kkbDrop
PricingAPISecurity
Sign inCreate accountJoin
Back to kbDrop

Legal

Privacy Policy

This policy describes the information kbDrop handles and the choices available to you.

Effective August 5, 2026

Terms of Service

1. Scope and operator

This Privacy Policy applies to the kbDrop website, application, API, and related support. kbDrop is operated by Corbin Caldwell. It does not cover a third party's own service or website, including a site you ask kbDrop to crawl.

2. Information we collect

  • Account information: your email address, password hash, email-verification and password-reset records, session records, account role, status, and preferences.
  • Customer Content: files and supported media you upload, URLs and public pages you direct us to crawl, extracted text and media analysis, knowledge-base names, questions, generated answers, conversations, citations, and suggested questions.
  • API and usage information: API-key identifiers and one-way key digests, request and operation identifiers, ingestion and answer counts, storage use, model and provider metadata, timestamps, outcomes, latency, and bounded cost information.
  • Billing information: Stripe customer and subscription IDs, plan, status, billing periods, invoices and payment outcomes, and portal or checkout activity. Stripe collects payment-card details; kbDrop does not store full card numbers.
  • Security and connection information: authentication source and account digests used for rate limits, request metadata, and redacted diagnostic logs needed to prevent abuse and operate the service. Application logs are designed not to contain email or IP addresses, Customer Content, questions, answers, credentials, cookies, or request bodies.
  • Communications: messages and information you send when you ask for support, report a problem, or make a privacy or billing request.

3. How we use information

We use information to:

  • create and secure accounts and authenticate requests;
  • ingest, store, crawl, index, retrieve, analyze, and answer questions about Customer Content;
  • provide API access, billing, subscriptions, invoices, and plan limits;
  • send verification, password-reset, billing, and service messages;
  • monitor reliability, measure usage, troubleshoot failures, prevent abuse, and enforce the Terms of Service;
  • comply with law and protect the rights, safety, and security of users; and
  • respond to support, billing, and privacy requests.

kbDrop does not use advertising or third-party analytics, and we do not sell personal information or Customer Content. We do not use Customer Content to train a kbDrop model.

4. AI processing

kbDrop uses OpenRouter to route requests to AI model providers. Depending on the feature, the information sent can include extracted content, selected image, audio, or video evidence, a question, retrieved excerpts, and instructions needed to generate embeddings, analyses, summaries, suggestions, or answers. OpenRouter and the selected model provider process that information under their own terms, policies, and service settings. Do not submit regulated or highly sensitive information to kbDrop.

5. Service providers and disclosure

We disclose information only as needed to the following categories:

  • Hosting and infrastructure: Render and Amazon Web Services host application, database, object-storage, queue, compute, and diagnostic infrastructure.
  • AI processing: OpenRouter and routed model providers process the inputs described above.
  • Payments: Stripe provides Checkout, subscription billing, invoices, payment processing, and the customer portal.
  • Email: Resend delivers account verification, password-reset, and other transactional messages.
  • Legal and safety: we may disclose information when reasonably necessary to comply with law, respond to valid legal process, investigate fraud or abuse, or protect rights, safety, and security.
  • Business transfer: information may transfer as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of the service, subject to applicable law.

6. Cookies

kbDrop uses a strictly necessary HTTP-only session cookie named kb_drop_session to keep you signed in. The cookie uses SameSite protections and expires after up to 30 days. We do not use advertising or analytics cookies.

7. Retention and deletion

Account and subscription records are kept while your account is active and as needed afterward for legitimate operational, financial, security, and legal purposes. Customer Content remains until you delete its knowledge base or conversation, request account deletion, or a shorter product limit applies. Deleting a knowledge base removes its application records and starts best-effort deletion of associated stored objects.

Authentication tokens expire on bounded schedules. Privacy-bounded operation traces and infrastructure logs normally expire after 30 days, though a different documented retention period may apply where needed for security or operations. Backups, billing records, fraud-prevention records, and information required by law can remain for a limited period after deletion. We may retain de-identified or aggregated information that no longer identifies you.

8. Your choices and rights

You can delete individual conversations and knowledge bases in the application, revoke or rotate API keys, update payment information in Stripe, and sign out to end the current browser session. You may also ask to access, correct, export, or delete personal information, or object to or restrict certain processing, by contacting us. Your rights depend on where you live, and we may need to verify your identity before completing a request.

We do not sell or share personal information for cross-context behavioral advertising and do not process it for targeted advertising, so there is no related opt-out required to use the service.

9. International processing

kbDrop is operated in the United States. Information may be processed in the United States and other countries where service providers operate, which may have different data-protection laws than your location.

10. Security

We use technical and organizational safeguards intended to protect information, including access controls, encrypted network transport, private object storage, one-way password and credential digests, rate limits, tenant authorization, and privacy-bounded logging. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.

11. Children

kbDrop is not directed to children under 13, and paid accounts are intended for adults. We do not knowingly collect personal information from a child under 13. If you believe a child has provided information, contact us so we can investigate and delete it where appropriate.

12. Changes to this policy

We may update this policy as the service or law changes. We will revise the effective date and provide reasonable notice of material changes, such as by email or in the service.

13. Contact

For privacy questions or requests, email corbin.caldwell@gmail.com.

kkbDrop

Private knowledge in. Cited answers out.

HomeKnowledge base softwareChat with your documentsWebsite to knowledge baseKnowledge base APINotebookLM alternativePricingAPI quickstartSecurityCrawlerTerms of ServicePrivacy PolicyLog inCreate account

Open sign-up · Built for support knowledge