Privacy Policy
This policy explains what personal data Middle East Software Solutions Limited (company number 15913819, registered in England and Wales) collects when you use htmldrop, why we collect it, how long we keep it, who we share it with, and what rights you have. We are the data controller for that data within the meaning of UK GDPR.
If you only read one section, read Your rights and Contact.
1. What we collect
If you create an account
- Email address — to identify your account, send sign-in / password reset / billing emails, and contact you about the Service.
- Password — stored only as an Argon2id hash. We never see your plain password.
- Plan and billing status — which plan you're on, whether your subscription is active. Card data is handled directly by Stripe; we receive a customer ID and high-level status only.
- Account activity timestamps — last sign-in, last activity. Used to auto-renew your free-tier drops and to spot inactive accounts.
- Sign-in records — every time you sign in we store that session's IP address and browser user-agent string next to the session. It's the trail we look at when someone reports that their account was accessed by somebody else, and when we investigate abuse coming from a signed-in account. We rely on legitimate interests here (Art. 6(1)(f)) — running a hosting service without any record of where sign-ins came from isn't something we're willing to do. See How long we keep it for when these records go.
- Social sign-in identity — if you sign in with Google or GitHub instead of a password, we store the provider's name, the account identifier that provider gives us, and the email address on that account. Your password at that provider never reaches us, and we don't ask them for anything beyond sign-in identity and your email address.
- Country and language, at sign-up only — a two-letter country code (from Cloudflare's edge, so we never store your IP to get it) and the primary language your browser asks for, e.g.
de. We record these once, when the account is created, to decide which countries and languages htmldrop should support. We do not track your location over time, and we never store anything finer than country level or the bare language code — not the region, city, or your full browser language header. If you change the dashboard language, we record that choice too, for the same reason.
If you drop a file anonymously
- A signed cookie (
htmldrop_anon) holding a random tenant ID. It's how we remember which anonymous drops belong to your browser. No personal data is encoded in the cookie itself. - Your IP address, stored on the anonymous workspace record itself — not just for the length of a request. It's what caps how many anonymous drops a single source can hold at once, which is the main thing standing between us and bulk abuse. It stays there while that anonymous workspace is alive, and is removed once it can no longer serve that cap — see How long we keep it.
Everyone (whether you have an account or not)
- Request logs — IP address, user agent, request path, response code, timestamp. Kept for security and debugging.
- Uploaded content — the HTML / Markdown files you publish, your chosen slug, any password hash you set. This is content you've chosen to put on the public web through us.
- Cookies — a session cookie (
hs_session, if signed in), the anonymous cookie above, and a share cookie that remembers you've unlocked a password-protected drop. We also load Google Analytics 4 (gtag.js) only after you click Accept on the cookie banner, and PostHog, which — unlike GA4 — currently loads on page load without waiting for that click. See Cookies in detail, which says plainly which of these are strictly necessary and which are not. No advertising cookies, no third-party ad networks, no profile resale.
Visitor analytics on published drops. When someone views a drop, we record a page view so the drop's owner can see their traffic. This is cookieless and stores no IP address or user agent: visitors are counted using a hash that is re-salted every day with a random key we never write down, so the same visitor cannot be recognised across two days and the hash cannot be reversed. Alongside the view we store the referring site's domain, the visitor's country (from Cloudflare's edge), and their browser's primary language code — country and language only, never region, city, or the full language header. None of this is linked to a name, an email, or an account.
MCP client metadata. When you publish a drop through the htmldrop MCP server, we log the name of the MCP client (e.g., "cursor", "claude-code") that initiated the publish. This is tool metadata, not user identity — we use it to prioritize which agent integrations to improve. It is never shared with third parties.
Public gallery participation. Listing a drop in the public gallery at htmldrop.app/gallery/ is opt-in. When a drop is approved and listed, the drop's title, content, agent identifier (e.g., "cursor"), and capture timestamp are publicly visible. We capture a screenshot of the drop for the listing; the screenshot is hosted at htmldrop.app/screenshots/. You can withdraw a listing any time from your dashboard.
