Privacy Policy
Last updated: May 22, 2026
1. Introduction
DropNotify ("we," "us," or "our") operates the dropnotify.app website, Chrome and Firefox browser extensions, and the Trainers Collective mobile apps for iOS and Android (collectively, the "Services"). This Privacy Policy explains how we handle information when you use our Services.
The mobile apps (published under "The Trainers Collective" on the App Store and Google Play) are part of the same DropNotify platform and are covered by this policy.
2. Information We Collect
We collect minimal information necessary to provide our Services. Specifically, we only collect:
- Account Identifier: When you sign in to the mobile app we create a stable internal user ID. Depending on the sign-in method you choose, this ID is derived from your Discord ID, Apple ID, Google account ID, or a username you created. We never see or store passwords for Apple, Google, or Discord — those credentials are verified by the identity provider, not by us.
- Email Address (Optional): If you sign in with Apple, you may choose to share your real email or Apple's private relay address. If you sign in with Google, your account email is provided as part of the sign-in token. We store the email solely to recognize you on future sign-ins from another device and to support account deletion requests. We never email you for marketing.
- Display Name: A username or display name you choose (or, for OAuth providers, the name returned by Apple/Google/Discord), used to greet you in the app.
- Alert Preferences: Your personally configured alert settings (which product categories, retailers, or specific SKUs you want notifications for). These preferences are stored solely to deliver the alerts you have requested.
- Followed SKUs: The list of specific products you have tapped "+" to follow. Stored server-side so your follows sync across devices and so we can route restock alerts to you.
- Push Notification Tokens: If you enable push notifications, we store your device's APNs (iOS) or FCM (Android) token. This token is what Apple or Google uses to deliver our alerts to your specific device. It does not identify you personally.
- Subscription Receipts: If you purchase the Trainer+ subscription via in-app purchase, the App Store or Google Play sends us a cryptographically-signed receipt confirming the purchase. We store this receipt solely to verify your subscription status. We never see your credit card or payment details — those stay with Apple or Google.
- Notification History: The titles and bodies of alerts we have sent you, stored so you can see your past alerts in the app's Feed tab. This is the same data the alert push itself contained — no additional tracking.
- Approximate Location (Opt-In Only): The app's In-Store Restock Map feature lets you enter a ZIP code or grant location permission to show nearby restocks. If you opt in, we store your latitude/longitude or ZIP code on your device only — we do not transmit your location to our servers and we do not track movement.
3. Information We Do NOT Collect
We do not collect, store, or process any of the following:
- Phone numbers or physical mailing addresses
- Credit card, debit card, or banking information
- Browsing history or web activity outside of our Services
- Advertising identifiers (IDFA on iOS, AAID on Android)
- Background location data or device-movement tracking
- Cookies for tracking or advertising purposes
- Contacts, photos, microphone, or camera data
- Any data from other apps or extensions on your device
- Analytics events identifying individual users (Firebase Analytics is disabled in the mobile apps)
4. How We Use Your Information
The information we collect is used exclusively to:
- Deliver restock alerts and push notifications you have opted into
- Authenticate you when you sign in across devices
- Sync your followed SKUs and preferences between phone, web, and extensions
- Verify your Trainer+ subscription status so paid features unlock correctly
- Show your past alerts in the in-app Feed
- Provide customer support when you contact us
We do not use your information for advertising, marketing, third-party analytics, or any other purpose.
5. Data Sharing
We do not sell, trade, rent, or otherwise share your information with any third parties for their own use. We rely on a small number of service providers strictly to operate the Services:
- Firebase Cloud Messaging (Google):receives the alert payload and your device's push token solely to deliver notifications. No analytics or advertising data is collected.
- Apple Push Notification service: same role as Firebase for iOS devices.
- Supabase: our backend database provider, hosts the data described in Section 2 on our behalf.
- Apple App Store / Google Play: process Trainer+ subscription purchases and return signed receipts to us. We never see your payment method.
We do not share your alert preferences, followed SKUs, or sign-in identifiers with anyone outside of these operational providers.
6. Data Storage & Security
Account data, alert preferences, and followed SKUs are stored securely on our servers, hosted in the United States. Push tokens, subscription receipts, and notification history are stored alongside your account record. We use HTTPS in transit and industry-standard access controls at rest. Since we collect minimal information, the risk surface is inherently small.
7. Account Deletion
You may at any time:
- Modify or delete your alert preferences within any of our apps or extensions
- Remove individual followed SKUs at any time from the Following list
- Uninstall our apps or extensions, which removes all locally stored data
- Delete your entire account, including all preferences, follows, push tokens, and notification history, by tapping Settings → Delete Account inside the mobile app, or by contacting us through our Discord community
Deleting your account does notautomatically cancel an active Trainer+ subscription — please manage subscriptions in your App Store or Google Play account settings.
8. Children's Privacy
Our Services are not directed to children under 13. We do not knowingly collect any personal information from children. If you believe a child has provided us with information, please contact us and we will promptly delete it.
9. Your Rights
Depending on your jurisdiction (GDPR, CCPA, etc.) you may have the right to access, correct, or delete the personal data we hold about you. Because we collect so little, most of these requests can be self-served via the in-app Delete Account flow. For anything else, contact us through our Discord community and we will respond within a reasonable timeframe.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date. Continued use of our Services after changes constitutes acceptance of the revised policy.
11. Contact Us
If you have any questions about this Privacy Policy, please reach out to us through our Discord community server.
