Privacy Policy
Last updated: 2026-09-10 · This policy explains what we collect, why, and your choices. Plain language, no surprises.
The short version
We do not sell or share your email or usage information with any other company. We collect the minimum needed to run the service, we don't rent it out, and we don't use your content to train AI models. Marketing email is strictly opt-in.
1. What we collect
- Account data: your email address and a securely hashed password. We never store your password in plain text.
- Content: the pastes and files you upload, and their settings (visibility, expiry, name).
- Usage & security data: we log view counts and, to prevent abuse and count views fairly, we store a one-way hash of visitor IP addresses — not the raw IP. We keep short-lived counters for rate limiting.
- API keys: stored only as a hash; the full key is shown to you once and never again.
2. How we use it
- To operate the service — store and serve your content, run your account, and provide the API.
- To keep the service safe — detect abuse, enforce rate limits, and act on reports.
- To send essential account email — verification, password resets, and security or suspension notices. These are not marketing and can't be opted out of while you hold an account.
- To send the newsletter and occasional deals or offers — only if you opt in.
3. We don't sell or share your data
We do not sell, rent, or trade your email address or usage information to any third party. We do not share it with advertisers or data brokers. Your content is yours; we don't use it to train models, and we don't hand it to anyone except as required by law (see section 6).
4. Marketing email is opt-in
When you register you can choose to receive our newsletter and occasional deals and offers by ticking the box — it is off by default. You can turn it on or off anytime from your account settings, and every marketing email includes an unsubscribe link. Turning off marketing never affects essential account email.
5. Service providers we rely on
We run on Cloudflare (hosting, storage, database) and use Resend to deliver email. These providers process data only to provide their service to us, under their own security and privacy commitments. They are not permitted to use your data for their own purposes.
6. Legal requests
We may disclose information if required by a valid legal process, or to protect the rights, safety, or property of DashDrop, our users, or the public — for example, responding to illegal content. We disclose the minimum necessary.
7. Data retention
Content created without an account is kept up to 90 days, then deleted. Account content is kept until you delete it or close your account. When you delete something, it stays recoverable for 7 days, then is permanently removed. IP hashes and rate-limit counters are short-lived and cleared automatically.
8. Your rights
You can access and export all your data at any time from your dashboard (or the export API). You can delete individual items, or your whole account. If you're in a region with data-protection laws (such as the EU/EEA under GDPR), you have rights to access, correct, export, and erase your personal data — the tools above let you do this yourself, and you can email us for anything else.
9. Security
Passwords are hashed, API keys are hashed, connections use HTTPS, and optional two-factor authentication is available. No system is perfectly secure, so please use a strong, unique password and keep your API keys secret.
10. Children
DashDrop is not intended for anyone under 16. We don't knowingly collect data from children. If you believe a child has created an account, contact us and we'll remove it.
11. Changes
We may update this policy. Material changes affecting account holders will be announced by email at least 14 days before taking effect.
12. Contact
Privacy questions: privacy@dashdrop.dev · General: support@dashdrop.dev
This is a plain-language policy, not legal advice. For your own compliance needs, consult a lawyer.