The Vault · a room in the House of Morpheus
Morpheus Privacy Policy
A dream is the most private thing you’ll write today. This is the full, plain account of what happens to it — and where our reach ends.
Last updated: August 18, 2026
Not kept on our side
Your dream is read live, turned into a reflection, then discarded on our systems — there is no standing database of dreams to breach.
Never sold or shared
No ads, no trackers, no cross-context advertising. We do not sell or “share” your information, and we never have.
Essential tech only
Only strictly-necessary processing runs the Site — no analytics or marketing cookies, and no tracking you across other sites.
Where our reach ends
The dream form is geo-blocked in the EEA and the UK — if we detect you there, no dream is collected or sent.
Each promise above is backed, word for word, by a numbered section below.
Notice at Collection
This is the short version. The full details are below. If you use the dream form, this summary is also linked directly at the point of collection.
| Question | Answer |
|---|---|
| Who runs this? | Morpheus, a dream-reflection service operated by ADON1S L.L.C., based in California, USA. Principal office: 6601 Bertrand Ave, Reseda, CA 91335, USA. Mailing address: 6702 Balboa Blvd #2, Van Nuys, CA 91406, USA. Website: https://askmorpheus.io |
| What do we collect on the website? | The dream text you choose to type in; your IP address (for abuse-prevention, and briefly as a rate-limit key); and basic technical metadata (request length, detected language, timing, and success/failure). |
| Is any of it sensitive? | Yes. We treat the dream text you submit as Sensitive Personal Information, because a dream can reveal intimate details. |
| Why do we collect it? | To generate your psychological interpretation, and to protect the service from bots and abuse. Nothing else. |
| Do we keep your dream? | Not on our systems. Your dream and its interpretation are processed live and then discarded on our side — not saved to any database, not used to build a profile. One caveat we will not hide: to interpret your dream we send it to our AI provider (Anthropic), which may retain the request briefly for its own security and abuse-prevention purposes. See “The AI Provider.” |
| Do we sell or “share” your information? | No. We do not sell your personal information and we do not “share” it for cross-context behavioral advertising, as those terms are defined under California law. We have no advertising and no marketing trackers. |
| Do we use it to train AI? | We do not train any model of our own on your dream, and we do not have one. We send your dream to a single AI provider (Anthropic) solely to produce your interpretation. What Anthropic does with an API request is governed by Anthropic’s terms, not our code — we do not claim a “no-training” commitment we have not contractually confirmed. See “The AI Provider.” |
| How long do we keep it? | The dream itself: not retained by us (ephemeral). Your IP as a rate-limit key: about 10 minutes, then auto-deleted. Technical metadata logs (which may include your IP): no more than 30 days (Owner to confirm the configured value). |
| Your rights | You have rights to know, delete, correct, and limit the use of sensitive information, among others. Because the website keeps no account and does not retain your dream, there is usually nothing to look up or delete for the web interpreter — see “Your California Privacy Rights.” |
| Contact | hello@askmorpheus.io |
Introduction, Scope, and Who We Are
Morpheus (“Morpheus,” “we,” “us,” or “our”) is operated by ADON1S L.L.C., a business based in California, USA, with its principal office at 6601 Bertrand Ave, Reseda, CA 91335, USA (mailing address: 6702 Balboa Blvd #2, Van Nuys, CA 91406, USA). We operate the website at https://askmorpheus.io (the “Site”), a free, anonymous, one-shot dream interpreter.
Morpheus is a psychology and self-reflection tool. It is not fortune-telling, divination, prophecy, or a medical, therapeutic, or mental-health service. The interpretations we generate are for personal reflection and self-knowledge; not professional, medical, or therapeutic advice, and should not be relied on as such.
We are based in California, USA, and this policy is governed primarily by California law, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”). If you use the Site from the European Union, the United Kingdom, or elsewhere, additional sections below (see “International Users and Transfers”) describe how the EU General Data Protection Regulation (“GDPR”) and the UK GDPR apply. Please note that the web dream form is currently geo-blocked in the EEA and the UK: if we detect that you are visiting from there, we do not offer the dream form and no dream is submitted (see “International Users and Transfers”).
