# Privacy Policy & Data Governance

Effective Date

November 11, 2025

Version

Protocol v2.1 (Stable)

## Table of Contents

- 01. Intro & Controller
- 02. Legal Basis
- 03. Data Categories
- 04. Third Parties
- 05. AI Training
- 06. International Transfers
- 07. Data Retention
- 08. Children's Privacy
- 09. Marketing
- 10. Data Breach
- 11. User Rights
- 12. Security
- 13. Cookies
- 14. Updates
- 15. Billing
- 16. Contact

This document outlines our commitment to data protection and privacy compliance.

## Section 01

### Introduction & Data Controller

This Privacy Policy ("Policy") governs the collection, processing, use, disclosure, and protection of personal data in connection with the Dropstone AI Development Platform and all related services (collectively, the "Service" or "Platform"). This Policy is issued by Blankline ("we," "us," "our," "Data Controller," or "Blankline").

#### Data Controller Information

**Entity**: Blankline  
**Location**: Chennai, Tamil Nadu, India  
**Data Protection Lead**: [privacy@blankline.org](mailto:privacy@blankline.org)  
**Legal Notices**: [legal@blankline.org](mailto:legal@blankline.org)

**Controller vs. Processor**: We act as a Data Controller for account, billing, and usage data. We act as a Data Processor for user-generated content and code transmitted to AI models.

By using the Service, you acknowledge and agree to the practices described in this Policy.

## Section 02

### Legal Basis & Compliance

We process personal data in strict compliance with international privacy frameworks, including India's DPDPA 2023, GDPR (EU), CCPA/CPRA (California), and UK GDPR.

#### Processing Legal Bases

- **Account & Billing**: Contractual Necessity  
- **Service Optimization**: Legitimate Interest  
- **Security & Fraud**: Legitimate Interest  
- **Marketing**: Consent (Opt-in)  
- **Legal Compliance**: Legal Obligation

## Section 03

### Data Categories & Technical Telemetry

#### 3.1 Directly Provided Data

- **Identity**: Name, email, SSH public keys (for git integration), and API tokens.  
- **Workspace Context**: Project file trees, dependency graphs, and environment configurations.

#### 3.2 Technical Telemetry & AI Context

- **Local-First Architecture**: Dropstone operates primarily on the client device. Indexing, AST parsing, and vector embedding generation occur locally.  
- **Ephemeral Context Windows**: When you trigger an AI agent, only the specific code snippets relevant to the prompt (the "Context Window") are transmitted to inference endpoints. We do not upload entire repositories.  
- **Operational Metrics**: Latency, token usage rates, and GPU/CPU thread utilization for performance debugging.

## Section 04

### Third-Party Processors

We engage verified third-party providers for specific service functions. All processors are bound by strict data protection agreements.

- **Payment**: Stripe Inc. (USA) - Payment processing and subscription management.
- **Analytics**: PostHog, Google Analytics - Usage behavior and product optimization.
- **AI Models**: OpenAI, Anthropic, Deepseek - Model inference and processing.
- **Monitoring**: Sentry - Error tracking and performance monitoring.

## Section 05

### AI Training & Model Hygiene

#### Zero-Retention Commitment

We distinguish between "Storage" and "Inference." Your code sent for inference is ephemeral and never used for downstream training of foundation models.

#### 5.1 Zero-Retention Inference Architecture

- **Inference (Processing)**: Code sent to our model partners (OpenAI, Anthropic) follows a strict stateless protocol. Data is held in volatile memory only for the duration of the generation request and is cryptographically wiped immediately after.  
- **No Downstream Training**: We have executed "Do Not Train" agreements with all LLM providers. Your code is never used to train OpenAI's GPT or Anthropic's Claude models.

#### 5.2 User-Owned Fine-Tuning

If you choose to fine-tune a model on your proprietary codebase (an Enterprise feature), the resulting model weights are owned exclusively by you and are siloed from other users.

## Section 06

### International Data Transfers

Your data may be processed globally. We ensure protection through:

- Standard Contractual Clauses (SCCs) for EU transfers.  
- Compliance with DPDPA (India) frameworks.  
- End-to-end encryption for cross-border data transmission.

## Section 07

### Data Retention

- **Account Data**: Active + 90 Days  
- **Billing Records**: 7 Years (Tax Law)  
- **Analytics**: 36 Months (Anonymized)  
- **User Content**: Until Deletion

## Section 08

### Children's Privacy

Dropstone is not intended for children under 16 (or 13 where applicable). We do not knowingly collect data from minors. If discovered, such data is immediately deleted.

## Section 09

### Marketing Communications

We send promotional content only with explicit opt-in consent. Transactional messages (billing, security) are mandatory. You may opt-out of marketing at any time via unsubscribe links.

## Section 10

### Data Breach Response

In the event of a breach, we notify affected users and authorities within 72 hours, as required by GDPR and other laws. We maintain 24/7 security monitoring to detect and contain incidents immediately.

## Section 11

### User Privacy Rights

You have rights to access, correct, delete, and port your data. Contact [privacy@blankline.org](mailto:privacy@blankline.org) to exercise these rights.

- **Access & Portability**: Request a copy of your data in a structured format.  
- **Correction & Deletion**: Fix inaccuracies or request the "Right to be Forgotten".  
- **Objection**: Object to specific processing activities or withdraw consent.  
- **Jurisdiction Specific**: Specific rights for GDPR (EU) and CCPA/CPRA (California) residents.

## Section 12

### Enterprise Security & Data Isolation

#### 12.1 Infrastructure Security

- **Encryption Standards**: Data at rest is encrypted using AES-256 (GCM mode). Data in transit is secured via TLS 1.3 with forced HSTS.  
- **Key Management**: Encryption keys are rotated periodically via a hardware security module (HSM) equivalent.

#### 12.2 Enterprise Data Isolation

For Enterprise Tier customers, we offer logical tenant isolation. Your vector indexes and usage logs are tagged with a unique Tenant ID, ensuring that your data is logically separated from other customers at the database level.

#### 12.3 Vulnerability Management

We conduct regular static code analysis (SAST) and dependency scanning to identify vulnerabilities. Security patches are deployed within 72 hours of critical disclosure.

## Section 13

### Cookies

We use essential cookies for functionality and security. Analytics and marketing cookies are optional and require your consent. You can manage preferences via your browser or our settings.

## Section 14

### Policy Updates

We may update this policy. Material changes will be notified 30 days in advance via email. Continued use constitutes acceptance.

## Section 15

### Financial Information & Refunds

We do not store full credit card numbers; these are handled directly by our PCI-DSS compliant provider, Stripe. For information regarding subscription cancellations and our No-Refund Policy, please refer to our [Terms of Service](/content/terms/index.html).

## Section 16

### Contact & Grievance Redressal

In accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, the contact details of the Grievance Officer are provided below:

- **Grievance Officer**: Legal Compliance Lead  
- **Entity**: Blankline  
- **Location**: Chennai, Tamil Nadu, India  
- **Email**: [legal@blankline.org](mailto:legal@blankline.org)

For general privacy inquiries or to exercise your data rights (GDPR/CCPA/DPDPA), please contact: [privacy@blankline.org](mailto:privacy@blankline.org).

BY USING THE DROPSTONE SERVICE, YOU ACKNOWLEDGE AND AGREE TO THE DATA PRACTICES DESCRIBED IN THIS POLICY. THIS POLICY IS A BINDING COMMITMENT TO YOUR PRIVACY RIGHTS.
