← DreamLayer AI

Privacy Policy

Last updated September 6, 2026

1. Introduction

DreamLayer AI (dreamlayer.io) is operated by DreamLayer Labs Inc., a corporation incorporated in the Province of Ontario, Canada (“We”, “Us”, or “Our”). DreamLayer helps photographers cull, edit, share, and deliver photo shoots, provides AI media-creation tools, and offers the DreamLayer Agent API for programmatic image generation and editing. This policy describes what We collect, what We deliberately do not collect, and how information is used across the application, the website, and the Agent API. Capitalized terms not defined here have the meanings given in our Terms of Use.

2. Information We Collect

Account information

You sign in with Google. We store your email address and a display name to operate your account. We do not receive or store your Google password.

Your photos and other content

When you cull RAW photos, your original RAW files stay on your computer. Your browser extracts reduced-size JPEG previews and technical metadata (filename, camera model, capture time, dimensions, exposure data), and only those previews and that metadata are uploaded to our servers. We never receive or store your RAW originals.

We also collect and store the other content you submit to the Service: prompts and instructions, uploaded images, previews, edited renders, and generated media. Previews, renders, and generated media are stored in Google Cloud Storage and are private to your account, except for content you explicitly share via a share link.

Face detection in culling

To cull a shoot, our systems detect faces in the previews you upload and evaluate technical qualities such as focus, expression, and whether eyes are open, and group similar photographs. Face detections and the scores derived from them are used only to select and group photos within the project they belong to: we do not use them to identify who a person is, do not match faces across unrelated projects, and do not build a face-recognition database. This data is stored with the project and deleted when the project is deleted. See Regional Disclosures below for how biometric-privacy laws in some places treat this kind of processing.

Usage, billing, and technical information

We keep records of your credit balances, purchases, and metered usage to operate paid features, including records of which Terms and Privacy Policy version you accepted and when. Payment card details are handled by Stripe; we do not see or store your card number. For the Agent API we keep records of API keys (stored as digests, never in plain text), request metadata, and operational state. Like most services, our servers also process technical information such as IP addresses and request logs to operate and secure the Service.

3. How We Use Information

We use the information described above to:

  • provide, operate, and maintain the Service and deliver the results you request;
  • meter usage, process payments, and maintain accurate billing records;
  • secure the Service, prevent abuse and fraud, and enforce our Terms of Use, including rate limiting and abuse detection;
  • diagnose and fix product failures (see Cookies, Analytics, and Diagnostics below);
  • measure how the Service is used and how people find it, using Google Analytics (see Cookies, Analytics, and Diagnostics below);
  • measure and attribute our advertising on Reddit, using the Reddit Pixel (see Cookies, Analytics, and Diagnostics below);
  • communicate with you about your account and the Service; and
  • comply with legal obligations.

We do not sell your personal information or your content, and we do not use your content for advertising.

4. AI Processing, Model Providers, and Training

Culling, editing, and generation use machine-learning models, including models operated by third-party Model Providers (listed in the Subprocessors and Model Providers section below). To fulfill your request, the relevant Inputs, such as your prompt and the image being processed, are transmitted to the Model Provider(s) involved, which process that content to deliver the Service under their own terms and data practices. Which provider processes a given request depends on our routing; the current provider set is described in our documentation.

How your content is and is not used for training:

  • Personalization for you. The Service learns from your own activity, such as your culling selections and editing adjustments, to personalize results for your account only.
  • Service improvement, with opt-out. Unless you opt out, we may use your content to evaluate and improve the culling, editing, and routing systems. Content used this way is not used to train generative models that produce content for other users. Opt out at any time by emailing mackenzie@dreamlayer.io from your account’s address (an in-product setting is planned); an opt-out stops future use but does not unwind systems already improved before it took effect.
  • Generative and identity training only with opt-in. We do not use your photographs or other content to train generative image models, or to create models or adapters that reproduce an identifiable person’s likeness or your distinctive artistic style, except under a program you separately and explicitly opt in to.
  • Never sold. We do not sell your content, and we do not use it for advertising.

