Effective date: 1 October 2026

This Privacy Policy explains how drop/expired (dropexpired.net, “we”, “us”) collects, uses and protects personal data when you use our website, web app, desktop and mobile apps, API and MCP server (the “Service”). Terms not defined here have the meaning given in our Terms of Service.

1. Who is responsible

dropexpired.net is the controller of the personal data described in this policy. For any privacy question or request, contact us at [email protected].

When a team owner invites you to a team, the team owner decides what is shared within the team; we process team data on behalf of the team to provide the Service.

2. Data we collect

Account data. Your email address, a password (stored only as a one-way hash, never in readable form), your name if you provide it, and, if you sign in with Google, Apple or GitHub, the identifier and email address those services share with us. Settings such as language, time zone, notification preferences and spending limits.

Workspace data. Watch lists, wish lists, saved filters, alerts, notes, searches you save, team membership and roles, and activity within teams.

Connected provider accounts. The API keys and other credentials you enter for registrars, auction houses, drop-catchers and marketplaces. They are encrypted at rest, decrypted only to carry out the operation you requested, never shown again in full and never returned by the API.

Orders. The order previews you request and the orders you confirm: domain, provider, order type, price and fees quoted by the provider, status and history. Payment for domains is made between you and the provider; we do not receive your payment card details for those purchases.

Subscription and billing data. Your plan, billing interval, subscription status and the identifiers of your Stripe customer, App Store or Google Play purchase. Card details are entered directly with Stripe, Apple or Google; we do not see or store full card numbers.

AI assistant data. The messages you send to the assistant, its replies and the actions it prepares. Unless you opt out, pseudonymised and scrubbed samples of assistant requests and answers are also kept to improve our own assistant models (see section 4).

Developer data. API keys (stored as a hash; shown in full only when created), webhook URLs and signing settings, and records of API and MCP calls.

Usage and device data. Searches, API calls and assistant messages counted against plan limits; IP address, browser or app type and version, device and operating system, and timestamps in technical and security logs; push notification tokens if you enable push notifications.

Communications. Messages you send us and our replies.

We do not ask for special categories of personal data, and we ask you not to put them in the Service.

Data about domains. The Service shows information about domain names compiled from public sources, such as WHOIS/RDAP records, registry and registrar lists, web archives and search results. Some of these records can contain personal data of domain registrants. We use such data only to provide domain information, limit it to what is publicly available and relevant, and handle requests about it under section 9.

Purpose Legal basis (GDPR and similar laws)
Create and run your account, provide search, lists, alerts, teams, notifications and the API/MCP Performance of our contract with you
Store your provider credentials and send the orders you confirm to providers Performance of contract
Run the AI assistant at your request Performance of contract
Manage subscriptions, payments, invoices and promotions Performance of contract; legal obligations (tax and accounting)
Enforce plan limits, prevent abuse, fraud and unauthorised access, and keep the Service secure Legitimate interests in operating a secure and fair service
Fix problems and improve the Service using aggregated or pseudonymised usage data Legitimate interests
Improve and train our own assistant models with pseudonymised samples of assistant requests and answers (section 4; you can opt out) Legitimate interests
Send service, security, billing and order messages Performance of contract; legitimate interests
Send optional news or product updates Consent, which you can withdraw at any time
Show public information about domain names Legitimate interests in providing domain research, balanced against the data subjects’ rights
Comply with law and respond to lawful requests; establish or defend legal claims Legal obligations; legitimate interests

We do not sell personal data, do not use it for third-party advertising, and do not use your provider credentials for anything other than the actions you request. Apart from the assistant samples described in section 4, which you can switch off, we do not use your content to train AI models. We do not make decisions that have legal or similarly significant effects on you solely by automated means.

4. Improving our assistant models

We are building our own assistant models, adapted to domain research and to each language the Service supports. To do that, we keep samples of real assistant requests and answers and use them to evaluate and train (fine-tune) these models.

What a sample contains. For each completed assistant answer: the text of your request, the tools the assistant used with short summaries of their results, and the final answer; plus the language, the service region, the plan type (for example Free or Pro, or “guest”) and the date. A sample does not contain your account ID, email address, name on the account or team ID, and never contains the assistant’s internal reasoning.

How samples are protected.

  • Pseudonymisation. Turns of one conversation are grouped by a random identifier that is not linked to your account. To be able to delete your samples on request, we store a keyed hash of your account ID that can only be computed with a secret key held on our servers; it is used for nothing else.
  • Removal of personal details. Before a sample is stored, we automatically remove email addresses, phone numbers, web addresses that contain login details, API keys and other access tokens, payment card-like numbers and names introduced with phrases such as “my name is”. If the automatic check is not confident that a sample is free of such details, the sample is discarded.
  • Restricted access and regional storage. Samples are stored separately from accounts, on our own servers, in a dataset kept per service region (this Service is our international region), and only staff working on the models can access them. They are never sold or shared for others’ purposes.

