Infidreams
Your information, your choices

Privacy Policy

Last updated 30 September 2026
Infidreams is provided by Infidreams Industries Private Limited. You can use it without an account. Your private notes, dreams, tasks, and attachments start in an encrypted notebook on your device. Signing in is optional and lets you sync saved pages across your devices. Hosted publishing, sharing, and AI remain unavailable. Advanced settings let you choose a compatible server; its operator is responsible for the information it receives. This policy explains the information involved in those optional connections.
Request account or data deletion

When you stay offline

The private core works without signing in or connecting to the internet. Infidreams encrypts your saved pages and attachments before storing them locally. On iPhone and Android, the encryption key is held in protected device storage. In a web browser, both the encrypted content and the key are held in that browser profile; someone who can access or compromise the profile may be able to read them. Keep your device secure and make an encrypted backup if you need a recovery copy.
Voice clips, photos, drawings, files, and local reminders are used only when you choose those features. A readable Markdown or text file that you export is not encrypted by Infidreams. An encrypted .infi backup is a separate export that you protect with a passphrase.
The web app also keeps an encrypted copy of your section searches, filters, selected collection and scroll positions in that browser tab so a refresh can return you to the same view. These choices are not sent to our servers or included in notebook sync or backups. Your browser may retain them when it restores a tab. Signing out, replacing the notebook or starting over clears this view history.

If you choose private sync or an account

Private sync sends encrypted copies of your vault and media to the sync service so devices you pair or sign in on can use them. Sync does not publish a page or send it to AI. The service stores ciphertext and operational information needed to deliver it, such as opaque vault and device identifiers, versions, sizes, and timestamps. It cannot read the contents of those encrypted copies through the sync service alone.
If you create an optional recovery account, the service also receives your email address, an authentication verifier, and an encrypted recovery bundle. An account is not needed for the offline app.
Account verification and password-recovery emails are sent through Amazon SES. SES receives the destination address and security message, not your notebook. We do not use these emails for marketing. Bounce and complaint alerts go to infidreams@infidreams.com; SES suppresses failed or complained-about recipients. Automatic delivery through a second provider is disabled.
Codes expire after ten minutes and allow at most five attempts. Password recovery requires both an emailed code and a connected device with your notebook key; an email code alone cannot decrypt your notebook. The server stores code digests, not readable codes. Sending and authentication limits use short-lived counters, including keyed hashes of email or IP addresses; no notebook content is included.

If you browse, publish, or share

Browsing Discover requests public posts from the service. It does not upload your private vault. Standard network requests may expose technical details, such as your IP address, to the service and its infrastructure providers.
Publishing is a separate action. Before it is sent, you review the public copy: your chosen profile name and handle, page type, title, text, and tags. That copy can be read by other people. Private source IDs, private links, attachments, and extra fields are not part of the public copy. You can unpublish the copy from the service, but that cannot erase copies, screenshots, or caches already held by others.
One-to-one trusted sharing is also separately reviewed. The selected page content is encrypted for the other member; the relay can still see opaque routing, membership, and timing information needed to deliver it. A person who has already received or saved a copy may keep it after you close the space.

If you ask for AI help

AI assistance is off by default and requires an online connection. Before each request, you see the page information that will be sent and approve that single request. The request can include the chosen page's type, title, text, tags, status, and progress, plus a code used to prevent misuse. It does not send your entire vault, profile, private links, or other pages. Infidreams sends the approved request to OpenAI and does not apply the reply to your notes automatically.
The API request asks OpenAI not to store the response as application state. OpenAI may still process or retain request information for abuse monitoring under its own data controls. Do not send material you do not want an AI provider to process.
Before showing a generated reply, our service also sends that reply to OpenAI for a safety check. A flagged reply, or one we cannot check, is not shown. Automated checks can make mistakes; you can report a reply that concerns you.
If you report an AI reply, you review and approve sending that reply, its model name, the reason and your explanation to your connected service's team. The report is linked to your account. The original page is not sent again, but the reply may quote it. Reports are kept for safety review until removed through an account or data deletion request; they are not published or used to change your private notebook.
Read OpenAI's API data controls

Optional blog updates

Our marketing website links to an optional email subscription on the Infidreams blog, hosted by WordPress.com. If you subscribe there, WordPress.com processes your email address and subscription preferences to deliver blog updates. Follow any inbox confirmation step and use the unsubscribe link in those emails to stop them. This subscription is separate from your Infidreams account; creating an account, sending feedback or requesting a login code does not subscribe you.
WordPress.com privacy information

Optional feedback and usage counts

Help & support lets you prepare an email describing a problem or idea. You review it and send it yourself; your email address and the message then reach our support team. No notebook content or diagnostics are attached automatically.
You can also choose to send a rating from 1 to 5 for an area of the app. Separately, you can turn on basic usage sharing on each device. It is off by default. We count app openings, successful saves, failed save attempts, sync outcomes and help visits. Neither option sends note content, titles, account identifiers, page addresses, precise location or a persistent device identifier to the product-reporting system. We do not use these signals for advertising or marketing consent.
Our server combines signals into daily counts by event, platform, area and rating. Reports cover the latest 90 days; older counters are removed during subsequent collection. A random, one-off receipt is retained for up to eight calendar days to avoid duplicates, then removed during subsequent collection. Short-lived network-based counters limit abuse. Hosting providers process request metadata, including network addresses, as part of running the service. Individual responses cannot be retrieved from the aggregate counts or linked back to an account.
Turn usage sharing off in Help & support to stop future counts from this device. Already combined counts cannot be individually identified or removed. Survey ratings are sent only when you press Send rating. These optional features need an internet connection; they do not affect offline writing, and unsent usage events are not queued for later delivery.

Service providers and security limits

Our hosting and database providers process the information needed to operate connected features. OpenAI processes only an AI request you approve. No security design can eliminate the risks of a compromised device or browser, an exposed passphrase, or a copy you deliberately share. The web app cannot provide the same protected-key or screen-capture boundary as the native apps.

Delete your Infidreams account or data

You can use the app offline, turn off AI, disconnect sync, remove local pages, unpublish a public post, and erase this device's local vault. An exported backup remains wherever you saved it. Removing local data or disconnecting sync does not by itself remove every server-held copy.
To request deletion without installing or signing into the app, email rohan@infidreams.com with the subject “Infidreams account or data deletion”. Say whether you want your account and associated data removed, or only particular data. If you created an account, write from its email address where possible and identify the server you used. We will verify your request before removing information. Never send a password, encryption key, pairing code, backup passphrase, or your notebook.
An account-wide request covers the account email and authentication record, encrypted recovery copy and synced notebook, published copies, and associated service records that Infidreams controls. You may instead request removal of particular published copies or other information without deleting your account. If you chose a different server, contact that server's operator; we cannot delete records on a service we do not control.
Where your connected service supports it, Account also offers Delete account and server data. Read its confirmation carefully: local notes, your exported backups, and copies other people have saved are separate. If deletion cannot be completed in the app, use the email request above.
Our current production database has a seven-day recovery window, so a deleted record may remain in a recovery copy until that window expires. Opaque records that prevent deleted accounts, old invitations, or sharing events from being reused can be retained without an automatic expiry; they do not retain your notebook text. Account and sync records otherwise have no automatic expiry. We will explain any other required retention when responding to your request. Copies held by recipients, exports you control, and records held by a custom server are outside this deletion process.
Email a deletion request

Contact and changes

For privacy questions or requests, including if you use Infidreams without an account, contact us directly:
rohan@infidreams.com
We will update this page when our features or handling of information change. The date above shows the latest policy revision.
Infidreams · Private on this device · Works offline