This Privacy Policy explains what information DropIn (the "Service"), operated by [your name / company name] ("DropIn", "we", "us"), collects when you use it, why, and who it's shared with.
| What | When | Why |
|---|---|---|
| Name, email, password (hashed by Firebase) | Creating an account | Sign-in, identifying you to contacts/messages |
| Google account basic profile | Signing in with Google | Alternative sign-in |
| Display name, profile photo | Set in your Profile | Shown to other participants |
| Call metadata — room ID, start/end time, duration, participant count | Every call | Your call history, reconnection, abuse response |
| Chat messages, whiteboard strokes, polls, Q&A, agenda, notes | Using those features in a call | Relaying them live to other participants in that call |
| Direct messages & attachments between accounts | Using Messages | Delivering the conversation |
| Recordings (local or cloud) | You choose to record | Storage and playback for you |
| Live caption transcript | You turn on captions / request an AI summary | Displaying captions, generating the summary you asked for |
| 2FA secret & backup codes (encrypted) | You enable 2FA | Account security |
| Device/camera/mic access | Joining a call | The call itself — never accessed without your browser permission prompt |
| IP address, rough network info | Any use of the Service | Establishing peer-to-peer connections (STUN/TURN), basic abuse prevention |
| Local browser storage (localStorage) | Theme choice, remembered name, your own AI API key if you add one, draft notes | Convenience — this stays on your device, we don't receive it |
Guests who join without an account provide only a display name for that call — no account is created, and nothing is retained for them after the call ends unless another participant's recording or chat log happens to include it.
DropIn calls are peer-to-peer: video and audio travel directly between participants' devices and are never sent to or stored on our servers. Our backend only handles "signaling" (helping devices find each other) and the supporting features listed above (chat, whiteboard, etc.), which are relayed through Firebase to reach other participants in real time and are not retained by us beyond what's needed to run the call, except where you explicitly choose to keep something (a recording, a saved chat thread, call history).
We don't sell your information. We share it only with the service providers that make DropIn work, each acting as a data processor on our behalf:
We may also disclose information if required by law, or to protect the rights, safety, or property of DropIn, our users, or the public.
DropIn doesn't use third-party advertising or tracking cookies. We use your browser's local storage to remember your theme preference, your display name, call/device preferences, and (if you add one) your own AI API key — all of this stays on your device and is never transmitted to us. The service worker that makes DropIn installable caches app files for offline/faster loading, not personal data.
Account data, call history, contacts, and messages are kept until you delete them or close your account. Cloud recordings and message attachments are kept until you delete them from Cloudinary via the app. Waiting-room, chat, and other in-call realtime data are cleared when a room empties out. [State your actual deletion timelines if different — e.g. "deleted accounts are purged within X days."]
DropIn is not directed at children under [13 / 16 — match the age in your Terms], and we don't knowingly collect information from them. If you believe a child has created an account, contact us and we'll remove it.
Our service providers (Firebase, Cloudinary, Anthropic) may process data outside your country of residence. [A lawyer should confirm what transfer safeguards — e.g. Standard Contractual Clauses — apply for your users' locations.]
Questions about this Privacy Policy, or requests about your data, can be sent to [your contact email].
We may update this policy from time to time. If we make material changes, we'll update the date at the top of this page.