HTMLDrop.
LOCAL RELEASE · DATA & PRIVACY

Know where your data lives.

This page describes the implemented development environment. It is not a production privacy policy or a claim of GDPR compliance.

Project data

All projects in this release are public guest projects. Source, metadata, settings, Yjs state, and immutable versions are persisted in .data/htmldrop/projects.json, or MySQL when configured. Browser caches live in OPFS or local storage. Project export is available from the workspace information dialog and the export API.

Accounts

Signing in with Google stores your Google account ID, name, email address, and profile picture URL, plus sign-in timestamps. Sessions use a random token in an HttpOnly cookie; only a hash of the token is stored, and signing out deletes it. Drops you create while signed in are owned by you: public to view, editable only by you, and deletable by you. Deleting a drop removes it and its versions from the service. Account export and account deletion are not implemented yet.

Billing and private drops

Pro payments are handled by Stripe Checkout; HTMLDrop stores your Stripe customer ID and subscription status, never card details. Private drops are visible only to you and your editors: they are excluded from the sitemap and search engines, and their previews use short-lived sessions instead of public runtime URLs. Private drops stay private if your subscription ends.

Presence and operational data

Presence, cursor selections, and rate-limit counters are held in memory. Preview session snapshots expire after 30 minutes. The development service has no analytics, tracking cookies, authentication, billing, or email collection. Infrastructure or reverse-proxy logging must be configured separately before deployment. The application fonts are self-hosted; user source can load external assets, and the Aurora example imports Google Fonts.

AI providers

When you send a request from the assistant sidebar, the drop’s HTML, CSS, JavaScript, JavaScript mode, HTTP headers, and your recent requests in that session are sent to the selected provider (Anthropic for Claude, OpenAI for Codex) under your own API key and that provider’s terms. Codex requests ask OpenAI not to store the response. Your key stays in browser local storage and passes through the backend without being stored or logged. Copying source for another assistant, or connecting an MCP client, may likewise disclose project data to that provider.

Local deletion and retention

The server retains projects until the developer removes its local data. Guest projects have no deletion authority, so the public guest API intentionally cannot delete shared history. With the server stopped, reset the file store by removing .data/htmldrop; for MySQL, remove the development volume. Clear browser site data to remove OPFS and local storage. Account export/deletion, production retention schedules, processor notices, and financial-record retention remain launch work.

Made to be explored. Open the workspace and try it for yourself.