KeyDrop KeyDrop trim. balance. trigger.

Privacy Policy

Last updated: 2026-07-25

Who we are

KeyDrop is a personal soundboard web app, built and operated by its developer (contact: [email protected]), who is the data controller. It runs on a single server rented from DigitalOcean and located in Germany (European Union).

What we collect, and why

  • Your account — name, email address and a hashed password. If you sign in with Google, we also store the Google account identifier and avatar URL Google returns. Purpose: to operate your account and keep your sounds yours.
  • Audio source files — the audio you upload, or the audio downloaded on your instruction from a YouTube URL you paste. Purpose: so you can cut clips from it.
  • Clips — the trimmed, loudness-normalized excerpts you create from those sources, plus the pad/hotkey they are assigned to.
  • Waveform peak data — a small numeric summary derived from each source so the editor can draw the waveform without re-reading the whole file.
  • Strictly-necessary cookies — a session cookie and a CSRF token. Nothing else.

Legal basis: performance of the service you asked for (Art. 6(1)(b) GDPR), plus your consent for holding the account itself (Art. 6(1)(a)), recorded when you tick the box at sign-up. KeyDrop does not collect or want special-category data (Art. 9) — please do not upload audio that contains it.

Where your audio is processed

On the same server that hosts the app. Downloading from YouTube (yt-dlp), loudness normalization and trimming (FFmpeg) all run locally on that machine. Your audio is never sent to any third-party AI, transcription, or audio-processing provider. There is no model training of any kind.

Who else is involved (sub-processors)

  • DigitalOcean — hosting of the server and its disk (EU region, Frankfurt, Germany). They hold the infrastructure your data sits on.
  • Google / YouTube — only when you ingest a YouTube URL. The download request goes to Google's servers from our server, so Google sees that request (and its originating server IP). If you use Google sign-in, Google also processes that authentication.

That is the complete list. No analytics, no advertising or tracking pixels, no marketing email, no newsletter, no data sold or shared with anyone else.

Security

Traffic is encrypted end to end over HTTPS. Passwords are hashed (bcrypt). Your audio is stored on a private disk area that is not publicly browsable and is served only through routes that check your session — sources and clips are kept under a directory keyed to your own account.

How long we keep it

Until you delete it. A clip or source is gone when you delete it; everything is gone when you delete your account. There is no hidden archive and no backup copy kept for marketing or analytics purposes.

Your rights

  • Access & portability (Art. 15 / 20) — download a machine-readable JSON export of everything we hold about you from your Profile page, at any time, with one click.
  • Erasure (Art. 17) — delete your account from your Profile page. This removes your account record and permanently deletes your uploaded sources, your clips and their waveform data from the server's disk. It cannot be undone.
  • Rectification (Art. 16) — edit your name, email and password from your Profile page; re-record, re-cut or delete any clip.
  • Restriction / objection (Art. 18 / 21) — write to the address above.
  • Withdrawing consent — deleting your account withdraws it in full.
  • Complaint — you may lodge a complaint with your national data-protection supervisory authority.

Changes to this policy

If the processing changes — in particular if a new processor is ever added — this page is updated with it and the date at the top changes.

← Back to sign in Create an account