Privacy Policy

Effective date: 15 July 2026

Last updated: 14 July 2026

Dreamport Technologies, Inc. ("DREAMPORT", "we", "us", or "our") provides an AI-powered cognitive orchestration platform that helps organizations and their people think through complex work (the "Service"). This Privacy Policy explains what information we collect, how we use and share it, and the choices you have.

This policy applies to the Service and to our website at dreamport.ai (the "Website"). The Service is offered to organizations ("Customers" or "Tenants") and the people they authorize to use it ("Users"). Where you use the Service through your organization, that organization directs how your information is used, and this policy operates alongside your organization's own privacy notice and our agreement with them.

1. Information We Collect

Information You Provide Directly

  • Account and profile information — your email address and display name. If you sign in through Google, we receive your Google account identifier, email address, and name (but not your Google password). You may add a profile picture and, during onboarding, information about your organization.
  • Content you submit — the messages and prompts you enter, files you upload, voice input you dictate, project names and instructions you create, and other material you provide to the Service (together, "Content").
  • Communications — information you provide when you contact us for support or by email.

Information We Collect Automatically

  • Authentication and session data — when you sign in, we create session records that include your IP address, browser and device information (user-agent), and session timestamps. Authentication is passwordless; we do not store account passwords.
  • Usage and telemetry data — information about how the Service is used and performs, including pages viewed, actions taken, feature usage, error and performance diagnostics, and — for the AI features — the AI models used and the volume of processing (for example, request counts and token counts used for metering and billing). This telemetry is used to operate the Service, diagnose and troubleshoot issues, and improve reliability.
  • Security and audit logs — records of security-relevant and administrative events, which may include the acting user, the action taken, IP address, and user-agent.
  • Organization context — because you access the Service through a Customer account, we associate your activity with the organization that authorized your account.

Cookies and Local Storage

We use a small number of first-party cookies that are strictly necessary to keep you signed in and to remember interface preferences:

CookiePurposeDuration
dt_access / refresh_tokenKeep you signed in and renew your session~30 days
dt_platform_access / dt_platform_refreshAdministrator sessions~30 days
dp_sidebar_expandedRemember your sidebar layout~1 year

To make the Service fast and resilient, we also store a copy of your recent conversations and interface preferences locally in your browser (using local storage and IndexedDB). This data stays on your device. Our analytics and monitoring providers (see Section 5) may also set cookies or similar identifiers; where required by applicable law, we obtain your consent before these are set.

2. How We Use Your Information

We use the information described above to:

  • provide, maintain, and secure the Service and your account;
  • generate AI responses and results from your Content (see Section 4);
  • authenticate you, enforce access controls and usage limits, and protect against fraud, abuse, and security threats;
  • meter usage and calculate charges;
  • provide customer support and diagnose and troubleshoot technical issues (including by reviewing product analytics and session diagnostics that show how a problem occurred);
  • improve and develop the Service, including reliability and user experience; and
  • comply with legal obligations and enforce our agreements.

Processing necessary to provide the Service

The processing described in this policy — including transmitting your Content to our AI providers to generate responses, storing your conversations, and maintaining security and audit logs — is necessary to provide the Service. If you object to this processing, please do not use the Service; you may close your account at any time as described in Section 9.

3. Third-Party Sharing

We do not sell your personal information, and we do not "share" personal information for cross-context behavioral advertising, as those terms are defined by applicable U.S. state privacy laws. We share information only as needed to run the Service, with service providers ("sub-processors") acting on our instructions, and as required by law.

ProviderPurposeInformation shared
AnthropicAI language model responses; web search groundingYour prompts, relevant conversation history, and attachment content; search queries derived from your requests
Google Cloud (Vertex AI / Gemini)AI language model responses; web search groundingSame as above
PerplexityWeb search grounding for research featuresSearch queries derived from your requests
Google Cloud Speech-to-TextVoice transcriptionAudio you dictate
Google Cloud (Storage, Key Management, database and compute)Hosting, file storage, encryptionAccount data, Content, uploaded files
SendGrid (Twilio)Transactional email (sign-in codes, invitations, notifications)Recipient email address and message content
PostHogProduct analytics and session diagnostics used to troubleshoot issues and improve the ServiceUsage events, session diagnostics, and account identifiers (see Section 5)

We may also disclose information to comply with the law or legal process, to protect the rights, safety, and security of DREAMPORT, our Customers, and others, and in connection with a merger, acquisition, or sale of assets, subject to appropriate protections.

A current list of sub-processors is available on request at humans@dreamport.ai.

Roles under data protection law

For personal data contained in Content that you submit through a Customer account, the Customer (your organization) is the controller and DREAMPORT acts as processor on the Customer's instructions. For account, authentication, telemetry, security, and billing data used to operate the Service, DREAMPORT acts as controller.

