← Back to Daydream Together

Privacy Policy

Last updated: July 13, 2026

The short version. Daydream Together stores the account, story, pairing, and usage information needed to run the game. Story text is sent to AI providers to generate narration, and optional narration text is sent to a voice provider. We do not sell your stories. We keep limited first-party product measurements; optional Meta advertising measurement is used only after an affirmative choice when it is configured.

Who this policy covers

This policy applies to Daydream Together at daydreamtogether.com (“Daydream Together,” “we,” or “us”). The service is intended only for people who are at least 18 years old. Questions and privacy requests can be sent to hunter@willisma.com.

Information we handle

Account and sign-in information

Google sign-in provides your Google account identifier, name, email address, email-verification status, and profile picture. We use the identifier—not your email address—as the stable key for your Daydream Together account. We never receive your Google password.

Stories and shared play

We store the worlds and characters you create, actions and prompts you submit, AI-generated narration, dice and game state, journals, maps, and related campaign history so that stories can continue. A campaign is visible to its owner and to accounts that the owner pairs with or invites. Pairing records, campaign invite codes, partner names, date-night settings, and shared-play presence are used to make two-screen play work.

Usage, billing, and support

For owner-only financial reporting, signature-verified Stripe webhooks produce a limited ledger of invoice amounts, refund changes, currency, timestamps, and one-way keyed Stripe deduplication markers. It may carry a one-way keyed account link while the account exists, but never the plain email, story, card number, or raw Stripe object id.

We keep usage and estimated-cost records to enforce the free and member allowances, along with subscription tier and Stripe customer/subscription references. A minimal anti-abuse copy of consumed allowance and whether the one-time grace scene was used is stored under a one-way keyed account marker; it does not contain a name, email address, profile, or story. Stripe—not Daydream Together—collects and processes full payment-card details. If you contact support, we receive the information you include in the message. If you use Report inside a story, we store your account id and email, the report category and note, campaign id/title and reported-turn number, and the latest AI narration (limited in length) so the issue can be reviewed.

Technical information

Our hosting and security systems process information such as IP address, request time, requested URL, browser/device information, referring page, rate-limit counters, cookies, and error or security logs. We use this to deliver the service, prevent abuse, diagnose failures, and protect accounts.

Product measurement

We record a limited set of product milestones—such as viewing the landing page, registering, pairing, starting a story, beginning checkout, or activating a subscription—with a timestamp, permitted event details such as plan or conservative campaign-source labels, and opaque hashed account, pair, campaign, or session identifiers when available. Registration, pairing, story, shared-turn, and checkout milestones are recorded only after the corresponding server action succeeds. These privacy-conscious first-party records operate separately from the optional Meta choice and are used to understand reliability and whether the launch funnel works. They are designed not to contain story text, prompts, character details, partner names, full payment-card information, or the plain Google email address.

How we use information

We do not use your stories to train our own model. Our current Anthropic and OpenAI API arrangements state that API inputs and outputs are not used for model training by default unless the API customer opts in. Those providers may retain limited data for abuse monitoring, safety, or legal compliance under their own terms.

Service providers

These companies process information for a specific part of the service:

Providers may process information in the United States or other countries under their own privacy terms and our service arrangements. Their independent records—such as Stripe transaction records or Google sign-in records—are governed by their policies.

Advertising measurement: Meta Pixel and Conversions API

The Meta Pixel and Meta's server-side Conversions API (CAPI) are optional and operate only when the operator configures them for an advertising campaign and you choose Allow Meta measurement. The Pixel can send permitted browser events such as page views, landing-page interest, and the browser copy of a server-verified subscription. Meta also receives the page URL, browser/device and network information, the IP address that connects to Meta, and Meta/browser identifiers or cookies such as _fbp and _fbc.

