COCOTOFY LLC / PRIVACY
PRIVACY POLICY
EFFECTIVE AND LAST UPDATED: AUGUST 16, 2026
DROP3 collects the account, build, and usage data needed to host your work, enforce limits, prevent abuse, and measure service cost. We do not sell personal information.
1. SCOPE
This policy explains how Cocotofy LLC processes personal information when you visit, sign in to, upload to, or administer DROP3. It does not govern code or services operated by users inside their hosted drops.
2. INFORMATION WE COLLECT
Account data
When you use Google sign-in, we receive your Google account identifier, verified email address, name, and profile image. We create a DROP3 username, role, plan, session, and terms-acceptance record. You may optionally add an X or Twitter handle. That handle is public and may be linked from your drops. Your email address is not shown on public drops and is available only in your account and restricted administration tools.
Build data
We process uploaded files, paths, content types, file sizes, drop names, deployment identifiers, timestamps, visibility, access level, and deletion status. Free hosted drops are public, may be unlisted from search, and should not contain confidential information.
Usage and device data
We record events such as sign-ins, uploads, publishes, deletes, storage totals, file operations, asset requests, response bytes, cache status, approximate country, browser information, errors, and security signals. Cloudflare processes IP addresses and network data to deliver and secure requests. For sign-in and upload-abuse monitoring, DROP3 derives a truncated keyed network fingerprint from the connecting IP address. The fingerprint is not the raw IP address and is used to identify repeated activity without retaining the address itself.
Communications and payments
If you contact us or purchase a plan, we process correspondence, support details, Stripe customer and subscription identifiers, billing status, renewal timing, and transaction references. Stripe handles full payment credentials under its own policies.
3. HOW WE USE INFORMATION
- Authenticate users and maintain sessions.
- Store, publish, replace, and delete drops.
- Show account usage and enforce quotas.
- Measure infrastructure cost and support future usage billing.
- Detect abuse, malware, fraud, outages, and policy violations.
- Provide support, legal notices, and service updates.
- Analyze and improve reliability and product design.
- Comply with law and protect rights and safety.
4. LEGAL BASES
Where applicable, we process information to perform our contract with you, pursue legitimate interests in operating and securing DROP3, comply with legal obligations, and act with your consent when consent is required.
5. SERVICE PROVIDERS
We use Cloudflare for compute, storage, databases, security, analytics, email delivery, and Turnstile human verification; Google for identity; and Stripe for subscription checkout, billing, and customer self-service. Turnstile is governed by Cloudflare's privacy addendum. We may use email, monitoring, or support providers as those features launch. Providers process information for us under their own contractual and legal obligations.
We may disclose information during a business transaction, to comply with valid legal process, to enforce policies, or to protect users, Cocotofy, and others. We do not sell personal information or share it for cross-context behavioral advertising.
6. COOKIES
DROP3 uses essential host-only cookies for login nonce protection and authenticated sessions. A private drop uses a short-lived, host-isolated access cookie after its owner opens it. Account cookies are not made available to user-hosted builds. Local storage remembers display preferences. Google and Stripe may set or read their own cookies when you use their sign-in or billing services.
7. RETENTION
Account and ownership records remain while your account is active and as needed for security, billing, disputes, and legal compliance. Keyed network abuse counters are normally retained for 30 days, but records connected to an investigation, suspension, payment dispute, or legal obligation may be retained longer. Expired sessions and incomplete uploads are periodically removed. Deleted or replaced files are scheduled for deletion but may remain temporarily in caches, logs, backups, or required records. Analytics retention depends on the applicable provider and configuration.
8. SECURITY
We use signed identity tokens, hashed session tokens, host-isolated cookies, access controls, encrypted transport, tenant-scoped object keys, quotas, logs, and platform security controls. No system is completely secure. Keep your originals and do not upload secrets or sensitive personal data.
9. YOUR CHOICES AND RIGHTS
You may update or remove your username and public social handle, delete drops, sign out, or request account access, correction, deletion, or export by contacting us. Depending on your location, you may also have rights to restrict or object to processing, withdraw consent, or appeal a decision. We may verify your identity before fulfilling a request and retain information where legally permitted or required.
10. CHILDREN
DROP3 is not directed to children under 13 and is not intended for anyone below the minimum digital-consent age in their jurisdiction. Contact us if you believe a child provided personal information improperly.
11. INTERNATIONAL PROCESSING
Cocotofy and its providers may process data in the United States and other countries. Where required, we rely on recognized transfer mechanisms and provider safeguards.
12. CHANGES AND CONTACT
We may update this policy and will revise the date above. Material changes may be announced in DROP3 or by email.
Cocotofy LLC
cocotofyllc@gmail.com
Use the subject "DROP3 PRIVACY REQUEST."