Liminal · by ProgramU LLC

Liminal Privacy Policy

Last updated: August 28, 2026

Your privacy matters to us more than most apps, because of what Liminal is. Liminal is a dream journal and sleep app, and the data you put into it — your dreams — is among the most intimate data there is. We treat it as sensitive personal information. This policy explains exactly what we collect, how we use it, who touches it, and the rights you have over it. Liminal is operated by ProgramU LLC. Questions: support@programu.app. Liminal is not a medical device and is not a substitute for professional medical or mental-health care. If you are experiencing a sleep disorder, severe distress, or a medical emergency, contact a qualified professional.

1. Who This Policy Applies To

This Privacy Policy applies to all users of the Liminal mobile application. Liminal is currently available to residents of the United States only. We do not knowingly serve users outside the United States. Liminal is intended for adults 18 years of age and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with their information, contact support@programu.app and we will delete it promptly.

2. Information We Collect

Account Data: • Your email address (from email sign-up, or from Apple/Google when you sign in with them) • Your display name (the name you give us, or your first name if shared by Apple/Google sign-in) We do not collect your date of birth. Age (18+) is confirmed by your attestation at consent. Dream Journal Data — this is sensitive data, and we treat it that way (see Section 4): • Dreams you record: voice recordings, transcripts, and text entries • Tags and details you add: dream type (lucid, OBE, oracular, recurring, and similar), emotions, people, places, lucidity ratings, techniques you tried, and sleep/wake times you log • Patterns computed from your own journal: recurring elements ("dream signs"), streaks, and trends • Conversations with Kairos, Liminal's AI dream specialist, in the Drift — transcripts saved to your history, plus a short running conversation memory (a few sentences summarizing what you two have discussed) kept so she can pick threads back up. You can turn this memory off in the app (About Kairos), and off means nothing new is stored. • Paper journal pages you photograph into the app: the photo itself, and the text read from your handwriting so the entry is searchable • Reality checks and practice sessions you log • Preferences: bedtime, capture settings, notification schedules, and sleep-audio mixes you save Voice recordings of your dreams are stored in your private account storage so you can replay them and so they can be transcribed for you. They are yours: you can delete any recording, and all of them are erased with your account. Usage Data: • Feature activity that is itself your own stored record (journal history, conversation history, reality-check logs) • In-app preferences and notification settings, including your quiet-hours window and a timezone offset used only to avoid notifying you during your sleep hours • Feature-usage state stored as simple flags and counts (for example, which first-days checklist steps you have completed, or whether we have shown you a satisfaction check) — never the content of what you wrote • When you write from a journaling prompt, the prompt text is saved together with your entry so the entry keeps its context We do not run a third-party analytics SDK, and we do not collect behavioral analytics beyond the records described above. Error Reports: If the app hits an error, a report may be sent to us containing the error message, a technical stack trace, your user ID, the app version, and platform — never your dream text, recordings, or conversation content. Reports are limited to a few per day per device. Device Information: We collect app version and operating system platform at consent time for audit purposes. We do NOT collect: device model profiles, IP-address-based location, advertising identifiers, precise location, or device fingerprinting data. Subscription and Payment Information (when subscriptions launch): Payments are processed by Apple (iOS) or Google (Android); they handle your payment details under their own privacy policies. ProgramU LLC receives only your subscription status and a transaction identifier — never your card details. We use RevenueCat to manage subscriptions; it receives your user ID and subscription state only. Current pricing is always shown in the app before you buy.

3. Third-Party Services (Sub-Processors)

We use the following sub-processors to operate Liminal. Each processes only the data necessary for its function: • Google Firebase: Authentication, Firestore database, Cloud Functions, and private file storage for your dream recordings. Data is encrypted at rest and in transit, and access is restricted to your authenticated account by security rules. • Inworld AI: Powers Drift's real-time voice conversations — speech-to-text, a fast language model reached through Inworld's model router, and text-to-speech for Kairos's voice. Your live voice audio is processed in transit for the conversation and is not stored by ProgramU LLC. • Google (Gemini): Transcribes dream voice recordings that could not be transcribed on your device, reads the handwriting in paper journal pages you photograph in, and powers Drift conversation processing through Inworld's router. • Anthropic (Claude): Background dream intelligence — generates titles, summaries, and theme/pattern detection from your dream entries so your journal can reflect your own patterns back to you. • Cloudflare R2: Object storage for our shared, pregenerated sleep-audio library (the same tracks for every user — no personal data). • Expo (EAS Update): Delivers app updates. Your device requests updates with the app version and platform — no personal data. • Sentry: Crash reporting. Reports are scrubbed before transmission — we strip your email, username, and IP address, keep only an opaque user ID, and drop console and input breadcrumbs, so your dream content is never included. • RevenueCat, Apple App Store, Google Play (when subscriptions launch): subscription management and payment processing as described in Section 2. None of these providers are permitted to use your content to train their models, and your data is never sold or used for advertising.

