LEGAL
Privacy Policy
Draft — last generated July 25, 2026
This is a draft prepared for attorney review — it is not final and has not been reviewed by a lawyer. In particular, the tasker document retention period, DPA status with Supabase/Stripe, and cookie-consent requirement are flagged below and need counsel input before this goes live.
1. Scope
2. Information we collect
- Account information: name, email, phone, password (encrypted), profile photo.
- Event and business data: event details, guest lists, budgets, vendor information, contracts, vision boards, and any content you upload to plan an event.
- Client and lead data: if you're a planner, information about your leads and clients that you or they enter into the Service (name, email, event details, messages, proposals, signed contracts).
- Payment information: processed directly by Stripe. Fever Dream does not receive or store raw credit card numbers — see Section 9.
- Tasker identity and tax documents: if you're a tasker, a signed work agreement, tax information (e.g. a W-9), a photo ID, and any certifications you choose to upload — see Section 6 for how this category is handled differently.
- Messages: content sent through the Service's planner-client messaging feature.
- AI-assisted feature inputs: if you use an AI-assisted feature (e.g. draft contract language, message summaries, vendor recommendations), the inputs and outputs of that feature may be processed as described in Section 5.
- Usage and device data: pages visited, actions taken, browser/device type, and IP address, collected automatically to operate and secure the Service.
3. How we use information
- To provide, maintain, and improve the Service.
- To process payments and manage subscriptions.
- To send transactional emails (contract activity, payment confirmations/failures, account notifications) and, if you've opted in, product updates.
- To detect, prevent, and respond to fraud, abuse, and security incidents.
- To comply with legal obligations, such as tax reporting related to payments facilitated through the Service.
4. Legal basis for processing (GDPR)
5. Who we share information with
- Service providers: Supabase (database and authentication), Stripe (payments), Resend (transactional email), Unsplash and Canva (photo/design content you choose to use), and, if used, an AI provider for AI-assisted features. Each processes data on our behalf, only as needed to provide their part of the Service.
- Other users, in context: if you're a planner, your client sees the proposal/contract/messages you send them. If you're a tasker, your documents are visible to any planner who accepts you onto their event — not the general public.
- Legal and safety reasons: if required by law, subpoena, or to protect the rights, property, or safety of Fever Dream, our users, or the public.
- Business transfers: if Fever Dream is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction, subject to this Policy or a successor policy.
6. Tasker identity and tax documents — handled differently
Tasker profiles can include a W-9 (which contains a Social Security Number or EIN) and a photo government ID — more sensitive than the rest of the data in the Service. By submitting these documents, a tasker consents that they become visible to any planner who accepts them onto an event, not just the planner who first invited them. Taskers may request deletion of these specific documents at any time by emailing privacy@feverdreamapp.com.
[Attorney/product note: given the sensitivity of this category, we recommend this data eventually sit behind additional safeguards beyond the rest of the Service — separate encrypted storage, stricter role-based access, access/download audit logging, and automatic expiration after a defined inactivity period. These are recommended hardening steps, not yet confirmed as implemented; see legal checklist, item 14, before real W-9s/IDs are treated as fully launch-ready.]
7. Data retention
We keep your information for as long as your account is active, plus a reasonable period afterward to comply with legal, tax, and dispute-resolution obligations. As a general practice, intended (but not yet finalized) retention periods are:
- Deleted account data: removed within 30–90 days of your deletion request, except where we're legally required to retain it longer.
- Payment records: retained as required by tax and financial recordkeeping law — Stripe separately retains records under its own policies.
- System and security logs: approximately 12 months.
- Database backups: currently up to 7 days, per our hosting provider's backup retention.
[Attorney/founder note: these periods are drafted defaults, not yet finalized business decisions — confirm actual intended retention before publishing, particularly for payment records and tasker documents (Section 6).]
8. Your privacy rights
If you're a California resident (CCPA/CPRA): you have the right to know what personal information we've collected about you, request deletion of it, correct inaccurate information, and opt out of the "sale" or "sharing" of personal information. Fever Dream does not sell your personal information for money; under California's broad definition of "sale," we also do not share it with third parties for their own advertising purposes.
If you're in the EEA/UK (GDPR): you have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing.
To exercise any of these rights — including requesting an export of your account or event content — email privacy@feverdreamapp.com. We'll respond within the time required by applicable law.
9. Payment card security
10. Cookies and similar technologies
11. Data security
We maintain reasonable administrative, technical, and physical safeguards designed to protect your information, including encrypted connections in transit (HTTPS/TLS), encryption at rest provided by our database host, row-level database access controls, and regular database backups (currently retained up to 7 days). We don't currently hold formal certifications such as SOC 2, ISO 27001, or HIPAA, and we don't represent that we do.
No system is completely secure, and we can't guarantee absolute security, but we work to protect your data and will notify affected users as required by law in the event of a breach.