1. Information we collect
We collect only the information needed to provide and secure the Drops service:
- Account information — your name and email address when you create an account on the Drops dashboard.
- User-generated content — the web apps, files and assets you create, upload or publish through Drops. This content belongs to you and is stored to serve it on the web.
- Usage data — basic metadata such as request timestamps, file sizes and site names, used to operate, troubleshoot and improve the platform.
- Authentication tokens — API keys and session tokens used to authenticate requests (see below).
We do not intentionally collect sensitive personal data such as health, financial or biometric information.
2. API keys
Drops API keys (drops_live_…) belong to you. They are the credentials that let
your account, your tools and AI agents such as Drops AI authenticate requests to the Drops
API.
- API keys are used only to authenticate API requests on your behalf.
- API keys are never shared with third parties.
- API keys are transmitted securely over HTTPS and stored using industry-standard hashing and encryption.
- API keys are only shown in full at the moment they are created.
- You can create and revoke API keys at any time from the dashboard or the API.
3. Authentication
We authenticate requests using secure bearer tokens. When you sign in, we issue session tokens; when you create an API key, we issue an API key for programmatic and AI-agent access.
- Session tokens keep you signed in to the dashboard and are linked to your account.
- API keys authorize access to the Drops API and Drops AI actions.
- All authentication traffic is encrypted in transit using TLS / HTTPS.
- Password hashes are stored using strong, one-way hashing algorithms — we never store or view your plaintext password.
4. Data usage
We use your information solely to provide and operate the Drops service:
- To create, host and serve the web apps you publish.
- To authenticate API requests and manage access.
- To maintain security, prevent abuse and respond to support requests.
- To improve reliability and performance of the platform.
In particular, for Drops AI (Custom GPT Actions):
- GPT Actions access the Drops API only when you initiate them as part of a conversation with the AI assistant.
- We only process the requests necessary to provide the service you asked for.
- Content you ask an AI agent to create or publish is processed in order to create or publish it — and for no other reason.
5. Data retention
- User-generated content is retained for as long as you keep it hosted, or until you delete your sites or files. Deleting content removes it from public availability immediately.
- Account information is retained while your account is active. You may delete your account at any time.
- Usage and request metadata is retained for a limited period (typically 12 months) for operational and security purposes, after which it is deleted or aggregated.
- API keys are retained until you revoke or delete them. Deleted keys are invalidated immediately and their secret values are permanently removed.
Some data may be retained longer where required by law or to defend against legal claims, in which case access is restricted.
6. Third-party services
Drops relies on a limited set of infrastructure providers to run the platform, including cloud hosting and content-delivery networks. These providers process data only to the extent necessary to deliver the service and are contractually bound to keep it confidential.
- We do not share your API keys with any third party.
- We do not share your uploaded content with third parties for marketing purposes.
- When you use Drops AI (Custom GPT Actions), your conversation and the resulting API requests are handled in accordance with the AI assistant's own terms and privacy policy, in addition to this policy.
8. Security
We take the security of your data seriously and apply industry-standard measures, including:
- End-to-end encryption of all traffic in transit using HTTPS / TLS.
- Encryption of sensitive data at rest.
- Hashed, one-way storage of passwords and API key secrets.
- Access controls and least-privilege policies for our team and systems.
- Monitoring for unauthorized access and abuse.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. Please report any suspected vulnerability or unauthorized access to the contact details below.
9. User rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate personal data.
- Delete your data and account.
- Export your data, such as your uploaded files and sites.
- Object to or restrict certain processing.
- Withdraw consent where processing is based on consent.
You can exercise most of these rights directly from the dashboard, including deleting your account and sites. For anything else, contact us using the details below and we will respond within a reasonable timeframe.
10. Contact information
If you have questions about this policy, your data, or privacy at Drops, please reach out:
- Website: https://drops.sh
- Dashboard: https://app.drops.sh
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology or legal requirements. When we make material changes, we will update the effective date at the top of this page and, where appropriate, notify you through the dashboard or by email.
Your continued use of the Drops service after changes take effect constitutes acceptance of the updated policy.
This policy was last updated on August 5, 2026.