How Dropstone handles your data
What Dropstone stores, for how long, who can see it, whether it is used to improve the models, and the commitments that apply to every account. A plain-language summary of Dropstone's data practices.
This is a plain-language summary of what happens to your data. The privacy policy is the authoritative version, and the Privacy controls page in your dashboard is where you change the parts you control.
What Dropstone stores
| Data | Stored | Why |
|---|---|---|
| Conversations and artifacts | Yes, with your account | So you can search, continue, and share them |
| Project files | Yes, with the project | So conversations in the project can use them |
| Memory (lessons, studied knowledge, summaries) | Yes, with your account | So Dropstone learns and carries it across surfaces |
| Usage records | Yes | To meter your allowance and show you your usage |
| Account details | Yes | Sign-in, billing, notifications |
| Incognito conversations | Not in your account | Your history keeps nothing. An organization with content logging on full records the turns in its own archive |
| CLI sessions | On your machine | Your history stays local. A session you share from the CLI, or run with the training setting on, is also held on Dropstone's servers |
You can see all of it, export the conversations, and delete the account. See Export and delete your data.
Model providers retain nothing
Dropstone runs its models through US-hosted inference providers. Those providers are under contract to discard your inputs and outputs immediately after the response is generated. They do not keep your prompts, your files, or the replies.
What Dropstone stores, it stores on its own systems, under the terms above.
Use of your data to improve Dropstone
On consumer accounts (Free, Pro, Max), Dropstone may use session content to improve its models. You can opt out from Privacy controls; after you do, conversations from that point on are not used.
On organization accounts (Enterprise), session content is never used for this. There is no switch because there is nothing to switch off.
Incognito chats are never used to improve the models, on any account. An organization's own archive is not used for this either.
Who can see your data
You. Your account, on every surface.
People you share with. A conversation you share is visible to whoever you shared it with, and a memory you share in an organization is visible at the level you shared it. Both are your decision. See Share a conversation and Memory in teams and organizations.
Dropstone staff access customer data only when needed to operate the service, investigate a problem you have reported, or comply with a legal obligation.
Nobody else. Data is isolated per account and per organization.
Security
All traffic is encrypted in transit with TLS 1.3. Internal service-to-service calls run inside an isolated private network. Sign-in supports Google, GitHub, email with phone verification, and, for organizations, SSO.
To report a security concern, see How to get support.
Enterprise agreements
Organizations can request a data processing agreement. See the DPA and Dropstone for teams and organizations.