Last updated: 25 August 2026
This policy explains how DropLive handles personal data when you browse the site, create an account, or start a demo. DropLive is responsible for this processing. Questions about this policy: [email protected].
We collect the data needed to operate and protect the service:
We use this data to:
Where data-protection law requires a legal basis, we process data to provide the service you request, to meet legal obligations, and for our legitimate interests in operating and securing DropLive. We ask for consent where the law requires it.
A demo machine is temporary and is removed when the demo ends. This does not remove all records about the demo. We may keep session and security records to operate DropLive and to monitor for abuse.
DropLive keeps a behavioural record of each demo, readable only by the account that ran it. A record identifies the software version and reports its recorded network activity. It does not show the private demo address, request URLs or methods, or a bring-your-own credential. Do not enter personal, confidential, or production data into a demo unless you accept the risk of using it with the software you chose to run.
Your run records feed a shared count. When a demo you run reaches a hostname, that contact is added to a total of how many demos across all accounts have reached the same hostname, and other people can see that total. We share the number, never your run: it does not name you, your account, your demo, or when you ran it.
Someone else only ever sees that number next to a hostname their own demo already reached, so your run cannot reveal a hostname to them that they had not already reached themselves. On public project pages we show how many distinct hostnames demos of a version have reached, and a hostname reached by only one demo is excluded from that entirely.
Some demos can offer a bring-your-own credential option. If you choose it, the credential is used only for that launch. We do not intentionally store it in our database, session record, logs, or run history. Do not provide a credential unless you have the right to use it.
We use service providers to run DropLive. They process data only as needed to provide their service to us. These include WorkOS for account sign-in and identity, Cloudflare for delivery and infrastructure services, PostHog for the product analytics described below, and hosting and storage providers for the demo service and its records. We can also disclose data when required by law or when necessary to protect DropLive, its users, or the public.
We keep each category of data only for as long as needed for the purpose described in this policy. A browser session ends when you sign out or it expires. A demo machine is removed when its session ends. Account, session, and security records can be kept longer where needed for fraud and abuse prevention, an investigation, a dispute, legal compliance, or to protect the service. We delete or anonymise data when we no longer need it.
If you ask us to delete your account, we review the request manually and complete deletion within 30 days. Your account backups are retained for 14 days. Copies in our system-wide backups can remain for up to 60 days. We can keep limited records for longer when we must do so to meet a legal obligation, prevent fraud or abuse, resolve a dispute, or protect the service.
We use cookies and similar browser storage that are needed for sign-in, session security, and site operation. You can block cookies in your browser, but you may not be able to sign in or start a demo.
We also use analytics storage, described in the next section. We ask before using it where the law requires us to, and we do not use advertising cookies or share anything with advertisers.
We use PostHog to understand how people move through DropLive: which pages they read, what they search the catalogue for, which demos they launch, and where a launch fails. We use it to decide what to fix and which projects to add. We do not use it for advertising, we do not sell it, and we do not track you across other websites.
Analytics is not loaded from a third-party address. The code runs from droplive.io and the measurements are sent to droplive.io, which then passes them to PostHog. This means the rest of the internet cannot watch you use DropLive.
If you are in the UK or the European Economic Area, we ask for your permission first and nothing is measured until you answer. Elsewhere, analytics runs when you open the site.
Declining does not switch measurement off, it switches identification off. Nothing is stored on your device, and instead of recognising your browser we count the visit against a code our own server works out from a secret that is thrown away at the end of each day. It cannot be turned back into you, it cannot be matched to anything you did yesterday, and it cannot follow you to another device or another site. What it leaves us is a count of how many people read a page, and nothing about who they were.
You can change your answer at any time by clearing site data for droplive.io in your browser, and we will ask again.
When you sign in, we connect your measurements to your account using an internal reference for your account rather than your email address. Session recording is switched off: we do not record video of your screen, and we do not capture the sign-in details a demo generates for you. If you delete your account, we delete your analytics record along with it.
Depending on where you live, you can ask to access, correct, delete, or restrict the use of your personal data, and you can object to some processing. You can also complain to your local data-protection authority. Signed-in users can make a request from Account settings, or email [email protected].
We can update this policy when DropLive or the law changes. We will post the updated policy here and change the date above.