Terms of Service

Effective: March 16, 2026 · Last updated: March 16, 2026

1. Introduction

These Terms of Service ("Terms") govern your use of Deadrop ("the Service"), operated at deadrop.dev. By accessing or using the Service, you agree to be bound by these Terms. If you do not agree, do not use the Service.

2. Service Description

Deadrop is a transient encryption tool, not a storage or backup service. The Service allows you to:

  • Encrypt a text message in your browser using AES-256-GCM
  • Generate a one-time link that can be viewed exactly once
  • Set an expiry time after which the secret is automatically deleted

Zero-knowledge architecture: All encryption and decryption occurs in your browser. The decryption key is embedded in the URL fragment, which is never transmitted to our servers. We cannot access, read, decrypt, moderate, or recover the contents of any secret.

This means:

  • If you lose the link, the secret is mathematically irrecoverable. We cannot help you retrieve it.
  • We cannot verify, review, or moderate the content of any secret.
  • We cannot selectively delete or modify the contents of a secret.

3. Acceptable Use Policy

3.1 Your Responsibilities

By using the Service, you represent and warrant that:

  • You have the legal right to share any content you encrypt through the Service.
  • The content of your secret does not violate any applicable local, national, or international law.
  • You will not use the Service for any unlawful purpose.

You are solely responsible for the content you share. Because we cannot see your content, you bear full legal responsibility for it.

3.2 Prohibited Uses

You may not use the Service to:

  • Distribute malware, ransomware, or malicious code
  • Share child sexual abuse material (CSAM)
  • Facilitate terrorism, violence, or threats of harm
  • Distribute stolen credentials, personal data, or financial information obtained without authorization
  • Infringe on intellectual property rights
  • Coordinate or facilitate any illegal activity
  • Circumvent rate limits or abuse the Service through automated means
  • Scrape, crawl, or programmatically access the Service without prior written consent

3.3 Enforcement

Due to our zero-knowledge architecture, we cannot monitor or inspect the content of secrets. However, we reserve the right to:

  • Block IP addresses or IP ranges associated with abusive behavior, botnets, or automated attacks
  • Suspend or restrict access based on metadata patterns (request volume, timing, origin) without inspecting encrypted content
  • Cooperate with law enforcement as described in Section 8
  • Terminate access to the Service at our sole discretion

3.4 Reporting Abuse

If you believe the Service is being used for illegal purposes, contact us at [email protected]. Due to our zero-knowledge architecture, we cannot view or verify the contents of any secret. However, we will review reports and take action where technically possible (such as blocking associated IP addresses or deleting specific secret IDs if provided before they are viewed).

4. Account-Based Features

The core Service does not require an account. If you create an account for premium or team features in the future, additional terms may apply. We will notify you of any additional terms at the time of registration.

5. Intellectual Property

The Service, its design, branding, and underlying code are the property of the operator. You are granted a limited, non-exclusive, non-transferable license to use the Service for its intended purpose.

The content you encrypt and share through the Service remains yours. We claim no ownership over your content and, by design, have no access to it.

6. Disclaimer of Warranties

The Service is provided "as is" and "as available" without warranties of any kind, whether express, implied, or statutory. We disclaim all warranties, including but not limited to:

  • MERCHANTABILITY — we do not guarantee the Service is fit for any particular commercial purpose.
  • AVAILABILITY — we do not guarantee uninterrupted or error-free operation.
  • SECURITY — while we use industry-standard encryption (AES-256-GCM), we do not guarantee that the encryption will remain secure against all future advances in computing, including quantum computing.
  • DATA PRESERVATION — secrets may be deleted before their TTL expires due to system maintenance, infrastructure failures, or other operational reasons.

We do not represent that the Service will meet your specific requirements or that any defects will be corrected.

7. Limitation of Liability

To the maximum extent permitted by applicable law:

  • The operator shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of profits, data, business opportunities, or goodwill.
  • The operator shall not be liable for any loss of data, whether through user error, link expiry, system failure, or infrastructure outage.
  • The operator shall not be liable for any damages arising from the actions of third-party infrastructure providers (including but not limited to Hetzner and Cloudflare).
  • The operator's total aggregate liability for all claims arising from your use of the Service shall not exceed the amount you have paid to use the Service in the twelve (12) months preceding the claim.

You acknowledge that the Service is a transient communication tool, not a storage or backup service, and that data loss is an inherent characteristic of its design.

8. Law Enforcement and Legal Process

We comply with valid legal process (subpoenas, court orders, warrants) issued by courts of competent jurisdiction.

Technical limitations: Due to our zero-knowledge architecture, we are unable to provide the plaintext content of any secret. We do not possess decryption keys and cannot reconstruct them.

Data we can provide in response to valid legal process:

  • Encrypted ciphertext (if the secret has not yet been viewed or expired)
  • Hashed IP addresses associated with secret creation (retained for one hour)
  • Server access logs (retained for 14 days)
  • Timestamps of secret creation

We will notify affected users of legal requests where legally permitted and where we have the means to do so (e.g., if an account exists).

9. Service Modifications and Termination

We reserve the right to:

  • Modify, suspend, or discontinue the Service (or any part of it) at any time, with or without notice
  • Change these Terms at any time by updating this page and the "Last Updated" date
  • Impose new limits on the Service, including but not limited to secret size, TTL options, and rate limits

We will make reasonable efforts to provide notice of material changes. Your continued use of the Service after changes constitutes acceptance of the updated Terms.

10. Indemnification

You agree to indemnify, defend, and hold harmless the operator from and against any claims, damages, losses, liabilities, costs, and expenses (including reasonable legal fees) arising from:

  • Your use of the Service
  • The content you share through the Service
  • Your violation of these Terms
  • Your violation of any applicable law or regulation
  • Your violation of any third party's rights

11. Governing Law and Dispute Resolution

These Terms are governed by the laws of Norway, without regard to conflict of law principles.

Any dispute arising from or relating to these Terms or the Service shall be resolved in the courts of Norway.

For consumers in the European Economic Area: Nothing in these Terms affects your statutory rights under mandatory consumer protection laws of your country of residence. You may have the right to bring proceedings in the courts of your home country.

12. Severability

If any provision of these Terms is found to be unenforceable or invalid by a court of competent jurisdiction, that provision shall be limited or eliminated to the minimum extent necessary, and the remaining provisions shall remain in full force and effect.

13. Entire Agreement

These Terms, together with our Privacy Policy, constitute the entire agreement between you and the operator regarding the use of the Service.

14. Contact

For questions about these Terms, contact us at:

Email: [email protected]

These Terms apply to the website at deadrop.dev and all services provided through it.