Privacy policy
pursuant to art. 13 of Regulation (EU) 2016/679 (GDPR)
This policy describes how the personal data of users who visit and use the Dreamer web application, available at www.dreamerapp.it (the "Application"), is processed.
It covers browsing the Application, creating and using an account, conversations with the conversational companion "Dreamer" and suggestions sent through the dedicated form.
1. Data controller
The data controller is Boutique AI LLC, a company incorporated under the laws of the State of Wyoming, with registered office at 5830 E 2nd St, Ste 7000, Casper, Wyoming 82609, United States of America, reachable at the email address: boutiqueai.office@gmail.com.
2. Scope of this policy
This policy applies exclusively to the Application indicated above and to the processing connected with its use.
It does not apply:
- to third-party websites, platforms or services that may be reached through links in the Application (for example the website elio-danna.com and the book purchase pages), over which the Controller has no control and for which reference is made to their respective privacy policies;
- to processing carried out within contractual relationships with clients, suppliers or partners, governed by separate policies.
The Controller has not appointed a Data Protection Officer (DPO), as the conditions of art. 37 GDPR do not apply.
3. Personal data processed
Through the use of the Application, the Controller may process the following categories of personal data:
a) account data: email address, name (optional), password (stored exclusively in encrypted form and never readable by the Controller), chosen language, registration date, date and version of acceptance of the Terms;
b) conversation content: the questions the user writes to the Dreamer and the generated answers, with the references to the passages of the books;
c) suggestions sent through the "Leave a suggestion" form, with the account email and the date sent;
d) usage data: number of questions asked per day, date and time of conversations;
e) technical browsing data, such as IP address, device identifiers, browser type, operating system, language settings, date and time of access, pages visited, needed for security, technical operation, prevention of abuse, unauthorised access or fraudulent activity.
Notice. Conversations with the Dreamer by their nature concern the user's personal life. Users are invited not to enter special categories of data under art. 9 GDPR (for example data concerning health, religious, philosophical or political beliefs), judicial data, login credentials, payment data, or confidential information or personal data relating to third parties. Any such data is provided spontaneously and under the user's responsibility.
4. Purposes and legal bases of processing
Personal data is processed for the following purposes.
a) Provision of the service
Account data and conversation content are processed to create and manage the account, authenticate the user, store their conversations, apply daily usage limits and provide the Dreamer's answers.
Legal basis: art. 6(1)(b) GDPR, performance of the contract to which the data subject is party (the Terms and conditions accepted at sign-up).
b) Features based on artificial intelligence
The Dreamer's answers are generated by artificial intelligence systems. The user's questions, the recent conversation and the selected passages of the books are transmitted to third-party providers of AI models and infrastructure (currently Anthropic PBC, United States of America), appointed as processors where they act on behalf of the Controller. Only the content needed for the single answer is transmitted, without the user's name or email.
The generated outputs are informational and for personal reflection and do not determine any decision with legal or similarly significant effects on the user.
Legal basis: art. 6(1)(b) GDPR, performance of the contract.
c) Improvement and training of the Dreamer
Conversations are stored in anonymous form: in the Controller's control centre users appear only under a pseudonym, never with name or email. In that anonymous form conversations are used to analyse the quality of the answers, correct mistakes, refine the instructions and the criteria for selecting passages and, in general, to train and improve the Application and the model behind it, so that it keeps improving.
Legal basis: art. 6(1)(a) GDPR, the data subject's consent, given at sign-up by accepting the Terms and this policy; art. 6(1)(f) GDPR, the Controller's legitimate interest in improving the service, for analyses carried out on anonymised data.
d) Technical operation and security
Technical browsing and usage data is processed to allow the Application to work correctly, guarantee the security of the infrastructure, prevent abuse, anomalies, cyber attacks, automated sign-ups or improper use, and to apply usage limits.
Legal basis: art. 6(1)(f) GDPR, the Controller's legitimate interest in the correct operation, security and protection of the Application.
e) Handling of suggestions
Suggestions sent by the user are processed to read and evaluate them and, where useful, to contact the user at the account email address.
Legal basis: art. 6(1)(b) GDPR and art. 6(1)(f) GDPR, the Controller's legitimate interest in improving the service.
f) Protection of the Controller's rights
Data may be processed to establish, exercise or defend a right of the Controller, including out of court, in court or before competent authorities.