4. Sensitive Data

Your dreams are yours. What you record in Liminal — the dreams themselves, the people and places in them, the patterns they reveal — is sensitive personal information that could embarrass or harm you if it were disclosed. We designed Liminal with that risk in front of us: • We will never sell your data. Not to data brokers, not to advertisers, not to anyone. • We will never show you ads or share your data with advertising networks. • We will never share your journal with any third party beyond the processing described in Section 3. • We delete your data on request. See Section 8. • You can lock the app behind Face ID / biometrics (Profile → App lock) — free, on-device. Your dream data exists for one purpose: to support your own practice inside the app. That is the only use we put it to.

5. How AI Data Processing Works

Liminal uses AI in two separate ways: Live conversations (Drift — voice and text) run through Inworld's realtime agent API. Section 13 covers these in detail. Background processing runs after you save or sync a dream: • Transcription of your voice recording (on your device when possible; otherwise via Google's speech models on our servers) • A title, short summary, and detected themes for each dream (Anthropic Claude) • Recurring-element detection across your journal — your dream signs (computed from Claude's per-dream output by our own code) These outputs are saved back to your account, marked as AI-generated, and deleted with it. Your numbers are computed, not generated. Streaks, counts, and pattern statistics shown in the app or spoken by Drift are computed by our servers from your own logged data. The AI model never invents these numbers. No training on your data. Your dreams and conversations are not used to train any AI model — ours or any third party's. AI-generated content can contain errors. Drift reflects your own journal back to you — it does not hand down dream "meanings," and nothing it says is advice or fact. Use your own judgment.

6. How We Use Your Information

We use your information to: • Provide the core Liminal service: your journal, transcription, dream intelligence, sleep audio, Drift conversations, and reminders you opt into • Personalize your experience from your own data: your dream signs, patterns, and preferences • Process subscriptions when they launch (via Apple and Google) • Catch and diagnose errors (PII-limited as described in Section 2) • Comply with legal obligations and prevent fraud or abuse We do NOT use your information to: • Show you ads or sell ad space • Train AI models • Sell, rent, or trade your personal data • Build advertising profiles of you or track you across other apps or websites Legal disclosures: we may disclose information where required by law or legal process; to enforce our Terms of Service; to respond to a payment dispute with records of the subscription and acceptance; or to protect the rights, property, or safety of ProgramU LLC, our users, or the public.

7. Data Security

Your data is stored in Google Firebase (database and private file storage), which employs industry-standard security practices: • TLS encryption for all data in transit • Encryption at rest for stored data, including your voice recordings • Firebase Security Rules restricting every read and write to your authenticated account We minimize logging of personal content: your dream text, recordings, and conversation content are never written to operational logs or crash reports. No system is perfectly secure, and we cannot guarantee absolute security. But we apply modern best practices and continuously work to improve our safeguards — because of what this data is.

8. Your Rights

Access and Correction: • Update your profile, journal entries, and settings at any time within the app • Request a copy of your personal data by emailing support@programu.app Deletion: You can permanently delete your account and all associated data at any time, in the app (Profile → Delete account) or by emailing support@programu.app. Account deletion permanently wipes your journal (text, transcripts, and voice recordings), Drift conversation history, computed patterns, preferences, and authentication account. Most deletions complete within 24 hours; in rare cases, full deletion may take up to 30 days. Data Portability: You can request a copy of your complete journal by email; a one-tap in-app export is planned. Right to Object: You may object to certain processing activities by contacting support@programu.app.

9. Data Retention

Your data is retained for as long as your account remains active. We do not automatically delete inactive accounts — your journal remains yours until you delete it. What gets deleted when you delete your account: • Firebase Auth account, your user document, and all subcollections (dreams, conversations, reality checks, preferences, computed patterns) • Every voice recording in your private storage • On-device data (preferences, local caches, profile photo) is removed when you delete the app After deletion, data may persist briefly at sub-processors under their own retention policies (for example: Firestore automatic backups for up to ~35 days, Google Cloud operational logs ~30 days, and AI-provider request data retained short-term for abuse detection under their terms). None of this retained data is used to contact you or re-identify you after deletion.

10. Children's Privacy

Liminal is intended for adults 18 years of age and older. Age is confirmed by your attestation during onboarding consent. ProgramU LLC does not knowingly collect personal information from anyone under 18. If we become aware that we have, we will delete that information immediately. If you are a parent or guardian who believes we have collected data from a minor, contact support@programu.app.

