PricingDevelopersSecurity
Sign inCreate accountJoin
Back to kbDrop

Legal

Privacy Policy

This policy describes the information kbDrop handles and the choices available to you.

Effective October 8, 2026

Terms of Service

1. Scope and operator

This Privacy Policy applies to the kbDrop website, application, API, and related support. kbDrop is operated by Corbin Caldwell. It does not cover a third party's own service or website, including a site you ask kbDrop to crawl.

We determine how account, billing, and service-security information is used. When an organization supplies personal information in Customer Content, that organization determines its purpose and permitted use. Contact that organization about information it supplies; we assist it with requests under the applicable agreement.

2. Information we collect

  • Account information: your email address, password hash, email-verification and password-reset records, session records, account role, status, and preferences. If you use Google sign-in, this also includes your Google account identifier and verified email address; we do not receive your Google password.
  • Connected services: when you connect Slack, we store workspace, channel, user, and message identifiers, selected conversation context, integration settings, and an encrypted bot credential. The information available to the integration depends on the permissions and channels you authorize.
  • Customer Content: files and supported media you upload, URLs and public pages you direct us to crawl, extracted text and media analysis, knowledge-base names, questions, generated answers, conversations, citations, and suggested questions. When you upload an app export, such as a Slack, Microsoft Teams, Google Chat, GitHub, GitLab, Jira, Linear, Confluence or Notion export, kbDrop indexes its content with each author's display name. By default it leaves out direct messages, private channels, internal notes, draft releases, comments that only some people may read, and any confidential issue or issue with a security level that an export shows, along with Confluence pages with view restrictions and notes in Google Keep's or Obsidian's trash. It doesn't index the email addresses, phone numbers, or other profile details the export contains. When a review offers private content, you may explicitly choose to include it. kbDrop keeps counts and channel, project and space names while waiting for your answer, then keeps your choices, including any Datadog site or Grafana address you give it for citation links.
  • Connected GitHub repositories: when you connect GitHub, we store your GitHub account and repository identifiers, encrypted access and refresh tokens, synchronization metadata, and copies of the selected repository content needed to keep its index current. You can choose code, issues, pull requests, reviews and published releases. Private repositories require an explicit choice before indexing. Draft releases, pending reviews and minimized comments are excluded. The connection has read access only.
  • API and usage information: API-key identifiers and one-way key digests, request and operation identifiers, ingestion and answer counts, storage use, model and provider metadata, timestamps, outcomes, latency, and bounded cost information. When kbDrop can't accept a file, it records the file's lowercase extension, a size range, and the reason, never its name or contents; for app exports it recognizes, such as a Slack or GitHub export, it records the app and how many records the export held.
  • Billing information: Stripe customer and subscription IDs, plan, status, billing periods, invoices and payment outcomes, and portal or checkout activity. Stripe collects payment-card details; kbDrop's billing integration does not receive full card numbers or card verification codes. Do not include payment-card details in Customer Content.
  • Security and connection information: authentication source and account digests used for rate limits, request metadata, and redacted diagnostic logs needed to prevent abuse and operate the service. Application logs are designed not to contain email or IP addresses, Customer Content, questions, answers, credentials, cookies, or request bodies.
  • Communications: messages and information you send when you ask for support, report a problem, or make a privacy or billing request.

3. How we use information

We use information to:

  • create and secure accounts and authenticate requests;
  • ingest, store, crawl, index, retrieve, analyze, and answer questions about Customer Content;
  • provide API access, billing, subscriptions, invoices, and plan limits;
  • send verification, password-reset, billing, and service messages;
  • monitor reliability, measure usage, troubleshoot failures, prevent abuse, and enforce the Terms of Service;
  • comply with law and protect the rights, safety, and security of users; and
  • respond to support, billing, and privacy requests.

kbDrop does not use advertising or third-party analytics, and we do not sell personal information or Customer Content. We do not use Customer Content to train a kbDrop model.

Where the GDPR applies to processing for our own purposes, we rely on performance of a contract with you, legitimate interests in administering business relationships and securing and operating the service, compliance with applicable legal obligations, or consent where required. You may object to processing based on legitimate interests. An organization that supplies Customer Content is responsible for identifying its own lawful basis and providing the required notices.

4. AI processing

kbDrop uses OpenRouter to route requests to AI model providers, Voyage AI for code embeddings, and a direct OpenAI connection when configured for answers. Depending on the feature, the information sent can include extracted content, selected image, audio, or video evidence, a question, retrieved excerpts, and instructions needed to generate embeddings, analyses, summaries, suggestions, or answers. So that an answer starts sooner, the signed-in chat can send a question you are still typing, with the recent conversation it follows, to generate its embedding before you submit it. Once a question looks finished, it can also be sent with the excerpts found for it to begin its answer. kbDrop does not save an unsent draft or an answer begun for it, and discards both, with the draft's embedding, within minutes. OpenRouter and the selected model provider process that information under their own terms, policies, and service settings. Do not submit regulated or highly sensitive information to kbDrop.

