Effective 30 September 2026
Privacy Policy
What Dreamboard receives, what stays on your device, why data is used, and the controls available to you.
1. Scope and contact
This Notice explains how Dreamboard handles personal information when you visit our sites, create an account, use cloud or agent features, purchase a subscription, contact us, or join a waitlist. Dreamboard is the business responsible for this handling unless we say otherwise.
Dreamboard GamesABN: 49 198 836 296
Email: legal@dreamboard.games
2. Local-only editing
You can use Studio locally without an account. Project documents, uploaded images and fonts, previews, thumbnails, preferences, and editor history are stored in your browser on your device. They are not sent to Dreamboard merely because you create or edit them.
Your browser and device still handle that storage, and ordinary web hosting may receive basic request data such as IP address, date/time, requested URL, user agent, and security logs when it serves the app. You can delete local Studio data through your browser’s site-data controls. Export anything you need first.
3. Information we collect when you choose connected features
- Account information: your email address, the account identifiers we receive from our sign-in provider, sign-in and session records, and your age confirmation. We use Supabase for sign-in and session management. When you choose Google sign-in, Google provides your account identifier, email address, name, and profile image. We use these to identify your account and display your account controls. We do not request access to your Gmail, contacts, or Google Drive files, and do not use Google account data for advertising or training AI models.
- Cloud content: project documents, assets, metadata, revision/sync information, exports, and deletion records for content you choose to sync. Supabase stores Studio cloud projects and assets in its US East (N. Virginia) region in the United States.
- Agent inputs and outputs: the prompt, the rules and project files selected for the run, the generated code, and the run’s logs and status. Dreamboard uses Cursor Cloud Agents supplied by Anysphere, Inc. (Cursor) to perform agent runs.
- Billing information: plan, Stripe customer and subscription identifiers, payment status, current period, invoice or tax information, and billing email. Stripe receives your payment-card details directly; Dreamboard does not store full card numbers.
- Support, waitlist, and complaints: contact details, messages, attachments you choose to send, complaint evidence, and our response. If you join the waitlist, we store your email address with Loops, our email provider.
- Service and security data: IP address, browser/device information, URLs, timestamps, authentication events, feature usage, quota totals, failures, and logs needed to operate and secure the Services.
4. Minimal telemetry and error monitoring
Dreamboard does not use targeted advertising and does not sell personal information. We collect only the telemetry we need to operate, secure, debug, and understand the Services. The Studio editor sends error reports and sampled performance measurements to Sentry, along with an aggregate counter of Studio opens. Studio session replay is disabled. We do not attach project documents, uploaded assets, or account profile information to Studio diagnostics.
Other parts of the Dreamboard site use Sentry for error and performance monitoring, including session replay, and Axiom for application logs. These tools may receive URLs, device and browser information, stack traces, and interaction context. Session replays mask all text and block all media, so what you type and upload is not recorded. Dreamboard does not intentionally include project documents, assets, prompts, or secrets in application logs. These tools are not used for advertising or model training.
5. Why we use information
We use information to:
- create and secure accounts and confirm eligibility;
- provide sync, backup, export, deletion, agent, and support actions you request;
- process subscriptions, show usage, prevent overages, and handle billing events;
- operate, diagnose, measure, and improve reliable product workflows;
- prevent fraud, abuse, security incidents, and rights violations;
- send service messages and marketing you consent to receive; and
- comply with law, enforce agreements, and resolve disputes.
Dreamboard does not use local-only or cloud project content to train AI models. We do not authorise Cursor or its inference providers to use customer project content for model training. They may process selected content only to perform the agent action you request and to secure and operate that service.
6. Service providers and disclosures
We disclose only what is reasonably needed to:
- Supabase for account authentication, session management, and Studio cloud storage;
- Google when you choose Google sign-in, using the account information described above;
- Stripe for checkout, recurring billing, refunds, fraud controls, and disputes;
- Loops for waitlist and opted-in product email;
- Sentry and Axiom where monitoring is enabled as described above;
- Amazon Web Services for hosted Playtest services when available;
- Anysphere, Inc. (Cursor) and its disclosed inference providers and subprocessors for an agent action you request;
- professional advisers, insurers, authorities, or courts where reasonably necessary; and
- a successor in a genuine business transfer, subject to appropriate safeguards.
Cloud project content is stored in the United States. Cursor and its disclosed AI model providers and subprocessors may process agent inputs in the United States and other countries where they operate. Their locations can change; we will update this Notice when a material provider or processing-location change affects customer content.
7. Browser storage, cookies, and email
Studio uses browser databases and storage for local projects, preferences, previews, and account/session state. Authentication and security providers may use cookies or similar storage needed to keep you signed in and protect the Services. We do not use targeted advertising cookies.
Marketing email is opt-in and includes an unsubscribe route. Essential account, billing, security, and service messages are not marketing, but we keep them proportionate to the service relationship.
8. Retention
Local-only content remains on your device until you delete it or the browser removes it. For connected services, we retain account, project, support, security, agent, and billing records only as long as needed for the purposes above, legal obligations, disputes, fraud prevention, and reliable backup deletion.
Cloud content remains available while your account is open, including after Pro cancellation because cloud sync is part of Free. Following a content or account deletion request, active copies are deleted within 30 days and routine backups within 90 days. Service and security logs are normally kept for 90 days; support and complaint correspondence for two years after closure; and billing and transaction records for at least five years or longer where Australian tax, accounting, fraud, dispute, or other law requires it.
Agent run records are also held by Cursor. Dreamboard keeps each agent run available for 90 days after its last activity so you can review or continue it, then asks Cursor to delete its transcript and outputs. Cursor also keeps an encrypted copy of the run’s working environment for up to 90 days after last use; that copy expires automatically under Cursor’s retention policy and cannot be deleted earlier on request.
9. Access, correction, export, and deletion
Registered users can export account data and cloud project content and request account/content deletion. You may also ask us to access or correct personal information, object to or restrict handling where applicable, withdraw marketing consent, or make a privacy complaint by emailing legal@dreamboard.games. We may need to verify your identity.
Deletion may not cover records we must retain by law, security records needed to protect the Services, or material preserved for a legal claim. We will explain a refusal or limitation where required.
10. Security and data incidents
We use reasonable technical and organisational safeguards appropriate to the information and service. No online system is risk-free. If an incident is likely to cause serious harm and notification is required, we will notify affected people and the Office of the Australian Information Commissioner as required by applicable law.
11. Age and complaints
Accounts are for people aged 16 or older. Purchases are for adults aged 18 or older. If we learn that an account was created contrary to this rule, we may close it and delete associated information, subject to legal retention requirements.
Send a privacy complaint to legal@dreamboard.games with enough detail for us to investigate. We will acknowledge and respond within a reasonable period. If you are not satisfied, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.
12. Changes to this Notice
We will update this Notice when our information handling materially changes. We will post the new effective date and give additional notice for significant changes where appropriate.