This policy covers the Site (the web dream interpreter). It also briefly describes what happens if you choose to follow the link from the Site to our separate Telegram bot; that bot is a distinct service with its own data handling, summarized in “The Telegram Bot (Separate Service)” below.
How we obtain your consent. Because a dream can reveal sensitive details, we do not rely on consent-by-conduct. Before you submit a dream, the dream-entry form shows a short Notice at Collection (linking to this policy) and a dedicated, un-pre-checked, unbundled consent checkbox. Ticking that box — a clear affirmative act — is the explicit consent we rely on to send your dream to our AI provider. If you do not tick it, you cannot submit, and no dream is sent.
Information We Collect
We practice data minimization: we collect only what is needed to interpret your dream and to keep the service running safely. We do not ask you to create an account, log in, or provide your name, email, phone number, or payment details to use the web interpreter. We map what we collect to the CCPA/CPRA categories below.
a. Identifiers and Internet / Network Activity
- IP address — used transiently for rate-limiting, abuse prevention, and a spending ceiling (protection against “denial-of-wallet” attacks); by our bot-protection provider (see “Cloudflare Turnstile”); and stored briefly (about 10 minutes) as a per-IP rate-limit key in a shared rate-limit store (see “Rate-Limiting and Denial-of-Wallet Store”). An IP address is personal information under the CCPA and personal data under the GDPR, and we treat it as such throughout this policy.
- Request metadata — such as request length, detected language, latency (timing), and whether the request succeeded or failed. This metadata does not contain your dream content.
b. User-Provided Content — treated as Sensitive Personal Information
- The dream text you type into the form. A dream can reveal intimate details that may touch on health, sexuality, religious or philosophical beliefs, and other private matters. For that reason, we treat the dream content you submit as Sensitive Personal Information under the CPRA, and as “special category” personal data under the GDPR / UK GDPR (Article 9) — even though we do not retain it.
What we do not collect on the Site
- No account credentials, name, email, or phone number.
- No payment or financial information (there are no payments on the website).
- No precise geolocation.
- No advertising identifiers; no analytics or marketing tracking data.
- No biometric data.
We collect the dream text directly from you, and the IP address and request metadata automatically from your device/connection when you use the Site.
How We Use Your Information, and Our Legal Bases
We use the information above only for these purposes:
| Purpose | What it involves | GDPR / UK legal basis (for EU/UK visitors) |
|---|---|---|
| Generating your interpretation | Sending your dream text to our AI provider to produce a psychological reflection, streamed back to your browser | Your consent (Art. 6(1)(a)); and for the sensitive/special-category content, your explicit consent (Art. 9(2)(a)), given by ticking the consent checkbox on the dream-entry form before you submit |
| Abuse and security protection | Using your IP address for rate-limiting, spend ceilings, and bot detection (Turnstile), including storing it briefly as a rate-limit key | Our legitimate interests (Art. 6(1)(f)) in keeping the service available, secure, and not abused |
| Operating and debugging the service | Server logs that may include your IP, containing length, language, latency, and success/failure — never dream content | Our legitimate interests (Art. 6(1)(f)) in a reliable, working service |
| Legal compliance | Responding to lawful requests and enforcing our terms | Legal obligation (Art. 6(1)(c)) / legitimate interests |
We do not use your information for advertising, profiling, or automated decisions that produce legal or similarly significant effects about you. Your dream is used to generate one interpretation for you — it is not used to build a profile.
You may withdraw consent at any time by not submitting further dreams; because the web interpreter does not retain your dream, there is typically no stored copy to withdraw. Withdrawing consent does not affect processing already carried out.
The AI Provider (Anthropic)
To generate your interpretation, we send your dream text to a single third-party AI provider, Anthropic (the Claude API), based in the US. Anthropic processes the text on our behalf to return a psychological interpretation, which we stream back to your browser.
- We send only the dream text needed to produce the interpretation. We do not send your IP address, an account identifier, or a persistent user ID to the AI provider with the dream, because the web interpreter has no accounts and creates no such identifier.
- After your interpretation is generated and streamed to you, we discard both the dream text and the interpretation on our systems. We do not store them in a database, persist them, or write them to our logs. This “not retained” statement describes our systems. Anthropic, as our provider, may retain and process the request transiently to provide the service and for its own trust-and-safety / abuse-prevention purposes, as described in Anthropic’s terms and policies.
