Privacy Policy
Short version. Dropbrook pays real money for actions on a website, which attracts large-scale automated abuse. To tell people apart from bots we collect more technical and behavioural data than an ordinary website does — how your connection behaves, how your device is configured, and how you interact with the page.
We use it to detect fraud and to run the service. We do not sell it. This page describes it in specific terms.
1. Who we are
Dropbrook operates the website at dropbrook.com and is the
controller of the personal data described in this policy.
You can reach us about anything in this policy, including to exercise the rights in section 7, at help@dropbrook.com. We read that address ourselves; there is no separate privacy department.
The operator is established in Ukraine, and your data is processed there. Ukrainian data protection law applies to us, and the supervisory authority competent for us is the Ukrainian Parliament Commissioner for Human Rights (the Ombudsman), who oversees personal data protection in Ukraine.
If you are in the European Economic Area or the United Kingdom, the protections described in this policy are offered to you as well, and you may also complain to the data protection authority of the country where you live. You do not have to come to Ukraine to raise a concern.
Dropbrook is run by a single operator rather than a large organisation; the operator’s registered details will be added to this section before registration opens. Registration is currently closed and no user data is being collected yet.
2. What we collect
2.1 Account data
| Data | Notes |
|---|---|
| Email address | Stored both as you typed it and in a canonical form (lowercased, dots and “+” suffixes removed) used to enforce one account per person |
| Password | Never stored. We store only a cryptographic hash from which the password cannot be recovered |
| Recovery codes | Stored as hashes only |
| FaucetPay identifier | A hash provided by FaucetPay that identifies your payout account |
| Account activity | Claims, rewards, holds, reversals, payouts, logins |
2.2 Technical and connection data
Collected automatically when you use the site:
| Data | Purpose |
|---|---|
| IP address, and the network/ASN it belongs to | Fraud detection, rate limiting, country |
| Approximate country and region from IP | Determined locally from an offline database; not sent to a lookup service |
| Whether the connection appears to use a proxy, VPN, hosting provider, or Tor | Access control and fraud scoring |
| Characteristics of the connection itself — timing, protocol behaviour, TLS and TCP properties | Distinguishing real browsers from automated clients |
| WebRTC and STUN probe results, including the network address our probe server observes where your browser exposes it, and whether that address differs from the one used for the website request | Detecting proxies, VPNs, and inconsistencies typical of automation |
| Browser and device configuration: user agent, screen size and pixel ratio, language, time zone, CPU cores, memory, graphics adapter, available fonts | Device consistency checks |
| Result and timing of a computational proof-of-work task | Making mass account creation expensive |
2.3 Behavioural data
We record how you interact with the page: pointer movement, click and key timing, focus changes, scrolling, the sequence of pages you move through, and how long each step takes.
This is used to distinguish human interaction from scripted interaction. We do not record the contents of what you type — only timing and structural characteristics. Passwords and recovery codes are excluded entirely.
Sampling is limited: detailed traces are captured at a bounded rate per user rather than continuously.
2.4 Advertising delivery signals
We check whether advertising that should have been shown was actually delivered — for example whether ad resources loaded or were blocked. We record the result of that check, not the content of any advertisement.
2.5 Email delivery records
For each verification or recovery email we record which provider sent it, the provider’s message identifier, when it was sent, when the code expires, whether and when the code was used, how many attempts were made, and any bounce or complaint reported back to us.
For support replies we record the provider, the message identifier, the time it was sent, and any bounce or complaint. There is no code involved.
We use this to route messages to whichever provider is delivering reliably. We do not use open-tracking pixels or click tracking in these emails.
2.6 Data we receive from partners
Offer and advertising providers send us notifications about your activity on their side. These contain a transaction identifier, the identifier we gave them for you, the reward, its monetary value, the status (including reversals), the offer or task involved, your IP address and country as recorded by them, and a signature. We store these records to credit rewards correctly and to investigate disputes.
2.7 Derived data
From the above we compute a risk score and related indicators, and we group accounts that appear to be operated by the same person or the same infrastructure.
2.8 Communications
If you email help@dropbrook.com, we keep the message body, your address,
any attachments, and the technical headers of the email.
