Privacy Policy
Effective date: 26 June 2026
Last updated: 28 July 2026
Dropframe ("Dropframe", "we", "us", "our") operates the web hosting platform at dropframe.run and the Model Context Protocol (MCP) server endpoints.
This Privacy Policy explains how we collect, use, store, and protect information when you visit our website, log into our application, or deploy HTML projects using your AI assistant or our dashboard.
1. Information We Collect
We adhere to strict data minimization principles. We only collect information essential for service delivery, security, and billing.
1.1 Account & Identity Data
- Authentication Data: When you sign in (via Clerk), we process your email address, primary name, username, and avatar URL. We do not handle or store raw account passwords.
- Connection Credentials: We store hashed MCP tokens (
df_...) used to authenticate AI assistant tool calls. Raw tokens are displayed only once upon generation and are never stored in plaintext on our servers.
1.2 Deployed Content & App Metadata
- HTML Content: When an app is deployed via MCP or web dashboard, the self-contained HTML payload is stored in Cloudflare KV storage.
- App Metadata: We record the app ID, name, creator user ID, creation timestamp, expiry date, custom domain (if assigned), and public visibility flag.
- Public Visibility Notice: Free and standard tier deployments are publicly accessible via their URL (
dropframe.run/preview/{id}). Any personal data embedded inside your HTML code is visible to anyone with the link.
1.3 Billing & Subscription Data (Paid Plans)
- Payment processing is handled entirely by Paddle (our Merchant of Record). We do not collect, view, or store credit card numbers, bank details, or payment credentials.
- We receive transaction confirmation metadata from Paddle, including subscription status, plan tier, transaction ID, and billing period.
1.4 Technical Telemetry & Security Logs
- Edge Telemetry: Cloudflare processes edge traffic for security and DDoS mitigation. Logs include IP address, request headers, timestamp, user agent, and HTTP response code.
- Application Analytics: We aggregate non-personally identifiable telemetry (e.g., total deployments count, active users count, system error rates) to maintain platform stability and monitor capacity.
2. How We Use Information
| Information Type | Primary Purpose | Legal Basis (GDPR/UK GDPR) |
|---|---|---|
| Account & Identity | Authenticating user sessions and mapping deployments to owners | Performance of Contract |
| Deployed HTML | Hosting and serving your apps on Cloudflare's edge network | Performance of Contract |
| MCP Tokens | Authorizing AI assistant tools (dropframe_deploy, etc.) |
Performance of Contract / Security |
| Billing Metadata | Provisioning Pro/Max tier quotas and maintaining active status | Legal Obligation / Contract |
| Edge & Security Logs | Protecting platform infrastructure against abuse, attacks, and rate limit violations | Legitimate Interest |
We never sell, rent, or trade your personal data or deployed content to advertisers, data brokers, or AI model trainers.
3. Sub-Processors and Data Infrastructure
Dropframe relies on trusted enterprise cloud infrastructure providers to run our service:
| Sub-Processor | Purpose | Location | Privacy Documentation |
|---|---|---|---|
| Cloudflare, Inc. | Global Edge Computing (Workers), KV Storage, D1 Database, WAF, DNS | Global | Cloudflare Privacy Policy |
| Clerk, Inc. | User Authentication & Session Management | United States | Clerk Privacy Policy |
| Paddle.com Market Ltd | Merchant of Record, Payment Processing, Tax Compliance | United Kingdom / Global | Paddle Legal Center |
4. Data Retention and Deletion
- Free Tier Deployments: HTML content and app records are permanently deleted after 14 days. Expired files cannot be recovered.
- Pro / Max Deployments: Content is retained indefinitely while your account remains active and in good standing.
- User Account Deletion: You can trigger self-service account deletion directly from your dashboard settings (
DELETE /api/account). Deleting your account immediately and permanently purges all your deployed apps, active MCP tokens, and account records. - Billing Records: Transaction records processed by Paddle are retained for legal, accounting, and tax compliance periods (typically up to 7 years).
5. Security Measures
- Encryption in Transit: All traffic to dropframe.run, preview URLs, and API endpoints is strictly enforced over HTTPS (TLS 1.2+).
- Hashed Tokens: MCP tokens are hashed using cryptographic SHA-256 algorithms before database storage.
- Origin & Frame Isolation: Preview apps are served inside sandboxed iframe containers (
sandbox="allow-scripts allow-forms allow-same-origin") to prevent guest code from accessing parent origin storage or administrative sessions.
6. International Data Transfers
As Dropframe operates on Cloudflare’s global edge network, your deployed content and HTTP requests may be processed in edge data centers located outside your country of residence. All cross-border data transfers comply with standard contractual clauses and applicable privacy frameworks.
7. Your Privacy Rights
Under applicable privacy regulations (including GDPR, UK GDPR, and CCPA/CPRA), you have the right to:
- Access: Request a copy of personal data associated with your account.
- Rectification: Update or correct inaccurate account details.
- Erasure: Request deletion of your account and associated deployments.
- Data Portability: Download your account data and deployed HTML code.
- Objection: Object to processing based on legitimate interest.
To exercise your privacy rights, contact us at hello@dropframe.run with the subject line "Privacy Request".
8. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect infrastructure improvements or legal compliance requirements. Material updates will be highlighted on our site or notified via email to registered users 14 days prior to taking effect.
9. Contact Us
For questions regarding this policy or data protection matters:
- Email: hello@dropframe.run
- Website: dropframe.run