← Dropbrook

Privacy Policy

Version 1.0 · Effective 10 August 2026

Short version. Dropbrook pays real money for actions on a website, which attracts large-scale automated abuse. To tell people apart from bots we collect more technical and behavioural data than an ordinary website does — how your connection behaves, how your device is configured, and how you interact with the page.

We use it to detect fraud and to run the service. We do not sell it. This page describes it in specific terms.

  1. Who we are
  2. What we collect
  3. Why, and on what legal basis
  4. Automated decisions
  5. Who we share it with
  6. How long we keep it
  7. Your rights
  8. Cookies and local storage
  9. Security
  10. International transfers
  11. Children
  12. Changes
  13. Contact

1. Who we are

Dropbrook operates the website at dropbrook.com and is the controller of the personal data described in this policy.

You can reach us about anything in this policy, including to exercise the rights in section 7, at help@dropbrook.com. We read that address ourselves; there is no separate privacy department.

The operator is established in Ukraine, and your data is processed there. Ukrainian data protection law applies to us, and the supervisory authority competent for us is the Ukrainian Parliament Commissioner for Human Rights (the Ombudsman), who oversees personal data protection in Ukraine.

If you are in the European Economic Area or the United Kingdom, the protections described in this policy are offered to you as well, and you may also complain to the data protection authority of the country where you live. You do not have to come to Ukraine to raise a concern.

Dropbrook is run by a single operator rather than a large organisation; the operator’s registered details will be added to this section before registration opens. Registration is currently closed and no user data is being collected yet.

2. What we collect

2.1 Account data

DataNotes
Email addressStored both as you typed it and in a canonical form (lowercased, dots and “+” suffixes removed) used to enforce one account per person
PasswordNever stored. We store only a cryptographic hash from which the password cannot be recovered
Recovery codesStored as hashes only
FaucetPay identifierA hash provided by FaucetPay that identifies your payout account
Account activityClaims, rewards, holds, reversals, payouts, logins

2.2 Technical and connection data

Collected automatically when you use the site:

DataPurpose
IP address, and the network/ASN it belongs toFraud detection, rate limiting, country
Approximate country and region from IPDetermined locally from an offline database; not sent to a lookup service
Whether the connection appears to use a proxy, VPN, hosting provider, or TorAccess control and fraud scoring
Characteristics of the connection itself — timing, protocol behaviour, TLS and TCP propertiesDistinguishing real browsers from automated clients
WebRTC and STUN probe results, including the network address our probe server observes where your browser exposes it, and whether that address differs from the one used for the website requestDetecting proxies, VPNs, and inconsistencies typical of automation
Browser and device configuration: user agent, screen size and pixel ratio, language, time zone, CPU cores, memory, graphics adapter, available fontsDevice consistency checks
Result and timing of a computational proof-of-work taskMaking mass account creation expensive

2.3 Behavioural data

We record how you interact with the page: pointer movement, click and key timing, focus changes, scrolling, the sequence of pages you move through, and how long each step takes.

This is used to distinguish human interaction from scripted interaction. We do not record the contents of what you type — only timing and structural characteristics. Passwords and recovery codes are excluded entirely.

Sampling is limited: detailed traces are captured at a bounded rate per user rather than continuously.

2.4 Advertising delivery signals

We check whether advertising that should have been shown was actually delivered — for example whether ad resources loaded or were blocked. We record the result of that check, not the content of any advertisement.

2.5 Email delivery records

For each verification or recovery email we record which provider sent it, the provider’s message identifier, when it was sent, when the code expires, whether and when the code was used, how many attempts were made, and any bounce or complaint reported back to us.

For support replies we record the provider, the message identifier, the time it was sent, and any bounce or complaint. There is no code involved.

We use this to route messages to whichever provider is delivering reliably. We do not use open-tracking pixels or click tracking in these emails.

2.6 Data we receive from partners

Offer and advertising providers send us notifications about your activity on their side. These contain a transaction identifier, the identifier we gave them for you, the reward, its monetary value, the status (including reversals), the offer or task involved, your IP address and country as recorded by them, and a signature. We store these records to credit rewards correctly and to investigate disputes.

