LEGAL

Privacy policy

Tierce is built so that we cannot read your dreams. Everything you record — the audio, the words, the interpretations, your sleep records — lives on your phone and nowhere else. This page names the data controller, lists the little that ever touches a network, and explains the rights you have. It covers both the Tierce iOS app and this website.

1. Who we are

The data controller is Francesco Dallatorre, a sole trader established at Via Gaetano Modonesi 24, 29122 Piacenza, Italy — VAT IT01934820331, Piacenza Companies Register REA PC-373714 (“Tierce”, “we”). For anything in this policy, write to privacy@tierce.app.

We have not appointed a Data Protection Officer: given the nature and scale of what we actually process — described honestly below — Article 37 GDPR does not require one.

2. What stays on your phone — all of it

The app keeps on the device: your voice recordings, transcripts and written dreams, the interpretations, the sleep records it reads from Apple Health, moods, tags, the people you name, medals, settings and — only if you have granted location — the night’s coordinate already rounded to about 11 km, the same one sent for the weather and nothing finer. That is also what lets the app tell a night spent at home from a night spent away: at that scale “away” means another town, never another street. The database is encrypted with a key held in the device keychain; recordings are additionally protected by iOS complete file protection.

None of this ever reaches us. We run no server that could receive it, and we hold no copy. To the extent this data never leaves your device, we do not process it at all — the only person who can read your dreams is you. We are aware that dreams and sleep are intimate matters that can touch on health, beliefs or sexuality; that is precisely why the app was designed this way (data minimisation and data protection by design, Articles 5(1)(c) and 25 GDPR).

“Erase everything”, in Settings, deletes the recordings, the text, and the encryption key that protected them. Deleting the app deletes its container.

3. Interpretation happens on the phone

Dreams are interpreted by an AI model running on your device: either the model that ships with the operating system, or an open model you can download (currently Qwen 3.5, Apache 2.0 licence). In both cases the dream, the instructions and the interpretation are processed locally. They are never sent to us or to any third party, and they are never used to train any model.

Interpretations are AI-generated text. The app says so next to each reading, and files you export carry a machine-readable notice, as required by Article 50 of Regulation (EU) 2024/1689 (the EU AI Act).

4. Apple Health

If you allow it, the app requests read-only access to one Health category: sleep analysis. It never writes to Health, never reads any other category, and the sleep records it reads are processed and stored on the device only. You can revoke access at any time in the iOS Health settings; the app keeps working without it, less precisely.

5. Microphone and speech

The microphone records only while you are recording a dream. Transcription is performed by the operating system’s speech engine with on-device recognition required — audio is never sent to a server to be transcribed. Recordings stay on the phone and are never included in the backup.

6. The complete list of network requests the app makes

That is the whole list. The app contains no advertising SDK, no cross-app tracking and no advertising profile, and we do not use Google Analytics. The counters above are the only measurement of any kind that reaches us, and they are deliberately built so that they measure a population and not a person: they say how many people got past a screen, never which screens you saw. Nothing in the app you actually use afterwards is measured at all — not what you record, not when, not how often, not what you look at. Apple may additionally share aggregated, opt-in crash and usage statistics with us through App Store Connect; whether that happens is controlled by your own iOS “Share with app developers” setting, and what reaches us is statistical and cannot identify you.

Crash reports and the counters rest on your consent (Article 6(1)(a) GDPR), asked once at the end of setup and withdrawable at any time in Settings ▸ Diagnostics; withdrawing stops everything further, and has no effect on what was lawfully sent before. The version and maintenance check rests instead on our legitimate interest in not leaving a broken build running (Article 6(1)(f)), and push registration exists only once you have granted notifications. All of this sits on Google infrastructure, which may involve a transfer outside the European Union under the Standard Contractual Clauses. Crash reports are kept for Crashlytics' own retention period and are not combined with anything else about you — we would have nothing to combine them with.

7. iCloud backup

If enabled, the app writes one backup file — dreams, settings, medals; never the audio — to your own iCloud Drive, under your Apple account and your agreement with Apple. We have no access to your iCloud and hold no keys to it. You can delete the backup from the app or from iCloud Drive at any time.

The file is encrypted before it leaves the phone. When you switch the backup on you choose a passphrase: the archive is encrypted with a random key, and that key is in turn locked with your passphrase. Only the encrypted result reaches iCloud Drive — unreadable to Apple and to us, whether or not you have Advanced Data Protection switched on.