5. Service providers and disclosure

We disclose information only as needed to the following categories:

  • Hosting and infrastructure: Render, Supabase, and Amazon Web Services host application, database, object-storage, queue, compute, and diagnostic infrastructure.
  • AI processing: OpenRouter and its routed model providers, Voyage AI, and OpenAI process the inputs described above when the corresponding feature or route is used, including code from connected GitHub repositories. A selected model name does not by itself specify the processing region or the provider's retention.
  • Payments: Stripe provides Checkout, subscription billing, invoices, payment processing, and the customer portal.
  • Email: Resend delivers account verification, password-reset, and other transactional messages.
  • Optional connections: Google supports Google sign-in; Slack receives requests and answers for a connected Slack workspace.
  • Legal and safety: we may disclose information when reasonably necessary to comply with law, respond to valid legal process, investigate fraud or abuse, or protect rights, safety, and security.
  • Business transfer: information may transfer as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of the service, subject to applicable law.

6. Cookies

kbDrop uses a strictly necessary HTTP-only session cookie named kb_drop_session to keep you signed in. The cookie uses SameSite protections and expires after up to 30 days. When you ask the home page's UFO Files demo a question, kbDrop also sets kb_drop_demo, a random ID that counts that browser's free questions for the day. It is sent only with demo questions and expires at midnight UTC. We do not use advertising or analytics cookies.

Connecting Slack uses the necessary kb_drop_slack_state cookie for up to ten minutes to protect the connection flow.

Connecting GitHub also uses a temporary HTTP-only cookie to verify the authorization response. It expires after ten minutes or is removed when the connection attempt finishes.

7. Retention and deletion

Account and subscription records are kept while your account is active and as needed afterward for legitimate operational, financial, security, and legal purposes. Customer Content remains until you delete its knowledge base or conversation, request account deletion, or a shorter product limit applies. Deleting a knowledge base removes its application records and schedules deletion of its recorded stored objects. Failed deletions are retried; backup copies, older storage versions, and any unrecorded files require separate retention or cleanup procedures.

Disconnecting a GitHub source removes it from search and stops updates. Access changes reported by GitHub or found during periodic checks have the same effect. Earlier conversations remain until deleted. Superseded GitHub index content is eligible for cleanup after seven days; unreferenced sync snapshots and archives are eligible after one hour. Delete the knowledge base to remove its retained application records and request object deletion.

Authentication tokens expire on bounded schedules. Privacy-bounded operation traces and infrastructure logs normally expire after 30 days, though a different documented retention period may apply where needed for security or operations. Counts of refused file types and recognized app exports are kept for up to 400 days. The demo's question counts for a browser or network are kept for a day. Backups, billing records, fraud-prevention records, and information required by law can remain for a limited period after deletion. We may retain de-identified or aggregated information that no longer identifies you.

8. Your choices and rights

You can delete individual conversations and knowledge bases in the application, revoke or rotate API keys, update payment information in Stripe, and sign out to end the current browser session. You may also ask to access, correct, export, or delete personal information, or object to or restrict certain processing, by contacting us. Your rights depend on where you live, and we may need to verify your identity before completing a request.

Where the GDPR applies, these rights include access, rectification, erasure, restriction, objection, and data portability where applicable. You can withdraw consent for processing based on consent, without affecting prior lawful processing, and complain to a supervisory authority. We respond without undue delay and normally within one month; if a permitted extension is necessary, we explain it within that month.

We do not sell or share personal information for cross-context behavioral advertising and do not process it for targeted advertising, so there is no related opt-out required to use the service.

9. International processing

kbDrop is operated in the United States. Information may be processed in the United States and other countries where service providers operate, which may have different data-protection laws than your location.

10. Security

We use technical and organizational safeguards intended to protect information, including access controls, encrypted network transport, private object storage, one-way password and credential digests, rate limits, tenant authorization, and privacy-bounded logging. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.

11. Children

kbDrop is not directed to children under 13, and paid accounts are intended for adults. We do not knowingly collect personal information from a child under 13. If you believe a child has provided information, contact us so we can investigate and delete it where appropriate.

12. Changes to this policy

We may update this policy as the service or law changes. We will revise the effective date and provide reasonable notice of material changes, such as by email or in the service.

13. Contact

For privacy questions or requests, email corbin.caldwell@gmail.com.

Your team’s docs in. Answers with sources out.

Free to startBuilt for support, sales and account teams

Product
  • Home
  • Pricing
  • Knowledge base software
  • Chat with your documents
  • Website to knowledge base
  • NotebookLM alternative
  • Security
Developers
  • Developers
  • API quickstart
  • Knowledge base API
  • Agent skill
  • For website owners
Account
  • Terms of Service
  • Privacy Policy
  • Log in
  • Create account