For a signed-in account with the choice saved on that account, CAPI can send the event name, time and deduplication id; source URL and user agent; _fbp/_fbc identifiers; plan, currency, or purchase value; and SHA-256 hashed versions of the Google email address and Daydream account identifier. Signed-out choices can enable the browser Pixel but never CAPI. High-value product milestones sent through CAPI come from completed server actions, and subscription measurement is sent only after the server verifies the Stripe checkout. Browser and server subscription copies use the same event id so Meta can deduplicate them. We do not send story text, prompts, character details, partner names, full card information, or Google passwords to Meta.

If a consented CAPI conversion cannot be delivered immediately, Daydream stores an encrypted retry record on its persistent storage for no more than seven days. Before every retry, Daydream rechecks the signed-in account's current Meta choice; if permission is no longer active, the record is discarded instead of sent. Choosing Keep Meta off or deleting the account is designed to purge that account's pending conversion retries. The private owner dashboard receives only aggregate delivery status, counts, and success/failure times—not queued conversion contents or identifiers.

Meta may associate this information with a Facebook or Instagram account and use it to measure and deliver advertising under Meta's Privacy Policy and Cookies Policy.

If you choose Keep Meta off, Daydream does not load the Meta Pixel; if it was previously allowed, Pixel consent is revoked. Daydream also does not send your events through CAPI. The limited first-party product reporting described above—including conservative arrival and campaign labels—continues separately from Meta. Signed-in players can change the Meta choice later through Privacy choices in the account menu; a signed-out visitor can clear this site's local storage to be asked again. The choice is stored in this browser and, when signed in, on the account; allowing Meta measurement additionally stores limited first-touch attribution and Meta click/browser identifiers. Browser tracking protection or an ad blocker may provide an additional control without preventing gameplay. You can also adjust off-Meta activity and advertising choices in Meta's settings.

Cookies and local browser storage

Retention

De-identified invoice and refund totals and one-way keyed deduplication markers may be retained for accounting, fraud prevention, disputes, tax, and legal obligations. Account deletion is designed to remove the optional one-way account link while retaining those aggregate financial records.

Your choices and deletion

Account deletion is designed to unlink the account from the verified-payment ledger. De-identified invoice/refund totals and their one-way deduplication markers may remain for the financial purposes described above.

You can delete a campaign from the game, sign out, change optional advertising measurement under Privacy choices, or ask for access, correction, objection, or account deletion by emailing hunter@willisma.com. We may need to verify the request through the email address attached to the signed-in account.

Before account deletion, an active subscription must be canceled or otherwise resolved so deletion does not leave an unseen recurring charge. For security, permanent self-service deletion also requires a recent Google sign-in. Account deletion is designed to remove the account record, revoke sessions, delete campaigns the account owns (including known backups, undo files, and attributable server exports), remove the account from campaigns owned by someone else, and clear partner links. The minimal one-way keyed allowance-abuse record described above remains. Story contributions already incorporated into another person's campaign may remain as part of that shared story after the account link is removed. Safety evidence, payment records, provider records, downloaded exports, and backups outside our direct control may also remain where reasonably necessary or required.

Rights vary by location and can have exceptions. We will evaluate verified requests under applicable law rather than promising that every record held by every independent provider can be erased.

Safety reports and human review

AI narration can be inaccurate, unexpected, or offensive. Use Report in an open story or email hunter@willisma.com with the campaign title, approximate date/time, and the smallest excerpt or screenshot needed to explain the issue. Do not send passwords, full card numbers, or unrelated sensitive information. We may review the reported content and related account/campaign records as needed to investigate, secure the service, enforce the Terms, or comply with law. When account deletion occurs, the stored in-app report is designed to remove the reporter's account id and email; the category, note, campaign context, and relevant output may remain as limited safety evidence where reasonably necessary.

Security and changes

We use access controls, secure cookies, provider authentication, and other safeguards appropriate to this small service. No online service can promise perfect security. If this policy changes materially, we will update the date and provide additional notice when appropriate.

Contact

Privacy, support, billing, deletion, or safety questions: hunter@willisma.com. You can also use the support and safety page.