Privacy Policy
Dream Flow ("Dream Flow", "we", "us") is operated by SOFTDREAMS SRL, a company registered in Romania (trade register J40/15096/2004, VAT RO16780255) with its registered office at 27 Muzelor Street, District 4, 040191 Bucharest, Romania. This policy explains what personal data we collect when you use the Dream Flow website and service, why we collect it, and the choices you have.
1. What Dream Flow is
Dream Flow is a software development service: it gives an organization its own private instance, a cloud development machine, and AI agents that carry out software tasks on the organization's code. You reach it through the website, the Dream Flow ID sign-in service, the Visual Studio Code extension, and the instance's web console.
2. Data we collect
- Account data. Your name, e-mail address and, if you enable it, a phone number for verification codes. If you sign in with Google or Microsoft, we receive your name, e-mail address and account identifier from that provider. We do not access your Google Drive, Gmail, calendar or any other content on those accounts.
- Organization data. The organization's name and web address, its members and their roles, and the settings of its instance.
- Billing data. Your subscription status, invoices and the last four digits and expiry of your card, held by our payment provider Stripe. Full card numbers never reach our systems.
- Content you bring. Source code, repositories, tasks, documents, chat messages with the AI agents, and credentials you choose to store (for example a GitHub or GitLab token). This content is processed only to provide the service to your organization.
- Technical data. IP address, browser and device information, sign-in events, error logs and usage metrics of the AI agents (tokens and estimated cost per run), used for security, billing and improving the service.
- Cookies. Strictly necessary cookies only: your sign-in session, a form-protection token, and an optional "trust this device" cookie that skips the verification code for 30 days. We do not use advertising or third-party analytics cookies.
3. Why we use it
- To create and secure your account and organization, and to sign you in.
- To provide the service: running your instance and development machine, executing the tasks you ask the AI agents to do, and storing your organization's work.
- To bill your subscription and send you receipts, trial reminders and account notices.
- To keep the service safe: detecting abuse, investigating incidents and keeping an audit trail of security-relevant actions.
- To improve Dream Flow, using aggregated usage measurements.
The legal bases under the GDPR are the performance of our contract with you, our legitimate interests in securing and improving the service, and, where required, your consent.
4. AI providers
The AI agents run with the AI accounts or API keys that your organization connects (for example Anthropic Claude, OpenAI, or GitHub Copilot). Prompts and code sent to those providers are governed by their terms and privacy policies. Dream Flow does not use your code or prompts to train models.
5. Who else sees your data
We share personal data only with providers that help us run Dream Flow, under contracts that limit their use of it:
- Hetzner Online GmbH (Germany) — servers and development machines.
- Stripe — payments and invoicing.
- Google and Microsoft — sign-in, when you choose to use them.
- Brevo — transactional e-mail.
- GitHub and GitLab — repository access, only through connectors you set up.
We do not sell personal data. We disclose it to authorities only when the law requires it.
6. Google user data
Dream Flow's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only use your Google account's basic profile (name, e-mail address and identifier) to create and sign you into your Dream Flow account.
7. Where data lives and how long we keep it
Data is stored in the European Union. Your organization's instance and data are kept while your subscription is active. If a subscription ends without payment, the instance is stopped and its data archived; after 60 days without reactivation the organization, its instance, its development machine and all archived data are permanently deleted. You can also ask us to delete your account at any time. Billing records are kept as long as tax law requires. Security logs are kept for up to 12 months.
8. Security
Each organization runs in its own isolated instance with its own database. Traffic is encrypted in transit, credentials you store are encrypted at rest, sign-in requires e-mail verification and supports two-factor authentication, and access by our staff is restricted, logged and limited to what support requires.
9. Your rights
You can access, correct, export or delete your personal data, object to or restrict certain processing, and withdraw consent where processing is based on it. Most of this you can do yourself from your account and organization pages; for anything else, write to contact@softdreams.eu. You also have the right to complain to your data protection authority.
10. Children
Dream Flow is intended for professionals and is not directed at children under 16. We do not knowingly collect their data.
11. Changes
We will post any changes to this policy on this page and, for significant changes, notify account owners by e-mail before they take effect.
12. Contact
SOFTDREAMS SRL
27 Muzelor Street, District 4, 040191 Bucharest, Romania
Trade register J40/15096/2004 · VAT RO16780255
contact@softdreams.eu · +40 31 226 10 73