10. Geographic Availability

ProgramU LLC is organized in the State of Wyoming, United States. Liminal is currently available only to residents of the United States. Our servers and sub-processors are based in the United States, and our crisis resources — the 988 Suicide & Crisis Lifeline (call or text 988) and the Crisis Text Line (text HOME to 741741) — are U.S. services. If you access Liminal from outside the United States, your access may be restricted, and we cannot guarantee compliance with the privacy laws of your country. When we expand to new regions, we will update this policy to address the privacy laws of those regions.

11. California and Other State Residents

Residents of certain U.S. states have additional rights under applicable privacy laws, including the right to know what personal information we collect, to delete it, to correct it, to opt out of its sale or sharing (Liminal does not sell or share personal information), to limit the use of sensitive personal information, and to non-discrimination for exercising these rights. To exercise any of these rights, email support@programu.app. We will respond within the timeframe required by applicable law (typically 45 days). ProgramU LLC does not sell or share personal information for cross-context behavioral advertising.

12. Drift — AI Dream Conversations (Voice and Text) — Data Flow

Drift is where you talk with Kairos, Liminal's AI dream specialist. This section describes exactly how conversation data moves. Live voice data flow. When you talk with Kairos, the conversation runs on Inworld's realtime agent API in three steps, in real time: 1. Your spoken audio is transmitted to Inworld and transcribed to text (speech-to-text) 2. The transcribed text — together with context from your own dream journal, so Drift can reflect your patterns back — goes to a fast language model reached through Inworld's model router, which generates the reply 3. The reply is synthesized into Kairos's voice (text-to-speech) and played to you In text mode, only step 2 applies. Your live voice audio exists in transit only. It is processed to be transcribed and is not stored by ProgramU LLC. It is NOT used to create a voiceprint and NOT used to train any model. (Your dream voice recordings from the journal are different — those you chose to record, and they are stored privately for you; see Section 2.) Journal context. Kairos knows your dreams because your own journal is injected as context — summaries and patterns computed from what you logged. That context exists to serve you and is never shared beyond the AI processing described here. Conversation memory. After conversations, a short structured summary (a few sentences: what was discussed, what you're practicing, open threads) is generated and folded into one running memory document in your account, so Kairos can remember your work across conversations. It is yours: view-adjacent controls live in the app (About Kairos), turning memory off stops new writing and removes it from her context, and the document is erased with your account. Your controls. In About Kairos you can switch off, independently: her access to your journal, her memory of your conversations, and her access to photographed handwriting. Off is enforced server-side — the data simply is not loaded into her context. Transcript storage. After each conversation, a transcript is stored in your account so you can revisit it. Transcripts are your data: you can delete them, and they are wiped with your account. Safety. Drift is an AI dream decoder, not a therapist, and it does not process crises. If a conversation indicates you may be in danger, the app routes you to real help (988, Crisis Text Line). A minimal internal alert (your user ID and a category only — never the content of what you said) may notify our team so we can review that our safety systems worked. Consent flow. Liminal's onboarding consent covers the AI nature of conversations, data handling, safe listening, and the not-medical-care acknowledgment. Your acceptance (timestamp + version) is stored at users/{your-uid}/consent/v1. You will be asked to re-accept when these documents materially change. The model behind Drift, precisely: replies are generated by Google's Gemini model, reached through Inworld's routing infrastructure. Because Inworld acts as a ROUTER, if Gemini is unavailable or fails, Inworld may automatically route the request to a comparable third-party model, which is outside ProgramU LLC's direct control. Anthropic's Claude does NOT power live Drift conversation; it is used for the background dream intelligence described in Section 3. Zero Data Retention status, honestly: ProgramU LLC does not currently have a Zero Data Retention agreement with Inworld, so Inworld and the routed model provider may retain conversation data for some period under their own platform policies (see inworld.ai/privacy). ZDR is offered on higher service tiers and we intend to adopt it as we scale, but it is not in place today. Treat Drift conversation content as data processed by third parties under those terms. Transcript storage: after a voice call ends, a text transcript (what was said by you and by Drift, with timestamps and a short AI-generated title) is stored in your private account so you can revisit conversations in the in-app history. Raw call audio is never stored on our servers. Transcripts and chat threads are deleted when you delete your account; per-conversation deletion from within the app is on our roadmap — until then, contact support@programu.app to remove a specific conversation.

13. Changes to This Policy

We may update this Privacy Policy as Liminal evolves. When we make material changes, we will notify you in the app and ask you to review and re-accept before continuing — quiet edits to the rules are not how we operate. The "Last updated" date at the top always reflects the current version. Continued use of Liminal after a change and re-acceptance constitutes agreement to the updated policy.

14. Contact Us

For privacy questions, data requests, or to exercise your rights: • support@programu.app ProgramU LLC · Wyoming, United States. Thank you for trusting us with something this personal. We take that trust seriously. — The Liminal Team