Privacy Policy
Last updated: August 21, 2026
Who we are
drophost ("we", "us", or "our") provides a file sharing service that lets you upload files and share them via a public URL. The service is available at drophost.space.
For privacy questions, contact us at savonen.emppu@gmail.com.
Information we collect
Depending on how you use drophost, we may process:
- Account data. When you sign up or sign in, our authentication provider (Clerk) processes identity details such as email address, name, and profile image. We store a corresponding user record so we can associate projects and plan entitlements with your account.
- Uploaded content. Files, filenames, content types, project names, slugs, optional passwords (stored as hashes), API keys (stored as hashes; the secret is shown once), branding settings, and custom domain settings you configure.
- Anonymous session identifiers. Before you create an account, we may set a first-party cookie so temporary projects can later be claimed by your signed-in account.
- Share visit data. When someone on a Starter or Pro plan shares a file, we count a view (at most once per visitor per file every 30 minutes) and a unique visitor, using a hashed IP. Free plans are not tracked. Share requests are rate limited in Postgres. Eligible owners can see views, uniques, and the last 14 days.
- Billing data. If you subscribe to a paid plan, our billing provider (Autumn, with payment processing typically handled by Stripe) processes payment and subscription details. We receive plan and entitlement status; we do not store full card numbers on drophost servers.
- Technical and usage data. Server logs and product analytics (including Vercel Analytics in production) may include IP address, timestamps, pages viewed, and similar diagnostics needed to run and improve the service.
How we use information
We use the information above to:
- Operate, secure, and improve the file sharing service
- Authenticate users and enforce plan limits
- Store and serve files at the URLs you create
- Provide optional password protection and custom domains
- Show visit analytics to project owners on eligible plans
- Process subscriptions, invoices, and customer support
- Detect abuse, fraud, malware hosting, and policy violations
- Comply with law and respond to lawful requests
Service providers
We use trusted processors to run drophost. They process data only as needed to provide their services to us:
- Clerk — authentication and account identity
- Autumn / Stripe — subscriptions and payments
- Cloudflare R2 — object storage for uploaded files
- Neon (PostgreSQL) — application database
- Vercel — hosting, edge delivery, and product analytics
These providers may process data in the United States, the European Economic Area, or other locations where they operate. We select providers that offer appropriate safeguards for cross-border transfers where required.
Retention and deletion
Uploaded files and project metadata generally remain until you delete the project or close your account, subject to backups and abuse-prevention logs that may persist for a limited period. Visit records are kept while the related project exists, or until we prune them as part of normal operations.
You can delete projects from the dashboard. To request account deletion or a broader data request, email savonen.emppu@gmail.com. We may retain information when required by law, to resolve disputes, or to enforce our Terms of Service.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data, object to or restrict certain processing, and withdraw consent where processing is based on consent. You may also have the right to lodge a complaint with a supervisory authority.
To exercise these rights, contact savonen.emppu@gmail.com. We may need to verify your identity before fulfilling a request.
Security
We use industry-standard measures such as HTTPS, access controls, and hashed share passwords. No method of transmission or storage is completely secure. You are responsible for choosing strong share passwords when available and for deciding what content to publish.
Children
drophost is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us personal data, contact us and we will take appropriate steps to delete it.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date. Continued use of drophost after changes take effect means you acknowledge the updated policy.
Contact
Privacy requests: savonen.emppu@gmail.com. General questions about the product can start from drophost.space.
Also see Terms of Service.