Privacy Policy
Last updated: August 2026
1. Controller
Nine to Zero UG (haftungsbeschränkt)
Malzer Chaussee 173, 16515 Oranienburg, Germany
Email: mail@ninetozero.de
2. Overview
Go Lucid is a local-first app for learning lucid dreaming. You can use its local features without an account. An account is optional and enables cloud-based features such as synchronization. We process personal data only as necessary to provide, secure and improve the app.
3. Website Access / Server Logs
When you access the site, the hosting server automatically processes access data (IP address, date/time, page requested, browser type). The legal basis is our legitimate interest in secure, functional operation (Art. 6(1)(f) GDPR).
Hosting
We use hosting and service providers to operate the website and app.
4. Local Storage in the Browser
The web app stores data in IndexedDB and localStorage; the iOS app stores corresponding app data on the device. This may include journal and draft data (such as dream text, title, tags, mood, emotions, sleep quality and lucidity), goals, sleep, reminder, language and appearance settings, progress data, WBTB and lock settings, and technical session and sync data. This local storage is necessary for app functionality (Section 25(2) TDDDG; Art. 6(1)(b) or (f) GDPR).
5. User Account & Cloud Sync
If you choose to create an account or use cloud synchronization, we process your email address, authentication data, display name and optional username. You can sign in with email and password, or with Google or Apple. OAuth sign-in takes place in a browser; the respective provider's privacy policy also applies.
We use Supabase for account functions and cross-device synchronization. It processes account data as well as journal, goal, sleep, emotion and settings data. Privately stored dream images generated by the app are also kept in Supabase Storage. The legal basis is performance of a contract (Art. 6(1)(b) GDPR).
6. Internal Registration Notification
Account-related email flows may include registration confirmations, password resets and confirmation of an email-address change. Your email address is processed for these account functions.
When you register, an internal notification is sent through Resend to our company mailbox. It contains your email address, user ID and registration time. This serves operational monitoring and abuse prevention (Art. 6(1)(f) GDPR).
7. Subscriptions and in-app purchases
Where native store purchase flows are available, purchases and subscription management are handled by the relevant app store under your store account. Deleting a Go Lucid account does not itself cancel a store subscription; manage or cancel it through the relevant store.
For native store purchase flows, we use RevenueCat to validate subscriptions, restore purchases and provide subscription support. RevenueCat receives a pseudonymous Go Lucid app user ID and subscription-related platform, transaction and entitlement data. When account deletion is completed, the app requests deletion of the associated RevenueCat customer record.
8. AI features (optional)
Only when you explicitly request AI dream interpretation or image generation do we send the dream text needed for that feature to OpenAI. Interpretation sends the submitted dream text; image generation uses up to the first 300 characters in the image prompt. No transfer to OpenAI takes place without your action. An interpretation result as well as technical request data and status information are processed on the server; generated images are stored privately in Supabase Storage. The legal basis is your request to use the feature (Art. 6(1)(b) GDPR).
9. Local Features, Sharing and Cookies
Reminders are scheduled as local notifications on your device; we do not use remote push notifications. You can revoke permission at any time in your device settings.
A PIN lock and Face ID/Touch ID protect content only locally on the device; related lock data is not synchronized. The sharing feature opens the operating-system or browser share sheet only after your explicit action.
Our review of this version's app source code did not identify advertising tracking or marketing cookies. The only collection for evaluation purposes is the anonymous usage counts described in section 10. This statement does not cover storage or processing that may be used by your browser, operating system, authentication provider or other service providers.
10. Anonymous usage counts
To see where new users stop during onboarding, the app counts which steps are reached. What is transmitted is only a list of step names taken from a fixed list held in the source code (such as “first dream recorded” or “paywall viewed”), together with the calendar day on which each step was first reached.
Not transmitted: name, email address, account or device identifier, times of day, and anything from the content of your dream entries.
On the server, only shared totals per calendar day and step are stored. The table has no column for a person or device identifier, so individual devices cannot be told apart in the stored data. Each step is reported at most once per device.
Because the stored data has no personal reference, it is not subject to the GDPR. To the extent that the transmission itself constitutes processing, we base it on our legitimate interest in improving onboarding (Art. 6(1)(f) GDPR).
You can switch the transmission off at any time in the app under Account → Privacy → “Anonymous usage counts”. Nothing is sent afterwards.
11. Your Rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You may also lodge a complaint with a supervisory authority. To exercise your rights, an email to mail@ninetozero.de is sufficient.
You can start account deletion in the app. The deletion flow removes the account and its private image storage, requests deletion of the associated RevenueCat customer record, and then clears local app data after the deletion is confirmed. Deleting an account does not itself cancel a store subscription. Provider backups, logs or retention obligations may mean that some data is retained for a limited period.
12. Retention
Account and cloud data, including technical AI-request data, are generally stored while your account exists. When account deletion is completed, the app initiates their removal as described above. Server and technical-operation logs are retained only as long as necessary for secure operation or legitimate legal purposes. Provider backups, logs and applicable retention obligations may result in limited further retention. No blanket retention periods are stated.