- Anthropic acts as our processor (service provider) under a data-processing arrangement. You should review Anthropic’s own privacy terms for details of its handling and retention.
Owner to confirm the exact commercial API tier, its retention window, its trust-and-safety retention, and whether a no-training / no-retention-for-training commitment applies — and align this section to the true contractual position. We do not claim “no training” unless the contract provides it.
We do not send your dream to any other third party for interpretation, analytics, advertising, or profiling.
Cloudflare Turnstile (Bot and Abuse Protection)
To protect the Site from bots and automated abuse, we use Cloudflare Turnstile, a privacy-friendly alternative to traditional CAPTCHAs, provided by Cloudflare, Inc. To perform its check, Turnstile processes your IP address and a challenge token through Cloudflare. This is used solely to distinguish real visitors from automated abuse; it is not used for advertising, and we do not receive your dream content through it. Cloudflare acts as our service provider/processor for this function. See Cloudflare’s own privacy documentation for how it handles Turnstile data.
Rate-Limiting and Denial-of-Wallet Store (Your IP Address)
Because the web interpreter is open and unauthenticated, we enforce a per-IP rate limit and a global daily interpretation ceiling to prevent abuse and “denial-of-wallet” attacks. So these limits hold across our serverless infrastructure (rather than per server instance), we use a shared rate-limit store — a managed key-value store (Vercel KV / Upstash Redis) acting as our service provider/processor.
- Your IP address is written to this store as a short-lived rate-limit key. It is stored for about 10 minutes (the length of the rate-limit window) and then auto-expires and is deleted. The daily-ceiling counter does not include your IP.
- This store holds only a counter keyed to your IP for that short window — never your dream, and no dream content ever reaches it.
- In deployments where this shared store is not provisioned, the same limits fall back to in-process memory (no external store). The shared store is the intended production configuration for the global spending ceiling.
Owner to confirm a data-processing agreement is in place with this store’s provider and its region — a store located outside the EEA is an international transfer of your IP (see “International Users and Transfers”) — and to consider hashing/HMAC-ing the IP before it is used as a key, so the store never holds a raw identifier.
Hosting and Server Logs
The Site runs on a serverless hosting platform (Netlify or Vercel) acting as our service provider/processor. *(Owner to confirm which host is live.)* Standard server request logs generated by the host as part of normal operation may include your IP address and request metadata (such as length, detected language, latency, and success/failure).
Our application logs are designed to exclude dream content, and we do not write your dream to any log. We treat any IP address that appears in host or application logs as personal information. These logs are retained for no more than 30 days *(Owner to confirm the configured value)* and used only to operate, secure, and debug the service.
How our logging holds this line: every log line we control carries strictly metadata — the request length, detected language, latency, HTTP status, and an error type (a short code such as “overloaded”), plus token counts. Even when our AI provider returns an error, we record only that error’s type and status code — never the provider’s free-text message body, and never your dream. No dream content, and no provider message text, is ever written to our logs, shown to you, or shared with any third party.
Your California Privacy Rights
If you are a California resident, the CCPA/CPRA gives you the rights below. An important, honest note first: the web interpreter has no accounts and does not retain your dream or its interpretation. For the web interpreter, when you submit a “know/access,” “delete,” or “correct” request, there is usually nothing for us to look up, return, delete, or correct, because we do not hold it.
What we do hold, and only briefly, is short-lived technical data tied to an IP address: an IP-keyed rate-limit counter (about 10 minutes) and host/application logs that may contain your IP (no more than 30 days). These are tied to an IP address, not to an account or your identity, and are not used to look you up. (If you use the separate Telegram bot, that service has its own erasure control — see “The Telegram Bot.”)
The categories of recipients to whom we disclose personal information for a business purpose are: our AI provider (Anthropic), our bot-protection provider (Cloudflare), our hosting provider (Netlify/Vercel), and our rate-limit store provider (Vercel KV / Upstash Redis). We disclose to none of them for money or for cross-context behavioral advertising.
Your rights
- Right to know / access. You may request the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of recipients (listed above). As noted, for the web interpreter we typically hold nothing tied to your identity.
