Privacy, plainly.
How Dropboard handles your information.
Dropboard lets you share notes, doodles, photo stickers and song cards with friends, including on Home Screen widgets. Panth Shah is responsible for the personal information handled by Dropboard. Contact panthshah27@gmail.com for privacy questions or requests.
What we collect
- Account information: your account identifier, email address and profile name, including information supplied by a sign-in provider you choose. Dropboard does not receive your Google or Apple password. If you previously used email/password authentication, authentication credentials are handled by Supabase.
- Friends and activity: invitation records, friend connections, selected recipients, delivery records and timestamps.
- Your drops: the messages, drawings, board text, selected photos or stickers, song information and artwork you send.
- Safety information: blocks and reports, including the reported person or drop, reason, optional details and review status.
- Device storage: unfinished drafts, cached drops, widget selections and sign-in session information. Drafts are separated by account on the device. The app and its widget share local storage to display your selected drop.
- Service and support information: information you email us and technical information processed by our service providers, such as IP addresses, request times, authentication events and errors.
Why we use it
We use this information to sign you in, connect you with friends, deliver drops, display widgets, remember drafts, answer support requests and prevent abuse. We do not sell personal information, use it for targeted advertising, or add advertising or cross-app tracking SDKs to Dropboard.
Where a legal basis is required, we process information to provide the service you request, pursue legitimate interests in service security and support, comply with legal obligations, or rely on consent where applicable. You can withdraw optional device permissions in iOS Settings.
Who can see it
Sending a drop shares its content with the recipient you choose. Friends see the profile information needed to recognize you. Recipients can save copies or take screenshots; only share information you are comfortable with them keeping.
Authorized administrators can access backend information when needed to operate the service, handle support or investigate abuse. Reports are not displayed to the reported person in the app. Dropboard does not provide end-to-end encryption.
We use Supabase for authentication and backend storage. Our current project database is in Oregon, United States. Sign-in providers process requests when you choose them. Apple music catalog services receive music searches and artwork requests; supported song metadata requests may contact Spotify. These requests can include a search term or track URL and network information. Opening a song in another app is covered by that service’s privacy practices.
Support email is handled through Gmail. These public pages are hosted using Sites; the hosting infrastructure may process standard network and request information to serve and protect the pages. We have not added analytics, advertising pixels or contact forms to these pages. Providers may process information outside your country under their own applicable safeguards and policies.
Provider information: Supabase, Google, Apple, Spotify and OpenAI. We may also disclose information when legally required or necessary to protect people, rights or service security.
Photos and camera
You choose which photos to add, or optionally take a photo. Sticker background removal runs on your device. A photo or sticker included in a sent drop is uploaded as part of that drop so your recipient can receive it. Dropboard does not upload your entire photo library. Manage camera and photo access in iOS Settings.
How long information stays
- Account and shared content: we retain account information and drop history while the account exists; there is no automatic expiry of old drops. Deleting an account removes its profile, related friendships, invitations, sending records and drops associated with it from the active application database, including drops sent to or received from that account.
- Invitation codes: codes normally expire after seven days. Expiry prevents their use; it does not automatically erase the invitation record. Associated records are removed through account deletion.
- Blocks and reports: a block lasts until you unblock the person or either account is deleted. Reports remain for abuse review unless removed by an administrator or either involved account is deleted. Marking a report resolved does not itself erase it. You may contact us about deleting report information.
- Local drafts and caches: signing out keeps account-specific drafts on that device so they can return when you sign in again. Editing or resetting a draft replaces or clears it. Account deletion clears that account’s local app data on the device performing deletion. Other devices and recipients’ cached drops or widgets may remain until they reconnect and successfully refresh. iOS controls widget refresh timing.
- Support emails: correspondence is kept to handle your request and follow-up; it has no automatic expiry and is separate from your app account. Request its deletion by email. We may retain information necessary for an unresolved dispute or legal obligation, and will explain applicable exceptions when responding.
- Operational logs and backups: Supabase currently provides one day of API and database log retention on our Free plan. Writing new authentication audit logs into our project database is disabled. This is not a promise that every provider-held security record expires within one day. Our current plan does not include scheduled project backups. Provider-held operational records and any internal recovery copies are governed by provider retention practices and are not erased instantly by deleting a Dropboard account.
Delete your account or request help
In Dropboard, open Settings → Delete account and confirm. This is different from signing out. If the request fails, reconnect and retry, or email us from the account’s email address. Account deletion does not delete your Google or Apple account. You can manage Dropboard’s access separately in your sign-in provider’s account settings.
Copies saved outside Dropboard, including screenshots or exported content, cannot be recalled. Device or operating-system backups you control may also contain local app data; manage those through your device or backup provider.
Depending on your location, you may have rights to access, correct, delete or receive a copy of your information, restrict or object to processing, withdraw consent, or complain to your local data protection authority. Email panthshah27@gmail.com. We may verify your identity before acting and will respond within applicable legal deadlines. Never send passwords or verification codes.
Age eligibility
Dropboard is intended for people aged 13 and older, or the higher minimum age required where they live. It is not directed to children under 13. If you believe a child below the applicable minimum age has provided personal information, contact us so we can investigate and address it.
Updates
We will update the effective date when this policy changes and provide additional notice where required. Questions? Visit Support or email panthshah27@gmail.com.