Skip to content

Legal

Data processing

For businesses who use Dripost to handle other people's personal data, for example a brand's audience.

Last updated 2026-09-21.

Draft. Dripost is in development. This document describes what the product does today and has not yet been reviewed by a lawyer.

The short version

A plain summary. The sections below are the agreement itself.

  • For your own account data we are responsible. For personal data inside the content you process here, you are, and we act on your instructions.
  • We process it only to give you the service, never for our own purposes.
  • Our sub-processors are named below, and we will update the list before we add one.
  • If something is exposed, we tell you without undue delay, and the regulators within the deadlines the law sets.
  • When your account closes, your content goes with it.

Roles

For personal data in the content you process through Dripost, you decide the purpose and means, and Dripost processes it on your behalf. For your own account data, Dripost is responsible, as the privacy policy explains.

What we do with it

We process it only to provide the service you ask for, on your instructions given through the product, and not for our own purposes.

Sub-processors

  • Cloudflare: hosting, the database, file storage and network protection.
  • OpenRouter: routes an AI request to a model provider, only when you use an AI feature.
  • Google (Gemini) and DeepSeek, through OpenRouter: the model providers themselves.
  • Resend: sends our email.
  • Razorpay: takes subscription payments.
  • The networks you connect — Google and YouTube, Meta and Instagram, X — receive what you publish, under their own terms.

We will update this list before a new sub-processor starts, and you may object; if we cannot resolve an objection, you may cancel and we refund the unused part of the period.

Hosting and AI processing happen outside India as well as inside it. The privacy policy says more about that.

Security

Connected-account tokens are encrypted before storage. Files are kept private. Every request is checked against the account that owns the data. The security page lists what is and is not in place.

Incidents

If we learn that personal data you process through Dripost was exposed, we will tell you without undue delay, with what we know, so that you can meet your own obligations.

We notify the Data Protection Board of India and affected people as the privacy policy describes, and report a reportable cyber incident to CERT-In within six hours.

Ending

When your account closes, we delete your content on request, apart from what the law requires us to keep.

Contact

Questions about processing: rajesh411232@gmail.com.

Questions about this page? Write to us.