Effective: September 15, 2026 Who we are: CtrlAltBreak LLC ("we", "us"). Contact: [email protected].
This is a separate document from our Privacy Policy, as required by Washington's My Health My Data Act (MHMDA). It covers the one kind of information the app can send us that may be considered consumer health data: the abstract tags about a dream that you may choose to share. Nevada's consumer health data law asks for substantially the same disclosures; this document is intended to satisfy both.
Dream tags can say something about your mental state — that is what makes them interesting in aggregate, and it is why we treat them as consumer health data rather than argue about whether the law reaches them.
When you share a dream, we receive exactly:
| Field | What it is |
|---|---|
date |
The calendar day of the dream, in your local date. Never a time of day. |
tags |
A short list of abstract words or phrases generated on your phone (for example "water", "being chased", "childhood home"). Capped in number and length. |
schema, checksum |
Technical fields: the payload version, and a hash so a corrupted upload is rejected. |
We do not collect: your dream text, the reading, audio, your name, any account or device identifier, precise or approximate location, time of day, or any other health information. There is no account. Our database has no column that could hold any of these.
The only source is you: the Dreamalickish app on your phone, sending the payload you approved. The tags are generated on your phone from your dream; the dream itself is the app's input and never leaves the phone.
One purpose: to combine shared tags with everyone else's into aggregate trend views inside the app (The Collective) — which tags are common on a given night, which are rising or fading over time, how many people dreamt. The same aggregate statistics may be provided to others through our data API (section 4). That is all.
We do not use shared tags to provide you with individual readings (those are generated on your phone from your own dream), to make decisions about you, to advertise to you, or for any other purpose.
No one receives shared tags. They are used only as aggregate counts and trends — shown inside the app to other people who have also contributed, and provided to third parties (media, researchers, developers) through a paid data API. No individual contribution is ever displayed, returned, or disclosed. A night's tags are only shown once enough separate people have contributed that no single contribution can be picked out.
The aggregate statistics provided through the data API are de-identified data, not consumer health data, and we hold ourselves to MHMDA's definition of that term:
We have no affiliates. We do not share consumer health data with processors, vendors or any third party. Our server is hosted by an infrastructure provider (DigitalOcean, with Cloudflare in front of it), which stores our database as any host does; it has no access to contributions beyond that, and contributions contain nothing identifying in any case.
We do not sell shared tags or any other consumer health data, and we will not. Under MHMDA, a sale would require your separate written authorization with specific contents. We have never asked for one and have no plan to. Licensing de-identified aggregate statistics (section 4) is not a sale of consumer health data: the statistics contain no consumer health data and cannot be traced back to any contribution or person.
MHMDA requires consent to collect and a separate consent to share. Ours works like this:
Shared tags are not connected to an account (there is none), a device identifier (none is sent), your IP address (used only to deliver the response and protect the service; not stored with contributions — our database has nowhere to put it), or a time of day (only the date is sent, and our server stores no timestamps at all).
The access token the app receives after sharing is a random signed string that lets the app read the trend views for about a day. It carries no information about you or about which dream you shared, and our server keeps no record of which token was issued for which contribution.
Because of this, sharing is permanent. Once a contribution is sent, there is no way — for us or for anyone — to find it again and connect it to you. We cannot return it to you and we cannot delete it, even if you ask, because we cannot tell which one is yours. This is the design, not an oversight: it is what makes "nothing about you" true. The app says so on the consent screen before you agree.
We do not use geofencing around any facility, and we collect no location data of any kind.
Washington (and Nevada) residents have the right to:
How to exercise them: email [email protected] with "consumer health data request" in the subject. We will respond within 45 days (extendable once by 45 days where reasonably necessary, in which case we will tell you). You may use an authorized agent; we will ask for evidence of the authorization.
What we can and cannot do:
We will not discriminate against you for exercising any of these rights.
Contributions travel over TLS. The server stores contributions in a database with no identifying fields — the strongest protection for this data is that there is nothing in it to protect.
When this document changes, the effective date above moves, and if the change is material the app will ask for your consent to share again before anything is shared under the new terms.
CtrlAltBreak LLC [email protected]