DropLine attaches photos to the place they happened. That is sensitive context: where and when a photo was taken often says more than the photo itself. This policy explains what data is processed and why, and what is never done. For users resident in Türkiye, the KVKK notice applies in addition.
The principles that do not change
- No advertising, no profiling for advertising, no sale of personal data to third parties.
- Private is the default. A photo becomes public only when the user explicitly publishes it.
- Group content is end-to-end encrypted on the device. DropLine's servers cannot open these photos, and neither can this website.
- Photos are re-encoded before upload and EXIF metadata is stripped; no hidden location data the user did not choose remains in the file.
Data that is processed
- Account: display name, e-mail address or phone number, optional public profile handle.
- Content: uploaded photos and videos, captions, likes, and comments.
- Location: the coordinates of a drop, taken from the photo's metadata, a point selected on the map, or device location where permitted.
- Technical: IP address, device type, app version, session and error logs, and the public part of device encryption keys.
- Subscription: Premium state and the store purchase record. Card details never reach DropLine.
Legal bases for processing
KVKK Article 5 applies in Türkiye and GDPR Article 6 in the European Union. Most data is processed to perform the contract (KVKK 5(2)(c), GDPR 6(1)(b)): there is no map without an account and no drop without a location. Security logs and abuse detection rest on legitimate interests (KVKK 5(2)(f), GDPR 6(1)(f)). Push tokens are processed on explicit consent only, withdrawable from device settings. Publicly published content is data made public by the data subject themselves (KVKK 5(2)(d)).
International transfers
All infrastructure used is located outside Türkiye. For Türkiye, transfers rely on the standard contract published by the Personal Data Protection Board (KVKK 9(2)(c)), notified to the Board within five business days of signature. For the European Union, transfers rely on the European Commission's Standard Contractual Clauses and, where necessary, supplementary measures. For end-to-end encrypted group content, the provider abroad sees only encrypted bytes.
Retention and deletion
- Account and content: for the life of the account; at most 30 days after a deletion request.
- Backups: up to 90 days, for disaster recovery only.
- Security logs: 12 months.
- Reports and moderation records: 2 years.
- Invoice and subscription records: 10 years, as required by financial legislation.
Your rights
You have rights of access, rectification, erasure, restriction, objection, and data portability. If you are resident in Türkiye, your rights under KVKK Article 11 and the application procedure are set out in detail in the KVKK notice; if you are resident in the European Union, GDPR Articles 15-22 apply. Requests may be sent to the privacy address below and are concluded within 30 days at the latest.
You can delete your account directly from within the app. You also retain the right to lodge a complaint with the Personal Data Protection Board in Türkiye, or with the supervisory authority of your country of residence in the European Union.
Children
The service is not directed at persons under 13. If data belonging to someone under that age is found to have been processed, the account and data are deleted without delay.
Changes to this policy
When this policy changes, the last-updated date on this page is revised. Material changes that widen the purpose or scope of processing are additionally announced inside the app before they take effect.
Recipients of personal data
| Recipient | Country | Purpose | Data transferred |
|---|---|---|---|
| Railway Corp. | United States | Hosting of the application server and the PostgreSQL database | Account records, drop metadata, location coordinates, server logs |
| Cloudflare, Inc. (R2) | United States | Object storage of photo and video files | Image and video files (end-to-end encrypted for group content), thumbnails |
| Cloudflare, Inc. (DNS/CDN/WAF) | United States | Domain resolution, content delivery, and attack filtering | IP address, request metadata |
| Resend, Inc. | United States | Delivery of the one-time sign-in verification code by e-mail | E-mail address, verification code |
| Google LLC (Cloud Vision SafeSearch) | United States | Automated screening of publicly uploaded images for illegal and harmful content | Thumbnails of public drops only. End-to-end encrypted group content is never sent. |
| Google LLC (Sign-In, Firebase Cloud Messaging) | United States | Google sign-in and mobile push notification delivery | Identity token (e-mail, name), device push token |
| Apple Inc. / Google LLC (uygulama mağazaları) | United States | App distribution and collection of Premium subscriptions | Purchase record and subscription state. Payment card details never reach DropLine. |
| CARTO / OpenStreetMap Foundation | United States / United Kingdom | Serving map tiles to the browser on this website | IP address and the coordinates of the viewed map frame. No drop content is sent. |
Data controller
This notice has not entered into force because the controller's name and address for service are not yet configured. Until they are, the page stays closed to search engines.