← Back to DropIn

Privacy Policy

Last updated: [insert date you publish this]
Before you publish this: this is a drafted starting point, not legal advice, and I'm not a lawyer. It's built from what DropIn actually collects and sends to which third parties, but data-protection law (GDPR, CCPA/CPRA, and similar) depends on where you operate and where your users are, and changes over time. Have a qualified lawyer review this before you rely on it — and read it together with the Terms & Conditions, which it accompanies but doesn't replace. Anywhere you see bracketed text, that's a placeholder you need to fill in yourself.

This Privacy Policy explains what information DropIn (the "Service"), operated by [your name / company name] ("DropIn", "we", "us"), collects when you use it, why, and who it's shared with.

1. Information we collect

WhatWhenWhy
Name, email, password (hashed by Firebase)Creating an accountSign-in, identifying you to contacts/messages
Google account basic profileSigning in with GoogleAlternative sign-in
Display name, profile photoSet in your ProfileShown to other participants
Call metadata — room ID, start/end time, duration, participant countEvery callYour call history, reconnection, abuse response
Chat messages, whiteboard strokes, polls, Q&A, agenda, notesUsing those features in a callRelaying them live to other participants in that call
Direct messages & attachments between accountsUsing MessagesDelivering the conversation
Recordings (local or cloud)You choose to recordStorage and playback for you
Live caption transcriptYou turn on captions / request an AI summaryDisplaying captions, generating the summary you asked for
2FA secret & backup codes (encrypted)You enable 2FAAccount security
Device/camera/mic accessJoining a callThe call itself — never accessed without your browser permission prompt
IP address, rough network infoAny use of the ServiceEstablishing peer-to-peer connections (STUN/TURN), basic abuse prevention
Local browser storage (localStorage)Theme choice, remembered name, your own AI API key if you add one, draft notesConvenience — this stays on your device, we don't receive it

Guests who join without an account provide only a display name for that call — no account is created, and nothing is retained for them after the call ends unless another participant's recording or chat log happens to include it.

2. How call data actually flows

DropIn calls are peer-to-peer: video and audio travel directly between participants' devices and are never sent to or stored on our servers. Our backend only handles "signaling" (helping devices find each other) and the supporting features listed above (chat, whiteboard, etc.), which are relayed through Firebase to reach other participants in real time and are not retained by us beyond what's needed to run the call, except where you explicitly choose to keep something (a recording, a saved chat thread, call history).

3. Who we share information with

We don't sell your information. We share it only with the service providers that make DropIn work, each acting as a data processor on our behalf:

  • Firebase (Google) — authentication, the app database, and realtime call signaling. See Google's Privacy Policy.
  • Cloudinary — stores cloud recordings and message attachments you choose to upload.
  • Anthropic — receives a call's caption transcript only when you request an AI-generated summary (via your own API key or our shared key), solely to generate that summary. See Anthropic's Privacy Policy.
  • Campi — if you connect a Campi account to verify student status, it shares that verification result with us.
  • Public STUN/TURN relay infrastructure — sees connection metadata (IP addresses) needed to establish a peer-to-peer link, not call content.
  • [If you add Stripe for donations: Stripe processes payment details directly — we never see or store your card number. See Stripe's Privacy Policy.]

We may also disclose information if required by law, or to protect the rights, safety, or property of DropIn, our users, or the public.

4. Cookies & local storage

DropIn doesn't use third-party advertising or tracking cookies. We use your browser's local storage to remember your theme preference, your display name, call/device preferences, and (if you add one) your own AI API key — all of this stays on your device and is never transmitted to us. The service worker that makes DropIn installable caches app files for offline/faster loading, not personal data.

5. How long we keep information

Account data, call history, contacts, and messages are kept until you delete them or close your account. Cloud recordings and message attachments are kept until you delete them from Cloudinary via the app. Waiting-room, chat, and other in-call realtime data are cleared when a room empties out. [State your actual deletion timelines if different — e.g. "deleted accounts are purged within X days."]

6. Your rights & choices

  • You can view, correct, or delete your profile information at any time from Settings.
  • You can delete individual recordings, messages, contacts, or your entire call history from within the app.
  • You can request a copy of your data, or full account deletion, by contacting us (Section 9).
  • If you're in the EU/UK or California, you may have additional rights (access, portability, objection, deletion) under GDPR or CCPA/CPRA. [A lawyer should confirm exactly which rights apply to your users and how you'll fulfil them.]

7. Children's privacy

DropIn is not directed at children under [13 / 16 — match the age in your Terms], and we don't knowingly collect information from them. If you believe a child has created an account, contact us and we'll remove it.

8. International data transfers

Our service providers (Firebase, Cloudinary, Anthropic) may process data outside your country of residence. [A lawyer should confirm what transfer safeguards — e.g. Standard Contractual Clauses — apply for your users' locations.]

9. Contact

Questions about this Privacy Policy, or requests about your data, can be sent to [your contact email].

10. Changes to this policy

We may update this policy from time to time. If we make material changes, we'll update the date at the top of this page.