Privacy Policy

Last updated: August 2, 2026

This page explains what data DeskFilter (operated by PopDrop) collects when you use the service, how we store it, and the choices you have. This is a plain-language summary maintained by the DeskFilter team — it is not legal advice.

What we collect

  • Account data: your email address, display name, and workspace memberships.
  • Workspace content: vendor files you upload, extracted offers, clients, packages, and events (audit log).
  • Configuration: agency name, logo, brand colors, and your encrypted Anthropic API key.

How we store it

Workspace data is stored in an isolated database with row-level security scoped per workspace — only members of a workspace can read its data. Your Anthropic API key is encrypted at rest using AES-256-GCM before being written to the database.

Third parties

  • Anthropic: uploaded files are sent to the Anthropic Claude API using your workspace-owned API key to extract offer data. Their handling is governed by Anthropic's own policies.
  • Supabase / Cloudflare: used for database, authentication, storage, and hosting.

We do not sell your data and we do not use your workspace content to train models.

Retention & deletion

Workspace data persists until you delete it or delete the workspace. Deleting an offer or a package removes the record and its files from storage; a minimal audit entry (vendor name, media type, market, net rate at the time of deletion) is kept so vendor history remains searchable.

Your choices

  • Owners can rotate or remove the Anthropic API key at any time in Settings.
  • Members can leave a workspace; owners can remove members and revoke invites.
  • To request full deletion of your account or workspace, email us at hello@popdrophq.com.

Contact

Questions about this policy? Reach us at hello@popdrophq.com.