Version 2.0 · Effective 26 September 2026
Privacy Policy
This policy explains what personal data Dropslate collects, why, how long it is kept, who processes it on our behalf, and what rights you have. It covers dropslate.top, app.dropslate.top, api.dropslate.top, mcp.dropslate.top, media.dropslate.top and docs.dropslate.top (together, “the Service”).
1. Who is responsible
The data controller is Dropslate (“Dropslate”, “we”). Dropslate is operated by a private individual (natural person) resident in Ukraine. The operator’s identity is provided on request to hello@dropslate.top. Data protection contact: dpo@dropslate.top. General contact: hello@dropslate.top.
2. What we collect
| Category | Data | Source |
|---|---|---|
| Account | name, email, password hash (or the identity returned by Google sign-in), locale, time zone, two-factor secret if enabled | you |
| Workspace | workspace name, members and roles, connected network accounts (network, account id, display name, avatar URL), groups, media files you upload and their metadata (name, size, duration, checksum), posts and their history, API keys (stored as hashes) | you, your members, your agents |
| Network tokens | OAuth access and refresh tokens for each account you connect, encrypted with AES-256-GCM before they are stored; a decrypted token exists only in memory while we publish, refresh or disconnect | the network, with your authorisation |
| Publishing results | the network’s response to each post: post id, URL, status, error text | the network |
| Billing | customer id, subscription id, plan, status, period end, invoice references, the last four digits and brand of your card. We never receive or store full card numbers | Paddle or WayForPay, once paid plans open (they are not on sale yet) |
| Technical | IP address and browser string on security-relevant actions (kept 90 days, see §7); request logs with emails masked and secrets removed; error reports with the same masking | your browser or client |
| Communications | emails you send to us, waitlist and resource sign-ups | you |
| Site analytics | aggregate, cookieless page statistics (Cloudflare Web Analytics). No identifiers, no cross-site tracking | your browser |
We do not collect special categories of data, and we do not profile you.
3. Why, and on what legal basis
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Operating the Service: storing your media, publishing your posts to the networks you connect, enforcing your plan’s limits, showing you what happened | contract (6(1)(b)) |
| Billing, invoices, tax records | contract and legal obligation (6(1)(b), (c)) |
| Security: login protection, abuse prevention, audit log, backups | legitimate interest (6(1)(f)) in keeping the Service and your data safe |
| Answering support requests | contract or legitimate interest |
| Emailing you after a resource or waitlist sign-up: one email right away with the resource’s link, and one when the resource changes or the network ships | consent (6(1)(a)) — withdraw it any time by replying to that email or writing to hello@dropslate.top; we then delete your address |
| Improving the product from aggregate usage | legitimate interest; the data is aggregated and not linked to you |
We do not sell personal data and do not use it for advertising.
4. Connected networks and their API services
To publish on your behalf we use each network’s official API, with an application registered and reviewed by that network. We request only the permissions publishing requires (for example, upload and read access for YouTube; content publishing for Instagram, Facebook and Threads; direct post for TikTok). We never ask for your network password.
YouTube. Dropslate uses YouTube API Services. By connecting a YouTube channel you agree to be bound by the YouTube Terms of Service (https://www.youtube.com/t/terms). Google’s privacy policy applies to Google’s handling of your data: https://policies.google.com/privacy. You can revoke Dropslate’s access at any time on the Google security page (https://security.google.com/settings/security/permissions) or by disconnecting the account in Settings, which also deletes the stored token.
Meta (Facebook, Instagram, Threads). Connecting uses Facebook Login for Business or Threads login. We store the page or profile id, name, avatar URL and the encrypted token, and delete them when you disconnect or delete your account. How to request deletion of your data: see /data-deletion.
TikTok. Connecting uses TikTok Login Kit; publishing uses the Content Posting API. Until TikTok completes its audit of Dropslate, TikTok itself restricts posts to private visibility; we display this in the product.
Data received from a network is used only to publish, show status and let you manage your accounts. It is not shared with any other network or third party, is not used to build profiles, and is deleted when you disconnect the account, delete your workspace or delete your account.
