1. Scope and who is responsible
This Privacy Policy applies to the DreamFrame mobile application, its Firebase-hosted pages, and related services (together, the “Service”). DreamFrame is responsible for deciding why and how personal data is processed and acts as the data fiduciary or controller where those terms apply.
This notice is intended to meet applicable privacy and consumer-transparency requirements, including India’s Digital Personal Data Protection Act, 2023 and rules brought into force under it, the Information Technology Act, 2000 and applicable rules, and platform requirements. Additional regional rights may apply based on where you live.
2. Information we collect
| Category | Examples | How collected |
|---|---|---|
| Account and profile | Google account identifier, name, email, profile photo, Firebase user ID, language and content preferences, creator profile, accepted legal-document versions and timestamps, and personalized-ad choice. | From you, Google Sign-In, Firebase Authentication, and the choices presented before sign-in. |
| Creative content | Prompts, scripts, series, characters, episodes, Sparks, titles, descriptions, reference images, uploaded media, generated images, audio and video. | When you create, upload, generate, edit, publish, or report content. |
| Voice and microphone | Voice recordings, spoken prompts, audio files, language selection, and transcripts. | Only when you start recording or speech input and grant microphone permission. |
| Activity and engagement | Watch history, saved content, likes, follows, episode access, eligible rewarded-ad completions, creator allocations, search and feature interactions. | Automatically as you use the Service. |
| Device and diagnostics | Device and app version, operating system, IP-derived region, timestamps, crash logs, performance and security signals, notification token, App Check signals. | Automatically through the app and service providers. |
| Purchases and payouts | Product ID, store transaction or purchase token, credit ledger, currency, purchase status, creator earnings and withdrawal records. We do not receive your full payment-card number from the app store. | From Apple or Google billing, your actions, and our ledger. |
| Advertising | Ad placement, impressions and rewarded completion, a random app-specific rewarded-ad identifier, ad session or transaction ID, device advertising signals, consent choices, fraud indicators, and network-reported revenue. The rewarded-ad identifier does not contain your Firebase user ID, email address, advertising ID, or profile details. | Generated by DreamFrame and processed through Unity LevelPlay and its mediated advertising partners. |
| Support and safety | Messages to us, reports, blocked accounts, moderation decisions, suspected fraud or policy violations. | From you, other users, and our safety systems. |
Please do not include unnecessary personal or sensitive information in prompts, uploads, stories, or public content. If you provide information about another person, you must have a lawful basis and all permissions needed to do so.
3. Why and how we use information
- Provide authentication, profiles, language preferences, content feeds, creation tools, publishing, playback, notifications, and support.
- Process prompts and media to produce requested AI-generated scripts, images, speech, video, lip-sync, captions, or related outputs.
- Maintain AI-credit, purchase, wallet, estimated earnings, finalized earnings, and withdrawal ledgers; validate store transactions; prevent duplicate crediting and fraud.
- Deliver ads, confirm eligible rewarded-ad completions, estimate and finalize creator reward pools, and detect invalid traffic.
- Operate, secure, troubleshoot, measure, and improve the Service, including aggregate product analytics, crash diagnostics, abuse prevention, and service communications.
- Moderate content, respond to reports, enforce our Terms, protect users and rights, and comply with legal obligations.
We process data to perform our contract with you, based on your consent where required, to comply with law, and for permitted uses such as security and fraud prevention. We do not sell your personal information for money. We do not use banner- or interstitial-ad interaction events for DreamFrame’s own Firebase Analytics; advertising SDKs may still process limited data needed to deliver, measure, secure, and report those ads.
Legal bases under the GDPR and UK GDPR
| Purpose | Primary legal basis |
|---|---|
| Create and manage your account; provide creation, publishing, playback, credits, purchases, and requested AI features. | Performance of our contract with you. |
| Optional microphone, photo, personalized-advertising, tracking, or other permission-based processing. | Consent where required. You may withdraw consent without affecting earlier lawful processing. |
| Security, fraud and invalid-traffic prevention, service diagnostics, aggregate improvement, abuse investigation, and protection of legal rights. | Our legitimate interests or those of users and partners, balanced against your rights; and legal claims where applicable. |
| Purchase, payout, accounting, tax, sanctions, regulatory, and lawful authority requirements. | Compliance with legal obligations and performance of our contract. |
| Public-interest or vital-safety disclosures in exceptional circumstances. | Applicable legal obligation, vital interests, or another basis permitted by law. |
Where we rely on legitimate interests, you may ask for information about the balancing assessment and object to that processing. We do not use consent where the processing is necessary to perform the core service you requested or to comply with law.
4. AI, recordings, images, and generated content
When you ask DreamFrame to create or transcribe something, the input required for that request may be transmitted to our cloud functions and relevant AI or media-processing provider. This can include prompt text, selected images, character references, audio recordings, transcripts, language, and technical request identifiers. Providers return generated or processed content to us for delivery and storage in your project.
