07 — Data Protocols

Privacy Policy &
Data Governance.

Effective Date
November 11, 2025
Version
Protocol v2.1 (Stable)
Section 01

Introduction & Data Controller

This Privacy Policy ("Policy") governs the collection, processing, use, disclosure, and protection of personal data in connection with the Dropstone AI Development Platform and all related services (collectively, the "Service" or "Platform"). This Policy is issued by Blankline ("we," "us," "our," "Data Controller," or "Blankline").

Data Controller Information

EntityBlankline
LocationChennai, Tamil Nadu, India
Data Protection Lead[email protected]
Legal Notices[email protected]

Controller vs. Processor: We act as a Data Controller for account, billing, and usage data. We act as a Data Processor for user-generated content and code transmitted to AI models.

By using the Service, you acknowledge and agree to the practices described in this Policy.

Section 02

Legal Basis & Compliance

We process personal data in strict compliance with international privacy frameworks, including India's DPDPA 2023, GDPR (EU), CCPA/CPRA (California), and UK GDPR.

Processing Legal Bases

Account & BillingContractual Necessity
Service OptimizationLegitimate Interest
Security & FraudLegitimate Interest
MarketingConsent (Opt-in)
Legal ComplianceLegal Obligation
Section 03

Data Categories & Technical Telemetry

3.1 Directly Provided Data

  • Identity: Name, email, SSH public keys (for git integration), and API tokens.
  • Workspace Context: Project file trees, dependency graphs, and environment configurations.

3.2 Technical Telemetry & AI Context

  • Local-First Architecture: Dropstone operates primarily on the client device. Indexing, AST parsing, and vector embedding generation occur locally.
  • Ephemeral Context Windows: When you trigger an AI agent, only the specific code snippets relevant to the prompt (the "Context Window") are transmitted to inference endpoints. We do not upload entire repositories.
  • Operational Metrics: Latency, token usage rates, and GPU/CPU thread utilization for performance debugging.
Section 04

Third-Party Processors

We engage verified third-party providers for specific service functions. All processors are bound by strict data protection agreements.

Payment

Stripe Inc. (USA) - Payment processing and subscription management.

Analytics

PostHog, Google Analytics - Usage behavior and product optimization.

AI Models

OpenAI, Anthropic, Deepseek - Model inference and processing.

Monitoring

Sentry - Error tracking and performance monitoring.

Section 05

AI Training & Model Hygiene

Zero-Retention Commitment

We distinguish between "Storage" and "Inference." Your code sent for inference is ephemeral and never used for downstream training of foundation models.

5.1 Zero-Retention Inference Architecture

  • Inference (Processing): Code sent to our model partners (OpenAI, Anthropic) follows a strict stateless protocol. Data is held in volatile memory only for the duration of the generation request and is cryptographically wiped immediately after.
  • No Downstream Training: We have executed "Do Not Train" agreements with all LLM providers. Your code is never used to train OpenAI's GPT or Anthropic's Claude models.

5.2 User-Owned Fine-Tuning

If you choose to fine-tune a model on your proprietary codebase (an Enterprise feature), the resulting model weights are owned exclusively by you and are siloed from other users.

Section 06

International Data Transfers

Your data may be processed globally. We ensure protection through:

  • Standard Contractual Clauses (SCCs) for EU transfers.
  • Compliance with DPDPA (India) frameworks.
  • End-to-end encryption for cross-border data transmission.
Section 07

Data Retention

Account DataActive + 90 Days
Billing Records7 Years (Tax Law)
Analytics36 Months (Anonymized)
User ContentUntil Deletion
Section 08

Children's Privacy

Dropstone is not intended for children under 16 (or 13 where applicable). We do not knowingly collect data from minors. If discovered, such data is immediately deleted.

Section 09

Marketing Communications

We send promotional content only with explicit opt-in consent. Transactional messages (billing, security) are mandatory. You may opt-out of marketing at any time via unsubscribe links.

Section 10

Data Breach Response

In the event of a breach, we notify affected users and authorities within 72 hours, as required by GDPR and other laws. We maintain 24/7 security monitoring to detect and contain incidents immediately.

Section 11

User Privacy Rights

You have rights to access, correct, delete, and port your data. Contact [email protected] to exercise these rights.

Access & Portability

Request a copy of your data in a structured format.

Correction & Deletion

Fix inaccuracies or request the "Right to be Forgotten".

Objection

Object to specific processing activities or withdraw consent.

Jurisdiction Specific

Specific rights for GDPR (EU) and CCPA/CPRA (California) residents.

Section 12

Enterprise Security & Data Isolation

12.1 Infrastructure Security

  • Encryption Standards: Data at rest is encrypted using AES-256 (GCM mode). Data in transit is secured via TLS 1.3 with forced HSTS.
  • Key Management: Encryption keys are rotated periodically via a hardware security module (HSM) equivalent.

12.2 Enterprise Data Isolation

For Enterprise Tier customers, we offer logical tenant isolation. Your vector indexes and usage logs are tagged with a unique Tenant ID, ensuring that your data is logically separated from other customers at the database level.

12.3 Vulnerability Management

We conduct regular static code analysis (SAST) and dependency scanning to identify vulnerabilities. Security patches are deployed within 72 hours of critical disclosure.

Section 13

Cookies

We use essential cookies for functionality and security. Analytics and marketing cookies are optional and require your consent. You can manage preferences via your browser or our settings.

Section 14

Policy Updates

We may update this policy. Material changes will be notified 30 days in advance via email. Continued use constitutes acceptance.

Section 15

Financial Information & Refunds

We do not store full credit card numbers; these are handled directly by our PCI-DSS compliant provider, Stripe. For information regarding subscription cancellations and our No-Refund Policy, please refer to our Terms of Service.

Section 16

Contact & Grievance Redressal

In accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, the contact details of the Grievance Officer are provided below:

Grievance Officer: Legal Compliance Lead

Entity: Blankline

Location: Chennai, Tamil Nadu, India

Email: [email protected]

For general privacy inquiries or to exercise your data rights (GDPR/CCPA/DPDPA), please contact: [email protected].

BY USING THE DROPSTONE SERVICE, YOU ACKNOWLEDGE AND AGREE TO THE DATA PRACTICES DESCRIBED IN THIS POLICY. THIS POLICY IS A BINDING COMMITMENT TO YOUR PRIVACY RIGHTS.