Privacy Policy
This policy explains what personal data Middle East Software Solutions Limited (company number 15913819, registered in England and Wales) collects when you use htmldrop, why we collect it, how long we keep it, who we share it with, and what rights you have. We are the data controller for that data within the meaning of UK GDPR.
If you only read one section, read Your rights and Contact.
1. What we collect
If you create an account
- Email address — to identify your account, send sign-in / password reset / billing emails, and contact you about the Service.
- Password — stored only as an Argon2id hash. We never see your plain password.
- Plan and billing status — which plan you're on, whether your subscription is active. Card data is handled directly by Stripe; we receive a customer ID and high-level status only.
- Account activity timestamps — last sign-in, last activity. Used to auto-renew your free-tier drops and to spot inactive accounts.
If you drop a file anonymously
- A signed cookie (
htmldrop_anon) holding a random tenant ID. It's how we remember which anonymous drops belong to your browser. No personal data is encoded in the cookie itself. - Your IP address, briefly, to rate-limit anonymous uploads and stop abuse.
Everyone (whether you have an account or not)
- Request logs — IP address, user agent, request path, response code, timestamp. Kept for security and debugging.
- Uploaded content — the HTML / Markdown files you publish, your chosen slug, any password hash you set. This is content you've chosen to put on the public web through us.
- Cookies — a session cookie (
hs_session, if signed in), the anonymous cookie above, and a share cookie that remembers you've unlocked a password-protected drop. We also load Google Analytics 4 (gtag.js) only after you click Accept on the cookie banner. No advertising cookies, no third-party ad networks, no profile resale.
MCP client metadata. When you publish a drop through the htmldrop MCP server, we log the name of the MCP client (e.g., "cursor", "claude-code") that initiated the publish. This is tool metadata, not user identity — we use it to prioritize which agent integrations to improve. It is never shared with third parties.
Public gallery participation. Listing a drop in the public gallery at htmldrop.app/gallery/ is opt-in. When a drop is approved and listed, the drop's title, content, agent identifier (e.g., "cursor"), and capture timestamp are publicly visible. We capture a screenshot of the drop for the listing; the screenshot is hosted at htmldrop.app/screenshots/. You can withdraw a listing any time from your dashboard.
Anonymous abuse reports. Visitors can report gallery drops for spam, phishing, CSAM, or other reasons without signing in. We log the reporter's IP address only for rate-limiting; it's purged 90 days after the report is resolved.
2. Why we collect it (legal bases)
- Performance of a contract — to run the account, host your drops, charge you for paid plans. (UK GDPR Art. 6(1)(b))
- Legitimate interests — to keep the Service secure, prevent abuse, debug problems, monitor traffic, and improve features. We've balanced these against your interests; you can object (see Your rights). (Art. 6(1)(f))
- Legal obligation — to respond to lawful requests from regulators or courts. (Art. 6(1)(c))
- Consent — only if we ever add optional features that need it (e.g. a marketing newsletter). We do not currently rely on consent for anything.
3. How long we keep it
- Anonymous drops: 7 days after upload, then deactivated (served as
410 Gone) for 30 days, then permanently deleted along with the underlying tenant record. - Free-tier signed-up drops: rolling 30 days from your last activity. Deactivated drops are kept 30 days before deletion.
- Paid-plan drops: kept while your subscription is active. After cancellation, deleted 30 days after the end of the paid period.
- Account data: kept while your account is open; deleted within 30 days of account closure.
- Request logs: up to 30 days for security and abuse investigation, then deleted or aggregated.
- Billing records: kept for at least 6 years to satisfy UK tax and accounting law.
- Back-ups: rolling back-ups may retain copies of deleted data for up to 30 days after deletion; they are then overwritten.
4. Who we share it with
We use a small number of processors that handle data on our behalf. They're contractually bound to only use the data to provide the service we've contracted them for. They are:
- Hetzner Online GmbH (Germany) — hosting infrastructure where the Service runs.
- Cloudflare, Inc. (USA/EU) — DNS and tunnel between the public internet and our cluster.
- Stripe Payments Europe, Limited (Ireland / USA) — billing and card processing for paid plans.
- Resend, Inc. (USA) — transactional email (verification, password reset, expiry warnings).
- MinIO, Inc. — object-storage software running inside the Hetzner cluster (not a third-party processor; the data stays with Hetzner).
We do not sell your personal data and we do not share it with advertisers. We may disclose data if we're legally required to, or to protect htmldrop, our users, or third parties from harm.
5. International transfers
Some of our processors are in the United States (Cloudflare, Stripe, Resend). Where we transfer your data outside the UK, we rely on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision — whichever applies for that processor.
6. Your rights
Under UK GDPR you have the right to:
- Access a copy of the personal data we hold about you.
- Correct data that's wrong or out of date.
- Delete your data ("right to erasure"). For account data this happens automatically when you close your account.
- Restrict or object to processing based on legitimate interests.
- Portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time, if processing is based on consent.
- Complain to the UK Information Commissioner's Office (ico.org.uk) if you think we've handled your data wrongly. We'd appreciate the chance to fix it first — email us.
To exercise any of these rights, email [email protected]. We'll respond within one month.
7. Security
We take reasonable technical and organisational measures to protect your data — TLS everywhere, password hashing with Argon2id, server-side validation, principle-of-least-privilege secrets, encrypted credentials at rest. No system is 100% secure; if you discover a vulnerability, please see our Security page.
8. Children
htmldrop is not directed at children under 13 and we don't knowingly collect personal data from them. If you believe a child has given us personal data, email [email protected] and we'll delete it.
9. Cookies in detail
hs_session— your signed-in session token. HTTP-only, Secure, Lax. Lifetime 14 days.htmldrop_anon— anonymous tenant identifier for visitors who haven't signed up. HTTP-only, Secure, Lax. Lifetime 30 days.hs_s_*— proof that you've unlocked a specific password-protected drop. Per-drop, lifetime 24 hours.
All of these are strictly necessary for the Service to work, so we don't ask for cookie consent for them.
10. Changes
We may update this policy. When we make a material change, we'll post the new version with a fresh effective date and email account holders at least 14 days before it takes effect.
11. Contact
Middle East Software Solutions Limited
Companies House registration: 15913819, England and Wales
Privacy: [email protected]