplication markers. It may carry a one-way keyed account link while the account exists, but never the plain email, story, card number, or raw Stripe object id.
We keep usage and estimated-cost records to enforce the free and member allowances, along with subscription tier and Stripe customer/subscription references. A minimal anti-abuse copy of consumed allowance and whether the one-time grace scene was used is stored under a one-way keyed account marker; it does not contain a name, email address, profile, or story. Stripe—not Daydream Together—collects and processes full payment-card details. If you contact support, we receive the information you include in the message. If you use Report inside a story, we store your account id and email, the report category and note, campaign id/title and reported-turn number, and the latest AI narration (limited in length) so the issue can be reviewed.
Technical information
Our hosting and security systems process information such as IP address, request time, requested URL, browser/device information, referring page, rate-limit counters, cookies, and error or security logs. We use this to deliver the service, prevent abuse, diagnose failures, and protect accounts.
Product measurement
We record a limited set of product milestones—such as viewing the landing page, registering, pairing, starting a story, beginning checkout, or activating a subscription—with a timestamp, permitted event details such as plan or conservative campaign-source labels, and opaque hashed account, pair, campaign, or session identifiers when available. Registration, pairing, story, shared-turn, and checkout milestones are recorded only after the corresponding server action succeeds. These privacy-conscious first-party records operate separately from the optional Meta choice and are used to understand reliability and whether the launch funnel works. They are designed not to contain story text, prompts, character details, partner names, full payment-card information, or the plain Google email address.
How we use information
- Provide sign-in, saving, pairing, shared play, narration, exports, support, and billing.
- Generate and read aloud story content at your request.
- Enforce allowances, prevent fraud and abuse, investigate safety reports, and secure the service.
- Understand service use and whether conservative campaign links lead to registrations through first-party product measurement; when separately enabled with permission, use Meta measurement as described below.
- Meet legal obligations and resolve billing disputes.
We do not use your stories to train our own model. Our current Anthropic and OpenAI API arrangements state that API inputs and outputs are not used for model training by default unless the API customer opts in. Those providers may retain limited data for abuse monitoring, safety, or legal compliance under their own terms.
Service providers
These companies process information for a specific part of the service:
- Google provides account sign-in.
- Anthropic receives relevant story instructions and history to generate story content.
- OpenAI receives narration text when you use the optional cloud read-aloud feature.
- Stripe provides checkout, subscription management, invoices, and payment processing.
- Render hosts the application and persistent storage.
- Cloudflare provides domain, network, delivery, and security services and may process IP address and traffic metadata.
- Meta receives advertising-measurement information only when the Meta Pixel or another Meta measurement feature is enabled as described below.
Providers may process information in the United States or other countries under their own privacy terms and our service arrangements. Their independent records—such as Stripe transaction records or Google sign-in records—are governed by their policies.
Advertising measurement: Meta Pixel and Conversions API
The Meta Pixel and Meta's server-side Conversions API (CAPI) are optional and operate only when the operator configures them for an advertising campaign and you choose Allow Meta measurement. The Pixel can send permitted browser events such as page views, landing-page interest, and the browser copy of a server-verified subscription. Meta also receives the page URL, browser/device and network information, the IP address that connects to Meta, and Meta/browser identifiers or cookies such as _fbp and _fbc.
For a signed-in account with the choice saved on that account, CAPI can send the event name, time and deduplication id; source URL and user agent; _fbp/_fbc identifiers; plan, currency, or purchase value; and SHA-256 hashed versions of the Google email address and Daydream account identifier. Signed-out choices can enable the browser Pixel but never CAPI. High-value product milestones sent through CAPI come from completed server actions, and subscription measurement is sent only after the server verifies the Stripe checkout. Browser and server subscription copies use the same event id so Meta can deduplicate them. We do not send story text, prompts, character details, partner names, full card information, or Google passwords to Meta.
If a consented CAPI conversion cannot be delivered immediately, Daydream stores an encrypted retry record on its persistent storage for no more than seven days. Before every retry, Daydream rechecks the signed-in account's current Meta choice; if permission is no longer active, the record is discarded instead of sent. Choosing Keep Meta off or deleting the account is designed to purge that account's pending conversion retries. The private owner dashboard receives only aggregate delivery status, counts, and success/failure times—not queued conversion contents or identifiers.
Meta may associate this information with a Facebook or Instagram account and use it to measure and deliver advertising under Meta's Privacy Policy and Cookies Policy.
If you choose Keep Meta off, Daydream does not load the Meta Pixel; if it was previously allowed, Pixel consent is revoked. Daydream also does not send your events through CAPI. The limited first-party product reporting described above—including conservative arrival and campaign labels—continues separately from Meta. Signed-in players can change the Meta choice later through Privacy choices in the account menu; a signed-out visitor can clear this site's local storage to be asked again. The choice is stored in this browser and, when signed in, on the account; allowing Meta measurement additionally stores limited first-touch attribution and Meta click/browser identifiers. Browser tracking protection or an ad blocker may provide an additional control without preventing gameplay. You can also adjust off-Meta activity and advertising choices in Meta's settings.
