Skip to content

Privacy Policy

This policy explains what information drophost collects, why we collect it, and the choices you have. It applies to drophost.space and related share links we operate.

Last updated: August 21, 2026

Who we are

drophost ("we", "us", or "our") provides a file sharing service that lets you upload files and share them via a public URL. The service is available at drophost.space.

For privacy questions, contact us at savonen.emppu@gmail.com.

Information we collect

Depending on how you use drophost, we may process:

  • Account data. When you sign up or sign in, our authentication provider (Clerk) processes identity details such as email address, name, and profile image. We store a corresponding user record so we can associate projects and plan entitlements with your account.
  • Uploaded content. Files, filenames, content types, project names, slugs, optional passwords (stored as hashes), API keys (stored as hashes; the secret is shown once), branding settings, and custom domain settings you configure.
  • Anonymous session identifiers. Before you create an account, we may set a first-party cookie so temporary projects can later be claimed by your signed-in account.
  • Share visit data. When someone on a Starter or Pro plan shares a file, we count a view (at most once per visitor per file every 30 minutes) and a unique visitor, using a hashed IP. Free plans are not tracked. Share requests are rate limited in Postgres. Eligible owners can see views, uniques, and the last 14 days.
  • Billing data. If you subscribe to a paid plan, our billing provider (Autumn, with payment processing typically handled by Stripe) processes payment and subscription details. We receive plan and entitlement status; we do not store full card numbers on drophost servers.
  • Technical and usage data. Server logs and product analytics (including Vercel Analytics in production) may include IP address, timestamps, pages viewed, and similar diagnostics needed to run and improve the service.

How we use information

We use the information above to:

  • Operate, secure, and improve the file sharing service
  • Authenticate users and enforce plan limits
  • Store and serve files at the URLs you create
  • Provide optional password protection and custom domains
  • Show visit analytics to project owners on eligible plans
  • Process subscriptions, invoices, and customer support
  • Detect abuse, fraud, malware hosting, and policy violations
  • Comply with law and respond to lawful requests

How sharing works

Projects you publish are available at a public URL unless you add password protection (on eligible plans). Anyone with the link can open the content subject to that protection. Do not upload files you are not prepared to share under those terms.

Recipients do not need a drophost account to open a share link. Opening a link may generate visit records associated with the project.

Uploads from the HTTP API or MCP are your files under the same sharing rules as dashboard uploads. API keys are stored as hashes and are never shown again after you create them.

Service providers

We use trusted processors to run drophost. They process data only as needed to provide their services to us:

  • Clerk — authentication and account identity
  • Autumn / Stripe — subscriptions and payments
  • Cloudflare R2 — object storage for uploaded files
  • Neon (PostgreSQL) — application database
  • Vercel — hosting, edge delivery, and product analytics

These providers may process data in the United States, the European Economic Area, or other locations where they operate. We select providers that offer appropriate safeguards for cross-border transfers where required.

Cookies and similar technologies

We use cookies and similar technologies that are needed to:

  • Keep you signed in (Clerk session cookies)
  • Unlock password-protected shares for a browsing session
  • Measure aggregated site usage in production

You can block or delete cookies in your browser. Doing so may prevent sign-in or share unlock features from working correctly.

Retention and deletion

Uploaded files and project metadata generally remain until you delete the project or close your account, subject to backups and abuse-prevention logs that may persist for a limited period. Visit records are kept while the related project exists, or until we prune them as part of normal operations.

You can delete projects from the dashboard. To request account deletion or a broader data request, email savonen.emppu@gmail.com. We may retain information when required by law, to resolve disputes, or to enforce our Terms of Service.

Your rights

Depending on where you live, you may have rights to access, correct, delete, or export personal data, object to or restrict certain processing, and withdraw consent where processing is based on consent. You may also have the right to lodge a complaint with a supervisory authority.

To exercise these rights, contact savonen.emppu@gmail.com. We may need to verify your identity before fulfilling a request.

Security

We use industry-standard measures such as HTTPS, access controls, and hashed share passwords. No method of transmission or storage is completely secure. You are responsible for choosing strong share passwords when available and for deciding what content to publish.

Children

drophost is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us personal data, contact us and we will take appropriate steps to delete it.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date. Continued use of drophost after changes take effect means you acknowledge the updated policy.

Contact

Privacy requests: savonen.emppu@gmail.com. General questions about the product can start from drophost.space.

Also see Terms of Service.