Privacy policy
What we keep, and why
In force from: 2 October 2026
01 Who is responsible
codearchive, operated by Taner Tombaş, Kuzguncuk Mah., İcadiye 9, Üsküdar, İstanbul, Türkiye, is responsible for the personal data described here (“we”). Questions and requests go to support@coverdropai.com.
02 What we collect
- Your account: your name and email address. If you sign in with Google, the name, email address and profile picture address Google shares with us, and the sign-in tokens Google issues. If you use a password, we store it only as a one-way hash.
- Sign-in sessions: a session token in a cookie, and with each session the IP address and browser description it was started from, and when it expires.
- What you make: the template and format you choose, your title, your description of the picture, any template fields (such as a day number), the instructions we send to the image model, the pictures it returns, the covers we make from them, and which one you circled.
- Photos you add: the photo, re-encoded when it arrives so that hidden metadata such as GPS location is removed and the long edge is at most 2048 pixels, and a record that you confirmed it shows you or someone who agreed, with the time and which version of that wording you agreed to.
- Credits and payments: a record of every credit added, spent or returned; your plan’s status and when its current month ends; and the notices Paddle sends us about your orders and subscription, which identify you and what you bought. Your card or other payment details go to Paddle and never reach us.
We don’t use advertising or analytics trackers, and we don’t sell personal data.
03 Why we use it
- To run your account and keep you signed in, and to make, keep and deliver your covers: needed to provide the service you asked for.
- To charge for credits through Paddle and keep your balance right: needed for the same reason, and for tax records Paddle keeps.
- To keep CoverDrop secure and prevent abuse, such as images of people without their consent: our legitimate interest.
- To use a photo of a person: on the confirmation you give when you add it that it shows you, or someone who agreed.
04 Who else sees it
- OpenAI (United States) makes the pictures. They receive your description of the picture, the template’s instructions and, if you added one, your photo. They do not receive your title, which we set on the picture ourselves. OpenAI’s data controls page, as we read it on 2 October 2026, says that data sent to its API is not used to train its models unless the customer opts in (we have not), and that abuse-monitoring logs for image generation are kept for up to 30 days, unless longer retention is required by law or is reasonably necessary to protect OpenAI’s services or any third party from harm.
- Paddle (Paddle.com, United Kingdom), our merchant of record, when you buy credits or the plan. Paddle receives what you give it at checkout, what you buy, and your account’s email address and our account id for you, so the purchase reaches the right account. Paddle handles that data under its own privacy notice.
- Google (United States), only if you choose to sign in with Google.
- Our hosting provider, Hetzner Online GmbH (Gunzenhausen, Germany). Everything we keep, including the database and your photos and covers, is stored with Hetzner in Falkenstein, Germany.
Using OpenAI, Paddle and Google means some data is processed outside Türkiye and the EU.
05 Cookies
We use two cookies, both needed for signing in. The session cookie keeps you signed in for up to 7 days, and is removed when you sign out. During a Google sign-in only, a second cookie protects the round trip to Google and back; it lasts 5 minutes. There are no analytics or advertising cookies.
06 How long we keep it
- Your account, your sheets and your covers: while your account is open, so your gallery stays there.
- Your credit and purchase records: while your account is open.
- Photos you add: deleted 24 hours after you add them if they are never used in a sheet; otherwise 30 days after the last sheet that used them. Pressing Remove on the form deletes one at once; after that, you can ask us to. Covers made with a photo stay in your gallery, and so does the record of your confirmation: each sheet made with the photo keeps when you confirmed it and which wording you agreed to.
- Sign-in sessions: until they expire or you sign out.
- Payment notices from Paddle: we intend to keep them for 30 days. Automatic deletion of them is not in place yet; until it is, they are kept.
- Closed accounts: deleted by hand when you ask (see below). There is no automatic deletion of accounts yet.
07 Your rights
You can ask us for a copy of your data, to correct it, to delete it and your account, to restrict or object to how we use it, and to withdraw a consent you gave. Write to support@coverdropai.com; we handle requests by hand and answer within 30 days.
If you are unhappy with how we handle your data, you can complain to Türkiye’s Personal Data Protection Authority (KVKK, kvkk.gov.tr). If you live in the EU or the UK, you can also complain to your local data protection authority, such as the ICO in the UK.
08 Children
CoverDrop is not for anyone under 18, and we don’t knowingly collect their data.
09 Changes
If we change this policy, we will update the date at the top and tell signed-in users at least 14 days before a change that matters takes effect.