Privacy, for both sides of the email.
This policy covers two different groups: account holders (our customers) and email recipients (founders who receive a proof email). They are not the same and are not treated the same. Last updated 2025-06-02.
1. Who we are
Proofdrop (“we”) operates a pipeline that finds publicly launched products, matches them against what a customer sells, and sends the founder one evidence-based email on the customer’s behalf. For account holders we are the data controller. For recipient data, the customer is the controller and we act as processor; in practice we apply the stricter of the two standards to everything we touch.
2. Account holders
We collect what is needed to run the service and nothing decorative:
- Account data. Name, email, billing details. Used to run your account and invoice you.
- ICP configuration. What you sell and who you sell to. Used to match launches. Never shared with other customers.
- Send and engagement data. Opens, clicks, replies, bounces and complaints per proof. Shown to you in your dashboard and used to enforce the sending policy.
- Usage data. Logins and actions in the product, kept for security auditing. We do not run third-party analytics or advertising trackers on the dashboard.
3. Email recipients
If you received a proof email, here is exactly what we hold about you and why:
- Your work email address, collected from the public launch listing of a product you launched (a directory, Show HN, or Product Hunt). The source of every address is logged.
- The finding itself: the probe or check result about your product that was sent to you.
- Engagement events: whether the email was opened, clicked, bounced, or marked as spam.
The lawful basis is legitimate interest: you launched a product publicly, and the email concerned a concrete, verifiable property of that product, sent once. You can end it permanently:
- Unsubscribe via the link in the email. One click, immediate, permanent for that sender.
- Global suppression by mailing support@mail.proofdrop.net with the subject STOP. Your address is suppressed for every account on the platform within the hour.
- Erasure on request to the same address. Suppression records themselves are kept (as a hash) so that your “never again” survives deletion requests, and that is the one thing we will not delete, because deleting it would expose you to future sends.
4. Evidence and probe data
Findings are produced by the customer’s own system against the recipient’s public surface: public APIs, published documentation, signup flows. We do not probe authenticated areas, attempt access, or collect personal data about a recipient’s users. Probe logs (timestamps, status codes, request ids) are retained for 90 days so a recipient can verify what was sent, then deleted.
5. Who we share with
- Infrastructure providers (hosting, email delivery, payment processing) under data processing agreements. The current list is available on request.
- Nobody else. We do not sell, rent, broker or “enrich” personal data. Recipient addresses are never shared between customers.
- Legal compulsion. If required by law we disclose the minimum necessary and, where permitted, notify the affected account holder first.
6. Retention
- Account data: kept while the account is active, deleted within 90 days of closure.
- Probe logs and findings: 90 days, then deleted.
- Engagement events: 12 months, then aggregated and anonymised.
- Bounce, complaint and suppression records: kept indefinitely as hashes, because they exist to prevent future sends.
- Billing records: kept for the period required by tax law.
7. Your rights
Whether you are an account holder or a recipient, you may request access, correction, export, or erasure of your personal data, and object to or restrict processing. Mail support@mail.proofdrop.net. We answer within 30 days, usually much faster. You also have the right to complain to your local supervisory authority; if you are in the EU, that is your national data protection authority.
8. Security
Data is encrypted in transit and at rest. Access to production systems is limited to the people who run them, logged, and reviewed. Suppression lists are stored as one-way hashes where the underlying address is not operationally needed.
9. Changes
Material changes are announced to account holders by email at least 14 days before they take effect, and noted on the changelog. The date at the top of this page always reflects the current version.
10. Contact
Privacy questions, requests and complaints: support@mail.proofdrop.net. A person answers.