Privacy Policy
Your privacy and your child's safety are our top priority
Last updated: March 2026
1. Introduction
At DreamBear ("we", "us", "our"), we take your privacy and your child’s safety very seriously. This privacy policy explains how we collect, use, store, and protect your personal information when you use the DreamBear app and our related services. DreamBear is an AI-powered bedtime story app designed for children aged 3–10, and we have developed our practices with a special focus on children’s data protection.
2. Information We Collect
We collect the following types of information to provide and improve our service:
- •Parent’s email: For account creation via Apple Sign-In or Google login, and for service communications.
- •Child’s first name: For personalization of bedtime stories, so your child can be the hero of their own story.
- •Child’s age: For age-appropriate content (ages 3–10).
- •Child’s interests and mood: Selected interests and mood settings for personalized stories.
- •Story data: Generated stories, favorites, and playback history.
- •Usage data: Anonymized information about app usage to improve the service.
- •Device identifiers: Anonymous identifiers to deliver the service correctly and prevent abuse.
3. Children’s Privacy & Parental Consent
DreamBear is specifically designed for children aged 3–10 and complies with all relevant children’s data protection regulations:
- •Parental consent required: By creating an account and adding a child profile, the parent or legal guardian provides verifiable consent for the collection and processing of their child’s data, including transmission to AI services for story generation.
- •COPPA compliance: Full compliance with the Children’s Online Privacy Protection Act. We do not collect data from children without parental consent, and parents can review, delete, or refuse further collection at any time.
- •GDPR Article 8: Special protection of children’s personal data in the EU. We require parental consent before collecting children’s data.
- •AI data processing: When a story is generated, your child’s first name, age, interests, and selected traits are sent securely (TLS 1.3) to Anthropic’s Claude AI and ElevenLabs for story creation and narration. This data is used solely for generating the requested story and is not stored by these providers for training or other purposes.
- •Age verification: The app requires a parent account. Children cannot create accounts themselves.
- •No advertisements: DreamBear never shows ads to children.
- •No third-party tracking: We do not use analytics SDKs, advertising trackers, or behavioral profiling in the app.
We never sell children’s data to third parties. Parents may revoke consent and request deletion of all child data at any time via the in-app account deletion feature or by contacting privacy@dreambear.app.
4. How We Use Your Information
- • Generate personalized bedtime stories with your child’s name, interests, and chosen theme.
- • Synthesize speech via ElevenLabs for high-quality narration.
- • Synchronize data across devices via Apple CloudKit (private database).
- • Save favorite stories and playback history.
- • Manage your subscription via the Apple App Store (StoreKit 2).
- • Improve our service based on anonymized usage data.
- • Send important service updates (to parents only).
5. Data Security
All data is encrypted in transit (TLS 1.3) and at rest. We use Supabase for authentication and database. CloudKit data is synchronized via Apple’s encrypted infrastructure in your private iCloud database. Access to data is strictly limited to authorized personnel. We implement industry-standard security measures, including secure token handling and rate limiting.
6. Third-Party Services
We use the following third-party services to deliver DreamBear:
- •Supabase: Authentication and database. Your login credentials are handled securely via Supabase Auth with Apple Sign-In and Google login.
- •Anthropic (Claude AI): Story generation. Your child’s name and preferences are sent to Claude to create personalized stories. Anthropic does not store personal data.
- •ElevenLabs: Voice synthesis. Story text is sent to ElevenLabs for narration.
- •Cloudflare (R2/Workers): Our API and audio files are hosted on Cloudflare for fast and secure delivery.
- •Apple CloudKit: Synchronization of stories and child profiles across your devices via your private iCloud database.
- •Vercel Analytics: Anonymous website usage (no personal data).
All third parties are GDPR-compliant and only process data according to our instructions via data processing agreements.
7. Your Rights (GDPR)
Under GDPR, you have the following rights:
- •Right of access: You can request a copy of all your personal data.
- •Right to rectification: You can have incorrect information corrected.
- •Right to erasure: You can have all your data deleted ("right to be forgotten"). You can delete your account directly in the app or contact us.
- •Right to data portability: You can receive your data in a structured, machine-readable format.
- •Right to withdraw consent: You can withdraw your consent to data processing at any time.
8. Account Deletion and Data Retention
You can delete your account at any time directly in the app under Settings. Account deletion permanently removes all personal data, including child profiles, stories, and usage data within 30 days. Anonymized, aggregated data may be retained for statistical purposes. As long as your account is active, we retain your data to provide the service.
9. Contact Us
Have questions about our privacy policy or want to exercise your rights?
Email: privacy@dreambear.app
DreamBear
10. Changes to the Privacy Policy
We may update this privacy policy from time to time to reflect changes in our practices or legislation. Significant changes will be communicated via email to registered users and via a notification in the app. We recommend that you periodically review this policy.