- Voice: recording starts only after your action and operating-system permission. Recorded speech may be uploaded for transcription, including to Sarvam AI for supported languages. You can cancel before submitting where the interface permits.
- Images and likeness: if an image or recording identifies a person, obtain that person’s informed permission before upload or AI manipulation. Never create deceptive, exploitative, sexual, or non-consensual impersonations.
- AI outputs: outputs may be inaccurate, unexpected, similar to other outputs, or raise third-party rights concerns. Review them before publishing or relying on them.
- Training: DreamFrame does not use private prompts or private creative uploads to train its own general-purpose AI models. Service providers may handle inputs under their agreements with us and applicable privacy terms to perform the requested service, maintain security, and comply with law.
6. Advertising and the creator rewards program
DreamFrame may show banner, interstitial, and rewarded ads through Unity LevelPlay mediation. LevelPlay and mediated networks may collect or receive advertising identifiers, IP address, device details, consent status, ad interactions, and fraud signals to select, deliver, cap, measure, secure, and report ads. Before serving personalized advertising or tracking where consent or an opt-out is required, DreamFrame and its partners must provide the applicable choice. You can also use device privacy controls and request non-personalized advertising where available.
For rewarded ads, DreamFrame creates a limited ad session and receives a server-to-server completion callback. Before initializing LevelPlay, our server issues a random identifier used only to associate signed reward callbacks with the applicable DreamFrame reward session. We do not send your Firebase user ID, email address, or device advertising ID as this rewarded-ad user identifier. Our server stores the identifier separately from public profile data and places only a one-way hash of it in new reward sessions. This identifier is used for reward delivery, duplicate prevention, fraud and security controls, eligible-completion counting, and creator-revenue allocation; it is not permission to personalize ads.
Choosing non-personalized advertising does not disable this limited reward-verification identifier because rewarded ads still need fraud-resistant completion verification. Personalized-advertising and tracking choices remain separate and are passed to the advertising SDK where supported. Estimates shown to creators are provisional. Finalized creator earnings are calculated after monthly network revenue is reconciled and may be adjusted for invalid traffic, reversals, fees, taxes, or reporting corrections.
7. Your choices and rights
Subject to applicable law, you may ask for a summary of personal data being processed and sharing information; access or correction; erasure; withdrawal of consent; grievance handling; and nomination of another person to exercise rights in the event of death or incapacity. Other jurisdictions may provide rights to portability, restriction, or objection.
- Update profile and content preferences in the app.
- Remove drafts or published content using available controls.
- Manage microphone, photos, camera, notifications, and advertising permissions in device settings. Disabling a permission may disable the feature that needs it.
- Use Account Center → Account Actions → Delete Account to request account deletion, or email us from your registered address.
- Withdraw optional consent by changing the relevant setting or contacting us. Withdrawal does not affect processing already lawfully completed.
We may need to verify your identity. We will respond within the period required by applicable law. If a request is denied or limited, we will explain why where required.
8. Regional privacy notices
European Economic Area, United Kingdom, and Switzerland
Where the EU GDPR, UK GDPR, or Swiss data-protection law applies, you may have rights to access, correct, erase, restrict or object to processing, receive portable data, withdraw consent, and complain to the supervisory authority where you live, work, or believe an infringement occurred. You may also object at any time to direct marketing. DreamFrame does not currently conduct direct-email marketing through the Service.
DreamFrame is the controller for account, product, creator-program, and platform-safety processing. Providers generally act as processors for infrastructure or requested AI services, or as independent controllers where they determine their own processing, such as app stores and some advertising partners. Contact us to request the relevant role or provider information. If appointment of an EU or UK representative or data-protection officer becomes legally required, their current contact details will be published in this notice before the affected offering begins.
California and other United States privacy laws
In the preceding 12 months, we may have collected the identifiers, account/profile details, internet or electronic activity, commercial and purchase records, approximate location, audio/visual content, user-generated content, inferences such as language or content preferences, and sensitive information you deliberately supplied as described in Section 2. We collect these categories from you, your device, app stores, sign-in providers, advertising partners, other users, and service providers for the purposes in Section 3, and disclose them to the recipients in Section 5.
Where the California Consumer Privacy Act (“CCPA”) and California Privacy Rights Act (“CPRA”) apply, you may request access to categories or specific pieces of personal information, correction, deletion, and information about collection and disclosure; opt out of sale or sharing; limit certain uses of sensitive personal information; and exercise these rights without unlawful discrimination. Authorized agents may submit requests where permitted and properly verified.
DreamFrame does not sell personal information for money. Disclosures by an advertising SDK for cross-context behavioural advertising may be considered “sharing,” targeted advertising, or a sale under some United States state laws even when no money is exchanged. Where applicable, you may opt out using device privacy controls and by emailing us with the subject US Privacy Opt-Out. Before DreamFrame serves targeted advertising in a jurisdiction requiring an in-app consent or opt-out control, that control must be made available. We will also honor legally required, technically applicable opt-out preference signals. We do not knowingly sell or share personal information of anyone under 18.