Anonymous abuse reports. Visitors can report gallery drops for spam, phishing, CSAM, or other reasons without signing in. We log the reporter's IP address to rate-limit reports and to spot campaigns of bad-faith ones. A daily job removes it: 90 days after the report is resolved, or a year after it was filed if it never gets resolved. The report itself stays; only the IP address goes.
Résumé templates. We offer a résumé template you fill in yourself, like any other template — you type your details into a form and publish the result. Nothing about it is sent to a third party for processing, and there is no AI involved. (Automatic import of an existing PDF résumé is not currently offered; if we bring it back, we will describe here exactly what happens to the file before we do.)
Product analytics and error reports. Two third-party tools run inside the pages you use — not on published drops, which load nothing from anyone but us. PostHog records product analytics (page views, which features get used). On the marketing site it sees only anonymous device and page data. In the signed-in dashboard it is also told who you are: when you sign in we pass PostHog your user ID, email address, plan, workspace ID, whether your email is verified, your role, and whether you're an admin, so that usage can be tied to a person. PostHog runs in its EU region. Be aware that at present PostHog loads whether or not you accepted the cookie banner — the banner currently gates Google Analytics only. We think that's wrong, and rather than quietly narrow what the banner promises, we would rather tell you plainly than let you assume Reject covers everything. Sentry receives error reports from both our servers and your browser: stack traces, the URL you were on, browser and OS metadata, and an identifier for the account involved. Errors are unpredictable by nature, so a report can incidentally carry personal data that happened to be in the failing request. Sentry's ingest for htmldrop is in the EU.
Email about upgrading, and how to stop it. Most of our email is service email you can't switch off (see Why we collect it). Two messages are promotional, and we send them without asking you first:
- A one-time discount offer — if you're on the free plan, verified, between 3 and 30 days old and have a live drop, a daily job may mint you a single-use promo code and email it to you. It happens at most once per workspace, ever. To send it we sync your email address, plan, drop count and whether you have a live drop to Resend, our email provider, as a contact in a "Users" list. That email carries Resend's unsubscribe link.
- A one-time "still thinking it over?" reminder — if you open the upgrade checkout and don't finish, Stripe tells us the session expired and we send one reminder to the address you typed into Stripe's checkout page. Once per workspace, ever, and never if your payment was declined or you upgraded some other way. Because that address comes from the checkout form, it may be one we have never seen on any account. We do not store it to send the message — it passes through from Stripe's notification. The email carries a visible unsubscribe link and a one-click unsubscribe header. If you use it, we do store your address, on its own suppression list, for the sole purpose of never mailing it again; there is no way to honour "don't email me" without remembering the address it applies to.
Email you send to us. Mail to [email protected], [email protected] and our other addresses is delivered through Amazon Web Services (Amazon SES, Ireland). Whatever you put in that email passes through them.
2. Why we collect it (legal bases)
- Performance of a contract — to run the account, host your drops, charge you for paid plans. (UK GDPR Art. 6(1)(b))
- Legitimate interests — to keep the Service secure, prevent abuse, debug problems, monitor traffic, and improve features. We've balanced these against your interests; you can object (see Your rights). (Art. 6(1)(f))
- Legal obligation — to respond to lawful requests from regulators or courts. (Art. 6(1)(c))
- Consent — we rely on it for analytics cookies. Google Analytics is loaded only after you click Accept on the cookie banner, and that click is your consent under PECR and Art. 6(1)(a). You can change your mind at any time from the Privacy pill in the corner of the page. As noted in Cookies in detail, PostHog does not yet respect that choice; while that's true we cannot claim consent as its basis, so we rely on legitimate interests for it and say so here instead of pretending otherwise.
Email is split in two. Service email — address verification, password reset, email-change confirmation, billing and payment notices, drop-expiry warnings, security messages and notices like this policy changing — is part of running your account under Art. 6(1)(b). It is not marketing, and there is no way to opt out of it while your account is open. Promotional email is only the two messages described in Email about upgrading. We currently send those on legitimate interests (Art. 6(1)(f)) to people who already have an account or who began a purchase, on an opt-out basis rather than asking first — each one is capped at once ever and carries a working unsubscribe. You can object at any time, and the unsubscribe link is the fastest way to do it.
3. How long we keep it
Unless a line below says otherwise, the period is enforced by a job that runs once a day. Where nothing enforces it, we've said so rather than quote you a schedule we don't keep.
