Privacy Policy
This policy describes how Dropdesk handles information when you pair a phone with the Chrome side panel and transfer files.
Summary
- Dropdesk does not create user accounts.
- Files are encrypted on your device before upload. We store ciphertext in cloud storage.
- Pairing uses a short-lived session (QR code or PIN). Anyone who can scan the QR or enter the PIN for an active session can access that session’s files.
- Uploads expire automatically (default 5 minutes, or up to 8 hours if you tap Keep).
- Filenames, file types, and sizes are stored so the product can show your list — these fields are not encrypted.
Information we process
On your devices
- Pairing session ID and pairing token (stored locally)
- Decrypted file previews while you use the app/extension
- Camera / photo library access only when you choose to scan a QR or pick/take photos (mobile)
On our servers (Supabase)
- Session metadata (pairing token, presence timestamps, expiry)
- Transfer metadata: filename, MIME type, byte size, storage path, expiry
- Encrypted file objects in storage (ciphertext)
We use a cloud backend (Supabase) for infrastructure. Network requests use HTTPS.
Permissions
Mobile
- Camera — scan the desktop QR and optionally take photos
- Photos / media — choose images to send
Chrome extension
- Storage — remember pairing for the session
- Downloads — save files when you ask
- Scripting — inject a local helper so dragged files can populate webpage file inputs
- Side panel — keep Dropdesk open while you work
- Host access (http/https) — required so the side panel can deliver a real file into page file fields during drag-and-drop
The extension includes a small content script that loads on http(s) pages and asks the background worker to install the page drop helper. That helper stays idle until you drag a file from the Dropdesk side panel. Dropdesk does not scrape page content, read browsing history, or inject ads.
How encryption works
File bytes are encrypted on the phone with a key derived from the active pairing session before upload. The Chrome extension decrypts them locally after download using the same session pairing material.
This protects files at rest on the server from casual inspection of storage objects. It is not a guarantee against someone who obtains your live pairing QR/PIN, or against disclosure of filenames and sizes stored as metadata.
Retention
- Sessions expire (typically within 24 hours).
- Transfers auto-delete after about 5 minutes unless Keep extends retention (about 8 hours).
- Expired transfer rows and storage objects are cleaned up on a schedule, and also when a paired client is open.
- You can delete a transfer from the phone or extension; we attempt to remove the storage object as well.
Sharing
We do not sell your personal information. Service providers (e.g. Supabase) process data only to run Dropdesk infrastructure.
Children
Dropdesk is not directed at children under 13. Do not use it to transfer a child’s personal information.
Sensitive documents
If you transfer IDs or similar documents, treat pairing like sharing a temporary unlock code: use QR when possible, keep the side panel private, and let files expire or delete them after use.
Your choices
- Disconnect / start a new session to invalidate pairing on your side
- Delete individual transfers
- Uninstall the app or extension to remove local pairing data
Changes
We may update this policy. The “Last updated” date will change when we do.
Contact
Privacy and support: pristinefr@gmail.com