5. How We Share Information

We share information only as needed to run the Service:

  • Service providers. Google Cloud (hosting and storage), Stripe (payments), Sentry (error monitoring and masked session replay), Google Analytics (usage measurement), PostHog, Inc. (product analytics and error tracking), Reddit, Inc. (advertising measurement and attribution), and the Model Providers described above, in each case only for the purposes described in this policy.
  • Adobe Lightroom (optional). If you choose to connect your Adobe account, we use Adobe’s official API, with your consent, solely to deliver your own culling and editing results into your own Lightroom catalog. We store the access credential Adobe issues for your account in encrypted form, use it only when you ask us to push work to Lightroom, and never read, modify, or delete anything in your catalog beyond that delivery. You can disconnect at any time, which deletes the stored credential.
  • People you share with. Content you explicitly share via a share link can be viewed by anyone with the link; copies made by people you shared with belong to their accounts.
  • Legal and safety. We may disclose information where required by law, or where reasonably necessary to protect the rights, safety, or property of users, the public, or the Service.
  • Business transfers. If the Company is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy.

6. Subprocessors and Model Providers

The third parties that may process your information or content on our behalf are:

  • Infrastructure. Google Cloud (hosting and storage), Stripe (payments), Sentry (error monitoring and masked session replay), Google Analytics (usage measurement), PostHog, Inc. (product analytics and error tracking), and Reddit, Inc. (advertising measurement and attribution).
  • Model Providers. The Model Providers whose models the Service may route to include, among others, Beeble, Black Forest Labs, Bria, ByteDance, fal.ai, Google, Grok (xAI), HitPaw, Ideogram, Kling, Krea, Luma, Magnific, OpenAI, Quiver, Qwen, Recraft, Reve, Runway, Topaz, Wan, and WaveSpeed. Your content is only ever sent to a provider in order to fulfill a request that is routed to it.
  • Optional integrations. Adobe (Lightroom delivery), only if you connect it.

We update this list as the catalog changes; the set in active use at any time is reflected in our documentation at docs.dreamlayer.io.

7. Cookies, Analytics, and Diagnostics

We use a session cookie to keep you signed in. We also use Sentry for error monitoring and sampled session replay so we can investigate product failures. Visible text and form values are masked, including names, email addresses, project titles, filenames, prompts, technical photo metadata, credit balances, and displayed error messages. Images and other media are blocked. Passwords, one-time codes, API keys, authentication tokens, and payment card fields are excluded. We do not authorize replay collection of request or response bodies, authentication headers, cookies, or payment details.

We also use Google Analytics to measure how the Service is used and how visitors find it, such as which pages are visited and which campaigns bring people here. Google Analytics sets its own cookies and processes usage information on our behalf. You can opt out of analytics by using Google’s browser opt-out tools, by blocking analytics cookies in your browser, or by contacting us; see Regional Disclosures below for choices under specific laws.

We also use PostHog to measure how the Service is used, such as which pages are visited, which developer actions are taken, and whether requests succeed or fail. Through these events PostHog receives a pseudonymous account identifier, page paths with identifiers removed, event names, and technical error categories; the events do not carry your email address, prompts, images, filenames, or API keys. Session recording, described in the next paragraph, captures more than the events do. PostHog stores this information in the United States on our behalf. You can opt out of analytics using the on this page, by enabling Global Privacy Control or Do Not Track in your browser, or by contacting us.

PostHog also records your session: a reconstruction of how you moved around the interface, so we can find layout and usability problems. Recording happens automatically as part of our analytics, and stops as soon as you opt out of analytics. The recording captures the text on your screen, including text you type: your prompts, the conversation, the names of your chats and projects, filenames, and your search terms. Images do not enter the recording: uploaded photographs, generated images, previews and thumbnails, and the editing canvas are replaced by an empty placeholder. Passwords, payment card details, API keys, and your email address are also excluded from the recording. We do not record the content of network requests or responses. Recordings are stored by PostHog in the United States on our behalf and are deleted after one year. You can stop recording at any time using the on this page, which stops the recording in progress immediately; enabling Global Privacy Control or Do Not Track in your browser, or contacting us, has the same effect.

We also use the Reddit Pixel, provided by Reddit, Inc., for advertising measurement and attribution, such as understanding visits and conversions resulting from Reddit ads. You can opt out using the on this page, by enabling Global Privacy Control or Do Not Track in your browser, or by contacting us.