Residents of states including Colorado, Connecticut, Delaware, Iowa, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, and Virginia may have similar rights where the relevant law applies, including access, correction, deletion, portability, opt-out of targeted advertising, sale, or qualifying profiling, and appeal of a denied request. Email us to exercise or appeal a request.
Brazil, Canada, Australia, and other regions
Where Brazil’s LGPD applies, you may request confirmation, access, correction, anonymization, blocking or deletion where appropriate, portability, information about sharing, review of certain automated decisions, and withdrawal of consent. Where Canadian privacy law applies, you may request access and correction and challenge compliance; consent will be meaningful and proportionate to the sensitivity and reasonable expectations involved. Where the Australian Privacy Act applies, you may request access or correction and complain about our handling of personal information. Comparable mandatory rights under other applicable laws are honored even if not listed by name.
9. Retention, deletion, and security
We keep account data while your account is active; project and published content until you delete it or your account; transaction, reward, fraud, tax, and withdrawal records for the period required to reconcile accounts, resolve disputes, and meet legal obligations; and diagnostics and logs for a limited period appropriate to security and troubleshooting. Backup copies may persist for a limited recovery cycle before deletion or de-identification.
Account deletion removes the Firebase Authentication account, deletes the separately stored LevelPlay reward-verification identifier, and soft-deletes the user profile. Historical reward transaction records may retain session identifiers or one-way hashes where required for security, duplicate prevention, fraud investigation, financial reconciliation, legal claims, or compliance, but cannot be used by the app to recover the deleted random identifier. Other associated data is deleted, anonymized, or retained only for those limited purposes. Published content may take time to disappear from caches and copies outside our control.
We use access controls, authenticated requests, Firebase App Check, encryption in transit, provider security controls, scoped storage rules, purchase verification, and audit/fraud records. No system is completely secure, so we cannot guarantee absolute security. Notify us promptly if you believe your account or data has been compromised.
10. International transfers
DreamFrame and its providers may process data in India and other countries where cloud, AI, advertising, billing, or support infrastructure operates. Those countries may have different data-protection laws.
When the EU GDPR applies to a restricted transfer, we use an available adequacy decision or appropriate safeguards such as the European Commission’s Standard Contractual Clauses, together with a transfer-impact assessment and supplementary safeguards where required. For restricted transfers governed by the UK GDPR, we use UK adequacy regulations, the International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or another permitted safeguard, together with the required data-protection assessment. Narrow statutory derogations are used only where legally available.
We also comply with applicable transfer restrictions under India’s DPDP framework, Brazil’s LGPD, and other governing laws. You may contact us for more information about the safeguard relevant to your data.
11. Children and COPPA
DreamFrame accounts and creator monetization are intended only for people aged 18 or older. The Service is not directed to children under 13 within the meaning of the United States Children’s Online Privacy Protection Act (“COPPA”), nor is it designed as a child-directed service. DreamFrame does not knowingly collect personal information from a child under 13, and it does not currently operate a verifiable parental-consent flow.
We also do not knowingly permit accounts for people under 18, including children under India’s DPDP framework. If we learn that an underage person supplied personal data, we will restrict the account and delete the information as appropriate, subject to safety, legal, and evidentiary retention requirements. A parent or guardian who believes a child has supplied data should contact us with the subject Child Privacy Request.
Users must not upload a child’s voice, image, likeness, location, or other personal information unless they are legally authorized, the use is safe and lawful, and any required consent has been obtained. Sexualized, exploitative, or deceptive content involving minors is strictly prohibited.
12. Automated decisions, profiling, and biometric information
DreamFrame uses automated systems to generate content, recommend content, detect abuse and invalid traffic, verify transactions, and calculate provisional creator allocations. These systems do not make decisions intended to produce legal or similarly significant effects about you without meaningful review where applicable law requires it. You may request human review of an account, fraud, moderation, or finalized-reward decision through our grievance channel.
Voice recordings, photographs, and videos may contain biometric characteristics, but DreamFrame does not use them to identify or authenticate people and does not intentionally create face geometry or voiceprint templates for biometric identification. If a future feature does so, we will provide a specific notice, obtain any consent required by biometric-privacy laws, publish a retention schedule, and update this Policy before collection.
13. Changes to this notice
We may update this Policy when our features, providers, or legal obligations change. We will post the revised date and provide prominent notice or request fresh consent when required. Material changes do not retroactively authorize a new use of personal data where further consent is required.
14. Contact and grievances
Contact DreamFrame’s privacy and grievance support for questions, rights requests, content complaints, or appeals. Include your registered email and enough detail to locate the issue; do not email passwords or full financial credentials.
DreamFrame Privacy & Grievance Support
Email: daydreamers0423@gmail.com
Response channel: email acknowledgement and resolution within the time required by applicable law.
If you are not satisfied after using our grievance process, you may pursue remedies available through the Data Protection Board of India, consumer authorities, or another competent regulator or court, as applicable.