Legal Document

Privacy Policy

Last Updated: August 2, 2026

1. Introduction

Welcome to ErikrafT Drop™. We respect your privacy and are committed to protecting any personal data that may interact with our platform. This Privacy Policy outlines our transparent practices regarding data processing, security, and alignment with major global privacy standard frameworks, including the European Union's General Data Protection Regulation (GDPR), Brazil's Lei Geral de Proteção de Dados (LGPD), and California’s Consumer Privacy Act (CCPA / CPRA).

Our service is built with a privacy-first architectural approach. Because we do not require account registration, email sign-ups, or login credentials to use our peer-to-peer file sharing mechanism, we avoid gathering traditional personally identifiable information (PII) from our users.

Although this website is operated from Brazil and is primarily subject to Brazilian law, it seeks to follow internationally recognized best practices for privacy, data protection, and information security whenever compatible with applicable law and the nature of the services provided.

2. Scope of Application

This Privacy Policy applies solely to your interaction with the marketing and information website, including the donation utility page, located at https://biodrop.erikraft.com, and any local client interactions associated with the open-source web application, browser extensions, desktop wrappers, or mobile applications that connect to our WebRTC infrastructure. It does not apply to third-party services, independent integrations, or repositories hosted by other contributors.

3. Definitions

  • Peer-to-Peer (P2P): A decentralized communication model where devices communicate directly with each other without files being stored on a central file server.
  • WebRTC (Web Real-Time Communication): An open-source technology framework that enables real-time peer-to-peer connection and transfer of data, audio, video, or files directly between web browsers.
  • Signaling Server: An intermediate server that facilitates connection initiation by exchanging connection metadata (session descriptions, candidate IPs) to establish a direct WebRTC P2P tunnel. The signaling server has zero access to the contents of file transfers.
  • End-to-End Encryption (E2EE): A system of communication where only the communicating users can read or decrypt the files being transferred.

4. Information We Collect

We categorize data handling strictly under "Information You Voluntarily Provide" and "Automatically Collected Information".

Information You Voluntarily Provide

Since there is no user account registration, newsletter subscription, or email list, we do not collect contact details unless you contact us directly via email (contact+drop@erikraft.com) or open an issue on our GitHub repository. Any correspondence details you voluntarily supply are used solely to address your technical support request or feedback.

Automatically Collected Information

When accessing our website or using our signaling server, the host infrastructure or network load balancers may temporarily record technical parameters:

  • Internet Protocol (IP) Address;
  • Device Operating System and Browser type (User-Agent string);
  • Date and time stamps of connections to the signaling channel;
  • Total transfer volume metrics (aggregated, without identifying contents).

These transient logs are strictly processed for system optimization, DDoS mitigation, and diagnostic analysis, and are purged on a rotating automated schedule.

5. Peer-to-Peer File Transfers

Zero-file-retention policy: Files transferred via ErikrafT Drop™ are **never** uploaded, compiled, cached, saved, or otherwise processed by our signaling server. The binary file content stays strictly within your browser environment.

Our peer-to-peer sharing capability is enabled by WebRTC technology. Once devices initiate connection via the signaling server, a direct cryptographic tunnel is established between the peer browsers.

The files are broken into chunks, encrypted locally on the sender's device, streamed directly to the recipient over the secure P2P link, and reassembled in the memory of the recipient's browser. At no point does the file data cross any intermediate server or third-party storage node.

6. Cookies & Web Storage

We respect your right to block cookies. ErikrafT Drop™ does not use third-party tracking, targeting, advertising, or profiling cookies.

We utilize standard HTML5 local web storage (localStorage and sessionStorage) exclusively to store local user choices:

  • Preferred visual UI layout adjustments;
  • Temporary network room setup configurations;
  • Your local custom peer nickname (if entered).

This local web data remains completely offline in your browser sandbox, and you may clear it at any time by resetting your browser cookies or cache.

7. Third-Party Services

Our application integrates several trusted utility frameworks to enable connection features, analytics, and social presence:

  • Web Hosting Platform (Render): Our website and signaling coordination services are deployed on the Render hosting platform. As our infrastructure provider, Render automatically processes basic network routing data, transient HTTP header info, and IP addresses solely as necessary to maintain host uptime, service availability, threat prevention, and CDN performance. Render does not inspect, collect, or store any file content, which stays strictly decentralized.
  • STUN/TURN Servers: To negotiate connections across complex NAT firewalls, our app uses standard Google STUN servers. These servers process your public IP address solely for real-time routing purposes and do not compile tracking logs.
  • Discord API / Bot Integration: If you interact with the Discord application wrappers or bot pairing systems, the transaction utilizes Discord's developer interfaces, which are governed directly under Discord's global privacy standards.
  • External Documentation Links: Our landing pages connect to resources like our general documentation site (docsdrop.erikraft.com) and our GitHub repositories. We hold zero governance over external sites' independent policies.

