Legal
Privacy Policy
Last updated: 6 July 2026
We are committed to protecting your privacy. Dream journals and personal reflections are among the most intimate data a person can record, and we treat your information with the seriousness that deserves.
1. Introduction
This Privacy Policy explains how Remnance ("we", "us", "our") collects, uses, stores, and protects your personal data when you use the Remnance application and related services ("the Service").
This policy applies to all users of the Service and is written in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Data Controller
Remnance acts as the data controller for personal data collected through the Service. If you have questions about how your data is handled, please contact us at: privacy@remnance.app
3. Data We Collect
3.1 Account Data
- Email address
- Display name
- Account creation date and time
- Timezone
3.2 Dream Journal Data
- Dream entry text content
- Dream titles
- Dates of dreams
- Emotions, themes, people, and places you tag
- Whether a dream was lucid, recurring, or a nightmare
- Your answers to REM's reflection questions
- Sleep quality ratings
- AI-generated summaries and tags
3.3 Day Log Data
- Date of log
- Bed time and wake time
- Sleep duration and quality
- Stress, mood, and energy levels (1–5 scale)
- Alcohol consumption (units)
- Caffeine consumption (mg)
- Exercise duration
- Screen time
- People seen that day
- Notable events
- Free-text notes, including optional answers to evening reflection prompts
- What you noted as "stuck in your head"
- Media consumed
- Strongest emotion of the day
3.4 Usage Data
- Pages and features accessed within the app
- Timestamps of activity
- Device type and browser (collected by our hosting infrastructure)
- IP address (collected by our hosting infrastructure)
- Product analytics events — the names of actions taken (for example “a dream was logged” or “a message was sent to REM”) together with neutral flags such as whether the action happened offline. Analytics events never include the content of your dreams, day logs, reflections, tags, or the names of people in your journal
3.5 Payment Data
- Subscription plan and status
- Billing history and dates
- Payment method details are held and processed by Stripe — we do not store full card numbers or CVV codes
3.6 AI Interaction Data
- Messages sent to the REM AI assistant
- AI responses generated
- Pattern cards and correlation cards generated during sessions
3.7 Technical Data
- Vector embeddings derived from your dream and day log content (used for semantic search within your own data)
- Push notification subscription tokens (if you opt in to notifications)
4. How We Collect Data
- Directly from you — when you create an account, log a dream, complete a day log, or interact with REM
- Automatically — usage data and technical data collected when you use the Service
- From third parties — authentication data from Supabase Auth; payment status from Stripe
5. How We Use Your Data
We use your data to:
- Provide and operate the Service
- Authenticate your identity and maintain your account
- Store and display your dream entries and day logs
- Generate AI-powered pattern analyses connecting your dreams and day logs
- Power the REM AI assistant with context from your personal journal data
- Process subscription payments and manage billing
- Send transactional emails (account confirmation, password reset, billing notices)
- Send weekly digest notifications if you have opted in
- Improve the reliability and performance of the Service
- Comply with legal obligations
We do not use your dream content or personal journal data to train AI models. Your content is processed by Google Gemini API solely to generate responses and insights for your personal use within the Service.
6. Encryption and Security
6.1 Encryption at Rest
Dream entry content, journal notes, and other sensitive free-text fields are encrypted at rest using AES-256-GCM encryption before being stored in our database. Encryption keys are managed separately from the encrypted data.
6.2 Encryption in Transit
All data transmitted between your device and our servers is encrypted using TLS (HTTPS).
6.3 Authentication
User authentication is handled by Supabase Auth. Passwords are hashed and never stored in plain text.
6.4 Access Controls
Row-Level Security (RLS) policies are enforced at the database level, ensuring that users can only access their own data.
6.5 Storage on Your Device
To support offline use, the app stores some data locally on your device: dream and day log entries you save while offline (until they sync), a lightweight index of your journal (titles, dates, and tags — not full dream text) used for offline search, and cached pages. This data lives in your browser's local storage and is removed when you clear your browser data for the site.
6.6 Limitations
No system is completely secure. While we take reasonable and industry-standard measures to protect your data, we cannot guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by law.
7. Legal Basis for Processing (UK GDPR)
We process your data under the following legal bases:
- Contract — processing necessary to provide the Service you have signed up for (account data, journal data, billing)
- Legitimate interests — improving the Service, preventing fraud, ensuring security, and understanding how features are used through content-free product analytics
- Consent — push notifications (you may withdraw consent at any time in your account settings)
- Legal obligation — where we are required by law to process or retain data
8. Data Sharing and Third Parties
We do not sell your personal data. We share data only with the following categories of third parties, and only to the extent necessary to provide the Service:
8.1 Supabase
Our database, authentication, and file storage provider. Your data is stored on Supabase-managed infrastructure. Supabase is SOC 2 Type II certified.