- Right to delete. You may request deletion of personal information we hold about you. Because we do not retain your dream, there is generally nothing to delete for the web interpreter.
- Right to correct. You may request correction of inaccurate personal information we maintain. Because we do not retain your dream, there is generally nothing to correct for the web interpreter.
- Right to opt out of sale/sharing. As stated above, we do not sell or share your personal information, so there is nothing to opt out of.
- Right to limit the use of Sensitive Personal Information. You may request that we limit our use of sensitive personal information to what is necessary to provide the service. We already use the dream content you submit only to generate your interpretation and then discard it on our systems — we do not use it to infer characteristics about you, and we do not retain it — so this limit is built in by design.
- Right to non-discrimination. We will not discriminate against you for exercising any of these rights (for example, by denying service or degrading quality).
- Authorized agent. You may use an authorized agent to submit a request on your behalf; we may require proof of the agent’s authorization and may still verify your identity.
- Verification. To protect your privacy, we may need to verify your identity before acting on certain requests. Because the web interpreter is anonymous and account-free, we may be unable to associate a request with any specific data, and we may ask for additional information to locate any records — or explain that we hold none.
How to exercise your rights: email us at hello@askmorpheus.io. We will respond within the timeframes required by law. If we cannot fulfill a request (for example, because we hold no data tied to you, or cannot verify your identity), we will explain why. You may appeal a decision by replying to our response. *(Owner: confirm whether a toll-free number or a second request method is required for your business.)*
Data Retention
- Your dream and its interpretation (web interpreter): not retained by us. They are processed live to produce your interpretation, streamed back to you, and then discarded on our side — not stored in a database, not persisted, and not written to logs. (Our AI provider may retain the request briefly — see “The AI Provider.”)
- Your IP address as a rate-limit key: about 10 minutes, then it auto-expires and is deleted.
- Technical metadata logs (which may include your IP): no more than 30 days *(Owner to confirm the configured value)*, then deleted.
- Bot-protection data (Turnstile): handled by Cloudflare per its retention practices for security tokens and IP addresses.
We keep information only as long as necessary for the purposes described, or as required by law.
Security
We take security seriously and treat every submitted dream as private.
- Encryption in transit: connections to the Site and to our AI provider are protected with industry-standard transport encryption (HTTPS/TLS).
- No retention of dream content on our systems: because we do not store your dream, there is no standing database of dream content on our side to be breached.
- Metadata-only logging: our logs are designed to exclude dream content.
- Identifier minimization: we keep IP-keyed rate-limit entries short-lived, and we are evaluating hashing the IP key so the store never holds a raw identifier.
- Secrets management: credentials and API keys are held in server environment configuration, not in client-side code or public repositories, and are not exposed to your browser.
- Least privilege and abuse controls: rate-limiting, a spending ceiling, and bot protection guard the service.
No method of transmission or processing is ever 100% secure, and we cannot guarantee absolute security; we work to protect your information using reasonable and appropriate safeguards.
International Users and Transfers (EU / UK / GDPR)
The Site is operated from the United States, and our AI provider (Anthropic), our bot-protection provider (Cloudflare Turnstile), hosting, and rate-limit store may be US-based. The web dream form is currently geo-blocked in the EEA and the UK: if we detect that you are visiting from the EEA or the UK, we do not offer the dream form, and no dream text is submitted or transferred. For visitors outside the EEA/UK, the information you provide — including the dream text you submit and your IP address — will be transferred to and processed in the United States (or wherever a subprocessor’s region is located). A request that reaches us from a blocked region may still involve transient processing of your IP address in the US to serve the region notice, but no dream is ever read or sent.
Where our reach ends — the EEA and the UK. Because interpreting a dream processes special-category data, we have chosen not to offer the web dream form to visitors we detect in the EEA or the UK for now. We resolve your country from a single trusted edge signal (never from anything you can set), and a blocked visitor is shown a short region notice instead of the form — no dream is collected or transferred. *(Owner/counsel to confirm this geo-block means an EU/UK Art. 27 representative is not required for the web interpreter.)*
- Controller. The controller of your personal data is ADON1S L.L.C. (California, USA), principal office 6601 Bertrand Ave, Reseda, CA 91335, USA (mailing address: 6702 Balboa Blvd #2, Van Nuys, CA 91406, USA). Contact: hello@askmorpheus.io.
