Home

DropBandit policy

Privacy Policy

Last updated September 5, 2026

This Privacy Policy explains what DropBandit collects, how it is used, and how connected creator-platform integrations work.

Information We Collect

DropBandit stores account details such as email, display name, username, profile settings, profile image, plan, billing state, and authentication records.

DropBandit stores creator content and metadata, including Drops, uploaded media, processed playback assets, DropBoards, hotkeys, DropKits, posts, messages, Watch comments, reactions, Voice Notes, reports, and usage events needed to operate the product.

How We Use Information

We use account, profile, board, media, and usage information to provide playback, upload processing, sharing, search, discovery, moderation, support, billing, reliability, security, and account-management features.

We use media metadata and processing state so Drops are shown as processing, ready, failed, or unavailable truthfully.

Storage, Authentication, and Media Processing

DropBandit uses Supabase for application database, authentication, and storage where configured. Uploaded files and processed assets may be stored in Supabase Storage and delivered through signed or application-routed media URLs.

DropBandit may use Railway-hosted workers to process uploaded audio or video into playable Drop assets. Vercel-hosted web requests should queue production processing rather than performing FFmpeg work directly.

Payments

Paid subscriptions and billing actions may be handled by Stripe or another payment processor. DropBandit receives billing status and related account records needed to activate, renew, cancel, or troubleshoot paid access.

Payment card details are handled by the payment processor and should not be stored directly by DropBandit.

Connected Social and Provider Accounts

If you connect a creator platform provider, DropBandit uses the provider access you authorize to identify the connected creator account, retrieve channel or profile metadata, and support truthful discovery, profile, or Watch features.

OAuth access tokens and refresh tokens are used server-side to maintain authorized provider connections. Raw provider tokens must not be exposed to ordinary client-side API responses.

YouTube and Google Data

DropBandit's intended YouTube OAuth scope is read-only YouTube access for connected creator/channel and broadcast metadata.

DropBandit does not use this permission to publish, edit, or delete YouTube content.

DropBandit's use and transfer of information received from Google APIs must comply with the Google API Services User Data Policy, including applicable Limited Use requirements.

Twitch and KICK Data

DropBandit's intended Twitch connection is used for creator/channel identity and live-status metadata where supported by official APIs.

DropBandit's intended KICK connection is limited to creator user and channel information where supported by official APIs.

Disconnecting Integrations

When provider integrations are available, you should be able to disconnect them from DropBandit account settings or the relevant provider's security settings.

Disconnecting should prevent DropBandit from continuing to use that provider connection. The provider may also offer separate token revocation or app-access controls.

Sharing and Service Providers

DropBandit may share information with infrastructure, storage, authentication, media processing, email, analytics, moderation, and payment providers only as needed to run and protect the service.

Public Drops, public profiles, public posts, public DropKits, public Watch activity, and shared Drop links may be visible to other users or visitors according to your settings.

Your Choices

You can update profile information, privacy settings, public visibility, and many content settings in DropBandit.

You may request account help, deletion, or provider-disconnect assistance by contacting dropbandits@gmail.com. Some records may be retained where required for billing, security, legal, abuse-prevention, or moderation purposes.

Contact

Privacy questions can be sent to dropbandits@gmail.com.