Doromir has no account, no cloud sync and no server. Your recordings, transcripts, journal entries and any health data you connect live in a database on your own phone. We run no analytics and no advertising, and we have no way to read your dreams. The one thing that can leave your phone is an optional crash report, which never carries dream content. See crash diagnostics. Deleting is entirely in your hands: see delete your data.
1. Who we are
Doromir is a dream-journal and alarm-clock app published by Nerdy Whiskers LLC ("we", "us"). This policy covers the mobile app and this website.
2. Why this policy is short
Most privacy policies describe what a company does with data it has collected. Doromir is built so that we never receive your data in the first place: no account system, no login, no backend, no cloud storage. That is not a promise about our intentions. It is a property of how the software is built. We could not hand your dream journal to anyone, because we do not have it.
3. What Doromir stores on your device
All of this is written to local storage on your phone and stays there:
- Audio recordings of your dream notes, and their transcripts.
- Journal entries: titles, tags, moods and anything you type.
- Numeric representations of entries ("embeddings") used for on-device search and recurring themes.
- Alarms, sounds and settings.
- Health and sleep figures, if you connect a health source or enter them by hand.
4. What leaves your device: optional crash diagnostics
Doromir contains no analytics SDK, no advertising SDK and no third-party trackers. We collect no device identifiers, usage statistics, contacts, location or email address. The single exception is crash reporting, and it is worth being precise about.
If crash reports are switched on in Settings, Doromir sends a technical report when the app crashes, using Sentry (sentry.io) as the error-tracking provider, processed in the United States. A report contains the error type, the position in the app's code where it happened, and basic device and app-version information.
It never contains dream text, audio, titles, tags, health data, file names, or any account or advertising identifier. Every report passes through a filter that strips content before it is sent, and that filter works by allowlist: anything not positively recognised as technical diagnostic data is dropped rather than transmitted.
On public releases from Google Play, crash reporting is off unless you turn it on. It is on by default only in internal testing builds, where testers have signed up to test. Either way you can change it at any time in Settings, and the change takes effect immediately.
5. Microphone, recordings and transcription
The microphone is used only while you are actively on the capture screen. It is not used at any other time, and the app does not listen in the background.
Recordings are written to local storage and are never uploaded. By default a recording is deleted as soon as it has been transcribed; if you turn on audio retention in Settings it is kept until you delete the entry. Discarding a capture deletes its audio immediately.
Transcription happens on your device. Doromir uses your phone's built-in speech recognition where available (a component of your operating system, governed by your device manufacturer's privacy policy), and otherwise falls back to a Whisper model that ships inside the app. If you would rather not use the system service, the bundled offline model works without it.
6. Health and sleep data
Connecting a health source is entirely optional; every other feature works normally without it, and you can enter sleep figures by hand instead. On Android, Doromir requests read-only access to six Health Connect record types and nothing else: sleep sessions (including REM and deep stages), heart rate variability, resting heart rate, steps, active calories and exercise sessions.
These are stored locally alongside your journal and analysed on the device to show reflective correlations, for example whether longer dream entries follow nights with more REM sleep. Results are shown only to you, in the app. Health data is never transmitted off your device, never sold or shared, never used for advertising, never used to make decisions about you regarding employment, insurance or credit, and never used to train any model. Doromir has read access only and never writes to or deletes anything in your health store.
You can withdraw health access at any time in Health Connect, which stops all further reads immediately.
Separately, if you have no wearable, you can let Doromir estimate when you slept using your phone's motion sensors via the system activity-recognition permission. This runs entirely on-device, keeps at most the last few nights' sleep windows locally, and is off unless you turn it on. It is not location tracking, and Doromir does not request location access.
7. On-device AI and the optional model download
Doromir generates titles, tags and reflective themes from your entries on your device, using a small model that ships with the app, a system AI service on your phone, or an optional larger language model.
Downloading that optional model is the only other time Doromir touches the network. If, and only if, you choose to download it, your device connects to Hugging Face (huggingface.co) to fetch the file. That is an ordinary file download: it reveals to that host the same things any download does, such as your IP address, and is subject to their privacy policy. No part of your journal, recordings, transcripts or health data is included in that request. Once downloaded the model runs offline, and you can delete it from Settings at any time.
