Back

Trust Center

How Noctely protects your data, which laws apply, who handles what.

This page is maintained by Hacktualiz Inc. (Delaware, USA) to answer common security and privacy questions about Noctely. It describes the controls we've enabled and the practices we follow — it is not an independent certification.

Data controller

Hacktualiz Inc., incorporated in Delaware (USA) via Stripe Atlas, is the sole data controller for your personal data. An EU Article 27 representative covers the European Union.

Compliance contact: hello@noctely.com

Applicable legal frameworks

  • GDPR (EU / France)

    EU Regulation 2016/679. Authority: CNIL.

    EU Art.27 representative being appointed.

  • CCPA / CPRA (California)

    California Consumer Privacy Act. Access, deletion, opt-out.

    "Do Not Sell/Share" honored: Noctely never sells data.

  • COPPA (US federal)

    Protection of children under 13.

    Sign-up refused under 16 (strict EU + US coverage).

  • SCC (EU → US transfers)

    Standard Contractual Clauses 2021/914 for non-EU transfers.

    Signed with each US subprocessor (see list below).

Your rights

Access, rectification, erasure, portability, restriction, objection, consent withdrawal, complaint to a supervisory authority (CNIL, FTC). Exercise these rights from /settings or by writing to hello@noctely.com — we reply within 30 days.

Subprocessors

These vendors process a portion of your data on our behalf, only on our instructions and under a signed DPA (Data Processing Agreement).

Loading…

What we will never do

  • Sell or rent your data to a commercial third party.
  • Train AI models on your dreams without explicit consent.
  • Use your dreams for targeted advertising.
  • Keep your account after a deletion request.

Operational security

  • In-transit encryption (TLS 1.3) on all connections.
  • Row Level Security (Postgres) on every table containing personal data.
  • Admin access logging, timestamped and tamper-resistant.
  • Turnstile (Cloudflare) in invisible mode to block automated abuse.
  • AES-256-GCM at-rest encryption of dreams — rollout in progress.

A question? hello@noctely.com