DRIPPY AI
Privacy Policy Terms of Service Cookie Policy
Get Started

Privacy Policy

Last updated: 22 September 2026

This Privacy Policy explains what data Drippy AI ("Drippy AI") collects, why it is collected, and the choices you have. It is written to describe exactly what this software does.

1. Data we collect

Account data: your name, username, email address and a hashed password. Passwords are stored only as bcrypt hashes and can never be read by anyone, including administrators.

Conversations: your chat messages, conversation titles and related metadata, so you can continue conversations and search your history.

Usage data: per-message usage records (message counts and token counts) used to enforce your plan's daily allowance.

Security data: login attempt records (including IP address), and security notifications, used to detect brute-force attacks and unauthorised access.

Google sign-in: if you use Google login, your Google account ID, email, display name and profile picture are stored to link your sign-in.

2. How your data is used

Your data is used to operate your account, provide the AI chat service (messages you send are transmitted to the Sarvam AI API to generate responses), enforce plan limits, secure the platform, and send transactional emails such as verification and password reset messages.

3. AI processing

To generate a response, your conversation is sent securely from our server to the Sarvam AI API. API access keys are stored only on the server and are never exposed to the browser.

4. Data retention & your controls

You can delete individual conversations, export your data as JSON, or permanently delete your account (which removes your conversations, messages and personal data) at any time from Settings. Verification and password-reset tokens expire automatically and are deleted after use.

5. Sharing

We do not sell your data. Data is shared only with the service providers strictly required to run Drippy AI: our AI model provider (Sarvam AI) and our email delivery provider, each receiving only what is needed to perform their function.

6. Security

Passwords are hashed with bcrypt. Sessions use hardened cookies and regular id rotation. Forms are protected against CSRF and inputs are escaped against XSS. No system can promise perfect security, and we encourage strong, unique passwords.

7. Changes

If this policy changes materially, we will notify you in the app. Continued use after changes means you accept the updated policy.

© 2026 Drippy AI. All rights reserved.