dropframe

Privacy Policy

Effective date: 26 June 2026
Last updated: 28 July 2026


Dropframe ("Dropframe", "we", "us", "our") operates the web hosting platform at dropframe.run and the Model Context Protocol (MCP) server endpoints.

This Privacy Policy explains how we collect, use, store, and protect information when you visit our website, log into our application, or deploy HTML projects using your AI assistant or our dashboard.


1. Information We Collect

We adhere to strict data minimization principles. We only collect information essential for service delivery, security, and billing.

1.1 Account & Identity Data

1.2 Deployed Content & App Metadata

1.3 Billing & Subscription Data (Paid Plans)

1.4 Technical Telemetry & Security Logs


2. How We Use Information

Information Type Primary Purpose Legal Basis (GDPR/UK GDPR)
Account & Identity Authenticating user sessions and mapping deployments to owners Performance of Contract
Deployed HTML Hosting and serving your apps on Cloudflare's edge network Performance of Contract
MCP Tokens Authorizing AI assistant tools (dropframe_deploy, etc.) Performance of Contract / Security
Billing Metadata Provisioning Pro/Max tier quotas and maintaining active status Legal Obligation / Contract
Edge & Security Logs Protecting platform infrastructure against abuse, attacks, and rate limit violations Legitimate Interest

We never sell, rent, or trade your personal data or deployed content to advertisers, data brokers, or AI model trainers.


3. Sub-Processors and Data Infrastructure

Dropframe relies on trusted enterprise cloud infrastructure providers to run our service:

Sub-Processor Purpose Location Privacy Documentation
Cloudflare, Inc. Global Edge Computing (Workers), KV Storage, D1 Database, WAF, DNS Global Cloudflare Privacy Policy
Clerk, Inc. User Authentication & Session Management United States Clerk Privacy Policy
Paddle.com Market Ltd Merchant of Record, Payment Processing, Tax Compliance United Kingdom / Global Paddle Legal Center

4. Data Retention and Deletion


5. Security Measures


6. International Data Transfers

As Dropframe operates on Cloudflare’s global edge network, your deployed content and HTTP requests may be processed in edge data centers located outside your country of residence. All cross-border data transfers comply with standard contractual clauses and applicable privacy frameworks.


7. Your Privacy Rights

Under applicable privacy regulations (including GDPR, UK GDPR, and CCPA/CPRA), you have the right to:

To exercise your privacy rights, contact us at hello@dropframe.run with the subject line "Privacy Request".


8. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect infrastructure improvements or legal compliance requirements. Material updates will be highlighted on our site or notified via email to registered users 14 days prior to taking effect.


9. Contact Us

For questions regarding this policy or data protection matters: