Drp Get started

// legal

Privacy Policy

Last updated: 25 June 2026

This policy explains what data Drp collects, why, and how it is stored. We aim to collect only what the product needs to work, and to describe it plainly. If anything here is unclear, contact us at privacy@drp.dev.

Who we are

Drp is a developer file host with a built-in MCP server. You upload files, images, markdown, code, and reports from your AI client or the dashboard, and share them with your team via a link. This policy covers the Drp website, dashboard, and API.

What we collect

Account information

When you create an account we store your email address and, optionally, your name and avatar image. If you sign in with a password, we store a hashed (not plaintext) password. If you sign in with a third-party provider (for example GitHub), we store the provider tokens needed to keep you signed in. You can also choose a data region (EU or rest-of-world) that determines where your content is stored.

Content you upload

The files, images, markdown, reports, code, and HTML you post ("drops") are stored so we can serve them. Object data lives in Cloudflare R2 and the associated metadata (titles, file names, visibility, timestamps, folder and team membership) lives in Cloudflare D1. Each drop has a visibility setting you control: private, team, or public. Public drops are accessible to anyone with the link.

Usage and technical data

To keep your sessions secure we store session records that include your IP address and browser user-agent string. API keys are stored only as a salted hash plus a short non-secret prefix for display; we cannot recover the full key after it is shown to you once. We keep a last-used timestamp per key so you can audit activity.

Analytics

We use piqo, a privacy-friendly analytics tool, to understand aggregate site traffic. It does not use tracking cookies and does not build cross-site profiles of you.

How we use your data

We do not sell your personal data, and we do not use the content of your drops to train models.

Service providers

We rely on a small number of processors to run Drp:

Data residency

When you (or your team) choose the EU region, your drop content is stored in EU infrastructure. The rest-of-world region stores content outside the EU. You select this when you create a team or account.

Data retention and deletion

We keep your account and content until you delete them or close your account. You can delete individual drops at any time, and revoke API keys immediately. To delete your account and associated data, contact privacy@drp.dev and we will remove it.

Your choices

Children

Drp is a tool for developers and is not directed at children under 16. We do not knowingly collect data from children.

Changes to this policy

If we make material changes, we will update the date above and, where appropriate, notify you. Continued use of Drp after a change means you accept the updated policy.

Contact

Questions about this policy or your data? Email privacy@drp.dev.