Last updated: 20 July 2026
Effective date: 20 July 2026
1. Scope
DreamSense uses cookies, local storage, session storage and similar technologies for authentication, security, preferences, requested features and optional analytics.
Product storage is managed by the DreamSense product operator. Rikama may use limited storage for billing and Merchant-of-Record functions. Stripe and social-login providers may use their own technologies on hosted pages.
2. Categories
Necessary
Used for login, session security, CSRF protection, consent records, checkout and functions requested by the user.
Preferences
Used for language, theme or interface settings.
Analytics
Used to understand product usage and technical performance.
Where consent is required, optional analytics must not load before the user accepts it. Rejecting analytics must not block the core Service.
Advertising
DreamSense does not currently use cookies to target advertising based on dream entries or AI reports.
3. Production inventory
Verified from the current product codebase (browser/network audit should be re-checked before launch):
| Name / key | Controller / provider | Purpose | Category | Domain / storage | Duration |
|---|---|---|---|---|---|
ds_access |
DreamSense product | Authenticated session | Necessary | HttpOnly cookie (API) | Session / server-defined |
ds_refresh |
DreamSense product | Session refresh | Necessary | HttpOnly cookie (API) | Session / server-defined |
ds_csrf |
DreamSense product | CSRF protection | Necessary | Cookie | Session / server-defined |
dreamsense_analytics_consent |
DreamSense product | Analytics consent choice (granted / denied) |
Necessary | localStorage | Until changed by the user |
dreamsense-theme |
DreamSense product | Theme preference | Preferences | localStorage | Until changed |
ds.locale |
DreamSense product | Language preference | Preferences | localStorage | Until changed |
ds.sidebar.width / ds.sidebar.collapsed |
DreamSense product | UI layout preference | Preferences | localStorage | Until changed |
ds_quiz_v1 / ds_quiz_ref |
DreamSense product | Pre-signup quiz progress and referral | Necessary | sessionStorage | Until the browser session ends, the quiz is submitted, or site data is cleared |
dreamsense_quiz_intake / dreamsense_referral_code / dreamsense_post_quiz_redirect / dreamsense_attribution / dreamsense_checkout_attribution / ds.oauth.next |
DreamSense product | Quiz handoff, attribution and OAuth return path | Necessary | sessionStorage | Until the browser session ends or cleared |
insights_growth_snooze_until / requiz_snooze_until / insights_teaser_snapshot |
DreamSense product | In-app UI snooze / teaser state | Preferences | localStorage | Short-lived (hours to days) or until cleared |
_ga / _ga_* |
Google Analytics | Optional product analytics | Analytics | Cookie | Up to 13 months (only after analytics consent) |
| Stripe cookies | Stripe | Checkout, customer portal, fraud prevention | Necessary | Stripe-hosted domains | Per Stripe |
| Google / Meta OAuth cookies | Google / Meta | Social login when selected by the user | Necessary | Provider domains | Per provider |
Dream text, complete reports, voice recordings and long-lived authentication secrets must not be stored in localStorage.
4. Analytics and logging
Optional analytics must not receive:
- dream text;
- report content;
- audio;
- life-event notes;
- passwords or complete authentication tokens;
- full payment information;
- sensitive URL or query values.
Billing analytics, if used, must be limited to checkout, payment and fraud/security information.
5. Pre-signup quiz
If quiz data is stored in the browser before registration:
- it remains local in sessionStorage until submission;
- the user is informed before upload;
- it is cleared when the browser session ends, after submission, or when the user clears site data;
- it is removable through browser site-data controls.
6. Stripe and social login
Stripe may use cookies and similar technologies on Checkout and customer-portal pages for payment, authentication and fraud prevention.
Google or Meta may use their own technologies when a user selects social login.
7. Consent controls
Where required, the cookie banner must provide equally clear options to:
- accept optional analytics;
- reject optional analytics;
- review categories.
Cookie Settings must remain available so the user can withdraw consent.
8. Contacts
Product cookies and analytics: privacy@dreamsense.me
Billing storage: billing@dreamsense.me