Legal · Transparency · YMYL
Privacy Policy
Oneirox is built without accounts. We do not sell dream data. This policy explains exactly what happens when you use the Dream Decoder and related tools.
At a glance
We collect
Dream text you submit to Decode
Sent to our API solely to generate your reading. Standard server logs (IP, timestamp, user agent) for security.
We do not
Require login or payment
No accounts. No subscription funnel. No selling or licensing your dream content to third parties for advertising.
On your device
Mapper somatic context
localStorage key onx_mapper_data — expires after ~30 minutes. Cleared when you clear browser data.
Your control
Clear browser storage anytime
Delete site data in browser settings. Do not submit content you are not comfortable processing through an API.
Dream Decoder (Decode)
When you press Decode, the dream text you enter is transmitted to the Oneirox API (oneirox-api-production.up.railway.app) over HTTPS. The API processes your submission and returns a mechanism-based reading (SIGNAL · BODY · MORNING). We use this interaction to operate the service — not to build marketing profiles.
Do not submit information you would not want processed by a web application: full names of third parties, addresses, medical record numbers, or other highly sensitive identifiers. Describe dreams in plain language; you remain responsible for what you type.
Sensory Dream Mapper
The Mapper may store somatic profile data locally in your browser (localStorage, key onx_mapper_data) so Decode can include interoceptive context automatically. This data does not leave your device until you run Decode — at which point relevant somatic context is included in the API request you initiate.
Hosting, logs & third parties
Oneirox is served via Cloudflare Pages. Our API runs on Railway. These providers may process standard technical logs — IP address, request time, user agent, error traces — for reliability and abuse prevention.
If you explicitly use a share feature (email, social), that action invokes the third-party service you choose. We do not auto-post your readings.
We do not use third-party advertising trackers on the core Decode experience. If analytics are added in future, this policy will be updated before they go live.
Retention, rights & children
Server-side retention of API submissions follows our infrastructure provider policies and operational needs (debugging, abuse prevention). We do not maintain a user account system — therefore there is no profile to export or delete by login. Clear local Mapper data via your browser.
Depending on your jurisdiction (GDPR, CCPA, and others), you may have rights to access, correct, or request deletion of personal data. Contact us via the method listed on About when available.
Oneirox is not directed at children under 13. We do not knowingly collect data from children.