Privacy Policy
What we collect, what we do with it, and the choices you have. Plain-English version, roughly a five-minute read.
- Effective:
- 2026-08-05
- Last updated:
- 2026-08-05
1. Who we are
Drop Skincare LLC (“Drop Skincare,” “Drop,” “we,” “us,” “our”) is a skincare guidance app that helps you understand the products you already own, build a routine, and decide whether to add more. We cite the studies behind every ingredient flag we surface.
This Privacy Policy explains what data we collect, what we do with it, and the choices you have. It applies to:
- The Drop Skincare mobile app (iOS and Android).
- The website at drop-skincare.com, including public sharing pages and the logged-out compatibility checker.
Contact us:
- Privacy questions: privacy@drop-skincare.com.
- General support: support@drop-skincare.com.
- Mailing address: Drop Skincare LLC, c/o Registered Agents Inc, 8735 Dunwoody Place, Ste R, Atlanta, GA 30350.
We are based in Georgia, United States (single-member LLC). We process data globally where our subprocessors operate (see Section 6).
2. What we collect
We collect what we need for the app to work, and nothing more.
2.1 Required for app function
- Anonymous account first — you can use Drop before giving us any contact information. Onboarding runs on an anonymous account (a random user ID with no email or phone attached), and everything below — your shelf, skin profile, pregnancy or breastfeeding status — is stored under that anonymous ID until you choose to save your account. Saving links the same ID to a contact identifier; nothing is copied or re-shared. Anonymous data gets the same protection and retention as everything else in this policy.
- Account identifier — an email address or a phone number, whichever sign-in method you choose when you save your account. Email sign-in uses a one-time code or sign-in link. Phone sign-in (a one-time SMS code) is offered where SMS delivery is available; when you choose it, your number is stored by our auth subprocessor (Supabase) and delivered to its SMS partner solely for the one-time-code exchange — not used for marketing, not shared elsewhere. If we add Apple or Google sign-in later, your Apple or Google ID would serve the same role and nothing else in this policy changes.
- Handle — a public-facing username you pick at signup.
- Skin profile— skin type, top concerns, sensitivities, age range (banded — we don’t collect exact date of birth), and pregnancy or breastfeeding status. The pregnancy and age fields are used only to exclude ingredients that aren’t appropriate for those contexts — not for advertising or recommendations.
- Inventory — products you tell us you own or have used.
- Routines — the morning and evening routines we build with you and any edits you make.
- Empties and wishlist— products you’ve finished and products you’d like to try.
- Effectiveness logs — when you started using a product and any check-in entries.
- Compatibility check history — recent results of the compatibility checker (saved for rate-limiting and so you can revisit recent checks).
- Affiliate click events — when you tap a recommendation link to a retailer. We log that the click happened so we can track revenue. We do not share your identity with the retailer beyond a pseudonymous link.
2.2 Optional, only with your explicit consent
- Photos for skin tracking. By default, photos stay on your device.Cloud sync is an opt-in toggle; if you don’t enable it, we never receive your photos.
- Geolocation if you enable Climate Mode (a future feature, not in V1). Coarse precision only, never your exact location.
- Push notification token, if you say yes to the iOS or Android notification prompt.
- Optional gender identity, defaulted to “prefer not to say.” If you choose to share this, it’s used only for aggregate analytics; it is never used to filter recommendations or personalize the routine engine.
2.3 What we never collect
- Your exact date of birth (we use age ranges).
- Your real name (handles only).
- Your home or shipping address.
- Government IDs.
- Browsing history outside our app.
- Voice or biometric data.
- Health data from Apple Health or Google Fit (not in V1; if added later, with explicit consent).
- Data from third-party advertising or tracking SDKs (we don’t install any).
2.4 Inventory-input photos (shelf and single-product photos)
Different from skin-tracking photos. When you photograph your shelf or a single product to add it to your inventory, the photo is transient:
- The photo bytes are sent to our LLM provider (Anthropic) for the duration of the API call to extract product names. EXIF metadata is stripped before the call.
- Anthropic does not retain the photo after the call and does not train its models on API inputs (per their published API policy).
- We retain only the structured output (the product names recognized).
- We do not store the photo bytes on our servers.
