Privacy policy
Tierce is built so that we cannot read your dreams. Everything you record — the audio, the words, the interpretations, your sleep records — lives on your phone and nowhere else. This page names the data controller, lists the little that ever touches a network, and explains the rights you have. It covers both the Tierce iOS app and this website.
1. Who we are
The data controller is Francesco Dallatorre, a sole trader established at Via Gaetano Modonesi 24, 29122 Piacenza, Italy — VAT IT01934820331, Piacenza Companies Register REA PC-373714 (“Tierce”, “we”). For anything in this policy, write to privacy@tierce.app.
We have not appointed a Data Protection Officer: given the nature and scale of what we actually process — described honestly below — Article 37 GDPR does not require one.
2. What stays on your phone — all of it
The app keeps on the device: your voice recordings, transcripts and written dreams, the interpretations, the sleep records it reads from Apple Health, moods, tags, the people you name, medals, settings and — only if you have granted location — the night’s coordinate already rounded to about 11 km, the same one sent for the weather and nothing finer. That is also what lets the app tell a night spent at home from a night spent away: at that scale “away” means another town, never another street. The database is encrypted with a key held in the device keychain; recordings are additionally protected by iOS complete file protection.
None of this ever reaches us. We run no server that could receive it, and we hold no copy. To the extent this data never leaves your device, we do not process it at all — the only person who can read your dreams is you. We are aware that dreams and sleep are intimate matters that can touch on health, beliefs or sexuality; that is precisely why the app was designed this way (data minimisation and data protection by design, Articles 5(1)(c) and 25 GDPR).
“Erase everything”, in Settings, deletes the recordings, the text, and the encryption key that protected them. Deleting the app deletes its container.
3. Interpretation happens on the phone
Dreams are interpreted by an AI model running on your device: either the model that ships with the operating system, or an open model you can download (currently Qwen 3.5, Apache 2.0 licence). In both cases the dream, the instructions and the interpretation are processed locally. They are never sent to us or to any third party, and they are never used to train any model.
Interpretations are AI-generated text. The app says so next to each reading, and files you export carry a machine-readable notice, as required by Article 50 of Regulation (EU) 2024/1689 (the EU AI Act).
4. Apple Health
If you allow it, the app requests read-only access to one Health category: sleep analysis. It never writes to Health, never reads any other category, and the sleep records it reads are processed and stored on the device only. You can revoke access at any time in the iOS Health settings; the app keeps working without it, less precisely.
5. Microphone and speech
The microphone records only while you are recording a dream. Transcription is performed by the operating system’s speech engine with on-device recognition required — audio is never sent to a server to be transcribed. Recordings stay on the phone and are never included in the backup.
6. The complete list of network requests the app makes
- Downloading an interpretation model. Only when you ask for it, the app downloads a public model file from Hugging Face’s servers. Like any internet request it reveals your IP address to that host; it carries no account, no identifier of ours, and nothing about you or your dreams. The model’s licence is shown before the download starts.
- Checking the model catalogue. Roughly once a day the app fetches a static JSON file that says which model version is current, so a faulty or withdrawn model can be replaced. It is a bare GET: no query string, no identifier, no cookie, nothing that says who asked.
- The weather. With your permission, the app sends two coordinates rounded to about 11 km — enough to know the sky, not enough to find a house — plus the date, to Open-Meteo, a keyless open-data weather service operated from the EU. No identifier travels with the request. Decline location access and a night simply has no weather.
- Crash reports. If the app crashes, it sends us the technical error — the kind of error, where in the code, your iPhone model and iOS version — through Google's Firebase Crashlytics, acting as our data processor. The content of your dreams never travels, nor do the titles, the tags, the people you name, your answers or the recordings: the app has no function capable of sending them, and every error message is stripped of file paths and quoted text before it leaves. An installation identifier generated by Google travels with the report; it is not your Apple ID and it does not follow you between apps. It is sent only if you agree: we ask once, at the end of setup, in the same question that covers the counters below — the switch is off until you turn it on, and nothing is sent from a phone that never turned it on. You can withdraw at any time in Settings ▸ Diagnostics, where the two are separate switches.
