1. Scope and controller
Dreamkrate is the controller of personal data used to operate the Services, manage accounts and billing, prevent abuse, and improve the product. If your employer, client, or another organization provides your Dreamkrate workspace, that organization may separately control the content and account data it manages. Its administrator may access, manage, export, or delete workspace content and may remove your access.
This Policy does not govern third-party websites or services you choose to access, including content sources you import from or destinations where you publish an output. Those third parties apply their own privacy notices.
2. Personal data we collect
| Category | Examples and source |
|---|---|
| Account and profile data | Email address, name, avatar, authentication provider, internal user identifiers, email-verification status, account status, preferences, account creation and last-sign-in times. We receive this from you and from the sign-in provider you choose, such as Google or Apple. |
| Team and collaboration data | Workspace name, membership, role, team invitations and invitee email addresses, API-key metadata, access settings, and the identity of members who create or change shared content. |
| Content and creative data | Prompts, reference images, uploaded images, video and audio, voice samples, generated outputs, characters, scenes, objects, music, projects, editing sessions, agent chats and memories, feedback, share links, and related metadata such as model, settings, timestamps, status, and credit usage. Content can contain personal data about you or other people. |
| Voice data | Voice recordings submitted for cloning, derived voice models and identifiers, voice descriptions and labels, generated speech, and voice-swap inputs and outputs. Depending on the feature and applicable law, some voice data may be treated as biometric or otherwise sensitive personal data. |
| Billing and transaction data | Plan, billing interval, seats, credit purchases and usage, transaction and invoice history, currency, amounts, payment status, refunds, disputes, billing address, tax information, and payment-provider identifiers. Our payment providers collect full payment-card or app-store payment details; Dreamkrate generally receives limited payment and transaction details rather than full card or account credentials. |
| Usage, device, and log data | IP address, user agent, browser and device information, approximate location inferred from IP, request IDs, API routes, status and error codes, timestamps, feature interactions, referring pages, and analytics events. |
| Security and abuse-prevention data | Hashed email, IP and user-agent values; device or session identifiers; account-linkage indicators; proxy, VPN, Tor and bot signals; fraud and abuse scores; payment-method and transaction-risk signals received from payment providers; moderation results; enforcement history; and records used to investigate suspicious registrations, payments, generations, or API use. |
| Communications | Messages, attachments, support requests, legal or privacy requests, survey responses, and other information you send to us or post in an official Dreamkrate community. |
Please do not submit sensitive personal data that is not needed for a feature. If you provide personal data about another person—including their face, image, voice, or likeness—you must have a valid legal basis, give any required notices, and obtain all required permissions.
3. How and why we use personal data
| Purpose | Typical legal basis in the EEA/UK |
|---|---|
| Provide the Services | Perform our contract: authenticate users, maintain workspaces, process prompts and files, generate and store outputs, enable sharing, provide APIs, and allocate or restore credits. |
| Process payments | Perform our contract and comply with legal obligations: create checkouts, manage renewals and cancellations, issue invoices, collect taxes, process refunds, and keep accounting records. |
| Operate teams | Perform our contract and pursue legitimate interests: deliver invitations, apply roles and permissions, and let workspace administrators manage members and shared assets. |
| Safety, moderation, and fraud prevention | Our legitimate interests and legal obligations: scan prompts or content, detect trial abuse, card testing, account compromise and prohibited conduct, investigate incidents, enforce our agreements, and protect users and providers. |
| Maintain and improve Dreamkrate | Our legitimate interests: troubleshoot failures, measure reliability and feature use, improve workflows and user experience, and develop new features. Where consent is required for analytics technologies, consent is the legal basis. |
| Communicate | Perform our contract, comply with law, or pursue legitimate interests: send verification, password-reset, billing, security, service, support, and policy-update messages. We use consent where required for marketing. |
| Comply with law and defend rights | Comply with legal obligations and pursue legitimate interests: respond to lawful requests, maintain tax and financial records, establish or defend claims, resolve disputes, and document compliance. |
We may aggregate or de-identify information so that it no longer reasonably identifies you. We may use that information for analytics, security, capacity planning, and product improvement. We do not attempt to re-identify properly de-identified information except to test our de-identification safeguards.
4. AI content, model providers, and voice data
Dreamkrate routes your prompt and the files needed for a generation to the provider that performs the selected task. For example, an image reference may be sent with your prompt to an image or video model, and a voice sample is sent to ElevenLabs to create a voice clone.