Cookies and local browser storage
- Essential session cookies.
cf_sidkeeps a Google account signed in for up to 30 days. A short-livedcf_oauthcookie protects the Google sign-in round trip and expires after about 10 minutes. - Local and session storage. The app stores appearance/read-aloud preferences, first-run state, short-lived pairing or story-invite handoff data, a session-scoped anonymous product-measurement id, and tracking-deduplication flags. It stores the Meta measurement choice and, only after permission, browser-side first-touch Meta attribution. Clearing site data removes these local values and may sign you out, interrupt a pending invite, or ask for the privacy choice again.
- Advertising technologies. After you allow configured Meta measurement, Meta may set or read cookies and similar identifiers such as
_fbpand_fbcas described above.
Retention
De-identified invoice and refund totals and one-way keyed deduplication markers may be retained for accounting, fraud prevention, disputes, tax, and legal obligations. Account deletion is designed to remove the optional one-way account link while retaining those aggregate financial records.
- Accounts and campaigns: kept while the account or campaign remains active, until deleted, or longer when limited retention is reasonably necessary for security, disputes, or law.
- Sessions: normally expire after 30 days; signing out revokes the current session, and account deletion is designed to revoke all sessions.
- Pairing and invite data: kept until used, rotated, unlinked, the campaign/account is deleted, or the data is otherwise no longer needed.
- Generated exports: a server-side copy may remain until its campaign or account is deleted. Copies you download or send to someone are outside our control.
- Generated audio: stored in a bounded, rotating content-addressed cache to avoid paying to recreate the same clip. That cache is not currently indexed by account, so account deletion may not immediately remove an otherwise unlinked clip; normal cache eviction or operator maintenance removes cached files.
- Product analytics: first-party milestone records are normally retained for 90 days (the configured window can be shorter or longer, up to one year) and then swept. Account- and pair-linked entries are designed to be removed during account deletion. Session-only entries that cannot reliably be connected back to the account remain until normal expiry. Meta deduplication records, which do not contain a user mapping, are normally kept for about 35 days.
- Meta conversion retries: consented CAPI records awaiting delivery are encrypted at rest, removed after successful delivery, and dropped after no more than seven days. Consent is checked again before each attempt. Opting out of Meta measurement or deleting the account is designed to purge its pending records; aggregate failed-or-dropped operational counts may remain without an account or event identifier.
- Allowance abuse prevention: after account deletion, the one-way keyed marker and the minimum usage state needed to prevent repeated free-trial resets may remain. This record is not used for advertising and does not retain the account profile or story content. It is kept while the free allowance remains a one-time offer or until it is no longer reasonably needed for fraud and abuse prevention.
- Logs and provider records: retained according to operational settings, provider policies, and any legitimate security, fraud, payment, dispute, tax, or legal need. Anthropic and OpenAI publish their own API retention rules, which may include limited abuse-monitoring retention.
Your choices and deletion
Account deletion is designed to unlink the account from the verified-payment ledger. De-identified invoice/refund totals and their one-way deduplication markers may remain for the financial purposes described above.
You can delete a campaign from the game, sign out, change optional advertising measurement under Privacy choices, or ask for access, correction, objection, or account deletion by emailing hunter@willisma.com. We may need to verify the request through the email address attached to the signed-in account.
Before account deletion, an active subscription must be canceled or otherwise resolved so deletion does not leave an unseen recurring charge. For security, permanent self-service deletion also requires a recent Google sign-in. Account deletion is designed to remove the account record, revoke sessions, delete campaigns the account owns (including known backups, undo files, and attributable server exports), remove the account from campaigns owned by someone else, and clear partner links. The minimal one-way keyed allowance-abuse record described above remains. Story contributions already incorporated into another person's campaign may remain as part of that shared story after the account link is removed. Safety evidence, payment records, provider records, downloaded exports, and backups outside our direct control may also remain where reasonably necessary or required.
Rights vary by location and can have exceptions. We will evaluate verified requests under applicable law rather than promising that every record held by every independent provider can be erased.
Safety reports and human review
AI narration can be inaccurate, unexpected, or offensive. Use Report in an open story or email hunter@willisma.com with the campaign title, approximate date/time, and the smallest excerpt or screenshot needed to explain the issue. Do not send passwords, full card numbers, or unrelated sensitive information. We may review the reported content and related account/campaign records as needed to investigate, secure the service, enforce the Terms, or comply with law. When account deletion occurs, the stored in-app report is designed to remove the reporter's account id and email; the category, note, campaign context, and relevant output may remain as limited safety evidence where reasonably necessary.
Security and changes
We use access controls, secure cookies, provider authentication, and other safeguards appropriate to this small service. No online service can promise perfect security. If this policy changes materially, we will update the date and provide additional notice when appropriate.
Contact
Privacy, support, billing, deletion, or safety questions: hunter@willisma.com. You can also use the support and safety page.