DROPVIA / DATA SAFETY
Data Safety and Permissions
A plain-language summary of the data Dropvia accesses, why it is used, platform permissions, and security measures.
This page does not replace Apple App Privacy, Google Play Data Safety, Microsoft Store, or Huawei AppGallery console disclosures. Store declarations are reconciled with actual code, permissions, and SDK behavior for every release.
1. Data summary
2. Data practices
- Dropvia does not sell personal data or file content. Processing by hosting, notification, and store providers to deliver the service is not a sale of data.
- File content is not used to train artificial-intelligence models.
- File content is not retained in the database; metadata and status records needed to establish and operate a live transfer may be processed.
- Free and Plus accounts may use up to 4 linked devices. Device records are processed to enforce the limit, pair devices, and protect the account.
- Permissions not essential to the service may be denied or later withdrawn in operating-system settings; the related feature may then be unavailable.
3. Platform permissions
- iOS/iPadOS: access to items you select through the system file or photo picker; permission to save received media to Photos when enabled; optional notifications and support for user-initiated transfers.
- Android: internet and network state; notifications and vibration according to user choice; background execution and wake lock for user-initiated transfers; storage permission on older versions and the system file picker on newer versions.
- Windows: files expressly selected by the user or shared through the ‘Send with Dropvia’ command; network access, notifications, and optional launch at startup.
4. Service providers
- İBT İstanbul Bilgi Teknolojileri Tic. Ltd. Şti.: the main server in Türkiye’s Black Sea region and backup infrastructure in Istanbul.
- Google Firebase Cloud Messaging and Apple Push Notification service (APNs): device notification tokens and delivery.
- SMTP delivery infrastructure: delivery of automated account, password, and account-deletion verification emails from no-reply@dropvia.app. This address does not accept or monitor incoming replies; user-initiated support, privacy, and legal correspondence must be sent to support@dropvia.app.
- Apple App Store and Google Play: app distribution, purchases, and subscription verification.
- Microsoft Store and Huawei AppGallery: distribution, licensing, and store operations for the applicable release.
5. Security design
File content is encrypted on the sender device with AES-256-GCM; the content key is wrapped to the recipient device’s RSA public key with RSA-OAEP-SHA256. The relay carries only encrypted data frames for the duration of the live transfer. Passwords are stored as secure hashes rather than plain text; session tokens are protected and time-limited. Access controls, transfer validation, and operational logging are applied. Nevertheless, no electronic system can guarantee absolute security.
6. Hosting, retention, and deletion
- File content is not stored in the Dropvia database and no permanent copy remains after a live transfer.
- Transfer, contact, and device-pairing requests and their related notifications are expired and cleaned within 7 days at the latest.
- Transfer history is limited to the latest 20 records per user and no more than 7 days; ‘Clear History’ immediately deletes active SQL history rows.
- Device heartbeat records and verification codes are retained for no more than 7 days; login/security records and revoked or expired tokens for 30 days.
- İBT creates daily incremental and weekly full backups. Written confirmation of the exact maximum for deleted data in backups is pending; backup copies are restricted from ordinary use and removed when the verified rotation/destruction cycle completes.
Account, device, subscription, support, and legal records are limited to the period required for the service or law. Account deletion and other privacy requests can be started from the Account and Data Rights page.
Account and data rights →7. Age requirement and contact
Dropvia is not offered to users under 16. If you believe a child’s data is being processed, or wish to report a data-safety, privacy, copyright, or abuse matter, contact support@dropvia.app.