DropBandit policy
Privacy Policy
Last updated September 5, 2026
This Privacy Policy explains what DropBandit collects, how it is used, and how connected creator-platform integrations work.
Information We Collect
DropBandit stores account details such as email, display name, username, profile settings, profile image, plan, billing state, and authentication records.
DropBandit stores creator content and metadata, including Drops, uploaded media, processed playback assets, DropBoards, hotkeys, DropKits, posts, messages, Watch comments, reactions, Voice Notes, reports, and usage events needed to operate the product.
How We Use Information
We use account, profile, board, media, and usage information to provide playback, upload processing, sharing, search, discovery, moderation, support, billing, reliability, security, and account-management features.
We use media metadata and processing state so Drops are shown as processing, ready, failed, or unavailable truthfully.
Storage, Authentication, and Media Processing
DropBandit uses Supabase for application database, authentication, and storage where configured. Uploaded files and processed assets may be stored in Supabase Storage and delivered through signed or application-routed media URLs.
DropBandit may use Railway-hosted workers to process uploaded audio or video into playable Drop assets. Vercel-hosted web requests should queue production processing rather than performing FFmpeg work directly.
Payments
Paid subscriptions and billing actions may be handled by Stripe or another payment processor. DropBandit receives billing status and related account records needed to activate, renew, cancel, or troubleshoot paid access.
Payment card details are handled by the payment processor and should not be stored directly by DropBandit.
Connected Social and Provider Accounts
If you connect a creator platform provider, DropBandit uses the provider access you authorize to identify the connected creator account, retrieve channel or profile metadata, and support truthful discovery, profile, or Watch features.
OAuth access tokens and refresh tokens are used server-side to maintain authorized provider connections. Raw provider tokens must not be exposed to ordinary client-side API responses.
YouTube and Google Data
DropBandit's intended YouTube OAuth scope is read-only YouTube access for connected creator/channel and broadcast metadata.
DropBandit does not use this permission to publish, edit, or delete YouTube content.
DropBandit's use and transfer of information received from Google APIs must comply with the Google API Services User Data Policy, including applicable Limited Use requirements.
Twitch and KICK Data
DropBandit's intended Twitch connection is used for creator/channel identity and live-status metadata where supported by official APIs.
DropBandit's intended KICK connection is limited to creator user and channel information where supported by official APIs.
Disconnecting Integrations
When provider integrations are available, you should be able to disconnect them from DropBandit account settings or the relevant provider's security settings.
Disconnecting should prevent DropBandit from continuing to use that provider connection. The provider may also offer separate token revocation or app-access controls.
Sharing and Service Providers
DropBandit may share information with infrastructure, storage, authentication, media processing, email, analytics, moderation, and payment providers only as needed to run and protect the service.
Public Drops, public profiles, public posts, public DropKits, public Watch activity, and shared Drop links may be visible to other users or visitors according to your settings.
Your Choices
You can update profile information, privacy settings, public visibility, and many content settings in DropBandit.
You may request account help, deletion, or provider-disconnect assistance by contacting dropbandits@gmail.com. Some records may be retained where required for billing, security, legal, abuse-prevention, or moderation purposes.
Contact
Privacy questions can be sent to dropbandits@gmail.com.