GitHub issues
Skip to document

Privacy notice

How we handle personal information on the Dryft website and Dryft Stacks, and how to exercise your privacy rights.

Last updated

Who handles your information

Charl Gottschalk operates usedryft.com and stacks.usedryft.com from South Africa. In this notice, “we” means Charl Gottschalk, the responsible party under South Africa’s Protection of Personal Information Act (POPIA) and the controller where the EU General Data Protection Regulation (GDPR) applies.

For privacy questions or requests, email support@usedryft.com. This notice covers both websites and their related support and registry services.

Information we handle

When you contact support, we receive your email address, any name you provide, your message and the files or diagnostic details you choose to share. Please remove passwords, access tokens and other people’s personal information before sending a report.

Stack listings contain public repository and release details, author attribution, descriptions, declared capabilities and review status. We obtain these details from submissions and public GitHub records. Published listings are visible to anyone and can be read through the registry.

Where GitHub sign-in is available for submissions, Supabase Auth receives your GitHub identity, public profile and email. Submission records link your account to the release and include review feedback and timestamps. OAuth credentials are used to verify your identity and repository access.

Vercel hosts both websites and processes connection information such as your IP address, requested URL and browser details to deliver pages and handle requests. Operational and security logs may contain this information to help diagnose errors and prevent abuse. We do not use Vercel Web Analytics.

Why we use it

We use support messages to answer you and investigate reported problems. Account and submission information lets us verify repository ownership, review releases, attribute published work and protect the registry against misuse.

Where GDPR applies, processing needed to provide an account or handle a submission you request is based on performing our agreement with you, or taking steps at your request before entering that agreement. Responding to general support questions, keeping the service secure and maintaining reliable release records are our legitimate interests, subject to your rights and interests.

We may also process information to meet a legal obligation. If we ask for consent for a separate purpose, we will explain that purpose when asking, and you can withdraw consent without affecting earlier lawful processing.

You can browse without supplying account or support details. If you do not provide information needed to verify a submission or investigate a report, we may be unable to complete that request.

Cookies and tracking

We do not use visitor analytics, advertising trackers, payment services or mailing-list services on these websites.

The Dryft website at usedryft.com does not set cookies. Dryft Stacks uses first-party authentication cookies when you start GitHub sign-in or have an existing sign-in session. They secure the login flow, identify your signed-in account and renew your session.

  • Cookies named sb-<project>-auth-token hold your Supabase session, including access and refresh tokens and account information. Larger values may be split into numbered cookies such as .0 and .1.
  • Cookies with names ending in -code-verifier hold the verification information used to complete sign-in securely. Supabase removes the verification data when the sign-in exchange completes.

We set these as browser-session cookies, without a persistent expiry date. Browsers normally remove them when the browser session ends, although session-restore settings can retain them. Signing out clears the authentication cookies. You can also remove or block cookies in your browser settings; blocking them prevents sign-in and account features from working, but public browsing remains available.

These cookies are necessary for the sign-in service you request. We do not ask for a separate cookie-consent choice for that essential use. If we introduce optional cookies, we will explain their purpose and obtain consent before setting them where required.

External websites, including GitHub, have their own storage practices and privacy policies. These apply when you choose to visit or sign in through those services.

Your local Dryft workspace

Browsing these websites does not upload your local Dryft brain, project files or agent conversations to us. Dryft’s workspace stores its knowledge on your device.

Your agent provider and any stack you choose to install may process information under their own terms. Review their policies and a stack’s declared capabilities before granting it access.

Providers and public information

We use Vercel for website hosting, content delivery and server-side request processing. Supabase stores service data and supports authentication. GitHub supplies repository, release and identity information for the stack registry. Our email provider processes support correspondence.

Vercel explains its handling of personal information in its privacy notice. You can contact us about information processed in connection with our websites.

Published stack information is public. Support correspondence, account email addresses and private review feedback are not part of the public registry. If you post a GitHub issue, the information you include may be public under that repository’s settings.

Information may also need to be disclosed where the law requires it or to establish, exercise or defend legal claims.

International processing

We operate in South Africa. Vercel, Supabase and our other service providers may process information in other countries, depending on their infrastructure and the services used. The protections and legal remedies in those countries may differ from those where you live.

Transfers must meet POPIA’s requirements and, where GDPR applies, its international-transfer rules. GDPR transfers require an applicable adequacy decision, appropriate safeguards such as standard contractual clauses, or a permitted exception. Contact us for the locations and safeguards relevant to your information, including how to obtain a copy of applicable safeguards.

How long information is needed

Retention depends on the purpose of the record: resolving a support request, operating an account, maintaining a published release’s attribution and review history, investigating operational or security incidents, or meeting a legal obligation. Information should no longer be kept in identifiable form once its purpose and any required retention have ended.

You can ask us to delete information that is no longer needed. Some records may need to remain to meet a legal obligation or address a dispute. Public repository material and copies downloaded by other people are outside our control.

Your privacy rights

Under POPIA, you may ask whether we hold your personal information, request access, and ask for correction or deletion where the law provides. You may also object to processing on the grounds available under POPIA.

Where GDPR applies, you may request access, correction, erasure or restriction of processing. You may object to processing based on legitimate interests. Where the conditions apply, you may receive information you supplied in a portable format and ask us to transmit it to another controller. You may withdraw consent at any time for processing based on consent.

Email support@usedryft.com with your request. We may need enough information to verify your identity before disclosing or changing personal records. Under GDPR, we respond without undue delay and normally within one month; if a permitted extension is needed, we will explain it within that first month.

You may complain directly to South Africa’s Information Regulator. Where GDPR applies, you may also complain to a competent supervisory authority, including the authority in the EU or EEA country where you live or work, or where you believe an infringement occurred. You do not have to contact us first.

Planned accounts and updates

Dryft accounts are planned. Before they launch, we will update this notice with the information they require, how authentication works and any new providers or uses of personal information.

We will update the date on this page when the notice changes. If a change requires separate notice or consent, we will provide it before using your information for that new purpose.

Questions about this document? Email support@usedryft.com.