This is surfaced to you at the moment you take your first shelf photo, not buried in settings.
3. How we use what we collect
- Account auth and core function — to give you a working app: routines, inventory, empties, wishlist, compatibility checks, effectiveness check-ins.
- Hard safety rules— pregnancy, breastfeeding, and age data filter the ingredients we recommend so you don’t see something contraindicated for your situation.
- Affiliate revenue — when you tap a recommendation link, we log the click so we know which recommendations earn revenue. We earn a commission when you buy through these links, at no extra cost to you. We never accept payment to recommend products.
- Product analytics(anonymized event counts, feature usage) — to understand which features people actually use, so we can improve the ones that matter and remove the ones that don’t. Processed by PostHog Cloud (EU region); the Data Processing Agreement is listed in section 6 and is signed before launch. Opt-out is available under Settings → Privacy.
- Customer support — to answer your emails about your account.
We do not use your data for:
- Advertising of any kind.
- Targeted product recommendations based on demographic data.
- Selling, leasing, or sharing your data with anyone for their own marketing.
- Training AI models on your photos or content (without separate, explicit consent).
4. Lawful basis for processing (for EU/EEA users)
If you’re in the European Union, the European Economic Area, or the United Kingdom, GDPR and the UK GDPR apply. We rely on the following lawful bases:
- Contract (Art. 6(1)(b)) — processing necessary to provide the app: auth, inventory, routines, compatibility checks, etc.
- Consent (Art. 6(1)(a)) — photo cloud sync, push notifications, geolocation, marketing emails (if any).
- Legitimate interest (Art. 6(1)(f)) — pseudonymous product analytics (you can opt out), fraud prevention, and rate limiting on the public compatibility checker.
Special category data:skin condition information and pregnancy status may qualify as “health data” under GDPR Art. 9. Every one of these fields is optional — you can skip them and keep using the app, with fewer safety checks and less personalisation. Before any of them is sent to our AI subprocessor for routine generation, we ask separately: that consent is off by default, has to be switched on deliberately, is enforced on our servers rather than in the app, and can be withdrawn at any time in Settings → Privacy. Withdrawing it stops the transmission; it does not delete what you have already saved, which you can export or erase separately.
5. Your rights
Whatever country you’re in, you have these rights. EU/EEA, UK, and California users have formal legal rights backing them; we extend the same controls to everyone.
| Right | How to use it |
|---|---|
| Know what we have about you | Settings → Privacy → “Export my data” |
| Correct it | All profile fields are editable in the app |
| Delete it | Settings → Account → “Delete account” — 30-day grace period, then full purge |
| Take it elsewhere | Same export flow as “Know” — JSON, machine-readable |
| Object to analytics | Settings → Privacy → “Pause analytics” toggle |
| Withdraw consent | Per-feature toggles for each consent-based feature |
| Lodge a complaint | Email privacy@drop-skincare.com or contact your local data-protection authority |
California (CCPA/CPRA):you have the rights above plus the right to opt out of “sale” or “sharing” of personal information. We don’t sell or share your data for cross-context behavioral advertising — the opt-out is honored by default. A “Do Not Sell or Share My Personal Information” link appears in the website footer.
We respond to verified rights requests within 30 days (typically much faster).
6. Who we share data with
We use a small set of subprocessors to run the service. We do not sell, lease, or share your data with anyone for their own marketing purposes.
| Subprocessor | Purpose | Region | Data-processing agreement |
|---|---|---|---|
| Supabase | Database, auth, storage | US | Pending — signed before launch |
| Vercel | Web hosting (drop-skincare.com) | US | Pending — signed before launch |
| Cloudflare R2 | Encrypted database backups | US | Pending — signed before launch |
| Anthropic | LLM (routine generation, ingredient Q&A, vision OCR for shelf photos) | US | Pending — signed before launch |
| PostHog Cloud | Pseudonymous product analytics | EU | Pending — signed before launch |
| Resend | Transactional email (signup, password reset, deletion confirmations) | US | Pending — signed before launch |
| Sentry | Crash and error reporting | US | Pending — signed before launch |
| Apple App Store / Google Play | Subscription billing for Patron tier (V1.5+) | US | Standard platform terms |
| Affiliate networks | Conversion tracking (e.g., Amazon Associates, Skimlinks) | US | Pseudonymous IDs only — no PII shared |
International data transfers:Drop is offered in the United States only, so we don’t knowingly hold data about people in the EU, EEA or UK, and Standard Contractual Clauses aren’t our transfer mechanism. Where a subprocessor’s own terms include them we accept them, and our analytics processor is EU-resident regardless — both are prudence rather than reliance.
