Privacy Policy
Last updated: June 1, 2025 · Effective immediately
1. Introduction
This Privacy Policy explains how ThyraAI ("we," "us," or "our"), the operator of DreamAPI ("the Service"), collects, uses, stores, and protects your information.
We take data privacy seriously — especially because our Service brokers authorized provider access. This policy is written to be transparent about exactly what we do and don't do with your data.
2. Information We Collect
Account Information
When you create an account through Clerk (our authentication provider), we receive:
- Email address
- Display name (if provided)
- Authentication identifiers (Clerk user ID)
OAuth Connections (Keyless)
When you connect a provider via Secure Sign-In:
- We store encrypted OAuth custody material (AES-256-GCM) for connected providers — never customer-pasted provider API keys
- Each encrypted payload includes a unique initialization vector (IV) and authentication tag
- Dream Keys are stored as SHA-256 hashes only; plaintext is shown once on mint/rotate
- We never log or return provider tokens to the browser or AI context
Usage Data
- Project names and descriptions you create
- Integration configurations (which services are enabled)
- Activity logs (key generation, rotation, project creation)
- Monthly cost estimates you enter for tracking
Billing Information
Payment processing is handled entirely by Stripe. We store your Stripe customer ID and subscription ID but never store credit card numbers, bank account details, or other payment credentials on our servers.
Webhook Data
When third-party services send webhooks through DreamAPI, the event payloads are stored temporarily for debugging purposes. Webhook data is scoped to your project and not shared.
3. How We Use Your Information
We use your information exclusively to:
- Provide and operate the DreamAPI service
- Authenticate your identity and authorize access
- Broker authorized provider access through your Dream Key and OAuth connections
- Process subscription payments via Stripe
- Display your activity history and project statistics
- Send transactional emails (e.g., billing confirmations)
- Improve the Service based on aggregate usage patterns
4. What We Do NOT Do
We want to be explicit about what we never do:
- We never sell your data to third parties
- We never ask you to paste provider API keys into DreamAPI
- We never use your credentials for our own purposes
- We never expose provider OAuth tokens to your app, builders, or prompts
- We never display ads or use data for ad targeting
- We never log raw provider tokens
5. Data Storage & Security
Encryption
- OAuth custody tokens are encrypted using AES-256-GCM
- Encryption keys are stored separately from the database in environment variables
- Dream Key hashes use SHA-256 — raw Dream Keys are never stored
Infrastructure
- Database: Neon (serverless PostgreSQL) hosted on AWS US-East-1
- Application: Netlify hosting and functions
- Authentication: Clerk (SOC 2 compliant)
- Payments: Stripe (PCI DSS Level 1 compliant)
Access Controls
- All data is scoped to your user account — no cross-user data access
- API routes verify authentication via Clerk on every request
- Database queries are parameterized to prevent SQL injection
6. Third-Party Services
We use the following third-party services to operate DreamAPI. Each has its own privacy policy:
- Clerk — Authentication & user management
- Stripe — Payment processing
- Neon — Database hosting
- Vercel — Application hosting & deployment
We only share the minimum data required for each service to function (e.g., email to Clerk, customer ID to Stripe).
7. Data Retention
- Account data: Retained while your account is active
- OAuth refresh tokens: Retained while your account is active; deleted within 30 days of account termination
- Activity logs: Retained for 90 days, then automatically purged
- Webhook events: Retained for 30 days, then automatically purged
- Revoked Dream Keys: Hash retained for security (to prevent reuse); raw key is never stored
8. Your Rights
You have the right to:
- Access — Request a copy of all data we store about you
- Correction — Update your account information at any time
- Deletion — Request complete deletion of your account and all associated data
- Export — Download your project configurations and integration settings
- Revocation — Revoke all Dream Keys and disconnect OAuth providers instantly
To exercise any of these rights, contact us at support@thyraai.com.
9. Cookies
We use essential cookies only — specifically those required by Clerk for authentication sessions. We do not use tracking cookies, analytics cookies, or advertising cookies.
10. Children's Privacy
DreamAPI is not intended for use by individuals under 18 years of age. We do not knowingly collect data from minors.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via the Service or email. The "last updated" date at the top of this page will be revised.
12. Contact
Questions or concerns about your privacy? Reach us at support@thyraai.com