Legal basis and balancing. We rely on our legitimate interests (GDPR art. 6(1)(f)) in improving the assistant and in running our own models rather than depending on outside providers. We have weighed these interests against your rights: samples are limited to assistant requests and answers (which users expect to be used to provide and improve the assistant), they are pseudonymised and cleaned of personal details, uncertain samples are discarded, access is restricted, retention is limited, and you can opt out at any time with one switch. We consider the impact on you to be low.

Your choices.

  • Opt out with the switch in the app under Settings → Privacy, or through the API (aiTrainingOptOut in your settings). Opting out applies from that moment on.
  • Delete past samples: when you opt out, the app offers to delete the samples already collected; you can also delete them at any time in Settings → Privacy, or ask us at [email protected]. Deleting your account also deletes them.
  • Teams: a team admin can opt the whole team out for requests made in the team’s context. Your own opt-out always applies, whatever the team setting.
  • Global Privacy Control and Do Not Track: if your browser sends a Global Privacy Control or Do Not Track signal, we do not keep samples of your requests, whether you are signed in or not.
  • Guests who use the assistant without an account are covered by the same rules; as we cannot link their samples to them, guests who want to be excluded should enable Global Privacy Control in their browser.

Feedback. If you rate an assistant answer or write feedback on it, we use that feedback to improve the Service and its AI features. Feedback text is cleaned of personal details in the same way, and if you have opted out it is not included in the samples described above.

The third-party AI model providers that generate the assistant’s answers (section 5) receive your messages only to produce those answers; this section does not change that.

5. Processors and other recipients

We share personal data only as needed with service providers that process it on our behalf under contracts requiring confidentiality and security:

  • Cloudflare — network delivery, DNS and protection against attacks (sees connection data such as IP addresses);
  • Stripe — web payments and subscription management;
  • Apple (App Store) and Google (Google Play) — in-app subscriptions, under their own privacy policies;
  • Google Firebase Cloud Messaging — delivery of push notifications;
  • our email provider — delivery of account, alert and order emails;
  • third-party AI model providers acting as processors — generating the AI assistant’s responses from the messages and context you send it;
  • Google, Apple and GitHub — only if you choose to sign in with them.

When you connect a provider account and confirm an order, we send the order data and your credentials to that provider, which processes them as an independent controller under its own privacy policy. Webhooks send alert data to the URLs you configure.

We may also disclose data to professional advisers, to a successor in a merger or sale of the Service (with notice to you), or where required by law or to protect rights, safety and the integrity of the Service. Within a team, members and admins see the team’s shared workspace and orders according to their roles; they never see connected-account credentials.

6. Where data is stored and international transfers

The Service runs on servers we operate, accessed through Cloudflare’s network. Our processors may handle data in other countries, including the United States. Where data is transferred outside the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK addendum) or the processor’s certification under an applicable data privacy framework. You can ask us for information about these safeguards.

7. Security

We protect data with measures appropriate to the risk, including encrypted connections (TLS), hashing of passwords, refresh tokens and API keys, encryption of provider credentials at rest, access controls and least-privilege access, rotation of session tokens, logging and regular backups. No system is perfectly secure; if a breach affects your data, we will notify you and the authorities as the law requires.

8. How long we keep data

  • Account and workspace data: while your account exists. When you delete your account, we delete or anonymise it within 30 days.
  • Provider credentials: until you disconnect the account or delete your account.
  • Orders: while your account exists, and afterwards only as long as needed for disputes with providers or legal obligations.
  • AI assistant conversations: while your account exists, or until you delete them.
  • Assistant improvement samples (section 4): up to 24 months from collection, then deleted automatically; earlier if you delete them, ask us to, or delete your account.
  • Usage records and API logs: up to 12 months.
  • Security and technical logs: up to 90 days, longer only when needed to investigate an incident.
  • Billing records: as long as tax and accounting law requires (typically up to 10 years).
  • Backups: we keep daily backups for 7 days and weekly backups for 4 weeks; deleted data disappears from backups when they expire, about five weeks after deletion.

9. Your rights

Depending on where you live, you have the right to:

  • access your personal data and receive a copy;
  • correct inaccurate data (most of it you can edit yourself in Settings);
  • delete your data — you can delete your account at any time in Settings; this removes your workspace and disconnects your provider accounts;
  • export your data in a portable format (lists can be exported as CSV on plans with export; for a full copy, write to us);
  • object to processing based on legitimate interests, and to direct marketing at any time — for the assistant improvement samples, simply switch them off in Settings → Privacy (section 4);
  • restrict processing in certain cases;
  • withdraw consent where processing is based on consent, without affecting earlier processing;
  • lodge a complaint with your local data protection authority.

To use these rights, write to [email protected] from the email address of your account. We may need to verify your identity and will reply within one month (extendable where the law allows). Residents of California and other US states have equivalent rights to know, delete and correct, and the right not to be discriminated against for using them; we do not sell or share personal data for cross-context behavioural advertising.

If you are a domain registrant and believe the Service shows your personal data, contact us with the domain name and your request.

10. Cookies and local storage

We use only the cookies and browser storage necessary to run the Service. See the Cookie Policy.

11. Children

The Service is not directed to children and may only be used by adults (see the Terms). We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy. We will notify you of material changes by email or in the app before they take effect. The date at the top shows when it last changed.

13. Contact

[email protected]