You can choose whether to save the key to your iCloud Keychain, which Apple encrypts end-to-end always: that is what lets the backup restore itself on a new phone. If you choose not to, your passphrase is the only copy that exists — and if you forget it, the backup stays unreadable for ever: we cannot recover it, and neither can Apple. The app tells you so, in those words, at the moment you make that choice.

8. Purchases

Purchases and subscriptions are handled by Apple through the App Store; we never see your payment details. To know whether your subscription or lifetime purchase is active, the app uses RevenueCat (RevenueCat, Inc., United States), acting as our processor. RevenueCat receives the App Store receipt and its purchase events — which product, when bought or renewed, in which country and currency — under a random identifier minted for the installation: the app has no accounts, so there is no name, email or payment detail to attach, and nothing of your dreams ever reaches it. It answers one question — whether the paid features are unlocked — and gives us aggregate revenue statistics; we build no profile from it. The transfer to the United States rests on the safeguards of Article 46 GDPR (Standard Contractual Clauses).

9. This website

10. Legal bases and retention

For the little we actually process: the newsletter email rests on consent and is kept until you unsubscribe; the weather request happens only to provide a feature you asked for and only with your iOS location permission; the model download and catalogue check are necessary to deliver and safeguard the interpretation feature (performance of the contract, and our legitimate interest in withdrawing a defective model); crash reports and the three sets of counters rest on your consent (Article 6(1)(a)), which is asked once at the end of setup and can be withdrawn at any time in Settings ▸ Diagnostics, as easily as it was given (Article 7(3)); the version and maintenance check rests on our legitimate interest in keeping the app working; purchase and entitlement data are necessary to perform the contract (Article 6(1)(b)); the push registration exists only after you grant notifications and serves to deliver them; website logs rest on legitimate interest. Nothing else about you is retained by us, because nothing else reaches us.

11. Your rights

Under Articles 15–22 GDPR you have the rights of access, rectification, erasure, restriction, portability and objection. For everything the app stores, those rights are in your own hands, immediately: read, edit, export and erase from within the app — we could not comply on your behalf even if asked, because we hold no copy. For the newsletter email or anything about this website, write to privacy@tierce.app; we answer within thirty days. You may also lodge a complaint with the Italian supervisory authority (Garante per la protezione dei dati personali, garanteprivacy.it) or with the authority of your country of residence.

The anonymous counters are the one thing we cannot delete on request — because they are not yours. When a counter goes from 3,310 to 3,311, nowhere does it record who moved it: no identifier, no document about you, no timestamp fine enough to line two writes up. That is true of all three of them — the answers, the setup screens, the thumbs on a reading. They are not personal data, so Article 17 does not reach them; and building a way to remove your contribution would require knowing it was yours — that is, keeping exactly the identifier this design does not have. What you can do at any time is withdraw consent in Settings ▸ Diagnostics: nothing further is sent from then on.

12. International transfers

The requests listed in section 6 are made directly by your device to the providers named there. The weather service operates from the EU; the model host may serve files through a content-delivery network outside the EEA — requests that contain no personal data beyond the IP address any internet request necessarily carries. The diagnostic, configuration, notification and purchase services — Google and RevenueCat — are United States providers: those transfers rest on the safeguards of Article 46 GDPR (Standard Contractual Clauses, and the EU–US Data Privacy Framework where the provider is certified). Your dreams take part in none of this: they are not in any of these systems.

13. Children

Tierce is not intended for anyone under sixteen, and we do not knowingly collect data from them.

14. Users in the United States

We do not sell or share personal information within the meaning of the California Consumer Privacy Act. We never receive consumer health data, so nothing is collected, shared or sold within the meaning of the Washington My Health My Data Act or similar state laws. The app is not directed at children under thirteen (COPPA).

15. Automated decisions

The app makes no automated decision that produces legal effects or similarly significant effects on you (Article 22 GDPR). Interpretations are reflections offered to you, on your device; they decide nothing.

16. Changes

If this policy changes, the date at the top changes with it, and material changes are announced in the app or on this site before they take effect. The promises about your dreams staying on the device are the architecture of the product, not a preference — a change to them would be a different product, and would require your explicit consent, not a quiet edit to this page.

Data controller: Francesco Dallatorre, Via Gaetano Modonesi 24, 29122 Piacenza, Italy. Supervisory authority: Garante per la protezione dei dati personali. Contact: privacy@tierce.app.