Legal

Privacy Policy

Effective 3 August 2026 · Version 1.1

This policy explains what personal data Middle East Software Solutions Limited (company number 15913819, registered in England and Wales) collects when you use htmldrop, why we collect it, how long we keep it, who we share it with, and what rights you have. We are the data controller for that data within the meaning of UK GDPR.

If you only read one section, read Your rights and Contact.

1. What we collect

If you create an account

If you drop a file anonymously

Everyone (whether you have an account or not)

Visitor analytics on published drops. When someone views a drop, we record a page view so the drop's owner can see their traffic. This is cookieless and stores no IP address or user agent: visitors are counted using a hash that is re-salted every day with a random key we never write down, so the same visitor cannot be recognised across two days and the hash cannot be reversed. Alongside the view we store the referring site's domain, the visitor's country (from Cloudflare's edge), and their browser's primary language code — country and language only, never region, city, or the full language header. None of this is linked to a name, an email, or an account.

MCP client metadata. When you publish a drop through the htmldrop MCP server, we log the name of the MCP client (e.g., "cursor", "claude-code") that initiated the publish. This is tool metadata, not user identity — we use it to prioritize which agent integrations to improve. It is never shared with third parties.

Public gallery participation. Listing a drop in the public gallery at htmldrop.app/gallery/ is opt-in. When a drop is approved and listed, the drop's title, content, agent identifier (e.g., "cursor"), and capture timestamp are publicly visible. We capture a screenshot of the drop for the listing; the screenshot is hosted at htmldrop.app/screenshots/. You can withdraw a listing any time from your dashboard.

Anonymous abuse reports. Visitors can report gallery drops for spam, phishing, CSAM, or other reasons without signing in. We log the reporter's IP address to rate-limit reports and to spot campaigns of bad-faith ones. A daily job removes it: 90 days after the report is resolved, or a year after it was filed if it never gets resolved. The report itself stays; only the IP address goes.

Résumé templates. We offer a résumé template you fill in yourself, like any other template — you type your details into a form and publish the result. Nothing about it is sent to a third party for processing, and there is no AI involved. (Automatic import of an existing PDF résumé is not currently offered; if we bring it back, we will describe here exactly what happens to the file before we do.)

Product analytics and error reports. Two third-party tools run inside the pages you use — not on published drops, which load nothing from anyone but us. PostHog records product analytics (page views, which features get used). On the marketing site it sees only anonymous device and page data. In the signed-in dashboard it is also told who you are: when you sign in we pass PostHog your user ID, email address, plan, workspace ID, whether your email is verified, your role, and whether you're an admin, so that usage can be tied to a person. PostHog runs in its EU region. Be aware that at present PostHog loads whether or not you accepted the cookie banner — the banner currently gates Google Analytics only. We think that's wrong, and rather than quietly narrow what the banner promises, we would rather tell you plainly than let you assume Reject covers everything. Sentry receives error reports from both our servers and your browser: stack traces, the URL you were on, browser and OS metadata, and an identifier for the account involved. Errors are unpredictable by nature, so a report can incidentally carry personal data that happened to be in the failing request. Sentry's ingest for htmldrop is in the EU.

Email about upgrading, and how to stop it. Most of our email is service email you can't switch off (see Why we collect it). Two messages are promotional, and we send them without asking you first:

Email you send to us. Mail to [email protected], [email protected] and our other addresses is delivered through Amazon Web Services (Amazon SES, Ireland). Whatever you put in that email passes through them.

2. Why we collect it (legal bases)

Email is split in two. Service email — address verification, password reset, email-change confirmation, billing and payment notices, drop-expiry warnings, security messages and notices like this policy changing — is part of running your account under Art. 6(1)(b). It is not marketing, and there is no way to opt out of it while your account is open. Promotional email is only the two messages described in Email about upgrading. We currently send those on legitimate interests (Art. 6(1)(f)) to people who already have an account or who began a purchase, on an opt-out basis rather than asking first — each one is capped at once ever and carries a working unsubscribe. You can object at any time, and the unsubscribe link is the fastest way to do it.

3. How long we keep it

Unless a line below says otherwise, the period is enforced by a job that runs once a day. Where nothing enforces it, we've said so rather than quote you a schedule we don't keep.

4. Who we share it with

We use a small number of processors that handle data on our behalf. They're contractually bound to only use the data to provide the service we've contracted them for. They are:

We do not sell your personal data and we do not share it with advertisers. We may disclose data if we're legally required to, or to protect htmldrop, our users, or third parties from harm.

5. International transfers

Several of our processors are outside the UK. For those in the United States — Cloudflare, Stripe, Resend, Sentry, GitHub and Google — we rely on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision, whichever applies to that processor. Hetzner (Germany), Amazon SES (Ireland) and PostHog's EU region sit inside the EEA, which the UK has found adequate.

6. Your rights

Under UK GDPR you have the right to:

To exercise any of these rights, email [email protected]. We'll respond within one month.

7. Security

We take reasonable technical and organisational measures to protect your data — TLS everywhere, password hashing with Argon2id, server-side validation, principle-of-least-privilege secrets, encrypted credentials at rest. No system is 100% secure; if you discover a vulnerability, please see our Security page.

8. Children

htmldrop is not directed at children under 13 and we don't knowingly collect personal data from them. If you believe a child has given us personal data, email [email protected] and we'll delete it.

9. Cookies in detail

Strictly necessary — the Service does not work without these, so we don't ask consent for them:

Not strictly necessary — analytics. These are the ones the banner is about:

Your banner choice itself is stored in your browser's local storage as htmldrop_consent_v1 (alongside htmldrop-theme, which just remembers light or dark). Neither is sent to us. The Privacy pill in the corner of every page re-opens the banner so you can change your answer at any time.

10. Changes

We may update this policy. When we make a material change, we'll post the new version with a fresh effective date and email account holders at least 14 days before it takes effect.

11. Contact

Middle East Software Solutions Limited
Companies House registration: 15913819, England and Wales
Privacy: [email protected]