Privacy Policy
What BlindDrop stores, for how long, and what it can never see.
Zero-knowledge architecture
BlindDrop is designed with your privacy as the absolute priority. All encryption and decryption of secrets happen directly in your browser. We never receive, store, or have access to your plaintext information, fragment keys, or passphrases. The v2 API stores only the versioned encrypted envelope, its non-secret passphrase salt when present, and a one-way burn-token hash until reveal or expiry.
Ephemeral storage
Secrets are stored in an encrypted format in our ephemeral storage (Redis). The encrypted envelope is deleted when it is delivered once or when its selected time-to-live expires. Browser copies, screenshots, backups, and infrastructure snapshots are outside the service's control.
- Immediately after the envelope is delivered to the recipient's browser.
- Automatically when the selected time-to-live (TTL) expires.
No personal data collection
We do not collect any personal information such as your name, email address, or IP address for tracking. We do not use third-party tracking cookies or sell your data. We use Cloudflare Turnstile to prevent automated abuse, which may collect minimal telemetry to ensure you are human.
Open and transparent
Our goal is to build trust through technology. BlindDrop is a utility provided by ATAS Tech to help the community share sensitive data securely and privately.