Apart from that download and the optional crash reports in section 4, Doromir makes no network requests. Alarms are scheduled and delivered entirely by your device: there is no push service, so no device token is registered anywhere and notification content stays on your phone.
8. Permissions, and why
- Microphone: to record dream notes.
- Notifications: to deliver alarms and reminders.
- Exact alarms: so an alarm fires at the minute you set it for.
- Full-screen intent: so the alarm can present its wake interface over the lock screen.
- Display over other apps: optional. Android suppresses a full-screen alarm while the phone is awake and in use; this lets the alarm open properly in that case. Doromir draws no overlay windows, and the alarm still rings without it.
- Run at startup: to restore your alarms after a restart.
- Foreground service, wake lock and vibration: to keep an alarm ringing and wake the screen.
- Physical activity: optional, for phone-sensor sleep detection.
- Health Connect (read): optional, for the six record types in section 6.
Every permission can be changed from your device's system settings, and the optional ones can be declined without losing the rest of the app.
9. Delete your data
All Doromir data is stored only on your device, so deletion is immediate and entirely in your hands. There is no server copy, no request to submit and nothing to wait for.
Deletion is permanent and we cannot reverse it. We have no copy to restore from. If you want to keep anything, export first: open Profile, choose the export option and pick a folder. Your entries and health snapshots are written out as a file you keep.
- One dream: open the entry from the Journal tab and delete it. The entry and its audio go immediately.
- Everything, keeping the app: Settings → Apps → Doromir → Storage & cache → Clear storage. This erases the journal database, every recording, your alarms, settings and any downloaded model. The app starts fresh, as if newly installed.
- Everything, including the app: uninstall Doromir. Android removes its entire private storage with it. Nothing survives, and nothing is left behind on any server.
- Just a downloaded AI model: remove it from Doromir's settings to reclaim the storage without touching your journal.
- Health access: open Health Connect → App permissions → Doromir and remove all permissions. Doromir only ever read from your health store, so there is nothing of ours to remove from it. Figures already copied into Doromir go when you clear its storage or uninstall.
On our side there is nothing to delete, because there is nothing to hold: no account, no sync, no analytics, no email address. The two exceptions are a file you exported yourself (once it is outside the app, deleting it is up to you) and any crash reports you opted into sending, which contain no dream content and no identifier tying them to you, but which you can ask us to purge by emailing the address below.
10. Security, and the trade-off
Your data is protected by your device's own security: your screen lock and the full-disk encryption modern Android applies by default. Doromir's storage is private to the app and not readable by other apps on a non-rooted device.
Because there is no server, there is no server to breach. The trade-off is real and worth stating plainly: if you lose your phone and have not exported your journal, the data is gone. We cannot recover it for you. Use the export feature if your journal matters to you.
11. Your rights
The GDPR, the CCPA and similar laws give you rights to access, correct, export and delete personal data a company holds about you. With Doromir you exercise all of them directly, without asking us: everything is accessible in the app, portable via export, correctable by editing an entry, and erasable as described in section 9. We do not sell or share personal information as those terms are defined under the CCPA, and never have.
Doromir is not directed to children and is not intended for anyone under 13, or the minimum age of digital consent where you live if that is higher. We do not knowingly collect information from children, and in fact collect none from anyone.
12. Insights are reflective, not medical
Patterns, themes and correlations in Doromir are generated locally as a tool for personal reflection. They are not medical advice, diagnosis, treatment or prediction, and Doromir is not a medical device. If you are concerned about your sleep or your mental health, speak to a qualified health professional. If you are in crisis, contact your local emergency number or a crisis line in your country.
13. This website
This site is a set of static pages. It sets no cookies, includes no analytics and embeds no third-party scripts or fonts. Our host records standard server logs, such as the IP addresses of requests, in order to serve the site.
14. Changes and contact
If Doromir's behaviour changes in a way that affects this policy, we will update this page and its effective date before that version is released, and surface material changes in the app. Questions can be sent to support@doromir.com.