Privacy Policy

Last updated: March 28, 2026

1. Introduction

Driplane (“we”, “us”, “our”) operates driplane.app. This Privacy Policy explains how we collect, use, and protect your information when you use our Service.

2. Information We Collect

Account Information

When you sign in, we receive your profile information including your name and email address from your authentication provider. This is used solely to create and manage your account.

API Keys and Credentials

You provide API keys to enable the Service to send emails on your behalf. Your credentials are encrypted using industry-standard encryption (AES-256-GCM) before storage. We never share your credentials with third parties.

Contact Data

Contact information (email addresses, names, and tags) is synced from your email provider. This data is stored to manage sequence enrollments and is used exclusively for delivering your email sequences.

Sequence and Email Content

The email sequences, step configurations, and email content you create are stored to provide the Service. This content remains yours and is not used for any other purpose.

Usage Data

We collect basic usage data such as email delivery status (sent, opened, clicked, bounced) to provide analytics and sequence functionality. We do not use third-party analytics trackers.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Authenticate your account
  • Send emails on your behalf through your email provider
  • Process sequence enrollments and automations
  • Provide analytics on email performance
  • Communicate with you about the Service (e.g., updates, security alerts)

We do not sell, rent, or share your personal information with third parties for marketing purposes.

4. Data Storage and Security

We implement industry-standard security measures to protect your data, including:

  • Encryption at rest and in transit (TLS/HTTPS)
  • Application-level encryption for sensitive credentials (AES-256-GCM)
  • Row-level security policies ensuring you can only access your own data
  • Webhook signature verification to prevent unauthorized access
  • Rate limiting and input validation on all endpoints
  • Regular security audits and vulnerability scanning

5. Third-Party Services

The Service integrates with third-party services for authentication and email delivery. Your use of these services is governed by their respective privacy policies. We only share the minimum data necessary for these integrations to function.

6. Data Retention

We retain your data for as long as your account is active. You may delete individual sequences, contacts, or your entire account at any time. Upon account deletion, all associated data is permanently removed within 30 days.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Export your data in a portable format (CSV)
  • Object to or restrict processing of your data

To exercise any of these rights, contact us at [email protected].

8. Cookies

We use essential cookies only for authentication and session management. We do not use advertising, tracking, or third-party analytics cookies.

9. International Data Transfers

Your data may be processed in the European Union. We ensure appropriate safeguards are in place for any international data transfers in compliance with applicable data protection laws.

10. Children's Privacy

The Service is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification. Continued use of the Service after changes constitutes acceptance.

12. Contact

If you have questions about this Privacy Policy or your data, contact us at [email protected].