Privacy Policy

Effective August 31, 2026

Template — not legal advice. This page documents Dropsera's own legal information as accurately as currently possible. Bracketed placeholders, where still present below (e.g. [COURT_JURISDICTION]), mark facts not yet finalized. Have this reviewed by a lawyer before relying on it for real payments.

1. Who is responsible, and how to reach us

Kilian Raffelsberger, In der Thann 10, 4644 Scharnstein, is the data controller for dropsera.com. For anything in this policy — access requests, questions, complaints — email team@dropsera.com.

2. Hosting and server logs

The site is hosted on Vercel. Every request generates standard server logs (IP address, timestamp, requested URL, user agent) used only for operating, securing, and debugging the service — not for tracking individuals across sessions. See the processor table in section 10.

3. Account and authentication data

Creating an account collects your email, an optional display name, and a password (stored only as a salted hash — we never see or store your plaintext password). Login sessions are tracked by a server-side session record tied to a cookie. Legal basis: performance of the contract you enter into by creating an account (Art. 6(1)(b) GDPR).

4. The product-analysis feature

When you submit a product link (or manually enter product details) for analysis, that data — the URL, and product fields such as title, description, price, images, rating, and supplier information — is processed to generate your Product Score. Once the real AI integration is active (see section 10 — it is not live yet; analyses currently run on a local, deterministic mock and never leave our servers), the same data is sent to Anthropic's API for the AI-assisted portions of the analysis (market/ad/branding potential, risk narrative). We do not send your account email or password to Anthropic. Legal basis: performance of the contract (Art. 6(1)(b) GDPR) — running the analysis you asked for. Retention: analyses are kept for as long as your account exists, so you can revisit past reports; you can request deletion at any time (section 12, or via Account → Privacy & Data).

5. Store generation

If you launch a validated product into a store, the branding, copy, and store configuration generated for you (and the underlying analysis it was built from) are stored under your account on the same legal basis and retention terms as section 4.

6. Payment data

Paid plans are processed by Stripe (not yet live — see section 10). Card and other payment-instrument details are entered directly into Stripe's own interface and never reach our servers. We store only what Stripe tells us back: your plan, subscription status, and a Stripe customer/subscription reference, so we can enforce your plan limits and show you your billing status. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).

7. Support communication

If you email team@dropsera.com for support, we process that email thread (via Google Workspace) to respond to you. Legal basis: legitimate interest in providing support to our users (Art. 6(1)(f) GDPR), or contract performance where the request relates to your paid plan.

8. Newsletter and marketing email

Marketing emails (product insights, platform updates, offers) are sent only if you separately, explicitly opt in during signup via an unchecked checkbox — this is never bundled with, or required for, account creation itself. Opting in triggers a confirmation email (double opt-in) with a link you must click before we send you anything further; your consent isn't active until then. Every marketing email carries a working unsubscribe link. Legal basis: consent (Art. 6(1)(a) GDPR), which you can withdraw at any time via that link or your account's marketing preferences — transactional emails (verification, password reset, billing, cancellation confirmations) are not marketing and don't require this consent.

9. Cookies

Cookie categories, what each one does, and how to change your choice at any time are covered on a dedicated Cookie Policy page, sourced from the same configuration the consent banner itself uses — this policy doesn't duplicate that list.

10. Sub-processors

External services that process data on our behalf, or that data passes through as part of running the service:

ProcessorPurposeProcessing locationTransfer safeguardStatus
Vercel Inc.Application hosting, request routing, server logs.United States (with edge locations globally)EU Standard Contractual ClausesActive
Neon Inc.Primary application database (accounts, analyses, stores).European Union (Frankfurt, Germany)EU Standard Contractual ClausesActive
Anthropic, PBCAI-generated product analysis, branding, and store copy.United StatesEU Standard Contractual ClausesNot yet active
Stripe, Inc. / Stripe Payments Europe, Ltd.Subscription billing and payment processing.United States and IrelandEU Standard Contractual ClausesNot yet active
Google Ireland Limited (Google Workspace)Operator email — support, account, and legal correspondence sent to/from team@dropsera.com.European Union / United StatesEU Standard Contractual ClausesActive

Entries marked "not yet active" are wired into the product but not currently receiving any data — Kilian's platform runs in demo mode today (deterministic mock AI analysis, no live payment processing). This table will be kept accurate as each is switched on.

11. How long we keep data

Account and analysis data: for as long as your account exists, plus a reasonable period afterward to comply with legal/accounting obligations where applicable. Server logs: short-lived, per Vercel's default operational retention. Support email threads: kept in our mailbox until no longer needed for the purpose they were sent for. Marketing-consent records: kept for as long as needed to demonstrate consent was given, even after you unsubscribe (so we can prove we stopped emailing you if asked).

12. Your rights (EU/EEA)

If you're in the EU/EEA, under the GDPR you have the right to: access the personal data we hold about you, request correction of inaccurate data, request erasure ("right to be forgotten"), request restriction of processing, object to processing based on legitimate interest, receive your data in a portable format, and withdraw consent at any time where processing is based on consent. You can exercise most of these directly under Account → Privacy & Data, or by emailing team@dropsera.com. You also have the right to lodge a complaint with your local supervisory authority — for Austria, that's the Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, Austria (dsb.gv.at).

13. United Kingdom

If you're in the UK, the same rights in section 12 apply to you under the UK GDPR, and our use of cookies/similar technologies is additionally governed by the Privacy and Electronic Communications Regulations (PECR) — reflected in the consent-first design of the cookie banner (section 9). Complaints can be directed to the UK Information Commissioner's Office (ICO, ico.org.uk) in addition to, or instead of, the Austrian DSB.

14. California

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, in the sense those terms are used under the CCPA/CPRA — so there is currently no "Do Not Sell or Share My Personal Information" opt-out to offer, because there is nothing to opt out of. If that ever changes, this section will be updated with the relevant opt-out mechanism before any such sharing begins.

15. Other US states and other countries

Depending on where you live, you may have additional statutory privacy rights beyond those listed above (for example under other US state privacy laws). Rather than list specific thresholds or state names that may go stale, we extend the same practical rights — access, correction, deletion, and opt-out of marketing — to every user regardless of location; email team@dropsera.com and we'll act on your request under whichever law applies to you.

16. Automated decision-making

The Product Score (TEST / CAUTION / SKIP) is a decision aid, not an automated decision that produces legal or similarly significant effects on you within the meaning of Art. 22 GDPR — no contract, benefit, or legal status is automatically granted or denied based on it. You review the score and every underlying number yourself before deciding whether to launch a store.

17. Children

Dropsera is not directed at, and is not intended for, anyone under 16. Paid use of the service requires the legal capacity to enter into a contract in your jurisdiction (generally, being an adult).

18. Changes to this policy, and contact

We may update this policy as the product evolves — the effective date at the top of this page reflects the current version. For anything in this policy, email team@dropsera.com.