2.7 Derived data

From the above we compute a risk score and related indicators, and we group accounts that appear to be operated by the same person or the same infrastructure.

2.8 Communications

If you email help@dropbrook.com, we keep the message body, your address, any attachments, and the technical headers of the email.

3. Why, and on what legal basis

PurposeBasis
Creating and running your account, crediting rewards, sending payoutsPerformance of our agreement with you
Sending verification and account codesPerformance of our agreement
Detecting and preventing fraud, automation, and multiple accountsOur legitimate interest in operating a service that pays money and cannot function if abused; also the interest of honest users, who are paid from the same budget
Security of the service and of our infrastructureLegitimate interest
Meeting the requirements of our advertising and payment partners regarding invalid trafficLegitimate interest, and compliance with the terms on which those partners serve us
Responding to your support messagesLegitimate interest
Accounting records and responding to lawful requestsLegal obligation

Where the law of your country requires consent for any of the above, we ask for it separately and you may withdraw it. Withdrawing consent to anti-fraud processing means we cannot operate the account, because we would be unable to establish that rewards are earned by a person.

4. Automated decisions

We make some decisions about accounts automatically, based on the data above. What a machine may decide on its own is deliberately limited.

Decided automatically: reducing limits, restricting features, placing a temporary hold on rewards, delaying a payout pending review, and reversing a reward that a third-party provider has itself reversed.

Decided only after a person has reviewed the case: permanently cancelling rewards that were not reversed by a provider, closing an account, and forfeiting a balance.

For any of these decisions you have the right to obtain human intervention, to express your point of view, to receive an explanation of the category of problem detected, and to contest the decision. Write to help@dropbrook.com from your account address and explain the situation.

We do not publish the detail of how the scoring works, because that would tell the people we are defending against exactly what to change. We will tell you what category of problem was detected.

5. Who we share it with

We do not sell personal data and we do not share it for third-party advertising profiling. We share it with the following service providers, each for a specific purpose:

ProviderWhat they receiveWhy
CloudflareAll traffic to the site, including IP address and request data; email sent to our domainDelivering the site, protecting it from attack, receiving mail
FaucetPaySent: your payout identifier, email, or address, the amount and currency, and your IP address where required. Received: validation status, payout status or error, a transaction identifier, and a FaucetPay user hashSending payouts and confirming they arrived
Brevo, Resend, MailtrapYour email address and the message sent to youDelivering verification, recovery, and support email
BitcoTasks, AdsLabA pseudonymous identifier for you (not your email), your IP address, and your countryProviding optional offers and attributing completion; their own fraud checks
Advertising networks — at launch, FaucetPay Ads and A-ADSData their ad code collects in your browser, which typically includes IP address and browser characteristicsDisplaying advertising, which funds the rewards

These providers process the data under their own privacy policies.

When you open or complete a third-party offer, task, or shortened link, you are dealing with that provider directly. They and their advertisers may collect their own identifiers, cookies, device or browser fingerprints, completion and reversal data, and fraud signals, and may share those with each other and with payment processors. Their policies apply to that processing, not ours. Offer providers state expressly that they may share such data with advertisers and partner networks for fraud prevention.

We may also disclose data where required by law, or to establish or defend legal claims.

6. How long we keep it

CategoryKept for
Raw behavioural traces (pointer, timing, page sequence)14–30 days
Session and connection signals used for scoring3–6 months
Daily per-account statistics180 days
Reward and payout ledger entries12 months in detail, then retained in aggregated form for accounting
Partner notifications (offer completions and reversals)12 months
Support email12 months after the matter is closed
Record of which version of these documents you acceptedFor as long as needed to show what applied, and after account closure for the limitation period
Administrative action logRetained as an audit record
Fraud records (identifiers of accounts closed for abuse, and the reason)Retained after closure — see section 7

These are the periods we apply. Where a period is expressed as a range, the exact value depends on the data volume we can hold; we will tell you the value in force for a specific category if you ask.