4. AI Processing of Your Content

When you use the AI features, your prompts, relevant conversation history, and the content of files and voice input you provide are transmitted to our AI model providers (listed in Section 3) to generate a response. We apply governance controls to these requests, including per-Customer usage budgets, model and policy controls, and automated safety filters on inputs and outputs.

Our AI providers process this Content to provide the Service to us under commercial or enterprise agreements — specifically, Anthropic's Commercial Terms and Google Cloud's Vertex AI terms — under which these providers do not use your Content to train their models. Provider terms may change, and we review them periodically; if a material change occurs, we will update this policy. Because AI outputs are generated by statistical models, they may be inaccurate or incomplete; you should review them before relying on them. Please do not submit sensitive personal information that you would not want processed by these providers.

Web search and browsing

Some features — particularly research workflows — search the public web to find and cite sources. To do this, the Service sends search queries derived from your request to third-party search providers (currently Perplexity, Anthropic, and Google search grounding), and may retrieve and process the content of publicly available web pages. These search queries are generated from your request and may reflect its subject matter, so avoid including sensitive personal information in requests that trigger web research.

For Customers with applicable requirements, the Service can be configured to route AI processing to models hosted in the European Union.

5. More About Analytics and Diagnostics

To keep the Service reliable and to help us investigate and resolve issues you experience, we use:

  • PostHog for product analytics and session replay. Session replay records how the interface rendered and how it was interacted with during a session so that our team can reproduce and fix problems. This may include Content you type into the interface. Password fields and one-time-passcode entries are masked or excluded, and replay is disabled on invitation pages. We associate this data with your account (user identifier, email, name, and organization) so that we can locate the relevant session when providing support.
  • Grafana Faro for error and performance monitoring, which captures diagnostic information such as JavaScript errors and page-performance metrics (with tokens, secrets, and identifiers removed before transmission). This telemetry is sent to our own self-hosted monitoring system within our cloud infrastructure and is not shared with a third party.

We use these tools for our legitimate interest in operating, securing, supporting, and improving the Service, and not for advertising. We do not use them to sell your information. Where required by applicable law, we obtain your consent before non-essential analytics are set.

6. Bases for Processing

Where data-protection laws such as the EU/UK GDPR apply, we rely on the following legal bases: performance of our contract with you or your organization (for providing the core Service, authentication, and billing); our legitimate interests in operating, securing, supporting, and improving the Service (for security logs, telemetry, and analytics); compliance with legal obligations; and your consent where required (for example, non-essential cookies). Where we rely on consent, you may withdraw it at any time.

7. Data Retention

We keep personal information for as long as needed to provide the Service and for the purposes described in this policy:

  • Security and AI-usage logs are retained for a configurable period, by default 90 days.
  • Your Content (conversations, files, projects) is retained for the life of your account or until you or your organization deletes it.
  • Session records expire on sign-out or after approximately 30 days.

When an account or organization is closed, we disable access and delete or de-identify the associated data within 90 days, subject to any legal retention requirements. You can request deletion as described in Section 9.

8. Security

We take the security of your information seriously and use industry-standard safeguards, including:

  • passwordless sign-in (email one-time passcodes and/or Google single sign-on), with additional authentication measures such as two-factor authentication that may be offered over time;
  • strong isolation between Customers, so one organization's data is not accessible to another;
  • encryption of data in transit (HTTPS/TLS) and encryption of sensitive data at rest, including two-factor secrets and AI-processing payloads;
  • storage of one-time passcodes and tokens only in hashed or encrypted form; and
  • managed secrets and access controls across our infrastructure.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

9. Your Choices and Rights

California residents: see Section 9A for additional disclosures required by California law. Residents of other U.S. states with comprehensive privacy laws: see Section 9B.

Depending on where you live, you may have the right to access, correct, export, delete, or restrict the processing of your personal information, and to object to certain processing or withdraw consent. To exercise these rights, contact us at humans@dreamport.ai. If you use the Service through an organization, we may refer your request to that organization, which controls the relevant data.

If you are in the EU, UK, or Switzerland, you also have the right to lodge a complaint with your local data protection authority.

We will not discriminate against you for exercising these rights. We do not sell personal information.

9A. Notice to California Residents

This section provides additional information required by the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), for California residents.

Categories of personal information we collect

We collect the following categories of personal information, as defined by the CCPA:

  • Identifiers — name, email address, Google account identifier, IP address, device identifiers, session identifiers.
  • Customer records — profile information you provide.
  • Internet or network activity — usage and telemetry data, security and audit logs, session diagnostics.
  • Geolocation data — approximate location derived from IP address (not precise geolocation).
  • Audio information — voice input you dictate for transcription.
  • Professional information — the organization associated with your Customer account.
  • Inferences — limited inferences drawn from usage patterns to operate and improve the Service.
  • Sensitive personal information — account access credentials (session tokens) and any sensitive information you choose to include in Content you submit. We use sensitive personal information only for the purposes permitted by California Civil Code § 1798.121(a) — namely, to provide the Service you request and for the operational purposes described in this policy — and not to infer characteristics about you.

