Privacy Policy

Last updated: 26 July 2026

Olorin ("Olorin", "we", "us") is a contemplative inner-work app for journaling, dreamwork, and reflective practice. This policy explains what we collect, how it is protected, and the choices you have. Please read it alongside our Terms of Use.

The short version

What we collect

Account information. When you create an account we store your email address (or Apple/Google sign-in identifier) and an internal account ID. This identity is never shown to other users.

Your private entries. Journal entries, dream entries, dream conversations, interpretations, tags, images, and inner-dialogue sessions are stored on our servers and are visible only to you. They are transmitted over TLS and encrypted at rest by our hosting provider, and row-level security rules restrict every one of these records to the account that created it, so no other user can read them.

Commons (public) content. If you create a public presence and publish a dream or comment, that content — including any text, images, and your chosen public handle and display name — is stored in readable form and shown to others according to the audience you select (everyone, close friends, or followers).

Technical data. Basic operational data needed to run the service (e.g. authentication tokens and error logs).

How your private content is protected

Your entries are protected by three layers: TLS while in transit, AES-256 encryption at rest in our hosting provider's database and storage, and row-level security rules that tie every record to the account that created it. No other Olorin user can read your entries.

What this does not mean. Olorin is not end-to-end encrypted. We hold the keys to the database, so our systems — and a small number of authorised personnel with production access — are technically capable of reading your entries. We access them only where necessary to operate the service, respond to a support request you make, or comply with a valid legal obligation. We do not read entries for any other purpose, and we never sell them or use them for advertising.

This is a deliberate trade. It is what allows you to sign in from any device, recover a forgotten password without losing your dreams, and use interpretation and image features. If you need a system where no operator can ever read your content, Olorin is not that system.

A note on the change

Earlier versions of Olorin encrypted entries end-to-end with a key held only on your device. We moved to the model described above so that ordinary sign-in and password recovery work the way people expect. Existing entries are converted on your own device the next time you open the app, because only your device could read them. A small number of entries may not be convertible; these stay unreadable and are removed in due course.

AI features

When you request an AI action — such as a dream interpretation, a generated image, tags, or a dialogue reply — the specific content you are acting on is transmitted, encrypted in transit, to our AI processing providers (currently Anthropic and OpenAI) to generate the result. The result is returned and stored encrypted. These providers process the content to produce your result and do not use it to train their models under our configuration. Features you do not use send nothing.

Data storage and processors

We use Supabase (database, authentication, storage) as our backend infrastructure provider, and the AI providers named above. These processors act on our behalf and are bound to protect the data they handle.

Your choices and rights

Children

Olorin is not directed to children. You must be at least 17 years old to use it.

Health data

Olorin does not currently read from or write to Apple Health or any other health data source.

Changes

We may update this policy; material changes will be reflected by the "last updated" date above.

Contact

Questions about this policy: support@olorin.health.