8. Donations (PIX & Ko-fi)

Our support mechanisms utilize static donations that safeguard user financial identity:

  • Client-Side PIX QR Code Utility: Our voluntary PIX generator generates standard EMV Pix Payload codes directly in your browser. No financial data, bank credentials, payment history, or personal identifiers are uploaded to, processed by, or transmitted to our web servers. The QR Code compilation operates entirely on the local client using static values.
  • Ko-fi Donations: When supporting via Ko-fi, you interface with their checkout processors. We never hold custody of credit cards, transaction tokens, or billing identifiers; your payment data is strictly managed under Ko-fi's secure privacy policies.

9. Information Security

We implement high-grade administrative, technical, and structural controls to preserve the integrity of your WebRTC signaling channels:

  • Signaling metadata streams use Secure WebSockets (wss://) encrypted via Transport Layer Security (TLS);
  • P2P data channels are cryptographically protected via DTLS (Datagram Transport Layer Security) and SRTP (Secure Real-time Transport Protocol);
  • Regular public code audits are encouraged, as our complete product structure is open source.

10. International Data Transfers

Your transient routing parameters (like IP addresses used to resolve WebRTC signaling or STUN routing) may be routed internationally across standard CDN clusters or Google STUN networks based in various global locations. By utilizing our platform, you acknowledge and agree to such global network routing, designed purely to enable international WebRTC connectivity.

11. Data Retention

We adhere to the principle of data minimization. We keep no persistent databases containing your file information, payment metadata, or sharing behavior. Server traffic diagnostic logs are kept purely on an automated temporary rolling basis for threat assessment, rotating automatically within 30 days.

12. Global User Rights

No matter where you reside globally, you have the right to know whether we process your data. Because we do not compile user accounts, profile patterns, tracking cookies, or databases of email addresses, we do not store personal data that we could retrieve, correct, export, or permanently delete upon request. Your usage remains inherently private and anonymous.

13. GDPR Rights (European Union)

For European Union residents, the General Data Protection Regulation (GDPR) establishes specific legal rights regarding personal information processing. As a data subject:

  • You have the right to access, rectify, or request erasure of personal data;
  • You have the right to withdraw consent at any time for future transient processing;
  • You have the right to lodge a complaint with your local Supervisory Authority.

Our processing legal basis for temporary signaling data is Article 6(1)(b) of the GDPR (processing necessary for the performance of a contract to deliver peer-to-peer connectivity requested by the user).

14. LGPD Rights (Brazil)

Para usuários localizados no Brasil, em conformidade com a Lei Geral de Proteção de Dados (LGPD), declaramos que não coletamos, comercializamos, compartilhamos ou armazenamos dados pessoais identificáveis. Consequentemente, os direitos de confirmação de tratamento, acesso, retificação, eliminação, portabilidade e revogação de consentimento previstos no Artigo 18 da LGPD são integralmente respeitados por meio de nossa arquitetura descentralizada de compartilhamento de arquivos.

15. California Privacy Rights (CCPA / CPRA)

If you reside in California, you are entitled to protections under the California Consumer Privacy Act (CCPA) as amended by the CPRA. We make the following disclosures:

  • We do not sell your personal information or compile commercial consumer files;
  • We do not collect "Sensitive Personal Information" as classified by California law;
  • You have the right to access and delete your collected information (which is inherently preserved via our zero-tracking design).

16. Children's Privacy

We recognize the significance of guarding children's digital safety. ErikrafT Drop™ does not intentionally target, gather, or compile data from children under the age of 13, in strict accordance with the US Children’s Online Privacy Protection Act (COPPA). Because we operate without account creations, we collect zero persistent identifiers or personal data from children.

17. Changes to this Policy

We may refine our Privacy Policy over time to reflect legal changes, technological enhancements, or alterations in our signaling mechanics. Any updates will be denoted by an updated "Last Updated" timestamp at the top of this document. We encourage users to periodically review this page to remain informed about our absolute commitment to data privacy.

18. Contact Information

If you have any questions or require clarification regarding this Privacy Policy or our decentralized P2P routing mechanisms, you may contact our maintainer:

Maintainer Identity:

ErikrafT

contact+drop@erikraft.com

Contact Maintainer