Sources

We collect this information directly from you, automatically from your use of the Service, and from your organization if you access the Service through a Customer account. For Google single sign-on, we also receive identifiers and profile information from Google.

Business purposes

We use this information for the purposes described in Section 2 of this policy, including providing and securing the Service, generating AI responses, authentication, metering and billing, support, and product improvement.

Categories of recipients

We disclose personal information to the categories of service providers listed in Section 3 — AI model providers, cloud hosting and storage providers, email delivery providers, analytics and diagnostics providers — for the business purposes described in this policy. We may also disclose information to comply with law or protect rights and safety as described in Section 3.

Sale and sharing

We do not sell personal information, and we do not "share" personal information for cross-context behavioral advertising, as those terms are defined by the CCPA. We have not sold or shared personal information since we began offering the Service. We do not have actual knowledge that we sell or share the personal information of consumers under 16 years of age.

Retention

We retain personal information for the periods described in Section 7.

Your California privacy rights

If you are a California resident, you have the right to:

  • Know what personal information we have collected about you, including the categories, sources, purposes, and recipients;
  • Access a copy of the specific pieces of personal information we hold about you;
  • Correct inaccurate personal information;
  • Delete personal information we have collected from you, subject to certain exceptions;
  • Opt out of the sale or sharing of personal information (not applicable, as we do not sell or share);
  • Limit the use and disclosure of sensitive personal information (not applicable, as we use sensitive personal information only for purposes permitted by § 1798.121(a));
  • Non-discrimination for exercising your rights.

How to exercise your rights

To submit a request, email us at humans@dreamport.ai with "California Privacy Request" in the subject line. We will verify your request by matching information you provide against information we already hold about you. You may authorize an agent to make a request on your behalf; the agent must provide written authorization signed by you, and we may separately verify your identity.

Global Privacy Control

We honor the Global Privacy Control ("GPC") browser signal as a valid opt-out request from users we can identify as California residents. Because we do not sell or share personal information, the GPC signal has no additional effect on how we process your information, but we recognize it as an opt-out request should our practices change.

If you access the Service through your organization

Your organization is the business responsible for personal information processed on its behalf. We will refer requests concerning that information to your organization.

9B. Notice to Residents of Other U.S. States

This section provides additional information for residents of U.S. states with comprehensive privacy laws, including (among others) Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky, and Rhode Island, as applicable to residents of each such state.

Categories of personal data

The categories of personal data we process, the sources, purposes, and categories of recipients are described in Sections 1, 2, 3, and 9A of this policy.

Sensitive data

Some state laws define certain personal data as "sensitive." We do not intentionally collect sensitive data as defined under these laws, but Content you submit may contain such information. We process any such information only to provide the Service and for the operational purposes described in this policy. Where your state's law requires consent to process sensitive data, your submission of that data through the Service constitutes your consent to processing for those purposes; you can withdraw consent by ceasing to submit such data and, where applicable, requesting deletion.

Sale, sharing, and targeted advertising

We do not sell personal data, we do not process personal data for targeted advertising, and we do not engage in profiling in furtherance of decisions that produce legal or similarly significant effects concerning you.

Your rights

Depending on your state of residence, you may have the right to:

  • Confirm whether we process your personal data and access that data;
  • Correct inaccuracies in your personal data;
  • Delete personal data we have collected from or about you;
  • Obtain a portable copy of your personal data;
  • Opt out of the sale of personal data, targeted advertising, and certain profiling (not applicable, as we do not engage in these activities).

Universal opt-out signals

We honor recognized universal opt-out mechanisms, including the Global Privacy Control, as opt-out requests where applicable under your state's law.

How to exercise your rights

Email humans@dreamport.ai with your state of residence in the subject line (for example, "Virginia Privacy Request"). We will verify your identity by matching information you provide against information we hold about you.

Appeals

If we decline to act on your request, you may appeal by replying to our response or emailing humans@dreamport.ai with "Privacy Rights Appeal" in the subject line. We will respond within the timeframe required by your state's law (typically 45 or 60 days). If your appeal is denied, you may contact your state attorney general.

If you access the Service through your organization

Your organization is the controller of personal data processed on its behalf. We will refer requests concerning that data to your organization.

10. International Data Transfers

We operate primarily on Google Cloud infrastructure hosted in the United States (Google Cloud region us-central1). Our AI, analytics, and email providers — including Anthropic, Google, Perplexity, PostHog, and SendGrid — are also located in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States and in other countries where we or our providers operate. Where required, we put appropriate safeguards in place for such transfers, such as Standard Contractual Clauses.

11. Children

The Service is not directed to children, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us information, please contact us and we will take appropriate steps to delete it.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, provide additional notice as required.

13. Contact Us

If you have questions about this Privacy Policy or our privacy practices, contact us at:

Dreamport Technologies, Inc.

Email: humans@dreamport.ai