5. Who processes data for us (subprocessors)
| Provider | Purpose | Location |
|---|---|---|
| Hosting provider (VPS) | servers that run the Service and store your media and database | Ukraine |
| Cloudflare | DNS, network protection, this website, cookieless analytics, encrypted backups (R2), routing of mail to our addresses | EU / US |
| Paddle | merchant of record and payment processing for USD plans, once paid plans open | UK / US |
| WayForPay | payment processing for UAH plans, once paid plans open | Ukraine |
| Resend | transactional email (sign-in links, receipts, failure digests) and the emails from the site’s forms | US |
| Google (Gmail) | the mailbox our support addresses (hello@, support@, dpo@) are delivered to, including sign-ups from the site’s forms | US / EU |
| Sentry | error reports, with personal data masked before sending | EU |
| BetterStack | uptime monitoring (no personal data) | EU |
| Google, Meta, TikTok | the networks you connect, only for what publishing to them requires | see their policies |
We have data processing agreements with each provider. We will update this table before adding a provider that handles personal data.
6. International transfers
The Service is hosted in Ukraine. If you are in the European Economic Area, the United Kingdom or Switzerland, your data is transferred to Ukraine under the European Commission’s standard contractual clauses (and the UK addendum where applicable). Transfers to US providers rely on the EU-US Data Privacy Framework where the provider is certified, and on standard contractual clauses otherwise.
7. How long we keep it
| Data | Retention |
|---|---|
| Account and workspace data | while your account exists; deleted within 30 days after you delete the account |
| Media files after a post goes live | the file itself is removed 72 hours after the post goes live, on every plan; the library entry (name, size, duration) stays; a pinned file, and a file still used by a draft or a queued post, is not removed; unpublished files stay until you delete them |
| Post history and publishing results | while the workspace exists |
| Network tokens | until you disconnect the account, delete the workspace or delete the account — then immediately |
| Audit log | the record of the action stays with the workspace; the IP address and browser string are erased after 90 days |
| Request and error logs | 30 days |
| Encrypted backups | 30 days, then overwritten |
| Billing and tax records | as long as Ukrainian tax law requires (currently 3 years after the year of the transaction) |
| Waitlist and resource sign-ups | the address is forwarded to hello@dropslate.top, a Gmail mailbox, only to send the email you asked for, and kept there until it is sent; deleted within 30 days after it, and in any case no later than 12 months after you signed up |
8. How we protect it
Network tokens are encrypted at rest with AES-256-GCM and a key that is never stored next to the data. Media is served only through signed, expiring links; directories are never listed. API keys are stored as hashes. Passwords are hashed with a modern algorithm. All traffic uses TLS. Two-factor authentication is available for every account. Our own staff access production only for support or incident response, and every such access is logged. Card data never touches our systems. If a breach affects your data, we will notify you and, where required, the supervisory authority within 72 hours of becoming aware.
9. Cookies
Only functional cookies, none of which require consent: your session, your CSRF token, your theme and your language. There are no advertising or tracking cookies, and no consent banner because none is needed. Site analytics is cookieless.
10. Your rights
Wherever you live, you can: access your data (export as JSON from Settings or through the API), correct it, delete your account (Settings, with an emailed confirmation; a workspace with other members needs an owner transfer first), and withdraw consent to emails with the link in any email. If you are in the EEA, UK or Switzerland you also have the rights to restriction, objection and data portability, and to lodge a complaint with your supervisory authority. If you are in Ukraine, you have the rights set out in the Law of Ukraine “On Personal Data Protection”, including the right to complain to the Ukrainian Parliament Commissioner for Human Rights. Write to dpo@dropslate.top for any request. We answer within 30 days and may ask you to confirm your identity through the email on your account.
11. Children
The Service is not intended for anyone under 16 (or under 18 where local law sets that age). We do not knowingly collect data from children; if you believe a child has created an account, contact us and we will delete it.
12. Changes
We will post changes here with a new version number and date. For a material change we will email account holders at least 14 days before it takes effect.
13. Contact
Data protection: dpo@dropslate.top · Support: support@dropslate.top · General: hello@dropslate.top