Cookie Policy
What Dropable stores in your browser, and why none of it needs your consent.
- Version:
- 2026-08-15
- In force since:
- 2026-08-15
- Last updated:
- 2026-08-15
Dropable stores only what is strictly necessary to provide the service you requested. We load no third-party analytics or marketing script, so no consent banner is shown.
This page lists every entry, what it is for, and how long it lasts.
2. No third-party tracking
We do not use Google Analytics, Google Tag Manager, Meta Pixel, or any comparable third-party analytics, advertising or tracking service. No such script is included in the pages we deliver.
We measure product usage ourselves, on our own infrastructure. On public pages that measurement records no visitor identifier and no session identifier, so it cannot be related to an individual and needs no consent. The privacy policy at https://dropable.io/privacy describes it in full.
3. Strictly necessary entries
These are set for every visitor or user for whom they are relevant.
| Name | Type | Purpose | Duration |
|---|---|---|---|
| sb-… (authentication) | Cookie | Keeps you signed in and refreshes your session. Set by our authentication provider. | Until sign-out; refreshed while active |
| NEXT_LOCALE | Cookie | Remembers the language you selected, so links sent by email open in it. | 1 year |
| theme | Local storage | Remembers your light or dark appearance preference and prevents a flash of the wrong theme. | Until you clear it |
| dropable_share_unlock_… | Cookie | Records that you successfully unlocked a password-protected share link, so you are not asked again on every file. | Session |
| dropable_referral_code | Cookie | Remembers the referral or access code you arrived with, so it survives sign-up. | 90 days |
| dropable_onboarding_flow | Cookie | Carries your selection through account creation, so choosing a plan before signing up is not lost. | Until onboarding completes |
4. Entries in the signed-in area only
These exist only after you sign in, and are never set on public pages.
| Name | Type | Purpose | Duration |
|---|---|---|---|
| dropable_product_analytics_anon_id | Local storage | Relates product events from the same browser, so a workflow can be followed across steps within the application. | Until you clear it |
| dropable_product_analytics_session_id | Session storage | Groups product events belonging to one working session. | Until the tab is closed |
These identifiers are neither read nor written on public pages. That boundary is enforced on the server as well, so a modified browser cannot opt itself in.
5. The consent record
Our consent mechanism exists but is inactive, because nothing currently requires consent. It would store one entry, and only once you had made a choice:
| Name | Type | Purpose | Duration |
|---|---|---|---|
| dropable_cookie_consent | Cookie | Records the choice you made, so you are not asked again. Not set unless the consent banner is active and you have decided. | 180 days |
If we ever introduce processing that requires consent, the banner is activated, this page is updated to describe the new entries, and consent is obtained before that processing begins.
6. Controlling browser storage
You can delete cookies and local storage at any time in your browser settings, and block them entirely for this site.
Blocking the entries above will sign you out, reset your language and appearance preference, and require you to unlock protected share links again. It does not stop any tracking, because none takes place.