Privacy Policy
This describes what happens to information about you in each part of Oreia, and it is written to be checked rather than trusted. Where a claim could be measured, it was measured; where the honest answer is unflattering, the unflattering answer is the one here. Last reviewed .
Who is responsible
The controller for all processing described here is:
Joelle JaraczKleinunternehmen
Sankt-Sebastianusstraße 1
52399 Merzenich
Germany
hello@oreiathejournal.com
+49 172 2827939
Oreia is run by one person as a small business. There is no data protection officer, because Art. 37 GDPR does not require one at this size and naming one who does not exist would tell you nothing true. Write to the address above for anything on this page, including any of the requests listed under your rights.
Visiting this website
This site sets no cookies. It writes nothing to your browser’s local storage, session storage, IndexedDB or cache storage, and it registers no service worker. That is a measurement taken in a real browser rather than an intention — including after the anti-abuse challenge on the dream reader has loaded and been solved. There is no analytics of any kind: no Google Analytics, no Cloudflare Web Analytics, no pixel, no tag manager, nothing that counts you.
The typefaces are served from this domain. They are not loaded from Google Fonts, so your IP address is not disclosed to Google in order to draw this page.
The site is hosted on Cloudflare Pages. Like any web host, Cloudflare necessarily processes the technical details of the request — your IP address, the time, the page asked for, your browser’s user-agent string — because a page cannot be delivered to you without them. That happens on the basis of Art. 6(1)(f) GDPR, my legitimate interest in operating a website that is reachable and defended against attack. I do not build profiles from it and I do not receive it as a report.
There is a separate page about what is stored on your device and why no consent banner is required.
Reading a dream without an account
The free reader takes a dream you type, produces an interpretation, and keeps none of it.
- What is sent. The text you wrote, plus a token from the anti-abuse challenge. No account, no email address, no name is asked for or attached.
- What produces the reading. Cloudflare Workers AI, running a large language model on Cloudflare’s infrastructure. Cloudflare states that inputs and outputs are not used to train the models it hosts and are not made available to its other customers, and that they are stored only if the developer deliberately writes them to a storage service.
- Nothing is written down. The program that serves the reading has no database, no key-value store and no object storage attached to it at all. There is nowhere for your dream to be saved, which is a stronger statement than a promise not to save it.
- Nothing sensitive is logged. Operational logs record events — that a challenge failed, that a model call fell back to its secondary — and never the text.
- Abuse prevention. Your IP address is used as the key for a short burst limit, at most a few requests per minute, handled by Cloudflare’s rate-limiting service. Oreia does not store it. The challenge widget is Cloudflare Turnstile: your browser loads it from Cloudflare, and the server-side check of your answer deliberately omits your IP address, which that check treats as optional.
The legal basis for producing the reading is Art. 6(1)(b) GDPR — it is the thing you asked for — and for the challenge and the rate limit, Art. 6(1)(f), my legitimate interest in not having an open, unmetered AI endpoint consumed by scripts.
Please read this part. A dream description can reveal things the GDPR treats as special categories of personal data under Art. 9 — health, sexuality, religious or philosophical belief — and I cannot know in advance whether yours does. Submitting a dream is entirely voluntary, and by sending it you explicitly consent, under Art. 9(2)(a) GDPR, to it being processed for the single purpose of returning that one reading to you. Nothing else is done with it and nothing is kept. Even so, the sensible way to use this is to describe the dream and leave out real names and anything that identifies another person.
Sending feedback
The feedback form asks for a message, and optionally an email address so I can reply. It also sends the page you were on and the build you were running, so a report can be reproduced.
That message is delivered to me as email through Resend, an email delivery provider, and arrives at the address in this page’s header. It is not stored by the website or by the program that sends it — the same program as the dream reader, with the same absence of any storage. If you give an address, it is used to reply to you and for nothing else; it is not added to a mailing list, because there is no mailing list. The log line written for a sent report records how many characters it was and whether an address was supplied, never the message.
Legal basis: Art. 6(1)(f) GDPR — my legitimate interest in being told when the product is broken — and, as to your email address, Art. 6(1)(a), since supplying it is optional and its only purpose is the reply you are asking for.
Having an Oreia account
The journal itself is a separate application at app.oreiathejournal.com.
- Identity. An email address and a display name. If you sign in with Google or with Apple instead, I receive the email address and name that provider releases to me, and a stable identifier for you; I do not receive your password for that account and ask for no access to anything else in it.
- Password. If you set one, what is stored is a PBKDF2-SHA-256 derivation of it with a random per-account salt and 100,000 iterations — not the password.
