Your dreams
stay yours
Dream content is sensitive. This page explains plainly what is collected, what is sent to the AI, how it is protected, and what you can do with your data.
Who is responsible for your data
Pierce the Shadow is run by one person: Gregor Vollmaier, based in Slovenia. The site falls under the GDPR, and Gregor is the data controller. You can reach him at [email protected].
What is collected and why
Only what is needed for the diary to work.
- Your email address — when you sign in Used only to send you a sign-in link. Never used for marketing and never shared beyond the email service that delivers the link.
- Your diary Your dreams (text, title, date), the elements linked to them (symbols, people, places and so on), your notes, your discussions with the AI, the thumbs up or down you give its replies, the summaries of those discussions, and any earlier Dig Deeper explorations you saved. All of it is encrypted, and none of it is read by a person.
- A dream written before you sign in While you type, the draft stays in your own browser. When you ask for a sign-in link, the dream is stored encrypted for up to 15 minutes; clicking the link saves it to your diary, otherwise it is deleted.
- Anonymous usage events A few counts of which features are used, for example that the donation link was clicked, and a daily count of how many dreamers opened their diary. These records hold no IP address, no email, no account ID and no dream content.
- Abuse limits To stop misuse, sign-in requests are counted per email address and per network address, and AI requests are counted per account per day. The counters delete themselves.
What is sent to the AI
The AI features — suggesting a dream's elements, finding other dreams that contain an element, and discussing a dream or an element with you — use Claude, through Anthropic's API. They only run when you ask for them.
Pierce the Shadow reads each dream against your whole diary, not on its own. So a request includes the dream or element you are working on, together with related parts of the rest of your diary: your recurring elements and how often they appear, your notes on them, the titles and dates of your dreams, excerpts of the dreams most connected to this one, summaries of earlier discussions, and, when the AI decides it needs one, the full text of another dream. Your email address is never sent.
By default, Anthropic does not use API inputs or outputs to train its models. How long it keeps requests and how it protects them is described at anthropic.com/privacy.
Services that handle your data
- Cloudflare Hosts the site and the database. The database is stored in the EU.
- Resend Delivers sign-in emails, so it receives your email address.
- Anthropic Provides the AI, so it receives the diary context described above when you use an AI feature.
Resend and Anthropic are based in the United States. Their data processing agreements, which are part of their terms, include the EU Standard Contractual Clauses that the GDPR requires for transfers outside the EU.
What is never done with your data
Dream data and personal data are never sold, shared, or licensed to any third party. Ever. This is written into the founding constitution of this project and cannot be changed by operational decisions.
There is no advertising on this site. No ad network sees your data. No tracking pixels, no third-party cookies.
How your data is protected
Everything in your diary is encrypted at rest using AES-256-GCM, with the key held separately as a server secret. Connections are encrypted with HTTPS. Dream text is never written to logs, and full dream text reaches your browser only when you open that dream.
In the event of a data breach, you and the Slovenian Information Commissioner will be notified within the time the GDPR requires.
How long data is kept
- Your diary and email addressUntil you delete them. Deleting a dream or your account takes effect immediately.
- Sign-inA sign-in lasts 30 days. An unused sign-in link, and a dream waiting for it, expire after 15 minutes.
- Usage events and daily countsDeleted after 90 days.
- Abuse-limit countersDeleted after an hour (sign-in) or a day (AI requests).
Your rights
Your account and diary are processed because you ask for the service. Dreams can touch on health, sexuality or beliefs, which the GDPR treats as especially sensitive, so they are only stored and sent to the AI because you choose to write them down and use these features. You can withdraw that at any time by deleting them.
You have the right to access, correct, export and delete your data:
- Export everything In your diary, open the account menu (top right) and choose "Export all my data". You get a file with every dream, element, note and discussion.
- Correct or delete a dream Open the dream to edit its text, title, date and notes. To delete it, use its "⋯" menu. It is gone immediately, together with its element links, notes and discussions.
- Delete your account In the account menu, choose "Delete my account". Your email address and everything in your diary are deleted permanently. There is no archive and no way to recover it.
- Anything else Email [email protected]. You'll hear back within a few days. You can also complain to the Slovenian Information Commissioner (ip-rs.si).
Cookies and local storage
Sign-in cookie. Set only when you sign in, to keep you signed in for up to 30 days. It holds a random token and nothing else, and is strictly necessary for signing in.
Local storage. Your browser keeps an unsaved dream draft and a pending sign-in on your own device, so nothing is lost if you close the tab.
There are no tracking, advertising or third-party cookies.
Changes to this page
If this policy changes in a meaningful way, a note will appear on the site. Last updated: September 2026.
Questions or concerns: [email protected].