Security at Ruya

A dream journal is one of the most personal things a person can keep. Protecting it is not a feature of Ruya — it is the condition for everything else we build. This page explains, in plain language, how your data is protected, what we deliberately never do with it, and how to reach us if you find a security problem.

How Your Data Is Protected

  • Encrypted in transit. Every connection between your device and our servers uses TLS (HTTPS). There is no unencrypted path to Ruya.
  • Encrypted at rest. Our databases and file storage are encrypted at rest, and your most sensitive data — the personal context used to improve your interpretations — is additionally encrypted at the application level with AES-256, so it stays unreadable even in a raw database export.
  • Passwords are never stored. We keep only a one-way bcrypt hash of your password. Nobody at Ruya can see it, and it cannot be recovered from our database.
  • Hosted in the European Union. Ruya runs on Microsoft Azure and MongoDB Atlas in EU data centres in Ireland.
  • Abuse protection. Sign-in and account flows are protected against bots with Cloudflare Turnstile, and our API applies rate limiting.

Your Dreams Stay Private

Your journal is for your eyes only. We treat the content of your dreams, diary and life events as radically private:

  • Never shared with analytics or advertisers. The text of your entries is never sent to any analytics or advertising service. Usage analytics can see that a dream was saved — never what it says.
  • Ruya staff cannot browse your journal. Our internal support tools show account and subscription information and entry counts only. There is no feature that displays a member's journal to an administrator.
  • Never used to train AI. Dream interpretation runs on Azure OpenAI under enterprise terms: your content is never used to train AI models.
  • Optional app lock. You can protect the mobile app with Face ID, Touch ID or your device passcode, so your journal stays private even if someone borrows your phone.

Payments

All subscriptions are processed by Apple's App Store, Google Play, or our payment partners RevenueCat and Stripe on the web. Your card details go directly to those providers: they never touch Ruya's servers, and we never store them.

Your Controls

  • Delete your account at any time. Deleting your account permanently removes your journal and personal data from our production systems.
  • Personal context is optional. You decide whether your interpretation answers are saved to improve future interpretations, and you can switch this off.
  • Take your dreams with you. You can export your journal as a beautifully formatted dream book whenever you want your own copy.

Reporting a Security Issue

No system is perfect, and we value the work of security researchers. If you believe you have found a vulnerability in any Ruya service — ruya.co, web.ruya.co, our API, or the iOS and Android apps — please email [email protected] with a description of the issue, steps to reproduce it, and its potential impact.

If you report in good faith, we promise:

  • We will acknowledge your report within 3 business days.
  • We will keep you informed while we investigate and fix the issue.
  • We will credit you publicly for a confirmed report, if you wish.
  • We will not take legal action against research conducted in good faith under this policy.

In return, we ask that you:

  • Only test against accounts you own — never access, modify or delete another member's data.
  • Do not run denial-of-service tests, spam, or social-engineering attacks against Ruya or its members.
  • Keep any automated scanning low-volume, so other members are not affected.
  • Give us reasonable time to fix an issue before disclosing it publicly.
  • Report vulnerabilities in third-party platforms we use (Apple, Google, Stripe, RevenueCat, Microsoft Azure, Cloudflare) to those vendors directly.

We do not currently run a paid bug-bounty programme, but every valid report is investigated, fixed and credited. Our machine-readable security contact is published at ruya.co/.well-known/security.txt.


Common Questions

Can Ruya staff read my dreams?
No. The content of your journal is never shown in our internal tools. Support staff can see account and subscription information and how many entries you have — not what any of them say.
Is my dream data used to train AI models?
No. Interpretation requests run on Azure OpenAI under enterprise terms that exclude your content from model training — by us and by the model provider.
Where is my data stored?
In EU data centres in Ireland, on Microsoft Azure and MongoDB Atlas, encrypted in transit and at rest.
What happens when I delete my account?
Your journal entries, interpretations and personal data are permanently removed from our production systems. Encrypted backups expire automatically on a rolling schedule.
How do I report a security problem?
Email [email protected] with steps to reproduce the issue. We acknowledge every report within 3 business days — see the disclosure policy above.

Security is never finished. We review our practices regularly and will keep this page updated as our security programme evolves. Last updated: August 2026.