The outer limit: five years

No personal data is kept for longer than five years, counted from the closure of your account or from your last activity, whichever is later — unless the law requires us to keep it longer, or a legal claim or investigation involving it is still open.

Five years is a ceiling, not a default. Most data is deleted far earlier, on the periods in the table above, and we do not extend those periods to the ceiling simply because we may. Two things justify the ceiling:

Records reaching the ceiling are the durable ones — account and payout history, records of decisions taken on an account, evidence of which version of these documents was accepted, and fraud records. Raw behavioural and technical data never reaches it: it is deleted within weeks or months, both because it is not needed for longer and because keeping years of it is not physically possible at the volume it is produced.

Some records are kept for as long as the account exists and are dealt with on closure rather than on a timer: your account and email records, the identity links used to enforce one account per person, the record of decisions taken on the account, and the queue of payouts in progress. Section 7 explains what happens to these when an account is deleted.

7. Your rights

Depending on where you live, you may have the right to:

To exercise any of these, write to help@dropbrook.com from your account address, or from another address with enough information for us to identify the account safely.

We normally respond within one month. Where the law allows an extension because a request is complex, we will tell you within that month and explain why. We may need to verify that the request really comes from the account holder, and we may refuse requests that are manifestly unfounded or excessive — if we do, we will say so and explain your options.

The limit on deletion, stated plainly

If you ask us to delete your account, we delete or anonymise your personal data. Some records necessarily survive. They are listed below.

What remainsWhy
Reward and payout records, in a form no longer linked to your identity where possibleAccounting, and the ability to answer a dispute about a payment we made
The record that a person accepted a given version of these documents, and whenWithout it we cannot show on what terms the account operated
Administrative actions taken on the accountAudit integrity — a log that can be edited by deletion is not a log
Where the account was closed for abuse: the identifiers needed to recognise the same person returning, and the reasonOtherwise deletion becomes a way to reset a fraud history and register again immediately

We keep the last of these on the basis of our legitimate interest in protecting the service and the honest users who are paid from the same budget. It is limited to what that purpose requires. You may object, and we will consider the objection on its facts — including whether the original finding was correct.

8. Cookies and local storage

We use browser storage only for what the site needs to work:

We do not use our own analytics or advertising cookies.

As for advertising: our intention is to use contextual advertising that does not require cookies or tracking-based consent, so that no consent banner is needed. If we ever serve advertising that sets cookies or similar identifiers on your device where consent is required, we will ask for that consent first, with an equally easy way to refuse and to withdraw it later, and this policy will be updated to name the partners involved before that happens.

9. Security

No system is perfectly secure. If a breach affects your data, we will notify you and the relevant authority where the law requires it.

10. International transfers

Our providers operate in several countries, including outside your own:

ProviderRoleWhere it processes data
Dropbrook (us)Running the serviceUkraine
CloudflareSite delivery, protection, inbound emailGlobal network, including the EU and the US
BrevoSending emailEuropean Union
ResendSending emailEuropean Union (region selected: eu-west-1)
MailtrapSending and testing emailEuropean Union
FaucetPayPayoutsOutside the EU
BitcoTasks, AdsLabOffer providersOutside the EU
Advertising networksServing advertisingVaries by network

We process your data in Ukraine. Ukraine is not among the countries the European Commission has recognised as offering an equivalent level of protection, so if you are in the EEA or the UK your data is processed outside that framework. We apply the protections described in this policy regardless, and you keep the right to complain to your own authority (section 1).

Our providers fall into two groups, and the protections differ:

We will update this section before adding any advertising network not named above.

11. Children

The Service is for people aged 18 and over. We do not knowingly collect data from children. If we learn that an account belongs to a child, we will close it and delete the data.

12. Changes

This policy is versioned. If we make a material change — for example adding a new category of data or a new recipient — we will inform you and, where required, ask for your agreement before it applies to you.

13. Contact

Privacy questions and rights requests: help@dropbrook.com