- Session. A signed token held in your browser’s local storage. The app uses no cookies for sign-in.
- Journal content. Entry titles and entry bodies are encrypted on your device, with AES-256-GCM, before they are uploaded. The server stores that ciphertext.
- What is not encrypted. Stored readable alongside each entry: its mood, its type (journal or dream), the symbol tags attached to it, and its dates — when it was written and when the experience it describes happened. Someone with access to the database could therefore see the shape and rhythm of your journalling, and which symbols recur, but not what you wrote.
- Derived material — encrypted. The written output Oreia produces about you is sealed with your key like an entry is: reflections and insights, the meanings it writes for a recurring symbol, its observations and the passages it quotes back to you, the weekly mirror, chat messages, onboarding answers, the notes on a mood check-in, and the titles you give collections.
- Derived material — not encrypted. Some of what is extracted from your writing is stored readable, and it is more revealing than the metadata above, so it is listed rather than summarised: the individual words you used for the people, places, emotions and body sensations Oreia recognised (the literal “mum”, not a paraphrase); the numeric scores it keeps for traits such as agency, self-compassion and boundary strength, with the entry IDs it drew them from; the profile facts it logs about you; the mood, energy and body labels on a check-in; affirmation text; vision-board captions; and the archetype scores and marker lists. Also unencrypted: the numeric embeddings of your entries, held in a vector index — not readable as text, but derived from it.
- Payments. Subscriptions bought on the web are handled by Stripe. Card numbers never reach Oreia; what is stored is a customer and subscription identifier and whether the subscription is active. The iPhone app is not released yet; when it is, purchases inside it will go through Apple rather than Stripe, and what is stored will be Apple’s transaction identifiers and the expiry date, again with no card details.
Legal basis for all of it: Art. 6(1)(b) GDPR, performance of the contract you entered into by creating an account — and Art. 9(2)(a), your explicit consent, for the journal content itself, which by its nature may include the special categories named above. You can withdraw that consent by deleting your entries or your account, which is described under retention.
What the encryption protects, and what it does not
This is the part most likely to be overstated elsewhere, so it is stated here in full.
Your journal is encrypted with a key generated on your own device. That key is then wrapped — encrypted — three separate times, and all three wrapped copies are held on the server:
- one under a key derived from your password;
- one under a key derived from your eight-word recovery phrase, which is shown to you once;
- one under a secret that belongs to the server.
The first two I cannot open: I never receive your password or your recovery phrase, and nothing stored on the server lets me derive the keys they produce. The third one I can open, and that is the honest and important limit of this design. It means I am technically able to decrypt your entries.
It exists for two reasons, both of which you can observe in the product. The first is that Oreia reflects on your writing — it produces the insights, patterns and archetypes that are the point of it — and that work happens on the server, which means the server has to be able to read the text while it does it. The plaintext exists only in memory for the duration of one reflection and the result is encrypted again before it is stored. The second is password reset: if you change your password without knowing the old one, the server re-wraps that same key under the new one. If the server could not open the key, a forgotten password would mean a lost journal, every time.
So: Oreia is not zero-knowledge and it is not end-to-end encrypted, and I will not use either phrase for it. What is true is narrower and still worth something — your entries are not stored in a form the database can read, an attacker who obtains a copy of the database gets ciphertext, and there is no interface anywhere in the product through which a person can read your journal. No human at Oreia reads your entries. But the capability exists in the system, and you are entitled to know that rather than to be reassured.
One related flow worth naming: turning a dream into a picture. The entry is first rewritten into a de-identified description, then run through a deterministic pass that strips anything resembling an identifier, and you are shown the result and can edit it before anything leaves. Only that approved description — not your entry — is sent to OpenAI’s image API.
Who else processes your data
Only these, and each is listed because it is actually in use rather than because it might be. All of them act as processors on my instructions.
- Cloudflare, Inc. (US, with processing on its global network) — hosting for this site and the app, the programs behind the API and the dream reader, the database, the private media storage, the vector index, the AI models behind the readings and reflections, the Turnstile anti-abuse challenge, operational logs, and the email routing behind the contact address.
- OpenAI, L.L.C. (US) — image generation from the de-identified dream description described above, and speech synthesis where a reading is played aloud.
- Resend (Plus Five Five, Inc.) (US) — delivery of transactional email: password resets, verification, and feedback you send me.
- Stripe, Inc. (US, with Stripe Payments Europe in Ireland) — payment processing for web subscriptions.
