Privacy policy
What we keep, and why
In force from: 4 October 2026
01 Who is responsible
codearchive is responsible for the personal data described here (“we”). Questions and requests go to support@coverdropai.com.
02 What we collect
- Your account: your name and email address. If you sign in with Google, the name, email address and profile picture address Google shares with us, and the sign-in tokens Google issues. If you use a password, we store it only as a one-way hash.
- Sign-in sessions: a session token in a cookie, and with each session the IP address and browser description it was started from, and when it expires.
- What you make: the template and format you choose, your title, your description of the picture, any template fields (such as a day number), the instructions we send to the image model, the pictures it returns, the covers we make from them, and which one you circled. With Auto, also the video title you type and, if you add an image, a short description of it that the model choosing the takes writes; each take is a sheet like any other. If you fill it in, what you wrote under “What is the video about?”; when you start from a video link and leave it empty, we fill it from the video’s reading (its topic and the first two sentences of its summary). A sheet started from a video link also keeps its own copy of that reading (see section 4). And the post text we suggest for the video: a title, a description and tags for posting it.
- Photos you add: the photo, re-encoded when it arrives so that hidden metadata such as GPS location is removed and the long edge is at most 2048 pixels, and a record that you confirmed it shows you or someone who agreed, with the time and which version of that wording you agreed to.
- Credits and payments: a record of every credit added, spent or returned; your plan’s status and when its current month ends; and the notices Paddle sends us about your orders and subscription, which identify you and what you bought. Your card or other payment details go to Paddle and never reach us.
- Videos you start from: when you start from a YouTube link, which video it was and when you asked. What we read from the video is kept apart from your account (see section 4), except the copy kept with a sheet you start from it.
- Feedback you send: what you wrote, your rating, what kind of feedback it is, the page you sent it from (without anything after a question mark in its address) and, if it was about one of your own sheets, which one; the site’s language; and your browser’s name, such as Chrome or Safari, without anything else your browser says about itself. Sent while signed in, it is linked to your account; sent signed out, to no one. We don’t store the IP address it came from: to limit how much can be sent from one place, we count a keyed one-way fingerprint of the address, deleted after about two days.
We don’t use advertising or analytics trackers, and we don’t sell personal data.
03 Why we use it
- To run your account and keep you signed in, and to make, keep and deliver your covers: needed to provide the service you asked for.
- To charge for credits through Paddle and keep your balance right: needed for the same reason, and for tax records Paddle keeps.
- To keep CoverDrop secure and prevent abuse, such as images of people without their consent: our legitimate interest.
- To read and act on feedback you send us: our legitimate interest in making CoverDrop better.
- To use a photo of a person: on the confirmation you give when you add it that it shows you, or someone who agreed.
04 Who else sees it
- OpenAI (United States) makes the pictures. They receive your description of the picture, the template’s instructions and, if you added one, your photo. The image model does not receive your title, which we set on the picture ourselves. OpenAI’s data controls page, as we read it on 3 October 2026, says that data sent to its API is not used to train its models unless the customer opts in (we have not), and that abuse-monitoring logs for image generation are kept for up to 30 days, unless longer retention is required by law or is reasonably necessary to protect OpenAI’s services or any third party from harm.
The content check. A photo you add is sent, made smaller, to OpenAI’s moderation service when you upload it, and checked against the content rules in our terms; if that service can’t be reached at that moment, the photo is checked instead when you first create a sheet with it. When you create a sheet, its title, description, template fields and what the video is about (what you wrote, or what we filled in from a video’s reading) are sent to the same service. Apart from Auto and the post text, below, this is the only time your title reaches OpenAI. A message you send with the feedback form goes to the same service too, only to set abuse aside: a message it flags is discarded, and if the service can’t be reached the message is kept unchecked. For the moderation service, the same page lists no abuse-monitoring retention and no application-state retention, and no use for training.
Auto. When you use Auto, your video’s title, what the video is about (as above) and, if you added one, your image (made smaller) are sent to an OpenAI language model, which chooses the takes and describes the image in a few fixed terms (such as what kind of image it is, how many people are in it and how it is framed, never who they are); we keep that description with the Auto sheet. Each picture made for an Auto take is also sent to that model once (twice if it has to be made again) before the words are set on it, to answer three yes-or-no questions: does it show a person, readable text, or a brand logo. Takes made with your own photo are checked too, so those pictures, which show you, also reach that model this way. We keep none of the answers. For this model the same page lists no use for training, abuse-monitoring logs kept for up to 30 days, and no application-state retention.