- Remote configuration and messages. The app asks Firebase Remote Config whether the version you have is still supported and whether the service is under maintenance, and uses Firebase Cloud Messaging for the notifications we may send you. Both are Google's, acting as our processor, and both carry the same installation identifier. Neither carries anything of your dreams.
- Three sets of anonymous counters. Each one adds 1 to a number on Firebase Firestore, and nothing else ever travels with it. They are:
- What people came for. How many answered “most mornings”, how many chose “lucid dreams”, and so on — sent once, when you finish setting the app up. Anything you type yourself under “add your own” never leaves the phone; only the fixed answers are counted.
- Where setup loses people. How many got past each screen of the setup, and how long those screens took in total, so we can see which one people give up on. The times are added into a single running total per screen; nothing records the order you saw them in, or how long you took. They are held on the phone while you are setting up and sent only at the end, together with the answer above — so a setup you abandon, or one where you leave the switch off, sends nothing at all.
- Whether an interpretation was any good. When you give a reading a thumb up or down, that adds 1 to a tally kept per app version and per model. Which model wrote it and which way you voted is all that reaches us. The dream is not sent, the reading is not sent, and what you write to us instead — if you use the feedback link — is an email you compose and send yourself.
That is the whole list. The app contains no advertising SDK, no cross-app tracking and no advertising profile, and we do not use Google Analytics. The counters above are the only measurement of any kind that reaches us, and they are deliberately built so that they measure a population and not a person: they say how many people got past a screen, never which screens you saw. Nothing in the app you actually use afterwards is measured at all — not what you record, not when, not how often, not what you look at. Apple may additionally share aggregated, opt-in crash and usage statistics with us through App Store Connect; whether that happens is controlled by your own iOS “Share with app developers” setting, and what reaches us is statistical and cannot identify you.
Crash reports and the counters rest on your consent (Article 6(1)(a) GDPR), asked once at the end of setup and withdrawable at any time in Settings ▸ Diagnostics; withdrawing stops everything further, and has no effect on what was lawfully sent before. The version and maintenance check rests instead on our legitimate interest in not leaving a broken build running (Article 6(1)(f)), and push registration exists only once you have granted notifications. All of this sits on Google infrastructure, which may involve a transfer outside the European Union under the Standard Contractual Clauses. Crash reports are kept for Crashlytics' own retention period and are not combined with anything else about you — we would have nothing to combine them with.
7. iCloud backup
If enabled, the app writes one backup file — dreams, settings, medals; never the audio — to your own iCloud Drive, under your Apple account and your agreement with Apple. We have no access to your iCloud and hold no keys to it. You can delete the backup from the app or from iCloud Drive at any time.
The file is encrypted before it leaves the phone. When you switch the backup on you choose a passphrase: the archive is encrypted with a random key, and that key is in turn locked with your passphrase. Only the encrypted result reaches iCloud Drive — unreadable to Apple and to us, whether or not you have Advanced Data Protection switched on.
You can choose whether to save the key to your iCloud Keychain, which Apple encrypts end-to-end always: that is what lets the backup restore itself on a new phone. If you choose not to, your passphrase is the only copy that exists — and if you forget it, the backup stays unreadable for ever: we cannot recover it, and neither can Apple. The app tells you so, in those words, at the moment you make that choice.
8. Purchases
Purchases and subscriptions are handled by Apple through the App Store; we never see your payment details. To know whether your subscription or lifetime purchase is active, the app uses RevenueCat (RevenueCat, Inc., United States), acting as our processor. RevenueCat receives the App Store receipt and its purchase events — which product, when bought or renewed, in which country and currency — under a random identifier minted for the installation: the app has no accounts, so there is no name, email or payment detail to attach, and nothing of your dreams ever reaches it. It answers one question — whether the paid features are unlocked — and gives us aggregate revenue statistics; we build no profile from it. The transfer to the United States rests on the safeguards of Article 46 GDPR (Standard Contractual Clauses).
9. This website
- Newsletter. If you subscribe, we process your email address, on the basis of your consent (Article 6(1)(a) GDPR), for the sole purpose of sending you the letter. You can unsubscribe from any email or by writing to us; we then delete the address. The mailing is operated by Brevo (Sendinblue SAS, France), acting as our processor, which handles the address within the European Union.
