Privacy
Updated 8 September 2026
Drophere hosts files and pages and provides account, sharing, and collaboration tools. This notice describes the information used to provide those services.
Account information
When you sign in with an email code, we use your email address to verify access to your account. We store an account identifier, email address, account credentials, and your account settings. We associate your files, access grants, routes, and billing status with that account.
Sign in with Google
Google sign-in is optional. When you choose it, Google sends a signed identity token to Drophere. We verify the token and use your Google account identifier, email address, email verification status, and, where present, Google Workspace domain information to identify your account. Basic profile information may be included in Google's response; we do not save your Google name or profile photo in the account record.
We store the association between your Google account identifier and your Drophere account. We use it to sign you in to the same account when you return. We may ask you to verify your email separately before linking an account. We do not request access to your Gmail messages, Google Drive files, contacts, or calendar.
Google identity tokens are processed for verification and are not retained in the account database. We keep short-lived login attempts and email-proof information to prevent replay and misuse. Attempts expire after ten minutes and are removed by scheduled cleanup. We do not use Google account information for advertising or sell it.
Files and collaboration
We store files, file metadata, comments, and access settings that you or your authorized agents submit. Public files can be read by anyone with access to their URL. Restricted files use the access rules set by their owner. Other users can see the content and collaboration information that those rules allow them to see.
Hosted pages can contain code or services selected by their publisher. Those publishers are responsible for information collected by their pages. This notice covers Drophere's service, not every independently published page.
Browser storage and service records
We use browser cookies for account, visitor, and protected-file sessions. The account page also uses local browser storage for its API key, email, settings, and login coordination. Treat your API key as a password. Sign out on shared devices.
We process request information, including IP addresses and error records, for service operation, security, abuse prevention, and usage measurement. File owners can see visit totals. Approximate unique-visitor counts use identifiers derived from a daily-changing hash.
Service providers
Cloudflare provides hosting and storage infrastructure. Neon provides the account database. Resend sends verification and service emails. Google provides Google sign-in when you choose that option. Stripe processes subscription payments and provides billing records. These providers process the information needed for their part of the service. Information may be processed in countries other than your own.
Retention and your choices
Account and file information is kept to operate your account and the files you publish. Temporary files expire according to their configured lifetime. Deleted information can remain in backups or records needed for security, recovery, billing, or legal obligations.
You can use email login without Google, sign out, manage your files and access grants, and rotate your API key. You can also remove Drophere's Google access in your Google account settings. Removing access at Google does not delete your Drophere account, files, or existing Drophere sessions.
To request access, correction, deletion, or an explanation of how your information is used, contact info@drophere.cc. We may need to verify account ownership before acting on a request.
Contact and changes
For privacy questions, contact info@drophere.cc. We will update this page when these practices change.