Privacy

Last updated July 18, 2026

Dropday.ai is a public directory of AI-built projects. You can browse without an account, there are no ads, and the analytics we run is privacy-friendly and cookieless — it never tracks you across sites or builds a profile of you. This page explains the small amount of data we collect and why. See also our Terms of Service.

The short version

We use a random browser ID to support voting, submissions, feedback, views, and click-through counts. We also use limited anti-abuse signals to keep votes and submission queues fair. For URL submissions, we retain the submitter's IP address and a record of their confirmation that the material is public and they have the right to share it. If you sign in to follow projects, your account is handled by our sign-in provider and we keep only the profile details needed to power follows, notifications, and creator features.

What we collect

  • Anonymous browser ID. When you vote, submit a build, send feedback, open a listing, or click through to a project, we may set a cookie with a random ID. It lasts up to two years. We use it to remember your vote state, limit abuse, and count anonymous activity.
  • Anti-abuse data. For actions like votes, submissions, and feedback, we use basic request information to rate-limit spam and prevent repeat abuse. Votes may retain a keyed, one-way hash derived from an IP address for network-level deduplication. We don't use it to identify you or build a profile.
  • Submission confirmation. When you submit a URL, we store the URL, your IP address, the date and time, and the version of the Terms you accepted. We use this record to document your confirmation that the URL and its contents are public and that you have the right to share them, as well as to investigate abuse or legal complaints.
  • Directory activity. We store which listings were voted for, viewed, or clicked through to, along with submitted URLs and feedback messages. Links shared in Dropday's own social posts may include a campaign identifier so we can count how many unique browsers followed that particular post. Anonymous activity is keyed to the browser ID unless you choose to sign in.
  • Display preferences. Dark/light theme and card layout live in your browser's local storage. They never leave your device unless you clear them.
  • Account data, if you sign in. Sign-in is optional. Our authentication provider (Clerk) handles credentials and sessions, and sets its own cookies that are needed to keep you signed in. We keep a small local profile record such as your name, avatar, email, and connected social handles when available, so we can support following, notifications, and creator ownership features.
  • Watches and notifications. If you watch projects, we store those follows and the in-app notifications generated for your account.
  • Email preferences. If you opt into a Dropday digest, we store your chosen frequency and use your account email to send it through Resend. Every digest includes a one-click unsubscribe link.
  • Public creator and project information. We index public names, handles, profile images, posts, project pages, and related source links to create directory listings. If that information is inaccurate, you can use the feedback form; we will attempt corrections or removals on a best-effort basis.
  • AI-assisted directory metadata. On a best-effort basis, public pages, posts, images, videos, and related sources may be analyzed by AI services to draft descriptions and tags, infer maker or model credits, capture shared prompts, and otherwise populate listing metadata. AI systems can misread material, omit context, invent facts ("hallucinate"), or attribute work incorrectly — so this metadata can be incomplete, outdated, or wrong. Where we surface AI-generated or inferred fields, we disclose that on listing and creator pages. Send feedback through the feedback form if something looks off; we will attempt to correct it on a best-effort basis and do not guarantee every report will result in a change.
  • Aggregate analytics. We use Vercel Web Analytics and Speed Insights, with your permission, to count page views and measure performance. They are cookieless, set nothing on your device, and don't track you across other sites.
  • Standard server logs. Our host (Vercel) may log IP addresses, browser type, and request paths for security and reliability.

What we don't collect

We don't collect payment info or precise location. We don't handle account passwords ourselves, and browsing does not require an account or email address. We don't run Google Analytics, Meta Pixel, or any advertising trackers of our own, and we don't sell your data or share it for advertising. The only third-party code that runs in your browser comes from the video and post embeds described below.

Source-hosted media and embeds

New listing images remain at their public source URLs rather than being copied into Dropday storage. Historical listings may still reference previously stored display images while those records are transitioned. When a source image or embed loads, your browser talks directly to that source or platform. It can see your IP address and browser details and may set its own cookies under its own privacy policy. Dropday requests images without sending the page referrer.

  • YouTube. We use the privacy-enhanced player (youtube-nocookie.com), which is designed not to set cookies unless you press play. Video thumbnails also load from YouTube's image servers.
  • X (Twitter). Listings sourced from X can show the original post or its video via X's official embed, which loads X's widget script in your browser. We request these embeds with X's "Do Not Track" option, which tells X not to use your visit for ad personalization. If the widget can't load — for example, your browser or an extension blocks it — we show a plain link to the post instead, and the rest of the site works normally.
  • Vimeo and Loom. Some demo videos play through Vimeo's or Loom's official player.

Why we collect it

Voting needs a stable anonymous ID so one person can't spam votes. Trending needs rough engagement counts. Follows and notifications need an account so they can stay with you across devices.

How long we keep it

Votes, views, click-throughs, submissions, feedback, follows, and account profile records stay in our database until we delete them unless a shorter cleanup rule applies. The anonymous browser cookie expires after two years unless you clear it sooner. A submission's IP address and confirmation record are retained with that submission record.

Your choices

  • Use to accept, reject, or change optional analytics and external-media choices at any time. Rejecting optional services does not limit core site features.
  • Clear Dropday's cookies or site data in your browser settings to remove the anonymous ID.
  • Block third-party embeds (for example with a content blocker) — listings fall back to a link to the original video or post, and everything else keeps working.
  • Use our feedback form to ask what we have linked to your device or to request deletion.

We do not sell personal information or share it for cross-context behavioral advertising, so there is no sale or sharing to opt out of. We treat a browser Global Privacy Control signal as a request to keep optional services off unless you make a different choice here.

Where data is processed

The site runs on Vercel, uses hosted Postgres for the app database, Clerk for optional sign-in, and Resend for opt-in email. Google, xAI, and OpenAI services may process public source material or derived directory metadata for AI-assisted discovery, classification, and search. Data may be processed or stored in the United States.

Changes

We may update this page as the site evolves. The date at the top shows when it last changed.

Contact

Questions about privacy? Reach us through the feedback form.

← Back to browse