Legal basis: art. 6(1)(f) GDPR, the Controller's legitimate interest in protecting its rights.
5. Cookies and tracking technologies
The Application uses exclusively first-party technical cookies, needed for authentication and to keep the user's session. It does not use statistical, advertising or profiling cookies, nor third-party tools that install cookies: for this reason no consent banner is shown.
For further information, please see the Cookie Policy.
6. Nature of the provision of data
Providing an email address and a password is necessary to create the account and use the Application: without them the service cannot be provided. Providing a name is optional.
Acceptance of the Terms and of this policy, including the use of conversations in anonymous form to improve the Dreamer, is a condition for sign-up. Users who do not wish to accept may choose not to sign up and may at any time delete their account from the dedicated page of the Application.
7. Processing methods and principles
Processing is carried out with IT, telematic and organisational tools suitable to guarantee the security, confidentiality, integrity and availability of personal data. The full text of the books is kept exclusively on the Controller's servers and is never transmitted to the user's device. Conversations are accessible only to the user who created them and, in pseudonymised form, to the service administrators.
The Controller processes personal data in compliance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability.
8. Recipients of the data
Personal data may be processed by persons authorised by the Controller, within the limits of their duties and according to the instructions received.
Data may also be processed by external providers supplying services functional to the operation of the Application, including:
- hosting and technical infrastructure providers (currently Vercel Inc., with execution in the Frankfurt region);
- database and authentication providers (currently Supabase Inc., with data stored in the Frankfurt region, European Union);
- providers of AI models, APIs and infrastructure (currently Anthropic PBC, United States of America);
- maintenance, IT security and technical support providers;
- consultants, professionals or authorities, where necessary for legal obligations or protection of rights.
Where these parties process personal data on behalf of the Controller, they are appointed as processors under art. 28 GDPR. Personal data will not be disseminated.
9. Transfers of data outside the European Economic Area
The Controller is established in the United States of America: users' personal data may therefore be transferred and processed outside the European Economic Area. In addition, the AI provider is established in the United States of America.
Transfers of personal data to third countries take place in compliance with arts. 44 et seq. GDPR, on the basis of one of the mechanisms provided by applicable law, including:
- adequacy decisions of the European Commission;
- the recipient's participation in recognised frameworks, such as the EU-US Data Privacy Framework, where applicable;
- Standard Contractual Clauses approved by the European Commission;
- supplementary technical, contractual and organisational measures, where necessary.
Users may request information on the safeguards adopted by writing to the email address indicated in section 1.
10. Retention period
- Account data: for the whole life of the account and until its deletion by the user or the Controller.
- Conversation content: for the whole life of the account. When the account is deleted the associated conversations are erased. Analyses and improvements already derived from conversations in anonymous form cannot be traced back to the user and may be retained.
- Suggestions: for the time needed to evaluate them and in any case no longer than 24 months.
- Technical browsing data, logs and usage counters: for the time strictly necessary for operation, security and maintenance, as a rule no longer than 12 months, unless further retention is needed to investigate offences or protect rights.
- Data needed to protect the Controller's rights: for the time needed to manage the dispute or within the applicable limitation periods.
11. Automated decision-making and profiling
The Application does not use personal data to take decisions based solely on automated processing that produce legal effects on the data subject or similarly significantly affect them, and does not carry out profiling for advertising purposes.
The answers generated by the Dreamer are personal reflection and inspiration based on the books of Elio D'Anna and do not constitute medical, psychological, legal or financial advice.
12. Rights of the data subject
In the cases provided by the GDPR, the data subject may exercise the following rights:
- right of access to personal data;
- right to rectification;
- right to erasure (exercisable directly from the "Account" page of the Application, with the "Delete my account" button);
- right to restriction of processing;
- right to object;
- right to data portability;
- right to withdraw consent, where processing is based on consent.
Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
Requests may be sent to the Controller at the email address: boutiqueai.office@gmail.com
The data subject also has the right to lodge a complaint with the competent supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement. For data subjects established in Italy, the complaint may be lodged with the Garante per la protezione dei dati personali.
13. Changes to this policy
The Controller reserves the right to amend or update this policy, including as a result of regulatory, technical or organisational changes or changes to the services used by the Application. The updated version is always published on this page.
Last updated: 5 September 2026