Privacy policy
What information DRD handles, how it is used, and how to ask about your data.
Last updated
Who this policy covers
DRD INDUSTRIES (“DRD,” “we,” or “us”) provides this website and the DRD building platform. This policy describes personal information handled through our website, accounts, project tools, public discussions, billing, and support. Contact us at hello@drdindustries.com with privacy questions.
A customer who operates a website or app built with DRD may be responsible for the information that app collects. Review that operator’s privacy notice and contact them about their use of your information. Where we process information on a customer’s behalf, the relevant service agreement also applies.
Information we handle
The information involved depends on how you use DRD. It can include:
- Account information: email address, account identifiers, sign-in information, and the public name or profile photo you choose. If you use social sign-in, we receive information made available by that provider and your permissions, such as an identifier, email, name, and profile photo.
- Project information: ideas, prompts, conversations with Droid, uploaded files, generated code, project settings, previews, and deployment records.
- Public contributions: comments, replies, and the public profile information displayed with them.
- Billing information: customer and transaction identifiers, purchased plans, subscription status, and payment-related records. Stripe handles payment details entered through its checkout; DRD’s billing records do not include your full card number or security code.
- Communications: contact-form submissions, support messages, and information you provide when discussing a custom project.
- Technical and usage information: request and error logs, IP addresses and browser information handled by service infrastructure, sign-in events, and project or model usage records needed to run the service and account for usage.
How information is used
We use information to create and secure accounts; generate, save, preview, and publish projects; deliver the features you request; process payments and account for usage; respond to inquiries; and manage public discussions. We also use relevant records to troubleshoot problems, protect the service, prevent abuse, resolve disputes, and meet legal obligations.
Where data-protection law requires a legal basis, processing may be necessary to provide the service under our agreement, meet legal obligations, or pursue legitimate interests such as service security and reliability. Where processing depends on consent, you can withdraw that consent; withdrawal does not undo processing that was lawful before it was withdrawn.
Droid and AI processing
When you ask Droid to work on a project, relevant prompts, conversation context, code, and attachments may be sent to AI providers and processed in hosted development environments. This processing is needed to generate, inspect, and run the work you request. Project conversations, files, and usage records are also stored so you can continue your work.
AI-provider processing and retention depend on the provider, service, and settings used. Contact us before submitting information that requires a particular confidentiality, training-use, or retention commitment. Do not include passwords, private keys, or unnecessary sensitive personal information in prompts or uploads.
What can become public
Your chosen public name, profile photo, and comments can be visible to others in public discussions. Uploaded profile photos are publicly accessible by their URL. Avoid putting private information in your public profile or comments.
Uploading a file for project work does not by itself publish that file as a website asset. However, content or files included in a project you publish can become publicly available. Removing an attachment from a draft message does not remove the uploaded file from the project’s resource library.
Other people may copy public content, and search engines may index published pages. Removing content from DRD does not necessarily remove copies held by others.
Providers and other disclosures
We share information with providers as needed for the features you use. These include Supabase for authentication, databases, and file storage; AI services such as Nous Research for model processing; AWS for development workspaces; GitHub for code repositories; Vercel for deployment and hosting; Turso for supported project databases; Stripe for payments; and Resend for contact-message delivery.
A connected sign-in or payment provider also handles information under its own privacy notice when you interact with it. Customer-configured integrations can involve additional providers; review the notices for services you choose to connect.
We may disclose information where required by law or where reasonably necessary to protect rights, investigate abuse, or address security threats. Information may also be involved in a business reorganization or transfer, subject to applicable privacy obligations and any required notice.
How long information is kept
We retain information for the purposes described here, considering whether an account or project is active, what is needed to provide and support the service, and obligations involving billing, security, disputes, and legal records. Different types of records can have different retention needs.
Deleting a project record or removing a file from a message may not remove all related storage objects, hosted deployments, or provider-held copies. A deletion request may require separate cleanup of those systems. Backups and records needed for legal or security purposes may remain for the period those purposes require.
Your choices and deletion requests
You can update your public name and manage your profile photo in your account. To request access, correction, a copy of your information, account closure, or deletion, email hello@drdindustries.com with the subject “Privacy request.” Contact us from the email associated with your account where possible, and explain which account or information your request concerns. Do not send your password.
This process also applies to information received through Facebook, GitHub, or another sign-in provider. Removing DRD from a provider’s connected-app settings stops that connection but does not itself delete your DRD account or existing records. Ask us separately if you want that information deleted.
We may need to verify your identity before acting on a request. Depending on where you live, you may also have rights to restrict or object to processing, obtain portable data, withdraw consent, or complain to a data-protection authority. We will handle requests in accordance with applicable law and explain any lawful reason we cannot fulfill a request in full.
Security and processing locations
DRD uses account authentication, access controls, and restricted storage for private project resources. No online service or storage system can guarantee absolute security. Contact us if you believe your account or information has been compromised.
Service providers may process information in countries other than where you live, where data-protection laws can differ. Contact us for information about processing locations and the safeguards applicable to your use of DRD.
Children’s information
DRD’s account and building services are intended for people able to enter a service agreement and are not directed to children under 13. If you believe a child has provided personal information through these services, contact us so we can investigate and address removal as appropriate.
Updates to this policy
We will update this policy as our services and information practices change. The date above identifies the latest version. We will provide notice of material changes and obtain consent where required. Contact hello@drdindustries.com with questions about this policy or a privacy request.
Let’s keep the conversation open.
Questions about these pages or your information? Contact DRD INDUSTRIES.
hello@drdindustries.com