CopOrDropCopOrDrop

Privacy Policy

Effective July 1, 2026

1. Overview

CopOrDrop ("we", "us", "our") operates the CopOrDrop mobile application and website at copordrop.app (collectively, the "Service"). This Privacy Policy explains what personal information we collect, why we collect it, how we use and share it, and the choices available to you.

By creating an account or using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.

2. Information We Collect

2.1 Account information

When you create an account, we collect:

  • Phone number — collected at sign-up or when you sign in with a phone OTP. Stored in E.164 format and used to verify your identity via Twilio.
  • Username and display name — chosen by you during onboarding. Visible to other users.
  • Birthday — used to enforce our minimum age requirement. Users under 13 are blocked from creating an account.
  • Email address — optional. If provided, used for transactional emails and account recovery.
  • Bio — optional text you add to your profile.
  • Profile photo — optional. Uploaded and stored on our servers (Cloudflare R2). We retain a history of your past profile photos for administrative purposes.
  • Privacy setting — whether your account is public or private, set at sign-up and adjustable at any time.

2.2 Sign-in with Apple or Google

If you sign in with Apple or Google, we receive:

  • A unique identifier from Apple or Google tied to your account on that platform.
  • Your name and email address, if you choose to share them (Apple gives you the option to hide your email).
  • We store only the identifier and, if shared, the name and email. We do not receive your Apple or Google password.

2.3 Content you create

  • Photos and images — photos you post as Drops or Vault Direct posts, including processed versions (thumbnails, card images, background-removed variants). Stored on Cloudflare R2.
  • Captions and descriptions — text you add to posts, including item names and collection names.
  • Product links — if you attach an external product URL to a post, we scrape and store publicly available metadata from that URL (product title, price, site name, and product image) to display within your Drop.
  • Comments — text comments you write on posts.
  • Votes — whether you voted Cop or Drop on a given post. We record your vote to prevent duplicate voting.
  • Likes — posts you have liked in the Cop feed.
  • Vault collections — the names and organisation of collections you create in your Vault.

2.4 Social and interaction data

  • Accounts you follow and accounts that follow you.
  • Follow requests you send or receive (for private accounts).
  • Accounts you have blocked.
  • Reports you submit about content or other users.
  • Appeals you submit against moderation decisions.

2.5 Contacts (optional, never stored)

If you grant permission, the app reads phone numbers from your device's contacts to identify which of your contacts are already on CopOrDrop. We send those numbers to our server for matching, then immediately discard them — we do not retain your contacts. You can revoke this permission at any time in your device's Settings.

2.6 Trust and safety data

To protect the integrity of the platform, we maintain:

  • A risk score associated with your account, based on behavioural signals.
  • A shadowban status (none, soft, or hard) that may affect the visibility of your content without notifying you directly.
  • Records of reports made against your content and any moderation actions taken.
  • Device identifiers (a hashed fingerprint of your device) to detect and prevent ban evasion by users who have been permanently removed from the Service.

2.7 Device and usage data

  • Push notification token — an Expo push token generated by your device, used to deliver in-app and push notifications.
  • Device type and OS version — collected passively for debugging and compatibility.
  • IP address — collected by Cloudflare (our CDN and WAF provider) for rate limiting and security. We do not permanently store per-request IP logs.
  • Error and crash reports — sent to Sentry when the app encounters an error. May include stack traces and limited device context.
  • In-app notifications — we store notification records (type, body, read status) for up to 90 days, after which they are automatically deleted.

3. How We Use Your Information

  • To create, authenticate, and manage your account.
  • To operate the core features of the Service: the Drop Zone voting feed, Vault, comments, likes, and social graph.
  • To verify your identity via SMS OTP (Twilio) or third-party sign-in (Apple / Google).
  • To scan all uploaded images for prohibited content before they go live (AWS Rekognition).
  • To send push notifications and in-app notifications about activity on your posts and account.
  • To send transactional emails (e.g., account changes) via our email provider (Resend).
  • To assess and enforce trust and safety rules, including detecting vote manipulation, spam, ban evasion, and prohibited content.
  • To process and respond to reports, appeals, and other user inquiries.
  • To aggregate and analyse usage patterns to improve the Service (using anonymised or de-identified data where possible).
  • To comply with applicable legal obligations.

