Legal

Privacy Policy

Last updated: June 1, 2026  ·  Effective immediately upon account creation

Plain-language summary

We collect only what we need to run the service. We do not sell your data. We do not serve ads. Your uploaded files are stored to serve them to people you share the link with — that's the whole point. You can delete your account and all your data at any time.

01 Who We Are

Drop Site is a free HTML app hosting platform. When this policy says "we", "us", or "Drop Site", it means the operators of the Drop Site service running at dropsite.pages.dev (or equivalent domain).

For questions about this policy, contact: privacy@dropsite.pages.dev

02 What Data We Collect

Here is a precise breakdown of what we store and why:

Data
When collected
Why / how long kept
Email address
Sign-up
Account identity and verification. Kept until you delete your account.
Password (hashed)
Sign-up
Authentication. We never store plaintext passwords. Handled by Supabase Auth.
Uploaded HTML files
Upload
Serving your app at its URL. Deleted when you delete the app, or after 90 days of no visits.
App metadata (name, description, view count)
Upload
Dashboard display and gallery. Deleted with the app.
Upload IP address
Upload
Abuse prevention and rate limiting. Not stored long-term in user profiles.
Storage usage total
Upload
Enforcing your 50 MB quota. Updated as apps are added or deleted.
Admin action log
Admin actions only
Accountability for moderation actions. Only visible to superadmins.
Report submissions
When a user reports an app
Moderation review. Retained until the report is resolved.

We do not collect: real names, phone numbers, location data, payment information (the service is free), browser fingerprints, or any tracking beyond what is listed above.

03 Cookies & Analytics

Drop Site uses session cookies only — these are set by Supabase Auth to keep you logged in. No advertising cookies, no cross-site tracking cookies.

We use Umami for anonymous, privacy-friendly analytics (page views, referrers). Umami does not use cookies and does not track individual users. No personal data is collected by our analytics.

We do not use Google Analytics, Meta Pixel, or any advertising network tracking.

04 Third-Party Services

Drop Site uses the following third-party infrastructure. Your data may pass through or be stored by these providers:

05 How We Use Your Data

We use your data exclusively to:

We do not use your data for advertising, profiling, or selling to third parties.

06 Public Content

When you publish an app as "public", anyone with the URL can view it. Public apps may also appear in the Drop Site gallery. This is the intended behaviour of the platform — it is a hosting service.

If you set an app to "unlisted", it is not shown in the gallery but is still accessible to anyone with the direct link.

Your email address is never publicly displayed anywhere on the platform.

07 Data Retention

We keep your data for as long as your account is active. When you delete your account, we delete:

We may retain anonymised aggregate statistics (e.g. total upload count for the platform) after deletion. These contain no personally identifiable information.

Admin audit logs referencing your account may be retained for up to 90 days after deletion for security and abuse prevention purposes.

08 Your Rights

You have the following rights regarding your data:

Access Request a copy of the personal data we hold about you.
Deletion Delete your account and all associated data at any time from the dashboard settings.
Correction Update your email address via account settings or by contacting us.
Portability Download your uploaded HTML files at any time from your dashboard.
Objection Object to any processing of your data beyond what is strictly necessary to provide the service.
Restriction Request that we restrict processing of your data while a complaint is being resolved.

To exercise any of these rights, contact us at privacy@dropsite.pages.dev. We will respond within 30 days.

09 Security

Your data is stored on Cloudflare and Supabase infrastructure. Passwords are hashed using bcrypt via Supabase Auth and never stored in plaintext. All connections use HTTPS/TLS.

Access to the admin panel is role-restricted. Admin actions are logged. Sensitive operations require superadmin role.

No system is perfectly secure. If you discover a security vulnerability, please report it to security@dropsite.pages.dev rather than disclosing it publicly.

10 Changes to This Policy

We may update this policy as the service evolves. We will update the "last updated" date at the top of this page. For significant changes, we will notify registered users by email.

Continued use of Drop Site after a policy update constitutes acceptance of the revised policy.

Privacy questions or data requests?

privacy@dropsite.pages.dev