- EU / UK representative (Art. 27) — addressed by the geo-block. An Art. 27 representative can be triggered where a service offers goods or services to individuals in the EEA/UK (Art. 3(2)). Rather than appoint one now, we geo-block the EEA and the UK from the web dream form, so the web interpreter does not offer that surface to EEA/UK visitors and does not collect special-category dream data from them. *(Owner/counsel to confirm this geo-block means an EU and a UK representative are not required for the web interpreter, before publishing. If the form is ever opened to the EEA/UK, an EU representative and a UK representative must be appointed and NAMED first.)*
- Legal bases. See the table in “How We Use Your Information.” For the sensitive dream content we rely on your explicit consent (Art. 9(2)(a)), given by ticking the consent checkbox on the dream-entry form.
- Article 9 special-category note. Dream narratives can reveal data about health, sex life, and religious or philosophical beliefs, which are “special category” data under Art. 9. We process this data only on the basis of your explicit consent (given by ticking the consent checkbox), solely to generate your interpretation, and we then discard it on our systems. We do not use it for any other purpose.
- International transfer safeguards. Transfers to the US (including to Anthropic, Cloudflare (Turnstile), the host, and the rate-limit store where US-based) are made under appropriate safeguards, such as the Standard Contractual Clauses (SCCs) and/or the EU–US / UK–US Data Privacy Framework where applicable, together with our data-minimization and no-retention practices. *(Owner/lawyer to confirm the specific transfer mechanism relied on with each subprocessor, including the region of the rate-limit store.)*
- Your GDPR/UK rights. You have the rights to access, rectify, erase, restrict, and object to processing, to data portability, and to withdraw consent at any time (which will not affect processing already carried out). Because we do not retain your dream, most access/erasure requests for the web interpreter will have nothing to return. You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office).
Children’s Privacy
The Site is intended for adults and is not directed to children. We do not knowingly collect personal information from children under 13 (in line with the US Children’s Online Privacy Protection Act, “COPPA”), and we treat under-16 users as children for the purposes of the CCPA/CPRA sale/sharing rules (which do not apply to us in any case, since we do not sell or share). For EEA/UK visitors, the minimum age for consent to use the Site is 16, or a lower age (down to 13) where your country’s law sets one. If you believe a child has submitted information to us, contact hello@askmorpheus.io; because we do not retain submitted dreams, there is typically nothing stored to remove, but we will address the matter.
The Telegram Bot (Separate Service)
The Site includes a soft call-to-action linking to our Telegram bot, @askmorpheus_dream_bot. The Telegram bot is a separate service with different data handling than the website. This policy primarily covers the Site. To be transparent about the difference:
- If you choose to use the Telegram bot, the dreams you send there are stored and linked to your Telegram user ID, so the bot can offer its memory/pattern features over time. *(Owner to confirm the exact at-rest protection before describing it here — do not overstate it.)*
- The bot provides an in-service erasure control: you can send the /forget command to have your stored dreams erased.
- Using the bot means interacting through Telegram, which is subject to Telegram’s own privacy practices.
If and when a standalone privacy notice for the Telegram bot is published, it will govern that service in detail. *(Owner: confirm whether the bot should have its own dedicated notice and link it here.)*
Changes to This Policy
We may update this policy from time to time — for example, if we add a feature, a new subprocessor, or (as noted) analytics. When we do, we will revise the “Last updated” date at the top and post the updated policy on this page. If we add analytics, advertising, or any new sharing of your information, or make other material changes, we will update this policy before those practices take effect and, where the law requires, seek your consent. Your continued use of the Site after an update means you acknowledge the revised policy.
Contact Us
If you have questions about this policy or want to exercise your privacy rights, contact us at:
- Email: hello@askmorpheus.io
- Operator / controller: ADON1S L.L.C.
- Physical address: 6601 Bertrand Ave, Reseda, CA 91335, USA
- Mailing address: 6702 Balboa Blvd #2, Van Nuys, CA 91406, USA
- Service: Morpheus — https://askmorpheus.io
The shorter, human version of these promises — and the terms of use — live in the back-room ledger. Nothing there contradicts this page.