4. How We Share Your Information

We do not sell your personal data. We share it only in the following circumstances:

4.1 Service providers

We use the following third-party processors to operate the Service. Each processes your data only as instructed by us:

  • Twilio — SMS OTP delivery.
  • Apple / Google — third-party sign-in authentication.
  • AWS (Amazon Web Services) — automated image content moderation via Rekognition.
  • Cloudflare — CDN, media storage (R2), and Web Application Firewall. IP addresses and request metadata pass through Cloudflare's network.
  • Railway — backend API hosting and primary Postgres database.
  • Upstash — Redis-based cache and queue (vote counts, feed sorted sets, job queues). Data is stored with TTLs and is not used for user profiling.
  • Sentry — error and crash monitoring. Error reports may include partial app state and device context.
  • Expo — push notification delivery infrastructure.
  • Resend — transactional email delivery from noreply@copordrop.app.

4.2 Other users

The following information is visible to other users of the Service, subject to your privacy settings:

  • Your username, display name, bio, and profile photo are always public.
  • Your posts and Vault content are visible to all users if your account is public, or only to approved followers if your account is private.
  • Your vote on any post is not publicly displayed — aggregate vote counts (Cop %) are shown, not individual voter identities.
  • Comments and likes you make on posts are visible to other users who can see that post.
  • Your follower and following lists are visible to other users.

4.3 Legal and safety disclosures

We may disclose your information if we believe in good faith that it is necessary to:

  • Comply with applicable law, regulation, legal process, or enforceable governmental request.
  • Enforce our Terms of Service, including investigation of potential violations.
  • Detect, prevent, or address fraud, security, or technical issues.
  • Protect the rights, property, or safety of CopOrDrop, our users, or the public.

4.4 Business transfers

If CopOrDrop is involved in a merger, acquisition, financing, or sale of all or a portion of its assets, your information may be transferred as part of that transaction. We will notify you via a prominent notice in the app or by email before your information becomes subject to a different privacy policy.

5. Data Retention

  • We retain your account data for as long as your account is active.
  • If you delete your account, we delete your personal data within 30 days, except where retention is required by applicable law or for legitimate business purposes (e.g., fraud prevention records).
  • Expired posts (Drops that have passed their time limit) are removed from the voting feed but the underlying data may be retained for a period of up to 30 days before permanent deletion. Aggregate statistics derived from expired posts may be retained indefinitely in anonymised form.
  • In-app notification records are automatically deleted after 90 days.
  • Content removed by us for policy violations may be retained in restricted form for up to 90 days for appeal purposes, then permanently deleted.
  • Backup copies may persist for a short additional period before being overwritten in the normal course of our backup rotation.

6. Children's Privacy

CopOrDrop is not intended for children under 13. We collect date of birth during sign-up and block account creation for anyone under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately at privacy@copordrop.app and we will delete it promptly.

7. Your Rights and Choices

  • Access and correction — you can view and edit your profile information (display name, bio, photo, email, username) at any time in the app under Profile > Edit Profile.
  • Delete your account — you can delete your account from Settings. This triggers deletion of your personal data within 30 days.
  • Notification preferences — you can manage which types of in-app and push notifications you receive in Settings. You can also disable all push notifications in your device's system settings.
  • Contacts permission — you can grant or revoke contacts access at any time in your device's Settings. We do not store your contacts regardless of whether permission is granted.
  • Private account — you can switch your account to private so that only followers you approve can see your posts and Vault. This can be toggled in Settings.
  • Blocking — you can block any user at any time. A blocked user cannot see your content, vote on your posts, or interact with you on the Service.
  • Data requests — to request a copy of the personal data we hold about you, or to request deletion of specific data, contact us at privacy@copordrop.app. We will respond within 30 days.

Depending on your jurisdiction, you may have additional rights under applicable data protection law (such as the GDPR or CCPA). These may include the right to object to processing, the right to data portability, or the right to lodge a complaint with a supervisory authority. Contact us at the email above to exercise any such rights.

8. Security

We implement industry-standard security measures to protect your data, including RS256 JWT authentication, TLS encryption in transit, access controls on all data stores, and rate limiting at both the network (Cloudflare WAF) and application (Redis sliding window) layers. OTP codes are compared using timing-safe comparison to prevent enumeration attacks.

Despite these measures, no method of transmission or storage over the internet is 100% secure. We cannot guarantee absolute security of your information. If we become aware of a security breach that affects your personal data, we will notify you in accordance with applicable law.

9. International Data Transfers

CopOrDrop and its service providers operate globally. Your information may be transferred to and processed in countries other than the country in which you reside. When we transfer personal data internationally, we do so in accordance with applicable data protection laws and rely on appropriate safeguards where required.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via a notice in the app, by email, or by updating the "Effective" date at the top of this page. Your continued use of the Service after any changes take effect constitutes acceptance of the updated policy.

11. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

privacy@copordrop.app