DreamInkBack to Home

Privacy Policy

Effective Date: July 10, 2026

DreamInk, Inc. ("we," "us," or "our") operates the DreamInk platform at dreamed.ink. This Privacy Policy describes how we collect, use, store, and share information when you use our services to create personalized children's picture books and co-created custom books.

1. Controller and Scope

DreamInk, Inc. is the controller responsible for the personal data described in this policy. Our operating address is Lüerstraße 8, 30175 Hanover, Germany. You can contact us at hello@dreamed.ink or +49 179 9684007. This policy applies to dreamed.ink, DreamInk accounts, personalized book creation, co-creation projects, purchases, support, and related communications.

2. Information We Collect and Its Sources

Parent / Account Holder Information

  • Email address (for account creation and order notifications)
  • First and last name
  • Shipping address (if you order a hardcover book)
  • Payment information (processed securely by Stripe; we never store card numbers)

Child Information

To create a personalized picture book, we collect the following information about the child who will be featured in the story:

  • Child's first name
  • Child's age
  • Child's gender (used for pronoun selection in the story)
  • A photograph of the child (used to generate character illustrations that resemble the child)

We use child and person information to create, review, support, store, print, ship, and operate the requested book, and to maintain required safety, fraud, consent, support, and legal records. We do not sell it or use it for public galleries or marketing without separate permission.

Co-Creation Project Information

If you use the co-creation flow, we may collect story prompts, recipient details, names, relationships, descriptions of people, places, objects, pets, outfits, family context, uploaded reference photos, generated drafts, comments, revision notes, and project status. This material is used to create and support the private book project you requested.

Information About Other People

An account holder may provide information about a child, recipient, family member, friend, or other person for a private book. We receive that information from the account holder, not normally from the person featured. The account holder must have authority or permission to provide it. The information may include a name, age, relationship, appearance, photograph, story details, and other material selected for the book.

Sensitive Information

Please do not include health, biometric, religious, political, sexual-orientation, or other special-category information unless it is genuinely needed for the book and you are authorized to provide it. If we intentionally process special-category data, we require an applicable Article 9 GDPR condition, such as explicit consent, in addition to an Article 6 legal basis.

Automatically Collected Information

We may collect standard web analytics data such as IP address, browser type, device type, and pages visited. We use cookies only for essential site functionality and, if you consent, for analytics purposes. Advertising click identifiers and browser conversion tags require separate marketing consent. See our cookie consent preferences for details.

3. Purposes and Legal Bases

We process personal data only when we have an applicable legal basis:

  • Contract performance and pre-contract steps: Article 6(1)(b) GDPR allows us to create and deliver the book or project you request, manage your account, process payment, provide support, and fulfill or ship orders.
  • Consent: Article 6(1)(a) GDPR applies when we ask permission for optional analytics, marketing, public use of customer material, or another clearly identified optional purpose. Where required, we also obtain parent or guardian consent before processing child information.
  • Legal obligations: Article 6(1)(c) GDPR allows us to keep tax, accounting, transaction, consent, and compliance records and respond to lawful requests.
  • Legitimate interests: Article 6(1)(f) GDPR allows us to secure the service, prevent fraud and misuse, diagnose failures, protect legal claims, provide customer support, and improve reliability using appropriately limited usage data. It may also support processing information about another person in the private project requested by the account holder when that use is reasonable and authorized. We balance these interests against the rights of the people concerned, with additional care for children and private source material.

Providing account, project, payment, and delivery information is necessary when you request the corresponding service. Without it, we may be unable to create the book, maintain the project, take payment, or deliver an order. Optional analytics and marketing consent is not required to buy or use DreamInk.

We do not sell personal information. We do not use child photos, private family details, or co-creation source material for targeted advertising, public galleries, or marketing without separate permission.

4. Recipients and Service Providers

We use third-party service providers to operate the platform. Each processes data only as necessary to provide its specific function. Current provider categories include:

  • Supabase - Authentication, database hosting, and file storage
  • Vercel - Application hosting, edge delivery, serverless processing, and operational request or function logs
  • Stripe - Parent payment and card verification using minimized commerce and keyed consent references (PCI DSS compliant; we never see or store your full card number)
  • Google Cloud Translation - Translating story text into your selected language
  • OpenAI, Anthropic, and Google Gemini - AI text, image, and structured generation in separately controlled scopes; Gemini is retained for the parent-operated DreamBooks title-image step where approved
  • Replicate - Optional image upscaling only when separately selected and approved; local processing is the default print path
  • Prodigi - Print production and shipping fulfillment for hardcover orders where live personalized fulfillment is approved
  • Resend and HubSpot - Transactional email, delivery status, customer support, and parent-only CRM order workflows where enabled. Generated child content, personalized titles, and raw book/project identifiers are excluded; transactional order references and information you deliberately submit in a support or privacy request may be included when needed
  • PostHog, Google Analytics, and Google Ads - consented public-acquisition measurement only. Creation, account, Library, checkout, reading, product, and commerce surfaces are excluded; Google Ads also requires marketing consent

Photos and private source material are transmitted to service providers only when needed to provide the requested generation, storage, support, print, payment, or delivery function. Provider retention, abuse-monitoring, and model-training rules depend on the provider, service tier, and contract terms, so DreamInk maintains these as a provider register rather than making one blanket promise here. DreamInk does not authorize providers to use customer source material for advertising or public sample galleries.

We may also disclose data to professional advisers, insurers, auditors, public authorities, courts, or transaction partners when necessary to meet legal duties, protect rights, or manage a corporate transaction. Service providers act under appropriate data-processing and confidentiality terms where required.

