Merely a Dream

Privacy policy

The short version: your boards are yours, we don't track you, we don't run ads, and we don't sell anything to anyone. Below is the detail.

Last updated 18 July 2026

Who is responsible

Merely a Dream is operated by Niels, Denmark. For anything on this page, contact hello@merelyadream.com.

What we store, and why

Your account

Your email address, your name, and optionally a company or organisation if you fill them in. Your password is never stored — only a one-way hash of it, which cannot be reversed back into your password. We record the time of your last sign-in so you can spot access you don't recognise.

We need these to give you an account at all. Your email is also how we send you a confirmation link and, if you ask for one, a password-reset link.

Your content

Everything you put into the app: Dreams, Visions, Mood boards, shot lists, itineraries, budgets, contacts, notes, and any images or documents you upload. It's stored so we can show it back to you. We don't read it, mine it, or use it to train anything.

Uploaded documents are encrypted at rest, so the raw files on the server are unreadable without the key held by the application.

Email log

When the app sends you an email (confirmation, password reset) we log the recipient address, the subject, whether it sent or failed, and the IP address the request came from. This exists so we can tell you what happened when a link doesn't arrive, and to stop the signup form being abused to send mail to strangers.

Failed sign-ins

When a sign-in attempt fails we record the address that was tried and the IP address it came from, so repeated guessing can be slowed down. Nothing is recorded when a sign-in succeeds, a successful sign-in clears any earlier failures for that address, and the rows are deleted after 24 hours.

Visit statistics

We count visits so we can tell whether anyone is finding the site and which pages are useful. We built this ourselves rather than using Google Analytics, and it is deliberately as thin as we could make it. For each page view we record: the date, the page address, the domain that linked you here (never the full referring address), any campaign tag in the link, whether you were signed in, and whether the device is a phone, tablet or computer.

Your IP address is never stored. To count a person once per day without identifying them, your IP and browser are combined with a secret value and the current date into a one-way fingerprint. It cannot be turned back into your IP, and because the date is part of it, the same visitor produces an unrelated fingerprint tomorrow — so nobody can be followed from one day to the next. Raw rows are deleted after about a year.

Cookies

One cookie: a session cookie that keeps you signed in. It's strictly necessary for the site to work and it disappears when you sign out.

There is no advertising, no third-party tracking, and no analytics cookie. Our visit statistics set nothing on your device and send nothing to anyone else — the data stays in our own database. Nothing follows you off this site. That's also why you aren't being nagged by a cookie banner.

The app also stores a little data in your browser's own storage — offline Dreams waiting to sync, shot ticks made with no signal, and whether you collapsed the sidebar. That never leaves your device except to sync your own content to your own account.

Who else can see your data

People you explicitly share a board with, under Roles & Permissions. Nobody else — with two exceptions you control:

  • Published Trip pages are public. If you switch on Publish as Trip, anyone with that link can read the page without an account. That's the purpose of the feature. The link is long and unguessable, but treat it as public: anyone you send it to can forward it. Switch the toggle off and the link stops working immediately.
  • Document download links work the same way. They're long and unguessable, but anyone holding one can download that file — that's what lets documents work on a shared Trip page.

Site administrators can access accounts for support purposes.

Where your data lives

On servers operated by DreamHost, our hosting provider, located in the United States. Using the service means your data is transferred to and stored there. They are our only processor: no analytics service, no email marketing platform, no CDN. Our visit statistics are calculated on our own server, not by anyone else.

How long we keep it

Your content stays until you delete it or ask us to delete your account. Email logs are kept as long as they're useful for support and abuse prevention.

Your rights

Under the GDPR you can ask us to show you what we hold about you, correct it, delete it, or give you a copy of it. You can object to how we use it. Email hello@merelyadream.com from the address on your account and we'll sort it out — no forms, no hoops.

If you think we've handled your data badly and we haven't fixed it, you can complain to the Danish Data Protection Agency (Datatilsynet).

Changes

If this policy changes in a way that matters, we'll update the date at the top and tell you by email before it takes effect.

A question this page doesn't answer?

Ask us