Privacy Policy
Last updated: August 23, 2026
At Rabbitdrop ("we", "our", or "us"), your privacy is important to us. This Privacy Policy explains what information we collect when you use rabbitdrop.com (the "Service"), how we use it, and what choices you have. By using the Service you agree to the practices described here.
1. Information We Collect
1.1 Information you provide
- Email address — collected only when you create a Verified account, purchase a paid plan, or contact us for support. Anonymous (Ghost) users are never asked for an e-mail.
- Files you upload — stored temporarily on our secure infrastructure for the sole purpose of delivery. We practice strict data minimisation: we do not open, read, or analyse the content of your files.
- File Processing (Local WASM) — We utilize WebAssembly (WASM) technology to process and chunk files locally in your browser before transmission. This structural analysis happens on your local device to enhance privacy.
1.2 Information collected automatically
- File metadata — name, size, and MIME type are automatically read to facilitate the transfer. This data is linked to your transfer and is purged simultaneously with the file.
- IP address — used transiently to enforce per-IP rate limits (e.g., the 2 GB daily limit for Ghost users) and detect abuse.
- Infrastructure Logs — upload/download timestamps, technical error logs, and performance metrics (such as upload duration). These are processed via Cloudflare to diagnose technical issues, measure service health, and optimize transfer speeds.
- Referral & campaign parameters — if you arrive from a link that carries campaign tags (
utm_source,utm_medium,utm_campaign) or an ad click identifier, we record those values together with the referring website's domain and the page you landed on. This is written once per browsing session as an aggregate counter; it is not tied to your identity, your files, or any advertising profile. - Usage events & a visit identifier — we count what happens on the site: which page was opened, which buttons were used, and whether an upload or download started, succeeded, or failed. So that the events of a single visit can be read together instead of as unrelated rows, each visit is given a random identifier generated in your browser. It is not derived from your device, your IP address, or anything about you; it renews after 30 minutes of inactivity; it is never shared with third parties and never used to build an advertising profile. If you are signed in, these events also carry your account identifier — never your e-mail address, and never anything about the contents of your files.
- Cloudflare Turnstile — we use Cloudflare Turnstile for bot protection on uploads. Turnstile may process certain browser signals on Cloudflare's behalf. See Cloudflare's Privacy Policy for details.
1.3 Cookies & local storage
We use browser local storage to keep you signed in when you have an account (session token only), and to hold the random visit identifier described in 1.2 together with a note that the referral information has already been counted for that visit. The visit identifier is a random value with no meaning outside our own statistics, and it is replaced with a new one after 30 minutes of inactivity. We also use session storage to remember that you have unlocked a password-protected transfer, so that you are not asked again on every page refresh; that value is cleared when you close the tab. Essential infrastructure cookies may be set by Cloudflare.
Advertising. We do not run advertising pixels or cross-site trackers, and we do not build advertising profiles. The usage measurement described in 1.2 is our own and stays on our own infrastructure.
2. How We Use Your Information
- To operate the Service (store, process, and deliver files within our retention lifecycle).
- To manage payments, subscriptions, and tax collection via Lemon Squeezy (Merchant of Record).
- To send transactional emails (verification, subscription receipts).
- To detect and prevent abuse or violations of our Terms of Service.
3. File Storage, Encryption & Hard-Delete Lifecycle
Files are stored on Cloudflare R2 and protected at every stage:
- In-transit encryption — all data is encrypted via TLS 1.2+ (HTTPS).
- At-rest encryption — Cloudflare R2 encrypts all stored objects using AES-256.
Every transfer follows a strict lifecycle before Hard Delete:
- Ghost/Verified Phase — files are deleted after 24 hours (Ghost) or 3 days (Verified).
- Flash Phase — files are active for 7 days.
- Subscription Phase — files stay active for up to 30 days (Hop) or 90 days (Burrow, Warren).
- Lazarus Window — on the plans that include it (Verified, Flash), files are not purged the moment the active phase ends: they stay in an inaccessible recovery state until the 14th day after upload. Ghost transfers have no recovery window and are purged as soon as they expire; subscription plans are purged at the end of their active phase. A paid recovery starts a new 7-day lifetime, after which the file is purged.
- Hard Delete — at the end of the lifecycle, the file is permanently and irreversibly deleted from our storage. No copy is retained.
This automatic mechanism is designed to be fully compatible with the GDPR right to erasure.
4. Third-Party Service Providers
We share data only with the following sub-processors necessary to provide the Service:
- Cloudflare, Inc. — infrastructure, R2 storage, and bot protection.
- Lemon Squeezy LLC — We process payments through secure, third-party PCI-DSS compliant payment providers. Upon merchant approval, Lemon Squeezy will act as our Merchant of Record for payment processing and tax management.. We do not store your credit card details; they are handled directly by Lemon Squeezy.
5. Your Rights
You have the right to access, rectify, or request erasure of your data. Uploaded files are automatically hard-deleted at the end of their lifecycle. For account-related inquiries, contact info@rabbitdrop.com.
6. Contact Us
Questions about this Privacy Policy? Contact us at:
info@rabbitdrop.com