8.2 Stripe
Our payment processing provider. Stripe processes your payment information and subscription status. We share only what is necessary for billing.
8.3 Google (Gemini API)
Your dream and day log data is sent to the Google Gemini API for the purpose of generating AI pattern analysis and REM assistant responses. We use the paid tier of the Gemini API; under these terms, Google does not use API inputs or outputs to train its models.
8.4 Vercel
Our hosting and deployment infrastructure provider. Vercel may process request logs and technical data as part of serving the application.
8.5 PostHog
Our product analytics provider, hosted in the European Union. PostHog receives content-free usage events (see section 3.4) so we can understand which features are used and improve the Service. It never receives your journal content, tags, or the names of people in your entries, and we do not use session recording. Our analytics run in “cookieless” mode — PostHog does not store cookies or persistent identifiers on your device.
8.6 GitHub
Our source code is hosted on GitHub. GitHub does not process your personal data as a user of Remnance.
8.7 Legal Requirements
We may disclose your data if required to do so by law, court order, or governmental authority, or if we believe disclosure is necessary to protect the rights, property, or safety of Remnance, our users, or others.
9. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. Specifically:
- Account data — retained until you delete your account
- Dream entries and day logs — retained until you delete them or delete your account
- Payment records — retained for 7 years as required for tax and accounting purposes
- Usage logs — retained for up to 90 days
When you delete your account, we will delete or anonymise your personal data within 30 days, except where we are legally required to retain it.
10. Your Rights
Under UK GDPR, you have the following rights:
- Right of access — you can request a copy of all personal data we hold about you
- Right to rectification — you can ask us to correct inaccurate or incomplete data
- Right to erasure — you can request deletion of your personal data ("right to be forgotten")
- Right to restriction — you can ask us to restrict processing of your data in certain circumstances
- Right to data portability — you can request your data in a structured, machine-readable format
- Right to object — you can object to processing based on legitimate interests
- Right to withdraw consent — where processing is based on consent (e.g. push notifications), you can withdraw at any time
You can exercise many of these rights directly within the app via Account Settings (export, delete account, manage notifications). To exercise rights not available directly in the app, please contact us at privacy@remnance.app. We will respond within 30 days.
11. Data Portability and Export
We provide a data export feature within the app that allows you to download a copy of all your dream entries and day logs in a portable format. This is available at any time from your account settings.
12. Cookies
The Service uses cookies and similar technologies for the following purposes:
- Authentication cookies — to keep you logged in across sessions (essential, cannot be disabled)
- Session cookies — to maintain your session state (essential)
We do not use advertising cookies or third-party tracking cookies. Our product analytics (PostHog) runs in cookieless mode and does not store cookies or persistent identifiers on your device. You can control cookie settings through your browser, though disabling essential cookies will prevent the Service from functioning correctly.
13. International Transfers
Your data may be processed in countries outside the UK, including the United States, where our third-party providers (Supabase, Google, Vercel, Stripe) operate data centres. Product analytics data is hosted by PostHog within the European Union. We ensure that such transfers are protected by appropriate safeguards, including standard contractual clauses where required.
14. Children's Privacy
The Service is not directed at children under 18. We do not knowingly collect personal data from anyone under 18. If you become aware that a child has provided us with personal data, please contact us and we will take steps to delete it.
15. Push Notifications
If you opt in to push notifications, we store a push subscription token associated with your account. This token is used solely to deliver notifications from Remnance to your device. You can withdraw consent and disable push notifications at any time in your account settings or through your browser settings.
16. AI and Automated Decision-Making
The Service uses automated processing (Google Gemini AI) to generate pattern analyses and insights from your journal data. This automated processing is used to provide you with insights for personal reflection purposes only. It does not produce legal or similarly significant effects, and you are always free to disregard AI-generated content.
17. Changes to this Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice within the Service at least 14 days before changes take effect. We encourage you to review this Policy periodically.
18. Complaints
If you believe we have handled your data unlawfully, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Telephone: 0303 123 1113
We would, however, appreciate the opportunity to address your concerns before you contact the ICO. Please contact us first at privacy@remnance.app.
19. Contact
For any privacy-related questions or to exercise your rights:
Email: privacy@remnance.app