Back to DropBG
GDPR (DSGVO) & Data Protection

Privacy Policy

Effective date: September 21, 2026 • DropBG (dropbg.io)

No Permanent Storage

Uploaded files are kept in volatile memory or ephemeral storage only for the processing duration, and cleared automatically.

Explicit Training Consent

Images are never used for AI training without your explicit affirmative opt-in via the quality feedback dialog.

Full GDPR Rights

Enjoy complete rights to access, rectification, objection, and deletion under Articles 15–22 of the EU General Data Protection Regulation.

1. Overview and Data Controller

DropBG (“we”, “us”, or “our”) operates the web service at dropbg.io providing automated, AI-assisted image background removal and edge segmentation.

We take the protection of your personal data very seriously. We handle your personal data confidentially and in accordance with statutory data protection regulations, specifically the European Union General Data Protection Regulation (EU GDPR / DSGVO) and applicable local data protection legislation.

Controller within the meaning of Art. 4(7) GDPR:
DropBG is an independent, single-developer project.
Direct contact: dropbg@pm.me

2. Processing of Uploaded Images and Content

When you upload an image to DropBG via our web interface or REST API, the image is transmitted over encrypted TLS 1.3 channels to our backend inference cluster.

  • Ephemeral Execution: The image is parsed to detect foreground contours (such as people, products, clothing, or objects) and render the transparent cutout or requested background effect.
  • Immediate Purge: Uploaded input images and generated cutouts are processed ephemerally. They are not stored permanently on persistent media. Temporary buffers or scratch cache files are automatically purged after the processing cycle concludes.
  • No Public Exposure: Your images are private to your current browser session and cannot be indexed, browsed, or viewed by other users.

3. AI Model Training & Voluntary Feedback Donation (Art. 6(1)(a) GDPR)

Unlike standard commercial services that covertly retain user data, DropBG never utilizes your uploaded photos for machine learning or neural network training by default.

You may optionally submit an image quality report if an edge or cutout did not meet expectations. In that feedback modal:

  • You are presented with a distinct, unchecked or selectable consent toggle: “Donate image to improve future model training”.
  • Only if you affirmatively consent will the failure image and accompanying issue tags be preserved in an isolated dataset for machine learning optimization.
  • Revocation of Consent: You may withdraw your consent at any time with future effect by emailing dropbg@pm.me citing your feedback date or session reference.

4. Local Browser Storage (Client-Side History)

DropBG offers a convenient client-side “Recent Creations” history tray. This feature uses your browser’s native localStorage.

This data remains strictly on your local device. It is not synchronized to external third-party marketing servers. You can clear this history anytime by using the “Clear” button or by clearing your browser site cache.

5. Server Logs and Technical Telemetry (Art. 6(1)(f) GDPR)

For system integrity, DDoS prevention, rate limiting, and capacity optimization, our web servers automatically process technical connection metadata:

  • IP address (anonymized/hashed where applicable)
  • Timestamp, request method, and HTTP status code
  • Processing time in milliseconds and image dimensions
  • User agent and operating system version

The legal basis for this processing is Art. 6(1)(f) GDPR (legitimate interests in operating a resilient, secure, and performant service).

6. Privacy-Friendly Analytics

We prioritize user privacy by avoiding intrusive cross-site tracking cookies. We utilize self-hosted or privacy-first telemetry (such as Plausible Analytics) that does not employ persistent tracking cookies, does not collect personally identifiable information (PII), and is fully compliant with GDPR, CCPA, and PECR without requiring an intrusive cookie consent banner.

7. Your Rights Under the GDPR (DSGVO)

As a data subject in the European Union / European Economic Area, you have the following guaranteed rights:

Right to Access (Art. 15 GDPR)Request confirmation and disclosure of data processed about you.
Right to Erasure (Art. 17 GDPR)Request immediate deletion (“right to be forgotten”) of your personal data.
Right to Rectification (Art. 16 GDPR)Request correction of inaccurate or incomplete personal records.
Right to Object & Restrict (Art. 18, 21 GDPR)Object to processing based on legitimate interests or request restriction.

To exercise any of these rights, simply reach out at dropbg@pm.me. You also have the right to lodge a complaint with a competent data protection supervisory authority.

8. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to adapt to technical advancements or evolving legal obligations. Any updates will be posted on this page with an updated revision date.