Privacy Policy

Last updated September 4, 2026

What Drop is

Drop is a place for musicians to share their work and for fans to follow it — on the web and in the Drop iOS/Android apps. This page explains what information Drop collects, why, and what happens to it.

What we collect

  • Account info — your email address, and if you sign up with a password, that password (stored securely by our authentication provider, never in plain text we can read). If you sign in with Google or Sign in with Apple, we receive the account details those providers share for sign-in (typically name, email, and for Google a profile photo).
  • Profile info — your display name, username, and any avatar photo you choose to upload.
  • Content you post — drops (photos, audio, video, or links) you upload, captions, and any comments you write.
  • Activity — who you follow, what you save or like, and reports or blocks you file. Likes and saves are private and never shown publicly; follows and comments are visible to others by design.
  • Device permissions (app only) — when you post media, Drop may ask for camera, microphone, or photo library access so you can take or pick that media. Those permissions are only used for posting (and for an avatar photo). Drop does not access camera, mic, or your library in the background.
  • Push notifications (optional) — if you turn Push on in Settings, we store a device or browser push token so we can send you notifications you asked for (for example follows, comments, or new drops from people you follow). You can turn Push off any time; we stop using that token.
  • Crash and error logs — if the app hits an unexpected error, we may store a short technical log (what went wrong and roughly where) so we can fix bugs. These are for reliability, not advertising.

What we don't do

Drop has no ads and doesn't sell or share your information with advertisers or data brokers. We don't run advertising analytics or tracking scripts. We don't show public like/comment counts — Drop is built around genuine listening, not vanity metrics. We don't use your content or account data to build advertising profiles.

Who we share it with

Drop runs on a small number of infrastructure providers who process data on our behalf to make the app work:

  • Supabase — database, authentication, and file storage.
  • Vercel — hosting the web app the native shells load.
  • Google — if you choose Google sign-in (on Google's own terms).
  • Apple — if you choose Sign in with Apple, and for Apple Push Notification service when you've turned Push on in the iOS app.

None of these providers use your Drop data for their own advertising because of how Drop is set up.

Your choices

You can edit your display name, avatar, and privacy toggles (like whether your follower count is public) any time from Settings. You can delete any drop or comment you've posted directly in the app. You can turn push notifications off in Settings. You can delete your entire account from Settings → Account → Delete account — that removes your profile, drops, and uploaded media. To request a copy of your data, email us at the address below.

Contact

Questions about this policy or your data? Reach out at support@makedrop.icu.