Post text. To suggest a title, a description and tags for posting your video, we send that same OpenAI language model your video’s title, what you wrote under “What is the video about?” if you filled it in, and the finished cover as a small picture: once when the first cover of a sheet is ready, and again each time you ask for a new suggestion. If the cover was made with your own photo, that picture shows you. For an Auto sheet the words on its covers go too. If the sheet started from a video link, the reading kept with it goes too: the summary, the key moments, the keywords, the sentence said at the start, the tone and who the video is for. So what Google’s model wrote about your video also reaches OpenAI. Your description of the picture is not sent for this. Suggestions pass the content check before we keep them, and are kept with the sheet.
- Paddle (Paddle.com, United Kingdom), our merchant of record, when you buy credits or the plan. Paddle receives what you give it at checkout, what you buy, and your account’s email address and our account id for you, so the purchase reaches the right account. Paddle handles that data under its own privacy notice.
- Google (United States), if you choose to sign in with Google, and when you start from a video link.
Video links. When you start from a YouTube link, CoverDrop uses YouTube API Services: we first ask YouTube once whether the video is public, how long it is and what it is called. Then we send the video’s public address, made from its id (never the text you pasted), and our questions about it to Google’s Gemini API, which looks at the video itself; we never download the video or keep any picture from it. What comes back is a reading: the language spoken, the topic, the key moment, the tone, what is on screen, the sentence said near the start that makes someone keep watching, a summary of what happens and is said (up to 1,200 characters), the main moments with their times, keywords as a viewer would search for them, and who the video is for. People are only a count (none, one or several), never what they look like or who they are, and a name only when it is said aloud or written on screen. We keep a reading for 30 days, apart from any account (one per video, for anyone who asks about the same video), with a note that you asked for it. A sheet you start from the link keeps its own copy of the reading, for as long as the sheet (section 6). Google’s Gemini API terms, as we read them on 4 October 2026, say that on the paid service Google doesn’t use what we send or what it answers to improve its products, logs both for a limited time only to detect abuse and for legal disclosures, and processes them under its data processing terms. YouTube’s data is subject to the Google Privacy Policy.
- Our hosting provider, Hetzner Online GmbH (Gunzenhausen, Germany). Everything we keep, including the database and your photos and covers, is stored with Hetzner in Falkenstein, Germany; the encrypted backups of the database (see below) are stored with Hetzner in Helsinki, Finland.
Using OpenAI, Paddle and Google means some data is processed outside Türkiye and the EU.
05 Cookies
We use two cookies, both needed for signing in. The session cookie keeps you signed in for up to 7 days, and is removed when you sign out. During a Google sign-in only, a second cookie protects the round trip to Google and back; it lasts 5 minutes. There are no analytics or advertising cookies.
When payments are switched on, the pricing page loads Paddle’s checkout script from Paddle (cdn.paddle.com), because Paddle’s checkout opens there. As we checked on 3 October 2026, loading and starting that script stores nothing under coverdropai.com: no cookies, no local or session storage. Paddle’s own servers set one short-lived security cookie on paddle.com (“__cf_bm”, from Cloudflare, which tells people from bots; it lasts about 30 minutes). The checkout itself opens in a frame on Paddle’s site and may store its own cookies or data there, under Paddle’s privacy notice. When you open a checkout, the browser tab also remembers which order it was, in the tab’s own session storage, so the credits page can tell when its credits have arrived; it is removed once they have, and when the tab is closed.
06 How long we keep it
- Your account, your sheets and your covers: while your account is open, so your gallery stays there.
- Sheets and covers you delete: removed at once, with their title, description, field values, what you wrote about the video, the copy of a video’s reading, post text and picture files. Copies in our database backups are gone within 35 days. To make sure a restored backup can’t bring them back, we keep a note of each deletion (what kind, its identifier and when, nothing of the content) for 40 days, a little longer than any backup exists; we keep the same note when an account is closed. Credits spent on them stay spent. Files you downloaded before deleting are on your device and beyond our reach. A photo you uploaded is not removed with a sheet; it has its own deletion and retention, below.