- Generation processing. Providers may receive prompts, source files, model settings, signed file links, outputs, technical identifiers, and moderation context needed to complete or secure a request.
- Dreamkrate model training. Dreamkrate does not currently operate a foundation model and does not use your content to train a Dreamkrate-owned foundation model.
- Provider practices. AI providers process submitted content under our arrangements with them and their applicable policies. Retention and model-improvement rules can vary by provider, account type, and feature.
- Voice cloning. We store the submitted reference recording in Dreamkrate storage and ElevenLabs stores or derives the voice model used for later synthesis. Deleting a Dreamkrate voice requests deletion of its ElevenLabs voice and removes the Dreamkrate reference recording from active storage, subject to technical failures, backups, legal retention, and the provider’s deletion process.
- Moderation. Prompts, inputs, or outputs may be assessed by automated systems and, when necessary, authorized personnel to investigate safety, fraud, abuse, legal, or support issues.
5. Service providers that may process data
We use vendors to operate Dreamkrate. The provider used for a generation depends on the model or feature you select, and providers may change as the Services evolve.
| Provider category | Current examples and purpose | Data that may be processed |
|---|---|---|
| Hosting and application infrastructure | Vercel; Microsoft Azure for certain hosted agent or file workloads | Account, content, logs, IP/device data, and application traffic |
| Authentication, database, realtime, and file storage | Supabase | Account data, workspace records, prompts and metadata, stored uploads and outputs, authentication and security logs |
| Payments and tax | Payment processors, billing platforms, and app-store payment providers | Contact and billing details, limited payment-method data, transaction-risk signals, purchases, subscriptions, invoices, refunds, disputes, and fraud signals |
| Transactional email | Resend and email-delivery infrastructure used by Supabase | Email address, invite or account event, and message-delivery metadata |
| Analytics | Google Analytics and Vercel Analytics | Online identifiers, IP/device and browser data, pages viewed, referrer, timestamps, and interaction events |
| Registration and fraud screening | IPQualityScore (IPQS) | Email, IP address, device or session identifiers, user agent, and fraud, bot, proxy, VPN, Tor, deliverability, or abuse signals |
| AI generation and compute | fal.ai, OpenAI, Google, Anthropic, ElevenLabs, RunPod, Kie.ai, Kinovi, and underlying model creators made available through those services | Prompts, selected model, input images/video/audio, signed asset links, outputs, request metadata, and safety signals |
| Specialized media processing | Sonauto, Rendi, LALAL.AI, and other providers shown in the relevant tool | Audio, video, music instructions, files, outputs, and technical request metadata |
| User-requested external sources | YouTube or other remote URLs, Wikimedia, Wikidata, OpenStreetMap/Nominatim, and Civitai when you use a feature that imports or searches those sources | Requested URL or query, IP/server request data, and imported content or metadata |
Vendors may use their affiliates and subprocessors. Some model names displayed in Dreamkrate identify the model creator even when Dreamkrate connects through a separate API or infrastructure provider.
7. How long we retain data
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including to provide the Services, satisfy legal and accounting obligations, prevent fraud and abuse, resolve disputes, maintain security, and enforce our agreements. The period depends on the data’s nature, sensitivity, context, and applicable legal requirements.
| Data | Typical retention approach |
|---|---|
| Account and profile data | While the account is active, then deleted or anonymized after a verified deletion request, except for records that must be retained for the purposes below. |
| Uploads, projects, chats, voices, and outputs | While stored in your account or team workspace. Items you delete are removed from active systems according to the relevant deletion workflow; residual copies may remain temporarily in backups, caches, provider systems, or logs. |
| Generation and workflow logs | For service delivery, credit accounting, troubleshooting, safety, abuse prevention, dispute resolution, and enforcing our agreements. Logs may be retained after account deletion where necessary and may be de-linked, minimized, hashed, or anonymized when practical. |
| Moderation, risk, and security records | For as long as reasonably necessary to detect repeat abuse, fraud, payment misuse, account compromise, policy violations, or threats, and to document enforcement. This may include hashed identifiers and device or payment-risk signals after deletion. |
| Transactions, invoices, subscriptions, refunds, and billing events | For the period required by tax, accounting, anti-fraud, chargeback, and other applicable laws, and for dispute resolution. Payment providers may separately retain payment data under their own legal obligations. |
| Team invitations | Until accepted, cancelled, or expired, plus a limited period for security, audit, and dispute purposes. |
| Support, privacy, and legal requests | For the time needed to respond and for a reasonable period afterward to document the request, resolution, and compliance. |
| Analytics and cookie data | According to the configured analytics and cookie lifespan, subject to your choices and applicable law. |
8. What happens when you delete your account
You can delete your account from Account Settings. Account deletion is permanent and is not the same as cancelling a subscription. Before confirming deletion, review any active subscription and cancel recurring billing if the deletion flow does not do so automatically. If you cannot access your account or need help, email privacy@dreamkrate.com from the account email address.
