Skip to content
Aish

Privacy Policy

What data Aish collects, why, and how you control it

Last updated September 21, 2026

This policy explains how the Aish app ("Aish", "the app", "we") handles your data. The data controller is the company registered in the Republic of Kazakhstan and named in the company details at the end of this document. We process data in accordance with the Law of the Republic of Kazakhstan "On Personal Data and Its Protection" and, for users in the European Union, the General Data Protection Regulation (GDPR).

By using the app you agree to this policy. If anything here does not suit you, do not use the app and contact us — we will delete your data.

1. What we collect

Account data

  • A guest account is created automatically on first launch: a random user identifier and a device identifier. At that point we know neither your name, phone number, nor email.
  • Phone number or email address — if you choose to sign in so your dream journal survives a change of device. To sign in, we send a confirmation code by SMS or Telegram.
  • Preferences: language, time zone, and the options you pick.

Dream conversations

  • Voice — audio of what you say is streamed in real time for speech recognition and Aish's reply.
  • Conversation text — the transcript of your words and Aish's replies.
  • Results — the pictures, comics, videos, and reflections created from your dream, and your dream journal.

Dreams can be deeply personal — about health, relationships, feelings. We process such content only to hold the conversation and create the result. We do not use it for advertising or profiling.

Technical data

  • Device model, operating system and app version, app identifiers on the device, system language.
  • IP address, request timestamps, error codes, and server logs.
  • App usage events (screen opened, conversation started, format chosen) — never the content of your dreams.

Purchases

Purchases of Sparks and the Pro subscription go through the App Store, Google Play, or the payment partner on our website. From them we receive a transaction identifier, the item, the amount, and the status — never your card details.

Waitlist

If you join the waitlist on our website, we keep your email address to tell you once when Aish launches and to send a promo code for 2 weeks of Pro and bonus Sparks. You can ask us to remove it at any time through the contact form.

Support requests

What you write in the contact form, the email address you leave for a reply, and any details you attach.

2. Why we process data

PurposeDataLegal basis
Hold the dream conversation and create the resultVoice, conversation text, resultsPerformance of a contract (GDPR art. 6(1)(b))
Keep your dream journal and sync it across devicesAccount, resultsPerformance of a contract
Confirm sign-in and protect the accountPhone or email, device identifiersPerformance of a contract, legitimate interest (GDPR art. 6(1)(f))
Grant and deduct Sparks, process purchasesPurchase data, balancePerformance of a contract, legal obligation (GDPR art. 6(1)(c))
Find and fix errors, prevent abuseTechnical data, logsLegitimate interest
Understand how the app is used and improve itUsage events without dream contentLegitimate interest; you may object
Answer support requestsContact form messagesPerformance of a contract, legitimate interest

3. Artificial intelligence

Aish runs on Google Gemini models. Your voice, conversation text, and dream description are sent to Google through its API for speech recognition, dialogue, Aish's voice synthesis, and the creation of pictures, comics, and videos. We use the paid Gemini API terms, under which Google does not use the data we send to train its models.

Aish's conversation and dream reflections are generated automatically. They are not medical, psychological, or any other professional advice, and any decisions based on them are your own.

4. Who receives your data

We do not sell data and do not share it with advertising networks. Data reaches only the services the app cannot work without:

  • Google (Gemini API, Google Cloud) — processing voice and text and creating results.
  • Langfuse — an observability service that stores conversation traces (text, request parameters, cost) so we can investigate errors and account for spending. Only the team has access.
  • Yandex AppMetrica — analytics of usage events and app crashes. Dream content is never sent to analytics.
  • Apple, Google, and the website payment partner — processing purchases and subscriptions.
  • Google reCAPTCHA — protecting the contact form on the website from bots; subject to Google's privacy policy and terms.
  • Code delivery providers (SMS, Telegram) — sending the sign-in confirmation code to your number.
  • Hosting provider — running our servers and storing data.

Some of these companies are located outside your country, including in the United States. Transfers rely on contractual data-protection safeguards (EU standard contractual clauses and similar mechanisms).

5. How long we keep data

  • Voice recordings — up to 7 days after the conversation; then the files are deleted automatically.
  • Conversation text, dreams, and results — as long as your account exists or until you delete them.
  • Account and purchase data — as long as the account exists; payment records for as long as tax and accounting law requires.
  • Technical logs — a limited period, usually no longer than a few months.
  • Guest accounts that have not been used for a long time may be deleted together with their data.

6. Your rights

At any time you can:

  • find out what data we hold about you and receive a copy;
  • correct inaccurate data;
  • delete your account together with dreams, results, and conversation history;
  • object to processing based on legitimate interest, including analytics;
  • withdraw consent where processing relies on it;
  • lodge a complaint with the data-protection authority of your country (in Kazakhstan — the Information Security Committee of the Ministry of Digital Development).

To exercise these rights, contact us and quote the user ID from the Settings screen of the app, or write from the email address linked to your account. We reply within 30 days. Account deletion is irreversible: dreams cannot be restored afterwards.

7. Children

The app is not intended for anyone under 16, and we do not knowingly collect their data. If you learn that a child is using Aish, contact us — we will delete the account.

8. Security

Data travels over encrypted connections (TLS); access to servers and services is limited to the team and protected by keys and authentication. Links to media files are temporary and expire. No storage method is absolutely secure, so please do not dictate passwords, card numbers, or document numbers to Aish.

9. Changes

We update this policy when the app or the law changes. The revision date is shown at the top of the page; we announce material changes in the app. Continuing to use Aish after a change means you accept the new version.

10. Contact

Questions about data and requests to exercise your rights are accepted through the contact form.

Company details

Full company details will be published here before sales start. Questions about this document — through the contact form.