Security Overview
Security Overview of Dreamdrive, operated by Synthetic White AB. Version 1.0, effective 3 October 2026.
1. Our approach
Dreamdrive is a small service with a narrow job, and our security approach reflects that: collect as little as possible, keep it in the EU, encrypt it, limit who can reach it, and keep the parts that touch third parties read-only. This page describes our technical and organisational measures in plain words. It is the public version of Annex II of the Data Processing Agreement. No service can promise absolute security, and we do not.
2. The extension is read-only
The extension reads pages on platforms you connect and files you import. It never clicks, types, submits or generates anything, and it uses no platform's private API. It reads only on sites you have granted permission for in Chrome, and it stays off pages that show other people's work. This design limits the data it can collect to your own work and means it cannot act on a platform in your name even if it misbehaves. Settings sent to the extension from our servers (such as page selectors) are data, not executable code.
3. Encryption
- Every connection uses TLS (HTTPS). The API and website do not serve plain HTTP, and the strict-transport-security header tells browsers to insist on HTTPS.
- Data stored in Cloudflare D1, R2 and KV is encrypted at rest by Cloudflare.
- Third-party API keys that the service holds (for Stripe, email and, if ever enabled, model providers) are encrypted with AES-GCM using a key derived from a secret kept in the platform's secret store, separate from the database. The administration screen shows only the last four characters of a key, never the value.
4. Where data lives
The database runs on Cloudflare D1 with the EU jurisdiction setting, and thumbnails, when enabled, are stored in a Cloudflare R2 bucket in the EU. Thumbnails are small (up to 512 pixels on the longest side) WebP images; the original images stay on the platform's own servers and we store only their addresses. Card details never reach us; Stripe hosts the checkout. Details on Cloudflare's safeguards are in the Subprocessors list.
5. Who can access what
- Administration is limited to the owner's Google account. There are no shared administrator passwords.
- Staff who run the service and give support can see customer records (email, plan, usage counts, capture metadata) only as far as needed for that work, and are bound by confidentiality.
- Every database query is scoped to the signed-in user's account. One user cannot read another's captures through the API.
- Share links use a random 32-byte token that cannot be guessed, are checked for revocation on every request, and ask search engines not to index the page.
6. Signing in
You sign in with Google (OpenID Connect; we never see your Google password) or with a six-digit code sent to your email, which expires within minutes and can be used once. Session tokens are random and can be revoked by signing out. Repeated failed code attempts are rate-limited.
7. Payments
Stripe handles all payments. Every webhook message from Stripe is checked against Stripe's signature before any change is made to a plan, so a forged message cannot change your account.
8. The website and API
- Security headers are set on every response: content security policy, frame protection, strict transport security, referrer policy and content-type protection.
- API input is validated and errors do not reveal internal details.
- Website analytics use a daily-rotating hash and no cookies, so there is no tracking identifier to leak.
- Server logs containing IP addresses are kept for a short period only.
9. Availability and backups
The service runs on Cloudflare's distributed network. The database has platform-level backups and point-in-time recovery. Code and configuration are kept in version control, and builds are type-checked before deployment, so a known-good version can be redeployed quickly.
10. Incident response
If we learn of a security incident, we assess it, contain it, fix the cause and record what happened. If personal data is affected in a way likely to put people at risk, we notify the supervisory authority within 72 hours and affected users without undue delay, as the GDPR requires. Business customers are notified under the Data Processing Agreement within 48 hours of our becoming aware.
11. Reporting a vulnerability
If you find a security problem, email info@dreamdrive.ai with enough detail for us to reproduce it. We will acknowledge your report, keep you informed, and credit you if you wish. Please give us reasonable time to fix the problem before publishing, do not access other people's data, and do not run denial-of-service or social-engineering tests. We will not take legal action against good-faith research that follows these rules.
12. What you can do
- Protect the Google account or email address you sign in with; it is the key to your Dreamdrive account.
- Connect only the platforms you actually use, and turn capture off for a platform when you no longer need it.
- Share usage sheets only with people you trust, and revoke links when a project is done.
- Keep Chrome and the extension up to date.