Privacy Policy
Last updated: March 31, 2026
1. Information We Collect
We collect the following information:
- Account data: Email address, name, and profile photo (via Clerk authentication)
- Shared content: Text and files you upload (stored temporarily until expiration)
- Usage data: IP address hashes (not raw IPs), user agent, and page views for analytics and abuse prevention
- Payment data: Processed by Razorpay — we do not store card numbers
2. How We Use Your Data
- To provide and maintain the Service
- To authenticate users and manage subscriptions
- To detect and prevent abuse (rate limiting, spam prevention)
- To provide analytics to document owners (Pro+ features)
- To respond to content reports and legal requests
3. Data Retention
Shared content is automatically deleted when it expires. Expired data is permanently removed within 24 hours by our cleanup process. Burn-after-read content is deleted immediately after the first non-owner view.
- View logs: Automatically purged after 90 days
- Server-side drafts: Purged after 30 days of inactivity
- IP hashes: Used for rate limiting and abuse prevention only; not reversible to raw IPs
4. Data Security
We implement industry-standard security measures including:
- HTTPS/TLS encryption for all data in transit
- PBKDF2 password hashing (100,000 iterations) for password-protected shares
- Short-lived JWT tokens (30-minute expiry)
- Content Security Policy, HSTS, and other security headers
- Optional client-side encryption for Elite users (E2EE)
5. Third-Party Services
- Clerk: Authentication and user management (Privacy Policy)
- Razorpay: Payment processing (Privacy Policy)
6. Cookies
We use essential cookies for authentication (Clerk session cookies) and theme preferences. We do not use tracking or advertising cookies. Third-party services (Clerk, Razorpay) may set their own cookies as described in their respective privacy policies.
7. Your Rights
You have the right to:
- Access your personal data
- Request deletion of your account and associated data
- Export your data
- Opt out of non-essential data processing
To exercise these rights, contact us at support@droptext.app.
8. Changes to This Policy
We may update this privacy policy periodically. Changes will be posted on this page with an updated "Last updated" date. Material changes will be communicated via email or in-app notification.