Privacy Policy
Our Commitments
This Privacy Policy describes how dechnologies, llc, a North Carolina limited liability company ("Dropboard," "we," "us"), collects, uses, and shares information when you use the Dropboard app and related services (the "Service"). It applies to everyone who uses the Service, including guest users who have not yet created an account.
Dropboard is built to be the opposite of a public feed: your canvases are shared only with friends you mutually accept. We collect what we need to run the Service — and:
- We do not sell your personal information
- We do not share it for advertising, and there are no ads in the Service
- We do not use your content to train AI models
- Apple Health data is never used for advertising, marketing, or data mining
1. Information We Collect
We collect the following categories of information. Under U.S. state privacy laws these include identifiers, customer records, commercial information, network activity, geolocation (only inside content you choose to include), audio/visual information, health information, and limited usage inferences.
Information you provide:
- Account and profile information — name, email, username, optional profile photo (sign-in is operated by our provider, Clerk)
- Your content — photos, notes, links, places you tag, movies/TV/books you log, workouts you import, content you select via iOS journaling suggestions, polls you create and the votes you cast (after you vote, your vote and the results are visible to the people who can see that poll), reactions and replies (including @mentions), and your friend connections, requests, and blocks
- Search text you type in the place/movie/TV/book pickers, sent to the relevant provider (Google Places, TMDB, OpenLibrary) to return results — without your name or account identity
- Communications you send us (support or privacy requests)
Information collected automatically:
- Usage information — screens viewed, features used, and in-app events, via our analytics provider (PostHog)
- Device and diagnostic information — device model, OS and app version, language, time zone, device identifiers, push tokens, IP address, crash and error logs from the app and our server functions (Sentry), and, for guest mode abuse prevention, device integrity attestations (Apple App Attest / Google Play Integrity) and a random guest identifier stored on your device
- Purchase information — subscription status, purchase and refund events, and platform receipts via Apple/Google billing and RevenueCat, plus our own record of your credit balance and credit activity (credits granted, spent, refunded, and expired); we never receive your full payment card number
Health and fitness information (optional, iOS):
- Only if you connect Apple Health: workouts (type, duration, date), related statistics (distance, energy, heart rate), and, where available, the workout's GPS route
- If you drop a workout onto your canvas, its details (including a rendered route map) are stored with your other content so your canvas syncs and your accepted friends can see it
- Used only to provide this feature — never for advertising, marketing, data mining, or sale, and never shared except as necessary to provide the feature you asked for
Location:
- We do not track your device's location in the background
- Location appears only inside content — a place you deliberately tag, or the route attached to a workout you import
2. How We Use Information
We use the information we collect to:
- Provide, maintain, and personalize the Service — your canvas, your friends' feeds, syncing, widgets, AI artwork generation, notifications you've enabled, and your preferences
- Process purchases and manage subscriptions through Apple/Google and RevenueCat, including free trials, entitlements, credit balances and allowances, and refund reversals
- Communicate with you — service messages, notifications you control, and support
- Understand and improve the Service — analytics, crash diagnostics, and research on aggregated or de-identified data
- Keep the Service safe — authentication, device integrity for guest mode, fraud and abuse prevention, enforcing limits, and moderating reported content
- Comply with law and enforce our Terms of Service
- For any other purpose disclosed at collection, or with your consent
3. AI Features
To generate day-card artwork, relevant content from your canvas is sent to third-party AI model providers — currently Google (image generation) and xAI (video generation) — acting as our processors, together with our own servers. Generation happens when you use the feature; for your first card, as part of onboarding you initiate; and automatically at the end of a day you added drops to — if you finished a day with several drops and no artwork, our servers generate it overnight (based on your local time zone) so it's ready in the morning, with the same content, providers, and protections as generation you request.