7. How long we keep data
- Active accounts — while your account is active and for as long as needed to provide the service.
- Deleted accounts — soft-deleted immediately when you click delete; fully purged from primary databases within 30 days. Encrypted backups follow a grandfather-father-son cycle — daily dumps are pruned after 35 days, and a small number of longer-horizon monthly copies are kept for up to 12 months before being overwritten. Your data is gone from anything we query the day the purge runs; the backup tail is retention we cannot selectively edit without corrupting the restore chain, and it is overwritten on the cycle above.
- Anonymous compatibility checker history — 30 days, then deleted.
- Event analytics — 6 months, then deleted or aggregated to anonymous counts.
- Affiliate click history — retained as anonymized aggregates for revenue accounting.
8. Children’s privacy
Drop is for users 13 and older; we do not knowingly collect data from anyone under 13, and the app is not directed at children. The app is rated 12+ in the App Store. Saving an account requires confirming you are 13 or older (stated on the sign-in screen, and required by our Terms of Service §2). Onboarding may ask for an age range; selecting the “Under 18” band enables age-appropriate ingredient filtering (no retinoids, etc.) without affecting your ability to use the app.
If you believe a child under 13 is using Drop, email privacy@drop-skincare.com and we will delete the account.
9. Security
- Encryption in transit — TLS 1.3 for all network traffic.
- Encryption at rest — handled by our infrastructure provider (Supabase) for the database and object storage.
- Auth — one-time codes (or a sign-in link) via email or SMS, through Supabase Auth. We do not store passwords ourselves.
- Principle of least privilege — only the systems that need access to a piece of data have it. Row-level security in the database scopes per-user data to its owner.
- No credentials in the client app — secrets stay on the server.
- Subprocessor incidents— if any subprocessor reports a breach affecting your data, we’ll notify you per the timeline GDPR requires (without undue delay, and at most 72 hours for material breaches).
10. Cookies and tracking on the website
We don’t use advertising or behavioral tracking cookies, and the website itself loads no analytics or tracking scripts — no Google Analytics, no Facebook Pixel, no PostHog script, no ad-tech of any kind. Pages like the compatibility checker and public sharing links render and run without client-side tracking.
- Session cookies — standard strictly-necessary cookies that keep you logged in if you have an account. Because these are the only cookies we set and none are used for tracking, no cookie-consent banner is required.
- Product analytics live in the app, not the website — the pseudonymous, aggregate feature-usage analytics described in section 3 are collected server-side from the mobile app (processed by PostHog Cloud, EU region; DPA status is listed in section 6), with an opt-out under Settings → Privacy. Nothing analytic runs in your browser when you visit this site.
11. Changes to this policy
If we change this policy in any material way, we’ll:
- Update the “Last updated” date at the top.
- Notify active users by email (via Resend) at least 14 days before the change takes effect.
- Post a notice in the app’s “What’s new” surface.
For minor changes (typo fixes, link updates), we’ll just update the page.
12. Contact
- Privacy questions and rights requests: privacy@drop-skincare.com.
- Postal mail: Drop Skincare LLC, c/o Registered Agents Inc, 8735 Dunwoody Place, Ste R, Atlanta, GA 30350.
- EU/UK representative: not designated, because Drop is offered in the United States only. App Store and Play availability are restricted to US territories, and GDPR Art. 3(2) turns on whether a service targets the Union rather than whether it can be reached from it — Drop is English-only, USD-only, carries US retailers and markets on US channels. If we ever widen availability, we appoint a representative first.
- Your controls don’t depend on where you live: export, deletion, correction and withdrawal of consent are available to everyone, worldwide. We offer them because it’s the right way to handle someone’s data — not because a particular law compels us to.
We respond within 48 hours for general questions and within 45 days for formal rights requests.
Privacy questions: privacy@drop-skincare.com.
Last updated: 2026-08-05