5. International Data Transfers

DreamInk operates from Germany and uses providers that may process data in the European Economic Area, the United States, and other countries. When personal data is transferred outside the EEA to a country without an adequacy decision, we rely on an applicable safeguard such as the European Commission's Standard Contractual Clauses under Article 46 GDPR, together with supplementary measures where appropriate. For a participating United States provider, we may rely on the EU-US Data Privacy Framework when that provider is certified for the relevant data.

Contact us to ask about the safeguard used for a particular provider or to request a copy of the relevant transfer protection, subject to necessary redactions.

6. Data Retention and Deletion

We retain your data for as long as your account is active or as needed to provide our services. Specifically:

  • Account data is kept while the account is active and then for the period needed to close it, answer requests, and protect legal claims.
  • Book and project data, including source material and generated content, is kept while needed to create the project and while you choose to keep it available in your account. Temporary processing files and failed-job payloads are removed on shorter operational schedules where feasible.
  • Transaction and compliance records are retained for applicable tax, accounting, consumer-protection, consent, fraud, and legal limitation periods.
  • Cookie and analytics data is retained according to the lifetime shown in the cookie preferences and provider settings.

You may request deletion of your account and all associated data at any time by contacting us at hello@dreamed.ink. We respond without undue delay and normally within one month as required by the GDPR. Some data may be retained in backups for a limited period or where required for active orders, payment records, fulfillment, support, legal obligations, or security. Co-creation draft material can usually be removed from DreamInk-controlled project records and storage before checkout; printed or paid orders may require a support or legal retention review before destructive deletion. Where project material has already been processed by a payment, print, support, or generation provider, DreamInk will handle deletion or erasure requests according to that provider relationship and applicable law.

7. Children's Privacy

DreamInk accounts and purchases are for adults. The service lets a parent, legal guardian, or other authorized adult create a book for a child. It is not designed for children to submit their own information or purchase books.

  • We do not knowingly collect personal information directly from children. In the United States, we do not knowingly collect it directly from children under 13. In the EEA, the applicable national age for a child's consent to online services may be higher. DreamInk therefore uses an adult-led flow rather than relying on a child's consent.
  • Where verifiable parental consent is required, DreamInk may use the consent method shown in the product flow, such as a temporary refundable card transaction. The current card verification amount is $0.70 and may change if processor minimums change. The product flow should provide the direct notice and consent details before collecting child personal information where that notice is required.
  • Child information is used to create, review, support, store, print, ship, and operate the requested book, and to maintain required safety, fraud, consent, support, and legal records. It is not sold or used for public marketing without separate permission.
  • Parents may review, request deletion of, or refuse further collection of their child's information at any time by contacting us at hello@dreamed.ink.

8. Your GDPR Rights

If the GDPR applies, you may request access to your personal data, correction of inaccurate data, erasure, restriction of processing, and data portability where the legal conditions are met. You may object to processing based on legitimate interests, including profiling, and you may object to direct marketing at any time.

When processing is based on consent, you may withdraw consent at any time through the available preference control or by contacting us. Withdrawal does not affect processing that was lawful before it. You also have the right to lodge a complaint with a data protection supervisory authority. For our German operating address, the relevant authority is the State Commissioner for Data Protection of Lower Saxony (LfD Niedersachsen). You may also contact the authority where you live or work.

To exercise a right, email hello@dreamed.ink. We may ask for information needed to verify your identity and authority. Rights can be subject to statutory limits, including obligations to retain transaction records and the rights of other people shown in a shared project.

9. AI Generation and Automated Processing

DreamInk uses automated systems and generative AI to turn prompts, text, and reference images into story plans, writing, illustrations, translations, layouts, and previews. These systems analyze the supplied material and predict suitable generated output. Outputs may be imperfect and are reviewed or revised through the product workflow.

DreamInk does not use this processing to make decisions about a person that produce legal effects or similarly significant effects within Article 22 GDPR. We do not use child photos to evaluate eligibility, credit, education, health, or other personal characteristics. You may contact support if you have a concern about an automated result.

10. Your California Privacy Rights (CCPA/CPRA)

If you are a California resident and DreamInk is subject to the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), you may have the following rights:

  • Right to Know: You may request details about the personal information we have collected about you and how it is used.
  • Right to Correct: You may request that we correct inaccurate personal information we maintain about you.
  • Right to Delete: You may request that we delete the personal information we have collected about you, subject to certain exceptions.
  • Right to Opt-Out of Sale or Sharing: DreamInk does not sell personal information. If analytics, conversion measurement, or advertising tools are configured in a way that is treated as sharing under California law, you may request an opt-out. DreamInk does not sell or share child photos, private source material, or generated books for cross-context behavioral advertising.
  • Right to Limit Sensitive Personal Information: You may request limits on uses of sensitive personal information where applicable.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.

To exercise any of these rights, contact us at hello@dreamed.ink. We will respond within 45 days.

11. Data Security

We implement reasonable technical and organizational measures to protect your information, including:

  • Encrypted data transmission (HTTPS/TLS)
  • Row-level security policies in our database ensuring users can only access their own data
  • Secure authentication via Supabase Auth
  • PCI DSS-compliant payment processing via Stripe

While no system is completely secure, we take commercially reasonable steps to protect your data from unauthorized access, alteration, or destruction.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice on our website prior to the change becoming effective. Where the law requires new consent, we will ask for it rather than treating continued use as consent.

13. Contact Us

If you have questions about this Privacy Policy, your data, or your rights, contact us:

DreamInk, Inc.

Lüerstraße 8, 30175 Hanover, Germany

Email: hello@dreamed.ink