Skip to content

Legal

Privacy policy

What we collect, why, who else touches it, how long we keep it, and how to make us change or delete it. Written plainly, and limited to what the product actually does.

Last updated 2026-09-21.

Draft. Dripost is in development. This document describes what the product does today and has not yet been reviewed by a lawyer.

The short version

A plain summary. The sections below are the agreement itself.

  • We collect what the product needs to work: your name and email, the posts and files you make, the connection to each network you link, and a record of what happened on your account.
  • We do not run advertising or tracking, we do not sell your data, and we never store your IP address against your consent record — only the country your request came from.
  • When you use an AI feature, the text (and, for a video, the video) goes to a model provider through OpenRouter. We have not been able to turn off their retention, so do not paste anything there you would not show a supplier.
  • We publish to a network only when you have connected it and told us to. You can disconnect any network, and revoke our access at the network's own settings, at any time.
  • You can download everything we hold about you, and delete your account and its data, yourself, from Settings. Deletion is immediate and it also revokes the network tokens.
  • Something wrong? Write to rajesh411232@gmail.com. Our Grievance Officer is Rajesh Kumar, and the Data Protection Board of India is above us.

What changed on 2026-09-21: We now ask you to agree to this policy explicitly when you create an account, and we keep a record of that. We have also listed every service provider by name, explained the AI processing in full, set out your rights under the Digital Personal Data Protection Act 2023, and named our Grievance Officer with response times.

Who we are, and who is responsible

Rajesh Kumar (sole proprietor) operates Dripost. Under the Digital Personal Data Protection Act 2023 we are the Data Fiduciary for your account data, which means we decide why and how it is used and we answer for it.

For personal data inside the content you process through Dripost — a customer's name in a caption, a face in a video — you decide why and how, and we process it on your instructions. The data processing terms set that relationship out.

Address: Whitefield, Bengaluru – 560048, Karnataka, India. Email: rajesh411232@gmail.com. Phone: +91 85278 77979.

What we collect, why, and who else sees it

Everything in this table comes from you, or from a network you connected, or from the request your browser makes. There is no fourth source: we buy no data and we take none from data brokers.

Every category of personal data Dripost holds today.

  • Name and email address

    Why we have it: To make your account, sign you in, email you a login code, and write to you about your account.

    Who else sees it: Resend, which sends our email. Cloudflare, which stores it.

  • Password, if you set one

    Why we have it: To sign you in. It is stored only as a bcrypt hash; we never see or store the password itself.

    Who else sees it: Nobody. It never leaves our database, and it is not in your data export.

  • Second factor and passkeys, if you set them up

    Why we have it: To protect your account from somebody who has your password.

    Who else sees it: Nobody.

  • Your posts, drafts, schedules, captions and hashtags

    Why we have it: To show your calendar and publish what you scheduled, at the time you set.

    Who else sees it: The network you publish to. A model provider, if you use an AI feature on that post. Anyone you send a review link to.

  • Images and videos you upload

    Why we have it: To attach them to a post and hand them to the network at publishing time.

    Who else sees it: Cloudflare R2, which stores them. The network you publish to. A model provider, if you ask AI to work from the video.

  • Connected accounts: an access token, plus the account name and picture the network returns

    Why we have it: To publish on your behalf and to show you which account a post will go to.

    Who else sees it: Nobody. Tokens are encrypted with AES-256-GCM before storage and are never sent back to your browser.

  • Published-post metrics we fetch back from a network

    Why we have it: To show you how a post did.

    Who else sees it: Nobody. They come from the network, to us.

  • Payment records: a subscription reference, plan, amount and status

    Why we have it: To give you the plan you paid for, and to keep the books.

    Who else sees it: Razorpay, which takes the payment. We never receive your card or UPI number.

  • An activity log: which actions happened on your account and when

    Why we have it: To show you what happened, to investigate a problem, and to prove what was agreed and when.

    Who else sees it: Nobody.

  • Your agreement to these policies: the date, which versions, whether you accepted, and the country of the request

    Why we have it: Because the DPDP Act requires us to be able to show that consent was given, and to what.

    Who else sees it: Nobody. We deliberately do not store the IP address.

  • Sign-in country and a coarse browser-and-system name

    Why we have it: To email you when your account is used from a place or a browser we have not seen, so a takeover is visible within minutes.

    Who else sees it: Nobody. Only a two-letter country, never the IP address.

  • Request counts used for rate limits

    Why we have it: To stop somebody flooding the service or guessing at addresses.

    Who else sees it: Nobody. They are counts, kept briefly.

What we do not collect

  • No advertising or analytics trackers. There is no Google Analytics, no advertising pixel and no third-party script following you around this site.
  • No advertising cookies.
  • No sale of your data, and no sharing of it for anybody else's advertising. We do not, and will not.
  • No IP address against your consent record. The law lets us keep one; we decided the country is enough.
  • The free tools run entirely in your browser. What you type into them is never sent to us.