- No training: we do not use your content or outputs to train AI models, and we use these providers under API terms that do not permit them to train their models on your data
- Provider retention is limited to delivering the output and operating the API (such as short-term abuse monitoring)
- We do not routinely review your content or artwork; we may review specific content to investigate abuse, a report, or a legal obligation
4. How We Share Information
We do not sell personal information, and we do not share it for cross-context behavioral advertising (and have not in the preceding 12 months). We share personal information only:
- With the friends you choose — your profile and dropped content are visible to your mutually accepted connections (including, after you vote on a poll, your vote and the poll's results); there is no public feed
- With service providers who process data only on our instructions: Clerk (authentication), Supabase (database and storage), RevenueCat (subscriptions), PostHog (analytics), Sentry (crash reporting), Expo/Apple/Google (app infrastructure and push delivery), Google (AI image generation and Places search), xAI (AI video generation), TMDB and OpenLibrary (movie/TV and book search — your search text, never your account identity), and Apple (platform services you invoke, such as HealthKit, Maps, sign-in, and billing)
- With app platforms (Apple, Google) as necessary for distribution, billing, and platform features
- For legal reasons — to comply with law or legal process, enforce our Terms, prevent fraud or abuse, or protect the rights and safety of our users and the public (we report child sexual abuse material to NCMEC as required by law)
- In a business transfer (merger, acquisition, financing, or asset sale), subject to commitments materially consistent with this Policy
- As aggregated or de-identified data that no longer identifies you — which we commit to keep de-identified and never attempt to re-identify
5. Data Retention
We keep personal information as long as needed for the purposes above, based on: whether your account is active; whether the content remains on your canvas; what the feature needs; security and abuse-prevention records; how long purchase, credit, and refund records are needed for accounting and dispute purposes; and what the law requires or permits for legal claims. In general, your content persists until you delete it or your account; unclaimed guest data is deleted on a routine schedule; analytics and diagnostics follow our providers' configured windows; and residual copies in encrypted backups persist for a limited period before rolling off. When retention ends, we delete or de-identify the data.
6. Your Rights and Choices
In-app and device controls: edit your profile, delete drops, remove or block connections, control notification categories, and manage the app's photo, camera, and Health permissions in iOS/Android settings.
Account deletion: you can delete your account in the app's Settings, or by emailing contact@dropboard.io. Deletion removes your canvases, drops, artwork, and profile from the Service (subject to the limited backup and legal-hold retention above).
Depending on your state (including California, Colorado, Connecticut, Texas, Virginia, and others), you may have the right to know/access the personal information we hold, obtain a portable copy, correct it, delete it, limit sensitive-data use (ours is already limited to providing the features you use), and not be discriminated against for exercising your rights. We do not sell or share personal information, so no sale/sharing opt-out is needed.
To exercise rights, email contact@dropboard.io from the email on your account. We verify requests against your authenticated account, an authorized agent may act for you with signed permission, and we respond within the time the law requires (generally 45 days). If we deny a request you may appeal by replying with "Appeal" in the subject line; if the appeal is denied you may contact your state Attorney General.
7. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn we have, we will delete it and terminate the account promptly. If you believe a child under 13 has used the Service, contact us at contact@dropboard.io.
8. Consumer Health Data
This section is the consumer health data notice required by the Washington My Health My Data Act, Nevada SB 370, and similar laws.
- Categories: with your consent via Apple Health — workout information, related statistics (including heart rate), and workout GPS routes; plus health-adjacent information you voluntarily put in content
- Sources: Apple HealthKit (with your iOS permission) and content you create
- Purposes: solely to provide the workout features you request — never advertising, marketing, inference-building, or sale
- Sharing: stored with our hosting processor like your other content, and visible to accepted friends only when you drop a workout onto your canvas; no processor may use it for its own purposes
- Consent: collection occurs only after you grant Health access in iOS; sharing occurs only when you drop the workout; withdraw anytime by disconnecting Health and deleting workout drops
- Rights: access your consumer health data, get a list of third parties it was shared with, withdraw consent, and have it deleted — email contact@dropboard.io; you may appeal a denial and contact your state Attorney General
9. Security
We use administrative and technical safeguards designed to protect personal information — encryption in transit, access controls and row-level authorization on our database, short-lived signed URLs for private images, and device-integrity attestation for unauthenticated flows. However, no method of transmission or storage is 100% secure, and we cannot and do not guarantee absolute security. Keep your device and sign-in credentials secure.
10. Where Processing Happens
We are based in the United States and the Service is currently offered to users in the United States. Your information is processed and stored in the United States (and wherever our processors maintain U.S.-serving infrastructure). If we later offer the Service in other regions, we will update this Policy accordingly.
11. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will notify you in advance through the app and/or the email on your account and update the effective date. Material changes will not retroactively reduce your rights with respect to previously collected data without any consent the law requires. Prior versions are archived and available on request.
12. Contact Us
Privacy requests and questions: contact@dropboard.io
4030 Wake Forest Road STE 349, Raleigh, NC 27609 USA