- Anonymous drops: 7 days after upload the drop and the anonymous workspace record behind it are deleted outright, files included. There's no grace period on this one — if you want a drop to outlive a week, sign up. (The
htmldrop_anoncookie in your browser lasts 30 days, but there's nothing left for it to point at after 7.) - The IP address on an anonymous workspace: removed as soon as it stops doing its job — immediately once you sign up and claim the workspace, or 7 days after the workspace expires if you never do.
- Free-tier signed-up drops: rolling 30 days from your last activity. Deactivated drops are kept 30 days before deletion.
- Paid-plan drops: kept while your subscription is active. After cancellation, deleted 30 days after the end of the paid period.
- Account data: kept while your account is open; deleted within 30 days of account closure.
- Sign-in records (session IP and user-agent): kept for 30 days after the session expires or you sign out of it, then deleted. A session itself lasts 14 days, so in practice a sign-in leaves a trace for at most about six weeks.
- Abuse-report IP addresses: removed 90 days after the report is resolved, or a year after filing if it's never resolved.
- Request logs: our web servers write a line per request — IP, user agent, path, response code — to standard output, and those lines are rotated by the hosting infrastructure rather than by us. We don't run a job over them, so we won't quote you a number we don't enforce. They aren't queried against individuals in the ordinary course; they exist for debugging and incident response.
- Visitor analytics on drops: individual view records are deleted 90 days after the view, whether or not the drop still exists, and are deleted with the drop if it goes first. The daily salt that makes a visitor countable is discarded every 24 hours, so views older than a day can no longer be tied to one another at all.
- Sign-up country and language: kept for 400 days (about 13 months), then deleted. These records aren't attached to your account by a database link, so closing your account does not remove them early — they carry a workspace identifier and run out on their own clock. They only ever inform which languages we build.
- Promotional-email suppression list: kept indefinitely, on purpose. If you unsubscribe, your address stays on that list for as long as htmldrop runs — deleting it is the one thing that would let us email you again by mistake. It holds nothing but the address and the date.
- Analytics and error data held by PostHog and Sentry: retained on their systems under their own schedules, not ours. We don't run a deletion job across them, so we won't quote you a period we don't enforce; ask us and we'll pursue a deletion with them directly.
- Billing records: kept for at least 6 years to satisfy UK tax and accounting law.
- Back-ups: the database is backed up nightly to Cloudflare R2 object storage. Deleting something from the live database doesn't reach back into a back-up that already captured it, so a copy can survive there for a while after deletion. Back-up rotation happens at the storage level rather than through one of our jobs, so we won't put a figure on it here. Deletion requests are honoured against the live service immediately; back-ups age out on their own.
4. Who we share it with
We use a small number of processors that handle data on our behalf. They're contractually bound to only use the data to provide the service we've contracted them for. They are:
- Hetzner Online GmbH (Germany) — the servers the Service runs on, and where the database lives: accounts, drop metadata, analytics, logs.
- Cloudflare, Inc. (USA, with EU processing) — DNS, TLS and the tunnel between the public internet and our cluster, so request metadata (IP, user agent, URL) passes through it; the Turnstile bot check on anonymous uploads; custom-hostname certificates for bring-your-own domains; the headless browser that captures gallery screenshots; and R2 object storage, which is where your uploaded drop files and our nightly database back-ups are actually stored — we have not pinned those buckets to a region, so Cloudflare places the data itself and we cannot promise you it stays in the EEA. An earlier version of this policy said drop files sat on MinIO inside the Hetzner cluster and never left it. That is no longer how production is configured, and we've corrected it here.
- Stripe Payments Europe, Limited (Ireland / USA) — billing and card processing for paid plans. Card numbers go straight to Stripe and never reach us.
- Resend (Resend.com, Inc.) (USA) — outbound email. Two jobs: service messages (verification, password reset, billing, expiry warnings), and the promotional messages in Email about upgrading, for which your email address, plan, drop count and live-drop flag are stored with Resend as a contact record.
- Sentry (Functional Software, Inc.) (USA, EU ingest region) — error and crash reporting from our servers and from your browser: stack traces, request URLs, browser and OS metadata, account identifiers, and whatever personal data happens to be caught up in a failing request.
