Skip to content

Privacy Policy


1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Modenics
Owner: Harrold Swalve
Chaukenstraße 11
26789 Leer (Ost-Friesland)
Germany

Email: support@nightmirror.app

2. Scope

This Privacy Policy applies to the website nightmirror.app, the NightMirror Progressive Web App at pwa.nightmirror.app, and related contact, support, payment and service functions.

3. Principles of processing

We process personal data only to the extent necessary to provide NightMirror, manage user accounts, process dream content, handle payments, communicate with users, ensure technical security, or comply with legal obligations.

The legal bases are in particular Art. 6(1)(b) GDPR for contractual or pre-contractual services, Art. 6(1)(c) GDPR for legal obligations, Art. 6(1)(f) GDPR for legitimate interests in operation, security and abuse prevention, and Art. 6(1)(a) GDPR for voluntary consent, for example optional telemetry.

4. Minimum age

NightMirror is intended for users aged 16 and over. Persons under 16 may not use NightMirror.

5. Website hosting and technical access data

The marketing website is operated using services provided by IONOS SE. Technical access data such as IP address or anonymized IP address, date and time of access, requested resources, HTTP status codes, browser information and technical error data may be processed. The processing serves availability, stability, security and error analysis.

The NightMirror PWA is provided through Netlify. Netlify processes technical access data, function calls and server-side API requests to the extent necessary for hosting, serverless functions, security, error analysis and operation of the PWA.

6. User account, login and email communication

NightMirror uses Supabase Auth for user accounts and email-based login. In particular, email address, user ID, login status and authentication events are processed.

Resend may be used for transactional emails, in particular login or service emails. This may involve processing the email address, the content of the respective service email and technical sending, delivery and error data. Resend is not used for newsletters or marketing broadcasts.

7. Processing of dream data and AI functions

NightMirror processes dream texts entered by users, optional audio transcripts and the results generated from them in order to provide dream interpretations, reflection questions, images, symbols, character types, Insights and Compare functions.

We use OpenAI for AI-supported functions. Depending on the function, dream texts, transcripts, derived prompts, translation content, moderation requests and summarized Insight data may be transmitted to and processed by OpenAI. OpenAI is accessed server-side through our infrastructure; API keys are not delivered to the client.

NightMirror is not a medical, psychotherapeutic or diagnostic service. The results are intended for personal reflection and may be incomplete, subjective or incorrect.

Special categories of personal data

NightMirror does not specifically request special categories of personal data. However, because users can enter free-form dream texts, they may voluntarily provide information that allows conclusions about health, religious or philosophical beliefs, political opinions, sex life or other sensitive personal topics. Such information should only be provided if users consciously wish to do so. Where explicit consent is required for the processing of special categories of personal data, this consent is obtained within the app process.

8. Audio input

If users use an audio function, the audio file is processed for transcription. According to the current product status, audio recordings are not permanently stored as audio files. The transcript may be used as a basis for dream generation and other NightMirror functions.

9. My Dreams, Community and visibility

Fully generated dream results are automatically saved in My Dreams. The original dream input remains private unless the user expressly makes it public.
Generated result components such as interpretation, image, symbols, character types or other result details may be part of the Community experience. Social sharing is separate from this. When sharing outside the PWA, additional notices, watermarks or links to NightMirror may be used depending on the user’s status.

10. Content filters and blocked input

NightMirror uses safety and content filters. If an input is identified as too explicit or not permitted, processing may be stopped. Blocked input is not used to create a dream result and is not saved as a dream result in My Dreams. Technical safety checks may nevertheless take place briefly to prevent abuse.

11. Payments and credits

NightMirror uses Stripe Checkout for the purchase of credits. NightMirror processes payment and order metadata such as user reference, selected credit package, amount, currency, payment status, checkout session references and credit bookings. Full card or payment instrument details are not stored locally by NightMirror, but are processed by Stripe and the selected payment method.

Depending on the selected payment method, banks, card providers, wallet providers or local payment service providers may be involved in addition to Stripe. Refunds are handled on a case-by-case basis through support and Stripe. Payment disputes or chargebacks may also be initiated through a bank, card issuer or payment service provider depending on the payment method.

12. Contact and support

If users contact us by email or contact form, we process the information provided, in particular name, email address, subject, message, technical metadata and, where applicable, user or case reference, in order to respond to the request. The central contact address is support@nightmirror.app.

For a future WordPress contact form, it is intended to use Contact Form 7 without Flamingo, without database storage, without attachments and without external spam services. The submitted information is to be forwarded only by email to the support mailbox.

13. Optional telemetry

Optional technical usage diagnostics are disabled by default. Users may voluntarily enable them in the settings and disable them again at any time. Without consent, no optional telemetry data is collected for product improvement. If telemetry is enabled, limited technical events, status information, error codes, feature usage and performance metadata may be processed; contents of dream texts are not intended to be used for this purpose.

14. Cookies, local storage and PWA functions

NightMirror uses technically necessary storage technologies to provide the website and PWA. Depending on use, these include cookies, Local Storage, Session Storage, IndexedDB, Service Worker Cache and similar technologies for login status, language settings, app functions, offline/cache functions and security. Non-essential telemetry is used only after voluntary activation.

According to the current status, we do not use Google Analytics, Google Tag Manager, Meta Pixel, TikTok Pixel or comparable marketing tracking services.

15. Recipients and service providers

We use technical service providers to provide NightMirror. These include in particular IONOS for WordPress hosting, email mailbox and domains, Netlify for PWA hosting and serverless functions, Supabase for database, authentication and storage, Resend for transactional emails, OpenAI for AI functions and Stripe for payment processing.

Some service providers or their subprocessors may process personal data outside the EU/EEA. Where required, this is done on the basis of appropriate safeguards, in particular standard contractual clauses, adequacy decisions or other transfer mechanisms provided for under the GDPR.

16. Storage period

Data categoryRegular storage period
Account dataFor the duration of the user account; after a deletion request generally within 30 days, unless legal obligations prevent deletion.
Dream content and resultsAs long as the account or the respective function is used; deletion upon user request or account deletion, where technically possible and legally permitted.
Audio recordingsNot permanent; only temporarily for transcription.
Contact and support requestsGenerally up to 12 months after the request is closed, longer in case of disputes or legal obligations.
Moderation/abuse dataGenerally up to 24 months, longer in cases of serious abuse or legal defense.
Payment and accounting dataIn accordance with commercial and tax law obligations, generally up to 8 years.
Raw data from Stripe webhooksShort-term for technical review; the goal is minimization or deletion after no later than 90 days, unless longer retention is required.
Technical logsGenerally up to 30 days, longer only in case of security incidents or enforcement of rights.
Optional telemetryOnly after consent; raw data as short as possible, aggregated/pseudonymous evaluations up to 12 months.

17. Rights of data subjects

Data subjects have, in accordance with the GDPR, in particular the right of access, rectification, erasure, restriction of processing, data portability, withdrawal of consent and objection to certain processing operations. To exercise these rights, a message to support@nightmirror.app is sufficient.

18. Right to lodge a complaint with a supervisory authority

Users have the right to lodge a complaint with a data protection supervisory authority. The authority expected to be responsible for Modenics is: Der Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany, https://lfd.niedersachsen.de/.

19. Automated decision-making

NightMirror does not make automated decisions with legal effect or similarly significant impact within the meaning of Art. 22 GDPR. AI results are intended for reflection and do not replace human review in legally relevant matters.

20. Changes to this Privacy Policy

We may amend this Privacy Policy if NightMirror, technical processes, service providers or legal requirements change. The current version is made available on the website.

Last updated

7 July 2026