How the AI features work

When you ask Dripost to write, adapt or enhance a post, we send the text you wrote — and, where the feature works from a video, that video — to a model provider. The request goes through OpenRouter, which routes it to the model we have chosen: today Google's Gemini models, with DeepSeek as a fallback when Google is unavailable. The answer comes back and is shown to you. It is not used to train anything of ours.

We have not been able to secure a contractual opt-out from retention or training with those providers on the plan we are on. So we say it plainly rather than implying otherwise: treat the AI features as you would treat a supplier you have not signed an NDA with, and do not paste anything into them that you would not want a service provider to see.

AI output can be wrong, dated, or wrong for your audience. Nothing an AI feature produces is published on its own — you read it, edit it and schedule it. You are the author of what goes out.

Who else handles your data

These are every processor and sub-processor we use today. If we add one that handles personal data, we will update this list before it starts.

  • Cloudflare — hosting, the database (D1), file storage (R2) and network protection. Data is stored on Cloudflare's network, which spans several countries.
  • OpenRouter — routes an AI request to a model provider. Used only when you use an AI feature.
  • Google (Gemini, through OpenRouter) — the primary model provider for AI features.
  • DeepSeek (through OpenRouter) — the fallback model provider when the primary is unavailable.
  • Resend — sends our email: login codes, sign-in alerts, approval requests and account notices.
  • Razorpay — takes and manages subscription payments.
  • Google and YouTube, Meta and Instagram, and X — the networks you choose to connect. Each receives what you publish and holds it under its own terms.

We use no advertising networks, no data brokers and no analytics vendors.

Where your data goes, outside India

Our hosting is Cloudflare's global network, so your data may be stored or processed outside India. AI requests go to model providers who operate outside India. Our email and payment providers may process outside India as well.

The DPDP Act permits transfers outside India except to a country the Central Government restricts; if such a restriction is notified and it affects a provider we use, we will change the provider or stop the transfer.

Cookies and what we keep in your browser

  • A sign-in cookie, so you stay logged in. Without it you would log in again on every page.
  • A short-lived cookie during a two-step sign-in, so the second step knows the first one succeeded. It is signed, cannot be read by any script, and dies in five minutes.
  • A short-lived cookie recording that you ticked the agreement boxes, so the account we then create can be created with your consent on record. Thirty minutes, signed, and deleted once the account exists.
  • A short-lived cookie while you connect a social account, which protects that connection from forgery.
  • A cookie naming the workspace you are currently working in.
  • In your browser's own storage, not ours: whether you chose light or dark, and whether you left the menu open or closed.

That is the whole list. There are no advertising or tracking cookies, so there is no consent banner to dismiss.

How long we keep things

We keep your account and its content while your account is open, because that is the service.

  • Delete your account and we delete it then and there: your posts, your uploaded files, your connected-account tokens, your settings. It is not a queue and not a 30-day grace period.
  • Emailed login codes die 10 minutes after they are issued, and are deleted the moment they are used.
  • Links that let somebody review a post without an account expire after 7 days, and you can revoke one sooner.
  • Links to your video and image files are signed and expire after 15 minutes. The file stays private; the link is what expires.
  • Rate-limit counters last minutes, not longer.
  • Payment and tax records are kept for as long as Indian tax and company law requires, which is longer than your account. They are financial records, not content.
  • Your agreement to these policies is kept for as long as your account exists and for a reasonable period after, because it is the proof that consent was given.

Backups: Cloudflare's database keeps a short rolling history that lets us restore after a mistake or an incident. A deleted row can therefore survive in that history for a brief period before it ages out. We do not read backups except to recover the service.

Your rights, and how to use them

Under the DPDP Act you have the right to know what we hold about you and who we have shared it with, to have it corrected or completed, to have it erased, to nominate somebody to exercise your rights if you cannot, and to have a grievance answered.

  • To see and download everything: Settings has an export. It hands you a JSON file with your profile, posts, versions, library, posting times and activity. Password data and connection tokens are deliberately left out of it.
  • To correct something: change it in Settings, or write to us for anything you cannot reach.
  • To erase everything: Settings, Delete account. It removes your posts and files and revokes every network connection at once. It refuses in two cases we cannot resolve for you — while other people are in your workspace, and while you have an active paid plan — and it tells you which. Or write to rajesh411232@gmail.com and we will do it.
  • To disconnect one network without deleting anything else: Channels, Disconnect. We delete our copy of the token, and you can also remove Dripost's access at the network's own settings.
  • To nominate somebody, or to ask anything the product cannot do: email rajesh411232@gmail.com from the address on your account.

