Privacy Policy

DE

Zuletzt aktualisiert: 20 August 2026

1. Controller

The controller for personal data on this website within the meaning of the GDPR is:

Maurice-Benjamin Huschke
Am Finkenherd 45, 13589 Berlin, Deutschland
Email: drop-in@cherry-drop.io
Data-protection requests: datenschutz@cherry-drop.io

A DPO is not legally required (Art. 37 GDPR, § 38 BDSG).

2. Your rights

  • Access (Art. 15), rectification (Art. 16), erasure (Art. 17)
  • Restriction (Art. 18), portability (Art. 20), objection (Art. 21)
  • Withdrawal of consent (Art. 7 (3))
  • Complaint to a supervisory authority (Art. 77) — competent for us: Berlin Commissioner for Data Protection and Freedom of Information

3. Server logs

Cloudflare Workers process technical data when you use the app: IP, date/time, URL, status code, user agent, referrer.

Legal basis: Art. 6(1)(f) GDPR. Retention: up to 14 days.

4. Hosting & infrastructure

4.1 Cloudflare

The web application is hosted via Cloudflare Workers/Pages (Cloudflare, Inc., USA; Cloudflare Germany GmbH). Cloudflare provides CDN, DDoS protection and TLS termination.

Legal basis: Art. 6(1)(f) GDPR. Third-country transfer: SCCs. DPA: cloudflare.com.

4.2 Lovable Cloud (Supabase)

Auth, database and file storage are provided via Lovable Cloud, a managed Supabase instance hosted in the EU (Frankfurt).

Legal basis: Art. 6(1)(b) and (f) GDPR. DPA: supabase.com/legal/dpa.

4.3 Lovable AI Gateway (Google Gemini)

For automatic enrichment of shared content (link metadata, classification, short summaries), we call Google Gemini models via the Lovable AI Gateway. Only the content needed for enrichment is transmitted; processing is transient and, per provider terms, is not used for model training.

Legal basis: Art. 6(1)(b) and (f) GDPR. Third-country transfer: SCCs. DPA: Google DPA.

5. Drops, uploads & storage

The core of the app is collecting drops — text, links, code, quotes, contacts, locations and images. Content is stored in the database and, where applicable, in the storage bucket in Lovable Cloud (EU/Frankfurt), accessible only to the authenticated user (row-level security).

Image uploads are stored in the private bucket drops. Access is only via short-lived signed URLs (TTL 1 hour).

Storage quota: 100 MB on the free tier, 50 GB with CherryDrop Plus.

6. Share Target / PWA

CherryDrop is installable as a Progressive Web App and registers a Web Share Target. Content shared via the system share sheet is delivered by the user's browser and processed like a manually captured drop.

7. User account

Required for using the app. Data processed: email address, password (hashed), OAuth identifier for Google/Apple sign-in, display preferences.

Legal basis: Art. 6(1)(b) GDPR. Deletion: at any time via account settings or by email to the data-protection address.

8. Push notifications

Push notifications are only activated after explicit browser consent. We store the push endpoint and encryption keys to deliver messages; actual delivery goes through the browser vendor's push services (Google FCM, Apple APNs, Mozilla). Payloads are end-to-end encrypted.

Legal basis: Art. 6(1)(a) GDPR, revocable at any time in settings.

9. Agent API keys & MCP

You can generate API keys so that AI agents or an MCP server can write drops to your inbox. We store only an irreversible hash; the plaintext secret is shown once and cannot be retrieved thereafter. Each API request logs timestamp and user agent for abuse detection.

9a. Connected AI clients (OAuth)

You can connect external AI clients (for example ChatGPT, Claude, Cursor) to your CherryDrop account via OAuth 2.1. Access is granted explicitly on a consent screen that shows the client name, the signed-in account and the capabilities being granted.

What is shared: a connected client can create drops on your behalf and read or search your own drops. Only the content you ask to save, or the results of your query, are transferred — together with drop ID, type, URL and timestamp. CherryDrop does not read, store or reconstruct any chat history from the client, and never accesses other users' accounts.

What we store: the OAuth grant itself (client identifier, timestamp) and, for drops created through a client, the client name as the source of the drop.

Revocation: you can disconnect at any time in CherryDrop settings and in the client's own connector settings. No further access is possible afterwards; drops already saved remain in your inbox until you delete them.

Legal basis: Art. 6(1)(a) and (b) GDPR.

9b. MCP tools: exact inputs and outputs

Through the MCP server (https://cherry-drop.io/mcp) CherryDrop exposes exactly the tools listed below to connected AI clients. Every request is authenticated against your account (OAuth 2.1 or an agent API key) and is scoped strictly to your own data (row-level security, user_id = auth.uid()). No other tools, fields or data sources exist.

