Cookie Policy & Tracking Technologies
Effective Date
November 11, 2025
Version
Protocol v2.1 (Stable)
This document outlines our use of cookies and tracking technologies.
Introduction & Data Controller
This Cookie Policy ("Policy") explains how Blankline ("we," "us," "our," or "Data Controller") uses cookies, web beacons, local storage, and similar tracking technologies when you access our website at www.dropstone.io, use our desktop application, or interact with the Dropstone AI Development Platform services (collectively, the "Service").
Data Controller Information
- Entity: Blankline
- Location: Chennai, Tamil Nadu, India
- Privacy Contact: privacy@blankline.org
- Legal Notices: legal@blankline.org
This Cookie Policy operates in conjunction with our Privacy Policy and Terms of Service and complies with applicable international privacy frameworks, including India's DPDPA 2023, GDPR, CCPA/CPRA, and UK GDPR.
Understanding Cookies
Cookies are small text files containing unique identifiers that are stored on your device when you visit a website or use an application. Cookies serve various functions, including enabling core website functionality, remembering user preferences, analyzing usage patterns, and facilitating personalized experiences.
Similar Technologies
- Web Beacons: Pixel tags monitoring user interactions.
- Local Storage: Persistent browser-based storage.
- Session Storage: Temporary session-based storage.
- IndexedDB: Advanced client-side database storage.
Distinction from AI Context
It is important to distinguish between "Cookies" (metadata about your session) and "AI Context" (code snippets you send for analysis).
- Cookies: Track who you are (e.g., "User ID 123").
- AI Context: Is the content you create.
This policy governs strictly the metadata (Cookies). For information on how we handle your code and AI Context, please refer to our Privacy Policy.
Cookie Classification
Strictly Necessary
Essential for website operation, security, and authentication. Cannot be disabled.
| Name | Purpose | Duration |
|---|---|---|
| dropstone_session | Authentication | Session |
| csrf_token | Security | Session |
| __stripe_mid | Fraud Detection | 1 Year |
| __stripe_sid | Session Mgmt | 30 Mins |
Functional
Enable enhanced functionality and personalization like language settings.
| Name | Purpose | Duration |
|---|---|---|
| theme_preference | UI Theme | 12 Months |
| workspace_config | Layout | 6 Months |
Performance & Analytics
Collect information about usage patterns to improve performance.
| Provider | Purpose | Duration |
|---|---|---|
| Google Analytics | Traffic Analysis | 2 Years |
| PostHog | Feature Usage | 12 Months |
Third-Party Processors
We work with carefully selected third-party service providers who may set cookies. All processors are bound by strict data protection agreements.
- Stripe (USA): Payment processing, fraud detection, and subscription management.
- Vercel (USA): Content delivery optimization, performance monitoring, and hosting.
- Google/GitHub: OAuth providers for single sign-on authentication.
Desktop Application & Local State
Local-First Architecture
Unlike our web platform, the Dropstone Desktop Application operates primarily on a "Local-First" architecture.
- Local File System: The application reads and writes directly to your local file system for project storage. This data is not considered a "Cookie" and is not transmitted to our servers unless you initiate a Cloud Sync or Inference request.
- Encrypted Tokens: Authentication tokens (JWTs) are stored in your operating system's secure keychain (e.g., Windows Credential Manager, macOS Keychain, Linux Secret Service), not in plain-text browser cookies.
- Electron Storage: We utilize Chromium's localStorage within the desktop container solely for UI state preservation (e.g., "Sidebar Open/Closed"). This data remains strictly on your device.
Consent Management
We implement a comprehensive consent management system compliant with GDPR Article 7. You have granular control over cookie categories.
- Options: Accept All, Necessary Only, or Custom Preferences.
- Withdrawal: Easy withdrawal of consent at any time via settings.
- Records: Detailed logs of consent timestamps and choices.
- Renewal: Consent automatically expires after 12 months.
Browser Controls
You can control cookies through your browser settings. Note that disabling necessary cookies may impact site functionality.
- Desktop: Chrome, Firefox, Safari, Edge settings.
- Mobile: iOS Safari, Android Chrome settings.
Automated Controls
Global Privacy Control (GPC)
We honor Global Privacy Control (GPC) signals. When detected, we automatically opt-out users from non-essential tracking and data sharing, compliant with CCPA/CPRA.
We also respect Do Not Track (DNT) signals by limiting non-essential tracking when detected.
International Transfers
Cookie data may be processed globally. We ensure protection through Standard Contractual Clauses (SCCs), DPDPA compliance, and end-to-end encryption for cross-border transmission.
Children's Privacy
We do not knowingly set cookies or collect data from children under 16 (or 13 where applicable). Any such data discovered is immediately deleted.
Policy Updates
We may update this policy. Material changes will be notified 30 days in advance via email and prominent website notices.
Enforcement & Complaints
If you have concerns about our cookie practices, contact our Data Protection Lead. We take all privacy concerns seriously.
- Contact: privacy@blankline.org
- Response Time: Acknowledged within 48 hours.
- Regulatory Authorities: You have the right to lodge complaints with local data protection authorities (DPB India, EU DPAs, ICO UK, etc.).
BY CONTINUING TO USE THE DROPSTONE SERVICE, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO THE COOKIE PRACTICES DESCRIBED IN THIS POLICY.