3. Why, and on what legal basis
| Purpose | Basis |
|---|---|
| Creating and running your account, crediting rewards, sending payouts | Performance of our agreement with you |
| Sending verification and account codes | Performance of our agreement |
| Detecting and preventing fraud, automation, and multiple accounts | Our legitimate interest in operating a service that pays money and cannot function if abused; also the interest of honest users, who are paid from the same budget |
| Security of the service and of our infrastructure | Legitimate interest |
| Meeting the requirements of our advertising and payment partners regarding invalid traffic | Legitimate interest, and compliance with the terms on which those partners serve us |
| Responding to your support messages | Legitimate interest |
| Accounting records and responding to lawful requests | Legal obligation |
Where the law of your country requires consent for any of the above, we ask for it separately and you may withdraw it. Withdrawing consent to anti-fraud processing means we cannot operate the account, because we would be unable to establish that rewards are earned by a person.
4. Automated decisions
We make some decisions about accounts automatically, based on the data above. What a machine may decide on its own is deliberately limited.
Decided automatically: reducing limits, restricting features, placing a temporary hold on rewards, delaying a payout pending review, and reversing a reward that a third-party provider has itself reversed.
Decided only after a person has reviewed the case: permanently cancelling rewards that were not reversed by a provider, closing an account, and forfeiting a balance.
For any of these decisions you have the right to obtain human intervention, to express your point of view, to receive an explanation of the category of problem detected, and to contest the decision. Write to help@dropbrook.com from your account address and explain the situation.
We do not publish the detail of how the scoring works, because that would tell the people we are defending against exactly what to change. We will tell you what category of problem was detected.
5. Who we share it with
We do not sell personal data and we do not share it for third-party advertising profiling. We share it with the following service providers, each for a specific purpose:
| Provider | What they receive | Why |
|---|---|---|
| Cloudflare | All traffic to the site, including IP address and request data; email sent to our domain | Delivering the site, protecting it from attack, receiving mail |
| FaucetPay | Sent: your payout identifier, email, or address, the amount and currency, and your IP address where required. Received: validation status, payout status or error, a transaction identifier, and a FaucetPay user hash | Sending payouts and confirming they arrived |
| Brevo, Resend, Mailtrap | Your email address and the message sent to you | Delivering verification, recovery, and support email |
| BitcoTasks, AdsLab | A pseudonymous identifier for you (not your email), your IP address, and your country | Providing optional offers and attributing completion; their own fraud checks |
| Advertising networks — at launch, FaucetPay Ads and A-ADS | Data their ad code collects in your browser, which typically includes IP address and browser characteristics | Displaying advertising, which funds the rewards |
These providers process the data under their own privacy policies.
When you open or complete a third-party offer, task, or shortened link, you are dealing with that provider directly. They and their advertisers may collect their own identifiers, cookies, device or browser fingerprints, completion and reversal data, and fraud signals, and may share those with each other and with payment processors. Their policies apply to that processing, not ours. Offer providers state expressly that they may share such data with advertisers and partner networks for fraud prevention.
We may also disclose data where required by law, or to establish or defend legal claims.
6. How long we keep it
| Category | Kept for |
|---|---|
| Raw behavioural traces (pointer, timing, page sequence) | 14–30 days |
| Session and connection signals used for scoring | 3–6 months |
| Daily per-account statistics | 180 days |
| Reward and payout ledger entries | 12 months in detail, then retained in aggregated form for accounting |
| Partner notifications (offer completions and reversals) | 12 months |
| Support email | 12 months after the matter is closed |
| Record of which version of these documents you accepted | For as long as needed to show what applied, and after account closure for the limitation period |
| Administrative action log | Retained as an audit record |
| Fraud records (identifiers of accounts closed for abuse, and the reason) | Retained after closure — see section 7 |
These are the periods we apply. Where a period is expressed as a range, the exact value depends on the data volume we can hold; we will tell you the value in force for a specific category if you ask.
The outer limit: five years
No personal data is kept for longer than five years, counted from the closure of your account or from your last activity, whichever is later — unless the law requires us to keep it longer, or a legal claim or investigation involving it is still open.
Five years is a ceiling, not a default. Most data is deleted far earlier, on the periods in the table above, and we do not extend those periods to the ceiling simply because we may. Two things justify the ceiling:
- Accounting. Records of payments we made have to be retainable for the period required of any business that pays money out.
- Legal claims. A claim about a payout or an account decision can be brought after the fact. If we deleted everything immediately, neither you nor we could establish what actually happened.
Records reaching the ceiling are the durable ones — account and payout history, records of decisions taken on an account, evidence of which version of these documents was accepted, and fraud records. Raw behavioural and technical data never reaches it: it is deleted within weeks or months, both because it is not needed for longer and because keeping years of it is not physically possible at the volume it is produced.
