Skip to main content
TrimCode
  • Dropvia
  • Apps
  • Support
  • TR/EN
Dropvia
Privacy KVKK Data safety Data rights Terms Subscriptions Content protection Support

DROPVIA / PRIVACY

Dropvia Privacy Policy

Explains how your account, device information, transfer records, and selected files are handled across the Dropvia mobile and desktop apps.

Version 1.3 · Last updated: 9 October 2026

1. Scope and controller

This policy applies to the Dropvia apps, accounts, file-transfer infrastructure, notifications, subscription verification, and support services. The data controller is Emre Çakıroğlu, an individual developer. Address: Mecidiyeköy Mah., Esentepe Cad., Hafız Ata Çık. Sok., Nuri Bey Apt. No:10 D:20, 34387 Şişli / Istanbul, Türkiye.

Privacy and personal-data requests: support@dropvia.app

2. Data we collect

  • Account and contact: name, display name, email, phone/country code, language, time zone, Dropvia ID, and a secure password hash.
  • Device and security: device name/type, operating system and app version, device identifier, public key, session/notification tokens, IP address, connection state, login, and security records.
  • Contacts and requests: connections created through Dropvia IDs, contact and transfer requests, and sender/recipient information. Your phone address book is not uploaded automatically.
  • Transfer metadata: file name, extension, size, hash, sender/recipient, devices, status, time, errors, and progress.
  • Subscription and support: store, plan, transaction/subscription token, renewal and expiry status, and correspondence you send us. Dropvia does not receive your full payment-card details.
  • File content: only files you select are processed temporarily and in encrypted form between devices to perform the transfer.

3. File content, ownership, and encryption

You retain ownership of your files; Dropvia does not claim ownership of file content. Content is encrypted on the sender device with AES-256-GCM, and the content key is wrapped for the recipient device using RSA-OAEP-SHA256. The relay service carries encrypted data frames during transfer; file content is not stored in the Dropvia database.

Dropvia does not sell your file content, use it for advertising or AI-model training, or license it for purposes beyond providing the service. Technical processing is limited to encrypting, temporarily buffering, transmitting, and delivering the file to the recipient you select.

4. Why we process data

We process data to create and verify accounts, link devices, deliver transfers to your selected recipient, display transfer history, send notifications, verify Free/Plus entitlements and store subscriptions, secure the service, prevent abuse, provide support, protect legal rights, and comply with law. Depending on context, the legal basis is performance of a contract, legal obligation, legitimate interests, establishment/exercise/defense of legal claims, or consent where required.

5. Permissions and choices

Dropvia uses operating-system permissions only to read or save files you select, continue user-initiated transfers in the background, check network state, and show notifications if you allow them. Optional features such as automatic saving to Photos can be disabled, and permissions may be withdrawn in device settings. Withdrawal does not affect prior lawful processing but may limit the relevant feature.

6. Providers and international transfers

The main infrastructure is hosted by İBT İstanbul Bilgi Teknolojileri Tic. Ltd. Şti. in Türkiye’s Black Sea region, with backup infrastructure in Istanbul. İBT address: Küçükbakkalköy Mah., Vedat Günyol Cad., Flora Rezidans No:1 Kat:28 E-Ofis, Ataşehir / Istanbul. Google Firebase Cloud Messaging and Apple Push Notification service (APNs) may be used for notifications, and Apple App Store, Google Play, Microsoft Store, or Huawei AppGallery for subscriptions and distribution.

Registration, password, and account-deletion verification emails are sent automatically from no-reply@dropvia.app through the configured SMTP delivery infrastructure; the registered email address, message headers, and security message are processed only as needed for delivery. no-reply@dropvia.app does not accept or monitor incoming replies; support, privacy, and legal messages must be sent to support@dropvia.app.

These parties process only data needed for service delivery, security, distribution, subscription/payment verification, or legal compliance; purpose-limited provider processing is not a sale. Store and notification providers may process data outside Türkiye. Where an international transfer occurs, no transfer is made without a valid mechanism under Article 9 of the KVKK and applicable law. Only the minimum necessary data is disclosed to competent authorities in response to a valid and sufficiently specific legal request.

7. Retention and deletion

  • File content is not stored in the database; Dropvia retains no permanent file copy after the live transfer ends.
  • Transfer, contact, and device-pairing requests and their related notifications are expired and cleaned within a maximum 7-day operational cycle even if an earlier expiry did not occur; an active transfer is first moved safely to a terminal state.
  • Transfer history shown in the app is limited to the latest 20 records per user and no more than 7 days per record. ‘Clear History’ immediately removes that user’s active SQL history rows and prevents older records from reappearing.
  • Device heartbeat records are retained for 7 days; login and standard security records for 30 days. Verification codes are removed on expiry or within 7 days at the latest; revoked or expired authentication tokens are cleaned after 30 days.
  • İBT creates daily incremental and weekly full backups. Data deleted from the active system leaves restricted backups when the provider’s verified rotation and destruction cycle completes; the exact maximum has not yet been confirmed in writing by the provider.

Account, device, subscription, support, and legal records are kept only as long as required to operate the account and service, meet legal duties, resolve disputes, or establish, exercise, or defend rights, then deleted, destroyed, or anonymized.

8. Age requirement

Dropvia is intended only for people aged 16 or older. Users under 16 may not create an account or use the service. If we learn that an account belongs to a person under 16, we may request verification, close the account, and delete related data in accordance with law. If your jurisdiction requires a higher age to enter into a contract, parental or guardian authorization or supervision may be required.

9. Your rights and worldwide availability

Depending on local law, you may have rights of access, information, correction, erasure, restriction, objection, data portability, and withdrawal of consent. Dropvia is offered worldwide where store availability and local law permit; mandatory local privacy and consumer rights remain unaffected.

Account and data rights →

10. Contact and changes

Send your request from your registered email address to support@dropvia.app or use the Account and Data Rights page. Never send a password, verification code, or private key. Material changes will be announced through the app, website, or registered contact channel before they take effect.

© 2026 TrimCode
Site Privacy Site KVKK Site Cookies Site Terms TrimCode Support