  • create_drop (write) — Input: drop type, content (max. 20,000 characters), optional http(s) URL, optional tag names (max. 10), optional context name. Output: drop ID, creation timestamp, type, content, URL. Stored: the drop in your inbox, including its source (client name and client identifier).
  • search_drops (read-only) — Input: search term (max. 200 characters), optional result limit (max. 50). Output: matches from your own drops with ID, type, content, URL and timestamp. Stored: nothing; search terms are not retained.
  • list_recent_drops (read-only) — Input: optional limit (max. 50). Output: your most recent drops with ID, type, content, URL and timestamp. Stored: nothing.
  • save_context (write) — Input: context name (max. 120 characters), a summary of the conversation state (max. 20,000 characters), optional "replace instead of append" flag. Output: context ID, name, stored summary, last writing agent, timestamp. Stored: the context text in your account — only what the client hands over at your explicit request; there is no automatic capture of chat history.
  • load_context (read-only) — Input: context name, optional limit of attached drops (max. 50). Output: context ID, name, summary, last writing agent, timestamp and the linked drops. Stored: nothing.
  • list_contexts (read-only) — Input: optional limit (max. 50). Output: context ID, name, last writing agent, timestamp. Stored: nothing.

Recipients: tool responses are returned only to the AI client you connected (for example OpenAI/ChatGPT, Anthropic/Claude, Cursor), where that provider's own privacy policy applies. CherryDrop does not pass this data to any other third party, never sells data, and never uses tool content for advertising or for training our own or third-party models.

Cross-agent contexts: a context saved from agent A can be loaded by agent B when both are connected to the same CherryDrop account. This is the intended feature — so do not store content in a context that you would not want the other client to see.

Technical logging: for MCP requests we record timestamp, client identifier, tool name and status code for abuse and error detection — the transmitted content itself is not logged. Retention: max. 30 days.

Legal basis: Art. 6(1)(b) GDPR (providing the function you requested), (a) (consent to the client connection) and (f) (security and abuse prevention).

9c. Your controls

  • Drops and contexts — view, edit and delete individually in the app.
  • Connected AI clients — disconnect at any time in CherryDrop settings and in the client's own connector settings.
  • Agent API keys — rotate or revoke under "API keys".
  • Push notifications — disable at any time in settings or in your browser.
  • Data export (Art. 20 GDPR) and access requests — by email to the data-protection address.
  • Full account deletion — in settings ("Danger Zone") or via account deletion. This removes your account, drops, contexts, tags, uploads, push endpoints and API keys; only invoicing data subject to statutory retention remains.

10. Payments via Stripe

Paid orders (CherryDrop Plus) are processed via Stripe as a payment service provider. The contractual counterparty remains the provider (Maurice-Benjamin Huschke); Stripe is not a Merchant of Record.

Provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Irland

Data transferred to / processed by Stripe includes: email; name and billing address (where provided); payment-method data (entered directly at Stripe, not accessible to us); IP, device and browser data (fraud prevention); internal user ID; order data (product, price, status, term).

Legal basis: Art. 6(1)(b), (c) and (f) GDPR. Retention: statutory record-keeping periods (§ 147 AO, § 257 HGB — generally 10 years). Third-country transfer: SCCs. DPA: stripe.com/legal/dpa. Privacy: stripe.com/privacy.

11. Email

Contact by email will result in your details being stored to handle your request. Auth emails (confirmation, password reset) are sent via Lovable Cloud from noreply@cherry-drop.io. System and contact emails come from drop-in@cherry-drop.io.

12. Cookies & Web Storage

We only use technically necessary storage. Details in the cookie policy.

No tracking or advertising cookies. No profiling, no cross-site tracking, no data shared with ad networks.

13. Retention

  • Cloudflare server logs: max. 14 days
  • MCP / API access logs (no content): max. 30 days
  • Auth token (browser): until logout / session expiry
  • Account data, drops, contexts, tags and uploads: until deleted by the user or until account deletion
  • OAuth grants for connected clients: until revoked
  • Agent API key hashes: until revoked by the user
  • Support and contact emails: 24 months after the request is closed
  • Billing / payment history: statutory retention periods (10 years)
  • Push endpoints: until revocation or invalidation

14. Third-country transfers

Where data is transferred to third countries (Cloudflare, Stripe, Google/Lovable AI Gateway), transfers are covered by EU Standard Contractual Clauses plus supplementary technical measures (encryption in transit and at rest). The production database is hosted in the EU region Frankfurt.

15. Data-protection impact assessment

A DPIA under Art. 35 GDPR is not required — no systematic large-scale profiling, no special-category data.

16. Breach notification

Please report data-protection incidents to datenschutz@cherry-drop.io. Notifiable breaches under Art. 33 GDPR are reported to the supervisory authority within 72 hours.

17. Contact

Questions about privacy: datenschutz@cherry-drop.io.