Privacy Policy
Effective 23 September 2026 · Last updated 23 September 2026
1. Who we are and what this covers
Dropwire is operated by Avigdor Leibzon, an independent sole trader registered in Israel, trading as Dropwire (the "Service Provider", "we", "us"). This policy explains what personal data we collect through the Dropwire website and application, why, who we share it with, how long we keep it, and what rights you have.
Because Dropwire is operated from Israel, the Protection of Privacy Law, 5741-1981, as amended by Amendment 13 which came into force on 14 August 2025, governs how we handle personal data. Where the EU General Data Protection Regulation also applies to you, we honour it in addition. Amendment 13 treats IP addresses, location data and other online identifiers as personal data, and this policy is written on that basis.
Dropwire is offered to business users. It is not directed at children, and we do not knowingly collect data from anyone under 18.
2. Two different roles, and why the distinction matters
For your own account data, we are the controller. We decide how your email address, login records and subscription status are handled, and this policy governs that.
For data about your audience, you are the controller and we are your processor. The people in your Telegram channels and WhatsApp groups are your contacts, not ours. We process data about them only to carry out your instructions, which in practice means delivering the posts you publish and counting the clicks they generate.
It follows that you are responsible for having a lawful basis to message those people and for answering their privacy requests. If someone in your audience contacts us directly, we will normally refer them to you.
3. What we collect, why, and on what basis
Account and authentication
Your email address, a hashed password if you set one, and your sign-in identity if you use Google or Facebook. We never store your password itself. Basis: performance of our contract with you.
Session security
The IP address and browser user agent recorded when you sign in, used to detect and investigate unauthorised access. Basis: our legitimate interest in securing accounts. These are erased after 90 days.
Connected credentials
The affiliate keys, bot tokens, model provider keys and WhatsApp connection you supply. These are encrypted at rest with AES-256-GCM under a key that is specific to your workspace, and they are deliberately excluded from every data export. Basis: performance of our contract.
Operational records
Products, posting history, channel configuration, conversions and revenue figures. These are business records rather than personal data about your audience, but they are associated with your account. Basis: performance of our contract.
Click tracking
When someone follows a tracked link we record the click, a coarse location derived from the IP address, the user agent, and a rotating daily hash used to distinguish repeat visitors without identifying them. The IP address, user agent and that hash are all erased after 90 days. We do not build cross-site profiles and we do not sell this data. Basis: your legitimate interest as controller in attributing your own affiliate activity.
Audit records
Records of significant actions, including consent you gave before enabling WhatsApp, and of any access by us to your workspace for support. Some carry an IP address and session identifier for incident investigation; those elements are erased after 90 days while the record of the action itself is retained. Basis: legal obligation and our legitimate interest in accountability and dispute evidence.
Billing
We store your subscription status and the identifiers our payment provider gives us. We never receive or store your card details, which are handled entirely by our payment provider as Merchant of Record. Basis: performance of our contract and legal obligation for tax records.
Waitlist
If you join the waitlist we store your email address to notify you about launch. Basis: consent, which you may withdraw at any time by asking us to remove you.
4. Who we share it with
We do not sell personal data and we do not share it for advertising. We use the following service providers, each under contract and each limited to what its function requires:
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Hetzner | Hosting of the application and database | All application data | Germany (EU) |
| Cloudflare | DNS, CDN, web application firewall, and page-performance analytics on this marketing site | Request metadata, IP addresses, page timings | Global |
| Backblaze B2 | Encrypted off-site backups | Full database, encrypted before upload | United States |
| Payment provider | Merchant of Record, payments (named at checkout) | Billing details and card data, held by them | Named at checkout |
| Resend | Transactional and waitlist email | Email addresses, message content | United States |
| Sign-in with Google, and product scoring via Gemini | Sign-in identity; product text and images | United States | |
| Meta | Sign-in with Facebook | Sign-in identity | United States |
| Sentry | Error monitoring | Diagnostic data, with personal data stripped before sending | United States |
| ImageKit | Product image rendering and delivery | Product images, not personal data | Global |
| AliExpress | Affiliate product data and link generation | Your affiliate credentials, server side | Global |
| Telegram | Message delivery to your channels | Channel identifiers, post content | Global |
| WhatsApp and Meta, via a self-hosted Evolution gateway | Message delivery to your WhatsApp groups | Your connected number, post content | Self-hosted, EU |
| OpenAI | Caption and content generation, usually under your own API key | Product text and your brand voice prompt | United States |
| Anthropic | Caption and content generation, usually under your own API key | Product text and your brand voice prompt | United States |
We may also disclose data where required by law, to establish or defend legal claims, or in connection with a transfer of the business, in which case you will be told before your data becomes subject to a different policy.