Some records are kept for as long as the account exists and are dealt with on closure rather than on a timer: your account and email records, the identity links used to enforce one account per person, the record of decisions taken on the account, and the queue of payouts in progress. Section 7 explains what happens to these when an account is deleted.
7. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you;
- correct inaccurate data;
- have data deleted;
- receive your data in a portable form;
- object to, or ask us to restrict, processing based on legitimate interest;
- withdraw consent where processing is based on consent;
- complain to your data protection authority.
To exercise any of these, write to help@dropbrook.com from your account address, or from another address with enough information for us to identify the account safely.
We normally respond within one month. Where the law allows an extension because a request is complex, we will tell you within that month and explain why. We may need to verify that the request really comes from the account holder, and we may refuse requests that are manifestly unfounded or excessive — if we do, we will say so and explain your options.
The limit on deletion, stated plainly
If you ask us to delete your account, we delete or anonymise your personal data. Some records necessarily survive. They are listed below.
| What remains | Why |
|---|---|
| Reward and payout records, in a form no longer linked to your identity where possible | Accounting, and the ability to answer a dispute about a payment we made |
| The record that a person accepted a given version of these documents, and when | Without it we cannot show on what terms the account operated |
| Administrative actions taken on the account | Audit integrity — a log that can be edited by deletion is not a log |
| Where the account was closed for abuse: the identifiers needed to recognise the same person returning, and the reason | Otherwise deletion becomes a way to reset a fraud history and register again immediately |
We keep the last of these on the basis of our legitimate interest in protecting the service and the honest users who are paid from the same budget. It is limited to what that purpose requires. You may object, and we will consider the objection on its facts — including whether the original finding was correct.
8. Cookies and local storage
We use browser storage only for what the site needs to work:
- a session identifier so you stay logged in;
- your theme preference (light or dark);
- short-lived technical values needed for security checks.
We do not use our own analytics or advertising cookies.
As for advertising: our intention is to use contextual advertising that does not require cookies or tracking-based consent, so that no consent banner is needed. If we ever serve advertising that sets cookies or similar identifiers on your device where consent is required, we will ask for that consent first, with an equally easy way to refuse and to withdraw it later, and this policy will be updated to name the partners involved before that happens.
9. Security
- Traffic is encrypted in transit.
- Passwords are stored only as hashes produced with a memory-hard algorithm and an additional secret that is held outside the database — so a copy of the database alone is not enough to test password guesses.
- Recovery codes and verification codes are stored as hashes.
- Access to production systems is restricted and logged.
No system is perfectly secure. If a breach affects your data, we will notify you and the relevant authority where the law requires it.
10. International transfers
Our providers operate in several countries, including outside your own:
| Provider | Role | Where it processes data |
|---|---|---|
| Dropbrook (us) | Running the service | Ukraine |
| Cloudflare | Site delivery, protection, inbound email | Global network, including the EU and the US |
| Brevo | Sending email | European Union |
| Resend | Sending email | European Union (region selected: eu-west-1) |
| Mailtrap | Sending and testing email | European Union |
| FaucetPay | Payouts | Outside the EU |
| BitcoTasks, AdsLab | Offer providers | Outside the EU |
| Advertising networks | Serving advertising | Varies by network |
We process your data in Ukraine. Ukraine is not among the countries the European Commission has recognised as offering an equivalent level of protection, so if you are in the EEA or the UK your data is processed outside that framework. We apply the protections described in this policy regardless, and you keep the right to complain to your own authority (section 1).
Our providers fall into two groups, and the protections differ:
- Providers acting on our instructions (Cloudflare, Brevo, Resend, Mailtrap) process data under a data processing agreement, and we rely on the transfer safeguards in it — normally standard contractual clauses.
- Providers acting on their own account (FaucetPay, offer providers, advertising networks) decide for themselves how they use the data they receive. The transfer happens because it is necessary to pay you, or because you chose to use an optional offer. We do not control their safeguards, and their own privacy policies apply.
We will update this section before adding any advertising network not named above.
11. Children
The Service is for people aged 18 and over. We do not knowingly collect data from children. If we learn that an account belongs to a child, we will close it and delete the data.
12. Changes
This policy is versioned. If we make a material change — for example adding a new category of data or a new recipient — we will inform you and, where required, ask for your agreement before it applies to you.
13. Contact
Privacy questions and rights requests: help@dropbrook.com