- PostHog, Inc. (EU region, Frankfurt) — product analytics on the marketing site and in the dashboard. In the dashboard it receives your email address, user and workspace IDs, plan, role, admin flag and verification status, plus the pages you visit.
- Google (Google Ireland Limited / Google LLC) (Ireland / USA) — two separate things. Google Analytics 4 and Google Tag Manager on the marketing site and dashboard, which see your IP address and browsing within our pages, and which we load only after you accept the cookie banner. And Google sign-in, if you choose it, which tells us your Google account identifier and email address. Our pages also load web fonts from
fonts.googleapis.com, which discloses your IP address to Google on every page load regardless of the banner. - GitHub, Inc. (USA) — GitHub sign-in, if you choose it: we receive your GitHub account identifier and email address.
- Amazon Web Services (Amazon SES, Ireland) — inbound email. Mail sent to our published addresses is delivered through Amazon's servers before it reaches us.
- Indian Type Foundry (Fontshare) (India) — web fonts loaded by our public pages. It receives no account data, but your IP address and browser reach it whenever you load a page, and it is not covered by the cookie banner.
We do not sell your personal data and we do not share it with advertisers. We may disclose data if we're legally required to, or to protect htmldrop, our users, or third parties from harm.
5. International transfers
Several of our processors are outside the UK. For those in the United States — Cloudflare, Stripe, Resend, Sentry, GitHub and Google — we rely on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision, whichever applies to that processor. Hetzner (Germany), Amazon SES (Ireland) and PostHog's EU region sit inside the EEA, which the UK has found adequate.
6. Your rights
Under UK GDPR you have the right to:
- Access a copy of the personal data we hold about you.
- Correct data that's wrong or out of date.
- Delete your data ("right to erasure"). For account data this happens automatically when you close your account.
- Restrict or object to processing based on legitimate interests.
- Portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time, if processing is based on consent.
- Complain to the UK Information Commissioner's Office (ico.org.uk) if you think we've handled your data wrongly. We'd appreciate the chance to fix it first — email us.
To exercise any of these rights, email [email protected]. We'll respond within one month.
7. Security
We take reasonable technical and organisational measures to protect your data — TLS everywhere, password hashing with Argon2id, server-side validation, principle-of-least-privilege secrets, encrypted credentials at rest. No system is 100% secure; if you discover a vulnerability, please see our Security page.
8. Children
htmldrop is not directed at children under 13 and we don't knowingly collect personal data from them. If you believe a child has given us personal data, email [email protected] and we'll delete it.
9. Cookies in detail
Strictly necessary — the Service does not work without these, so we don't ask consent for them:
hs_session— your signed-in session token. HTTP-only, Secure, Lax. Lifetime 14 days.htmldrop_anon— anonymous tenant identifier for visitors who haven't signed up. HTTP-only, Secure, Lax. Lifetime 30 days.hs_s_*— proof that you've unlocked a specific password-protected drop. Per-drop, lifetime 24 hours.
Not strictly necessary — analytics. These are the ones the banner is about:
_ga,_ga_*— Google Analytics 4. Set only if you click Accept. Click Reject and they are never set; Google is told to deny analytics storage by default before you choose, and we hold the first page view for up to half a second so a prior Reject is applied before anything fires.ph_*— PostHog. These are currently set whether you accept or reject. The banner today controls Google Analytics only, and PostHog initialises on page load regardless of your choice. That is not what the banner implies, and we would rather say so than narrow the banner's promise to match. While that's the case, if you want no analytics at all, a browser that blocks third-party analytics scripts is the reliable answer, and you can email us to have your PostHog data deleted.
Your banner choice itself is stored in your browser's local storage as
htmldrop_consent_v1 (alongside htmldrop-theme,
which just remembers light or dark). Neither is sent to us. The
Privacy pill in the corner of every page re-opens the banner so
you can change your answer at any time.
10. Changes
We may update this policy. When we make a material change, we'll post the new version with a fresh effective date and email account holders at least 14 days before it takes effect.
11. Contact
Middle East Software Solutions Limited
Companies House registration: 15913819, England and Wales
Privacy: [email protected]