This document outlines our commitment to data protection and privacy compliance.
This Privacy Policy ("Policy") governs the collection, processing, use, disclosure, and protection of personal data in connection with the Dropstone AI Development Platform and all related services (collectively, the "Service" or "Platform"). This Policy is issued by Blankline ("we," "us," "our," "Data Controller," or "Blankline").
Controller vs. Processor: We act as a Data Controller for account, billing, and usage data. We act as a Data Processor for user-generated content and code transmitted to AI models.
By using the Service, you acknowledge and agree to the practices described in this Policy.
We process personal data in strict compliance with international privacy frameworks, including India's DPDPA 2023, GDPR (EU), CCPA/CPRA (California), and UK GDPR.
We engage verified third-party providers for specific service functions. All processors are bound by strict data protection agreements.
Stripe Inc. (USA) - Payment processing and subscription management.
PostHog, Google Analytics - Usage behavior and product optimization.
OpenAI, Anthropic, Deepseek - Model inference and processing.
Sentry - Error tracking and performance monitoring.
We distinguish between "Storage" and "Inference." Your code sent for inference is ephemeral and is never used for downstream training of third-party foundation models.
This commitment concerns our model partners, and is narrower than the heading alone suggests. Two things sit outside it: Dropstone may use your session content to post-train our own models (5.2), and we retain derived context against your account so the assistant has memory between sessions (5.3). Enterprise accounts are excluded from 5.2 entirely.
Consumer accounts (Free, Pro, and Max) participate in two consent-based programs. Both are on by default and both can be turned off at any time in dashboard settings. Enterprise accounts are excluded from both, regardless of setting, and that exclusion is enforced when data is written rather than by configuration.
Turning either program off stops future collection; it does not by itself delete samples already stored. You may request deletion of previously collected samples at any time by contacting [email protected], and we will action it without requiring a reason.
To give the assistant continuity between sessions, we store context derived from your work against your account. This is retained rather than ephemeral, and it is separate from the training programs in 5.2. It consists of:
Each item is stored with a vector embedding — a numerical representation of its text — so it can be retrieved by relevance later. Embeddings are derived from your content and are treated as your content.
This memory is scoped to your account. It is retrieved to inform your own sessions and is not served into another user's assistant. You can review and delete individual memory items from your dashboard, and request deletion of all of it at [email protected]. Deleting your account removes it.
If you choose to fine-tune a model on your proprietary codebase (an Enterprise feature), the resulting model weights are owned exclusively by you and are siloed from other users.
Your data may be processed globally. We ensure protection through:
Dropstone is an 18+ service. It is not directed to children, and we do not knowingly collect personal data from anyone under 18. This matches Section 04 of our Terms of Service, which sets the same minimum age.
India's Digital Personal Data Protection Act, 2023 defines a child as anyone under 18 and requires verifiable parental consent before their data may be processed. We do not operate a verifiable parental consent mechanism, and we therefore do not permit under-18 accounts at all rather than rely on a self-declared claim of consent.
If we become aware that we hold data belonging to someone under 18, we delete it and close the account. If you believe a child has created an account, contact us at [email protected] and we will act on it.
We send promotional content only with explicit opt-in consent. Transactional messages (billing, security) are mandatory. You may opt-out of marketing at any time via unsubscribe links.
In the event of a breach, we notify affected users and authorities within 72 hours, as required by GDPR and other laws. We maintain 24/7 security monitoring to detect and contain incidents immediately.
You have rights to access, correct, delete, and port your data. Contact [email protected] to exercise these rights.
Request a copy of your data in a structured format.
Fix inaccuracies or request the "Right to be Forgotten".
Object to specific processing activities or withdraw consent.
Specific rights for GDPR (EU) and CCPA/CPRA (California) residents.
For Enterprise Tier customers, we offer logical tenant isolation. Your vector indexes and usage logs are tagged with a unique Tenant ID, ensuring that your data is logically separated from other customers at the database level.
We conduct regular static code analysis (SAST) and dependency scanning to identify vulnerabilities. Security patches are deployed within 72 hours of critical disclosure.
We use essential cookies for functionality and security. Analytics and marketing cookies are optional and require your consent. You can manage preferences via your browser or our settings.
We may update this policy. Material changes will be notified 30 days in advance via email. Continued use constitutes acceptance.
We do not store full credit card numbers; all payment card data is handled directly by our PCI-DSS compliant payment processor, Stripe. We retain only billing metadata (transaction IDs, subscription tier, billing history, and invoices) as required for accounting and tax purposes.
Subscriptions, Upgrades & Refunds: All subscription fees, including fees paid when upgrading from the Pro tier to the Max tier, are final and non-refundable. Upgrading from Pro to Max does not entitle you to any refund, credit, or proration of fees already paid for your prior tier. For full details on billing, automatic renewal, cancellations, downgrades, and our Strict No-Refund Policy, please refer to Section 08 of our Terms of Service.
In accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, the contact details of the Grievance Officer are provided below:
Grievance Officer: Legal Compliance Lead
Entity: Blankline
Location: Chennai, Tamil Nadu, India
Email: [email protected]
For general privacy inquiries or to exercise your data rights (GDPR/CCPA/DPDPA), please contact: [email protected].
BY USING THE DROPSTONE SERVICE, YOU ACKNOWLEDGE AND AGREE TO THE DATA PRACTICES DESCRIBED IN THIS POLICY. THIS POLICY IS A BINDING COMMITMENT TO YOUR PRIVACY RIGHTS.