After we verify and process a deletion request:
- Your authentication account and directly identifying profile information will be deleted or anonymized from active Dreamkrate systems, unless retention is required or permitted by law.
- Personal workspaces and content controlled solely by you will be scheduled for deletion. Content in a team workspace may remain under that team’s control if other members or an organization continue to use the workspace.
- Active API keys and sessions associated only with the deleted account will be revoked. Public share links associated with content being deleted will be disabled where technically linked to that content.
- Where supported, we will delete stored voice reference files and request deletion of associated provider-side voice models. Provider systems and backups may take additional time to complete deletion.
- Unused trial, subscription, promotional, and top-up credits associated with a deleted workspace are forfeited, except where applicable law requires otherwise.
- Some records may remain. These can include generation logs, workflow events, moderation and abuse-prevention records, transaction records, invoices, subscription history, billing information, refund and dispute records, security logs, legal requests, and an audit record showing that the account was deleted. We retain these only where reasonably necessary for legal compliance, fraud prevention, accounting, dispute resolution, security, audits, and enforcing our agreements.
- Where practical, retained records will be minimized, anonymized, pseudonymized, or separated from your active profile. Deletion from encrypted backups occurs through the normal backup lifecycle unless earlier deletion is technically feasible and required by law.
If an organization controls your workspace, ask its administrator to delete workspace content. Deleting your Dreamkrate login may remove your access without deleting data that the organization lawfully retains.
10. International data transfers
Dreamkrate and its providers may process personal data in the European Economic Area, the United States, and other countries where they operate. These countries may have privacy laws different from those where you live. Where required, we use an approved transfer mechanism such as an adequacy decision, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful safeguard. You may contact us to ask about the safeguards relevant to your data.
11. Security
We use technical and organizational measures designed to protect personal data, including authenticated access, team-based authorization, hashed API keys and risk identifiers, signed private file links, role-based permissions, logging, rate limits, and provider security controls. No online system is completely secure. You are responsible for using a strong password, protecting credentials and API keys, limiting team access, and promptly notifying us of suspected unauthorized use.
12. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or receive a portable copy of personal data; restrict or object to certain processing; withdraw consent; appeal a refusal; and complain to a data-protection authority. You may also have rights to know the categories and sources of data we collect and the parties to whom it is disclosed, and to opt out of certain targeted advertising, sale, or sharing as those terms are defined by applicable law.
To exercise a right, email privacy@dreamkrate.com. We may need to verify your identity and authority. You may use an authorized agent where local law permits. Rights are not absolute; for example, we may retain transaction or security records when legally permitted or required. We will not discriminate against you for exercising a privacy right.
EEA and UK users may complain to their local supervisory authority. We encourage you to contact us first so we can try to resolve the issue.
13. Automated fraud and abuse screening
We use automated signals from Dreamkrate, fraud-prevention services, payment providers, model providers, and other security services to assess suspicious registration, payment, account, API, and content activity. Signals can include device linkage, email reputation, IP risk, bot or proxy indicators, payment patterns, content-safety results, and prior abuse. These systems may limit trial credits, block a registration or prompt, require additional review, suspend access, or flag an account for investigation. You may ask us to review a decision by contacting us, subject to measures needed to prevent revealing or weakening our security systems.
14. Children
The Services are not directed to anyone under 18, and users must not create an account for a child or upload a child’s voice for cloning. If you believe a minor has provided personal data to Dreamkrate in violation of this Policy, contact us so we can investigate and take appropriate action.
15. Changes to this Policy
We may update this Policy to reflect changes to the Services, providers, law, or our practices. We will post the updated version and change the “Last updated” date. If a change materially affects your rights or how we use personal data, we will provide additional notice where required, such as by email or an in-product message.
16. Contact us
For privacy questions, rights requests, or account-deletion requests, email privacy@dreamkrate.com. Please do not send passwords, payment-card numbers, government IDs, or sensitive source files by email unless we specifically ask for them through a secure channel.