We act on a verified request without undue delay, and in any case within 30 days. We may need to check that the request is really from you; we will not use that check to delay you.

Children

Dripost is for people aged 18 and over. We ask you to confirm it when you create an account, and we do not knowingly collect data from anyone younger.

If you believe a child has an account here, write to rajesh411232@gmail.com and we will delete it.

How we protect your data

This is what is actually in place, not a wish list:

  • Connected-account tokens are encrypted with AES-256-GCM before they are stored, and are never sent to your browser. There is an automated test whose whole job is to fail if one ever leaks into a response.
  • Passwords, where set, are stored only as bcrypt hashes.
  • Your uploaded files are private. They are reached only through signed links that expire in 15 minutes.
  • Every request is checked against the account and workspace that owns the data, and there is a test that fails the build if a new route forgets.
  • Optional two-factor authentication and passkeys are available on every account.
  • We email you when your account is signed into from a country or a browser we have not seen before.
  • Sign-in, code and password routes are rate limited, and login codes expire in 10 minutes with 5 attempts.
  • An append-only activity log records what happened on your account.

No system is perfectly secure, and we will not pretend otherwise. What we commit to is the list above, and telling you quickly when something goes wrong.

If something goes wrong

We have a written breach plan and we follow it. If personal data we hold is exposed, lost or accessed without authorisation:

  • We contain it first, which may mean rotating secrets, revoking network tokens so you have to reconnect, or taking a route offline.
  • We tell the Data Protection Board of India, and every person affected, with what happened, what data, what we have done and what you should do. Under the DPDP framework this is without delay and within 72 hours of becoming aware, and we will not wait to be sure it was serious before telling you.
  • Where the incident is also a reportable cyber incident, we report it to CERT-In within the 6 hours their directions require.
  • We tell the networks and our payment provider if their tokens, app secrets or payment identifiers were involved.
  • Afterwards we write up the cause and the fix, and add a test that would have caught it.

We will not minimise, and we will not make you find out from somebody else.

The networks you connect

Connecting a network is you giving us permission, at that network, to act for you in specific ways. What we get and what we may do with it is set by the network, not by us.

  • Google and YouTube: Dripost uses YouTube API Services. By using Dripost's YouTube features you also agree to the YouTube Terms of Service, and Google's own handling is described in the Google Privacy Policy. You can revoke Dripost's access to your Google and YouTube data at any time at the Google security settings page.
  • Dripost's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use that data only to provide the features you can see in the product. We do not transfer it, sell it, or use it for advertising, and no human at Dripost reads it except with your explicit permission for support, to comply with the law, or where it is aggregated and anonymised for a security or operations reason.
  • Meta, for Instagram: you can remove Dripost's access in Instagram's own settings, under apps and websites.
  • X: you can remove Dripost's access in your X settings, under connected apps.

We keep only what those permissions give us, and we delete our copy when you disconnect or delete your account.

If you are outside India

Dripost is built and operated from India, and Indian law governs it. We apply the protections in this policy to everyone, wherever you are.

If you are in the UK or the European Economic Area: we process your data to perform our contract with you, and on your consent where this policy says consent. You have the rights you would expect — access, correction, erasure, portability, objection, restriction — and the way to use them is the same as above. Since we have no establishment in the EEA or the UK, complaints come to us first, and we will answer them properly.

If you are in a US state with its own privacy law: we do not sell personal information or share it for cross-context behavioural advertising, and you may ask us to access or delete your data by writing to us.

Complaints

If anything here worries you, tell us first — most things are a misunderstanding we can fix the same day.

Grievance Officer

  • Rajesh Kumar, Grievance Officer
  • Email: rajesh411232@gmail.com (put "Grievance" in the subject)
  • Address: Whitefield, Bengaluru – 560048, Karnataka, India
  • Phone: +91 85278 77979
  • We acknowledge a complaint within 24 hours and aim to resolve it within 15 days. Where a complaint is a consumer complaint, we acknowledge it within 48 hours and resolve it within one month.
  • If you are not satisfied with how we handled personal data, you can complain to the Data Protection Board of India. If your complaint is a consumer one, you can also approach the consumer commission where you live.

Changes to this policy

If we change this policy in a way that matters, we will tell you inside the product before it takes effect, and we will ask you to agree again. Each version carries its date, and the record of what you agreed to names the version, so it is always possible to say which text you accepted.

This version is dated 2026-09-21.

How to reach us

For anything about this policy, or about data we hold:

How to reach us

  • Rajesh Kumar (sole proprietor)
  • Whitefield, Bengaluru – 560048, Karnataka, India
  • Email: rajesh411232@gmail.com
  • Phone: +91 85278 77979
  • We answer email on working days, usually within two.

Questions about this page? Write to us.