- Cookies. The site sets at most three first-party cookies: one essential (remembers your consent choice), one optional for anonymised visit counts, one optional for attribution. The optional ones stay off until you switch them on. The full table is in the cookie policy, and you can change your choice there at any time.
- Hosting. The site is served by Cloudflare (Cloudflare, Inc., United States), acting as our processor, which processes ordinary technical server logs (IP address, user agent) to deliver the pages and keep them secure — our legitimate interest, retained briefly. The transfer to the United States rests on the Article 46 GDPR safeguards (Standard Contractual Clauses).
10. Legal bases and retention
For the little we actually process: the newsletter email rests on consent and is kept until you unsubscribe; the weather request happens only to provide a feature you asked for and only with your iOS location permission; the model download and catalogue check are necessary to deliver and safeguard the interpretation feature (performance of the contract, and our legitimate interest in withdrawing a defective model); crash reports and the three sets of counters rest on your consent (Article 6(1)(a)), which is asked once at the end of setup and can be withdrawn at any time in Settings ▸ Diagnostics, as easily as it was given (Article 7(3)); the version and maintenance check rests on our legitimate interest in keeping the app working; purchase and entitlement data are necessary to perform the contract (Article 6(1)(b)); the push registration exists only after you grant notifications and serves to deliver them; website logs rest on legitimate interest. Nothing else about you is retained by us, because nothing else reaches us.
11. Your rights
Under Articles 15–22 GDPR you have the rights of access, rectification, erasure, restriction, portability and objection. For everything the app stores, those rights are in your own hands, immediately: read, edit, export and erase from within the app — we could not comply on your behalf even if asked, because we hold no copy. For the newsletter email or anything about this website, write to privacy@tierce.app; we answer within thirty days. You may also lodge a complaint with the Italian supervisory authority (Garante per la protezione dei dati personali, garanteprivacy.it) or with the authority of your country of residence.
The anonymous counters are the one thing we cannot delete on request — because they are not yours. When a counter goes from 3,310 to 3,311, nowhere does it record who moved it: no identifier, no document about you, no timestamp fine enough to line two writes up. That is true of all three of them — the answers, the setup screens, the thumbs on a reading. They are not personal data, so Article 17 does not reach them; and building a way to remove your contribution would require knowing it was yours — that is, keeping exactly the identifier this design does not have. What you can do at any time is withdraw consent in Settings ▸ Diagnostics: nothing further is sent from then on.
12. International transfers
The requests listed in section 6 are made directly by your device to the providers named there. The weather service operates from the EU; the model host may serve files through a content-delivery network outside the EEA — requests that contain no personal data beyond the IP address any internet request necessarily carries. The diagnostic, configuration, notification and purchase services — Google and RevenueCat — are United States providers: those transfers rest on the safeguards of Article 46 GDPR (Standard Contractual Clauses, and the EU–US Data Privacy Framework where the provider is certified). Your dreams take part in none of this: they are not in any of these systems.
13. Children
Tierce is not intended for anyone under sixteen, and we do not knowingly collect data from them.
14. Users in the United States
We do not sell or share personal information within the meaning of the California Consumer Privacy Act. We never receive consumer health data, so nothing is collected, shared or sold within the meaning of the Washington My Health My Data Act or similar state laws. The app is not directed at children under thirteen (COPPA).
15. Automated decisions
The app makes no automated decision that produces legal effects or similarly significant effects on you (Article 22 GDPR). Interpretations are reflections offered to you, on your device; they decide nothing.
16. Changes
If this policy changes, the date at the top changes with it, and material changes are announced in the app or on this site before they take effect. The promises about your dreams staying on the device are the architecture of the product, not a preference — a change to them would be a different product, and would require your explicit consent, not a quiet edit to this page.
Data controller: Francesco Dallatorre, Via Gaetano Modonesi 24, 29122 Piacenza, Italy. Supervisory authority: Garante per la protezione dei dati personali. Contact: privacy@tierce.app.