- Google Ireland Limited / Google LLC — only if you choose to sign in with Google, and only for that sign-in. Google Fonts is not used.
- Apple Inc. / Apple Distribution International — only if you use Sign in with Apple, which passes me your email address and a stable identifier; and, once the iPhone app is released, for purchases made inside it.
There is no advertising, no ad network, no data broker and no analytics provider in this list, because there are none in the product. Nothing about you is sold, and nothing about you is shared for anyone else’s purposes.
Transfers outside the EU
The providers above are United States companies, so personal data does reach the US. Each of them offers the European Commission’s standard contractual clauses within its data processing terms, and that is the transfer mechanism relied on here. Cloudflare’s network is global and will serve you from a nearby location, but that is a performance property and not a guarantee about where data rests.
How long things are kept
- Visiting this site: nothing is kept by me. Cloudflare holds request logs for its own operational purposes, under its own retention policy.
- A free dream reading: nothing, beyond the moment it takes to answer you. There is no store to keep it in.
- Feedback: as email in my mailbox, kept for as long as the matter it concerns is open.
- An account: until you delete it. There is no automatic expiry, because deleting a dream journal after a period of quiet would be the wrong default for something people return to after years.
- Abuse counters: asking for a password reset or a verification email is counted against your email address and against your IP address, so that neither can be used to flood someone’s inbox. The counter resets after an hour, and the row holding your address is deleted along with your account. One case is still uncovered: if someone asks for a reset for an address that has no account here, that row has no account to be deleted with and no job clears it. Write to me and I will remove it.
Deletion is real, it is in the product, and it now reaches every store rather than only the database. “Erase all entries” hard-deletes every entry and the derived material built from it — including the numeric embeddings — while keeping the account.
Deleting the account removes, in one pass: your user record and any linked sign-in account; your entries and the photos attached to them; your insights, symbol meanings, observations and weekly mirrors; the extracted words, the trait and archetype scores and the archetype history; your chat messages and onboarding answers; your mood check-ins, collections, pattern check-ins, saved affirmations and saved quotes, and the record of which daily quote you were shown; the receipts for analysis runs; your settings, rewards and encryption key material; the abuse counter holding your email address; every stored image file — vision board, entry photos and anything Dream Vision generated; and the numeric embeddings of your entries and of the symbols recognised in them, in both vector indexes. It also cancels an active web subscription at Stripe and deletes the customer record there.
Two things are kept, deliberately rather than by omission. The App Store purchase ledger — transaction and product identifiers, no card details — stays, because §147 AO makes it a business record I am obliged to retain and Art. 17(3)(b) GDPR permits exactly that; it is also what stops an Apple renewal notice being replayed against an account that no longer exists. And the records the processors above hold for their own legal purposes — Stripe’s record of payments already taken, Cloudflare’s request logs — are theirs to retain, not mine to delete.
How it behaves when it fails, because “deletion works” is only honest with that included. The image files and the embeddings live outside the database, and the only way to find them is a list of identifiers the database holds — so they are deleted first, before the rows that name them. If that step fails, nothing at all is deleted and you are told the deletion failed, rather than your account vanishing and leaving material behind that nothing could name any more. Pressing delete again is the retry. If you want it confirmed by a person, write to me.
Your rights
Under the GDPR you can ask me to:
- confirm what I hold about you and give you a copy of it (Art. 15);
- correct it if it is wrong (Art. 16);
- delete it (Art. 17) — which you can also do yourself, in the app;
- restrict what I do with it while a question about it is unresolved (Art. 18);
- hand it to you in a portable form, or send it to someone else (Art. 20);
- stop processing that rests on legitimate interest, on objection (Art. 21);
- withdraw a consent you gave, at any time, without that affecting what was lawful before (Art. 7(3)).
Write to hello@oreiathejournal.com. One practical note on access and portability: because your entries are encrypted with a key derived from secrets only you hold, the complete and readable copy is the one your own signed-in app can produce. What I can send you from the server, without your password, is the account record and the ciphertext.
You can also complain to a data protection supervisory authority (Art. 77). The one competent for me is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenKavalleriestraße 2–4
40213 Düsseldorf, Germany
www.ldi.nrw.de
You may also complain to the authority where you live or work.
Children
Oreia is not intended for children. Do not create an account if you are under 16, which is the age at which consent stands on its own under Art. 8 GDPR in Germany. I do not knowingly hold data about children, and if you believe a child has an account, write to me and I will delete it.
Changes
This page changes when the system changes, and the date at the top says when it was last reviewed against the code. If something material changes for people with accounts, I will say so in the app rather than quietly editing this page.