- Auto sheets: their video title, what you wrote about the video, the copy of a video’s reading, image description and post text go with the account, or once every one of their takes is deleted. Of a free Auto sheet we then keep only that it was used, with no title, description, image or post text, so the free ones can’t be had twice.
- Your credit and purchase records (what you bought, and every credit added, spent or returned): kept, also after you close your account, because payment records must be kept. Once the account is closed they no longer carry your name or email address; they keep Paddle’s order numbers, which tie them to Paddle’s own record of each payment.
- Photos you add: deleted 24 hours after you add them if they are never used in a sheet; otherwise 30 days after the last sheet that used them. Pressing Remove on the form deletes one at once; after that, you can ask us to. Covers made with a photo stay in your gallery, and so does the record of your confirmation: each sheet made with the photo keeps when you confirmed it and which wording you agreed to.
- Sign-in sessions: until they expire or you sign out.
- Video readings: deleted 30 days after the video was first read, and with them the note that you asked; closing your account removes the note sooner. The copy kept with a sheet goes when the sheet is deleted or the account is closed.
- Feedback: kept so we can act on it, and deleted two years after it was sent, whether it was sent signed in or not. A message the content check flags as abuse is discarded at once. Deleting a sheet removes the feedback’s link to it; closing your account removes its link to you, and the feedback is kept without it until its two years are up.
- A photo or a sheet the content check refuses: nothing of it is kept. A photo refused when you upload it is never stored; one refused with a sheet is deleted at once. We keep only a count of refusals for that day, for the daily limit in our terms.
- Invitations: if we invite you, the address the invitation went to, when, and who sent it, until you sign up (signing up removes it) or 30 days after it was sent or renewed, whichever comes first. We can remove it sooner.
- Payment notices from Paddle: we intend to keep them for 30 days. Automatic deletion of them is not in place yet; until it is, they are kept.
- Closing your account, when you ask (see below), removes your name, email address, sign-in sessions and sign-in records, sheets, covers and photos, your plan’s details, and our copies of Paddle’s notices about you (Paddle keeps its own records under its own privacy notice). Only the credit and purchase records above stay, without your name or email address, and any feedback you sent, no longer linked to you. Credits left on the account are lost, and the email address can be used for a new account. A running plan ends first: at the end of the month you paid for, or at once if you ask, giving up the rest of that month. Accounts are not closed automatically.
- Short-lived copies of the database, taken before each update of CoverDrop (the last three are kept), can hold your data for a short time after it has been deleted.
- Backups: every night we take an encrypted backup of the database, which holds your account (name and email address), your sheets, your credit and purchase records and any pending invitation. Each backup is kept for up to 35 days and then deleted. A backup is locked once it is made, so it can’t be changed or deleted early, not even by us: data you delete, or an account you close, is gone from the backups within 35 days. Your photos and covers are not in the backups.
07 Your rights
Two of your rights you can use yourself, from the credits page, at any time. A copy of your data: one zip file with your account details, every sheet with its title, description, what you wrote about the video, fields, template and format, your Auto sheets with their video title and image description, your covers at full size, the photos we still keep, your credit and purchase record, the feedback you sent while signed in, and the video links you started from that we still hold; it is made as you download it and not stored, and you can download it a few times a day. Deleting your data and closing your account: at once, with the credit and purchase records in section 6 staying, without your name or email address, and any feedback you sent staying without its link to you.
You can also ask us to correct your data, to restrict or object to how we use it, and to withdraw a consent you gave, or ask for any of the above if you can’t sign in. Write to support@coverdropai.com; we handle these requests by hand and answer within 30 days.
If you are unhappy with how we handle your data, you can complain to Türkiye’s Personal Data Protection Authority (KVKK, kvkk.gov.tr). If you live in the EU or the UK, you can also complain to your local data protection authority, such as the ICO in the UK.
08 Children
CoverDrop is not for anyone under 18, and we don’t knowingly collect their data.
09 Changes
If we change this policy, we will update the date at the top and tell signed-in users at least 14 days before a change that matters takes effect.