These diagnostics and analytics are used to operate, troubleshoot, and improve DreamLayer, not to advertise to you elsewhere; the Reddit Pixel is the exception, and it is used only to measure and attribute our own advertising on Reddit. Sentry session replay is limited to fixed public marketing and legal routes. PostHog session recording, described below, additionally covers the editor and the pages that lead into it, and never runs on the sign-in pages, the developer console, the billing and checkout pages, the culling pages, or any page whose address identifies a specific project, conversation, share link, or job.

8. Data Retention and Deletion

We retain information for as long as needed to provide the Service and for legitimate business or legal purposes. By category:

  • Content and projects are stored until you delete them or your account. Deleting a project deletes its stored media from our active storage systems; residual copies may persist in backups for a limited period before being purged.
  • Face detections and culling scores are stored with their project and deleted with it.
  • Share copies made by people you shared with belong to their accounts and are not deleted by your deletion.
  • Billing, credit-ledger, and acceptance records are retained as required for accounting, tax, audit, and legal purposes, including after account deletion.
  • API keys and request metadata are retained while your account is active and as needed for security and billing.
  • Diagnostics and analytics (Sentry events and replays, Google Analytics data, Reddit Pixel data) are retained on a rolling, time-limited basis under those tools’ retention settings; PostHog events are retained for 12 months, and PostHog session recordings are retained for one year.
  • To delete your account and associated data, contact mackenzie@dreamlayer.io.

9. Security

We use reasonable technical and organizational measures to protect your information, including encryption in transit, encrypted storage of integration credentials, hashed API keys, and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security; we encourage you to protect your own sign-in credentials and API keys.

10. International Transfers

Our infrastructure is hosted on Google Cloud, and the service providers and Model Providers we use may process information in countries other than the one you live in, including the United States and Canada. Where we transfer personal information across borders, we take reasonable steps to ensure it receives a comparable level of protection.

11. Your Rights and Choices

Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal information, to withdraw consent, and to complain to a privacy regulator (in Canada, the Office of the Privacy Commissioner). You can delete projects and their media in the product, disconnect the Adobe integration at any time, and request account deletion or exercise any other right by contacting mackenzie@dreamlayer.io. We will respond within the time required by applicable law.

12. Regional Disclosures

European Economic Area, United Kingdom, and Switzerland

The controller of your personal information is DreamLayer Labs Inc. Where the GDPR or equivalent laws apply, we process personal information on these legal bases: performance of our contract with you (operating the Service and fulfilling your requests, including transmitting content to Model Providers); our legitimate interests (securing the Service, preventing abuse and fraud, improving the Service under the safeguards described in the training disclosures above, and measuring usage); your consent (optional integrations such as Adobe, opt-in training programs, and analytics cookies where consent is required); and compliance with legal obligations (such as retaining billing records). You may exercise the rights described in Your Rights and Choices, withdraw consent at any time, and lodge a complaint with your local supervisory authority. Transfers out of Europe rely on appropriate safeguards, such as standard contractual clauses with our processors.

United States state privacy laws

Depending on your state, you may have the rights to know, access, correct, delete, and obtain a portable copy of your personal information, and to not be discriminated against for exercising those rights. Exercise them by contacting mackenzie@dreamlayer.io (we may need to verify your request, and an authorized agent may act for you). We do not sell personal information. Some state laws treat third-party analytics and advertising cookies as a “sale” or “sharing” of personal information; you can opt out of those cookies as described in Cookies, Analytics, and Diagnostics above.

Biometric information

Some jurisdictions (for example Illinois, Texas, and Washington) regulate biometric identifiers such as face geometry. The face detection described in Information We Collect is used solely to select and group photographs within your project, is not used to identify individuals, is not shared with third parties for identification, and is deleted with your project. If you upload photographs of other people, you are responsible for providing any notice to, and obtaining any consent from, the people depicted that applicable law requires.

13. Children

The Service is intended for users who are at least eighteen (18) years of age, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact mackenzie@dreamlayer.io and we will delete it.

14. Changes to This Policy

We may update this policy from time to time. Each version is identified by its “Last updated” date, the Service records which version you accepted, and material changes will be notified in the Service or by email before they take effect.

15. Contact Us

For any privacy question or request: mackenzie@dreamlayer.io. DreamLayer Labs Inc., Toronto, Ontario, Canada.

Analytics opt-out is OFF for this browser. Use the opt-out link in Cookies, Analytics, and Diagnostics to disable PostHog product analytics, Google Analytics, and the Reddit Pixel here.