5. International transfers
Dropwire is operated from Israel, so sending personal data out of Israel is governed by the Israeli Transfer of Data to Databases Abroad Regulations. The EU adequacy decision for Israel is often cited in this context. It runs the other way: it permits transfers from the EU into Israel, and it is not the basis on which we send data out.
The application and database are hosted in Germany. Several providers listed above are in the United States or operate globally, so personal data does leave Israel and does leave the European Economic Area.
We would rather be plain about where this stands than claim more than we hold. We have not yet executed separate data processing agreementswith those providers, and this policy does not assert safeguards we do not have in place. Putting them in place is an open item. If the position for a particular provider matters to you before you use Dropwire, write to us and we will tell you exactly what is and is not in place.
6. How long we keep it
- Account data: for as long as your account exists. After you delete it there is a 30 day grace period during which it can be restored, after which it is erased.
- Session and click identifiers (IP address, user agent, visitor hash): 90 days, then irreversibly removed.
- Audit records: retained for up to seven years for tax, accounting and proof-of-consent purposes, with the identifying user reference removed when you erase your account.
- Backups: encrypted backups are retained on a rolling basis and expire between 30 and 35 days. Data you delete persists in a backup until that backup expires.
- Connected credentials: deleted with your account.
7. Your rights, and how to use them
Under the Israeli Protection of Privacy Law you may inspect the personal data we hold about you (section 13), ask us to correct or delete data that is wrong, incomplete, unclear or out of date (section 14), and demand removal from a direct mail database (section 17F). Where the GDPR also applies to you, you additionally have the right to a portable copy, to restriction of processing, and to object to processing based on legitimate interests. Where processing rests on consent you may withdraw it at any time, without affecting what was lawful before.
You do not have to ask us for most of this. Signed-in users can download their own data and erase their own personal data from the "Your data" section of account settings. Owners can additionally export the whole workspace. For anything else, write to avigdor@dropwire.cc and we will respond within 30 days.
If you are unhappy with how we have handled your data you may complain to your local supervisory authority. In Israel that is the Privacy Protection Authority; in the EEA it is the data protection authority where you live or work. If we do not answer an inspection or correction request within 30 days, Israeli law also lets you take the matter straight to a Magistrate's Court, which is usually faster than waiting for the Authority.
8. Cookies and similar technologies
The application sets a session cookie so that you stay signed in. It is strictly necessary and cannot be switched off without signing you out. The waitlist form on this marketing site runs a Cloudflare Turnstile check to keep bots out, which is likewise necessary for the form to work at all.
This marketing site can load Cloudflare Web Analytics, which measures page timing. It is off until you turn it on. We ask once, in a banner, and keep your answer on your own device so that we can honour it and show that we did. Refusing takes one click and carries the same visual weight as accepting. You can change your mind at any time from the Cookie settings link in the footer, and we ask again after twelve months.
Cloudflare Web Analytics sets no cookie of its own and does not follow you between sites. Cloudflare already serves this page, so your IP address reaches them whether or not you switch it on. What switching it on adds is page timing measurement, not a new company seeing you.
We do not use advertising cookies and we do not do cross-site tracking. Tracked affiliate links count a click server side and set no cookie on the visitor's browser.
9. How we protect it
Measures include encryption in transit, encryption of connected credentials at rest under per-workspace keys, database-level isolation so one workspace cannot read another's rows, encrypted off-site backups, restricted and audited administrative access, two-factor authentication on administrative accounts, and monitoring configured to strip personal data before diagnostics leave our systems.
No system is perfectly secure. If a severe security incident occurs, we report it to the Israeli Privacy Protection Authority immediately on discovering it, based on what we know at that point, and complete the picture in a follow up report. We do not wait for our investigation to finish first, because Israeli law treats that delay as a breach of the duty in its own right. We notify affected individuals where the Authority directs us to. Where the GDPR applies to the data involved, we also notify the competent supervisory authority without undue delay, and you directly where that regulation requires it.
10. Changes
We may update this policy. Where a change is material we will give notice by email or in the product before it takes effect, and the date at the top of this page will change.
11. Contact
Privacy questions, requests and complaints: avigdor@dropwire.cc.