Privacy Policy

Last updated: April 2026

Backdrop is committed to protecting your privacy. This privacy policy explains how we collect, use, and protect your personal data when you use our website at https://getbackdrop.ai and our services, including when you connect a third-party account such as Google.

What data do we collect?

Backdrop may collect the following data:

  • Website Analytics Data: Through Google Analytics, we collect information about how you use our website, including pages visited, time spent on site, browser type, device information, and IP address (anonymized)
  • Contact Information: Name and email address if you sign up or contact us
  • Technical Data: Browser type, operating system, referring website, and other technical information
  • Google Account Data:If you authorize Backdrop to access your Google account, we receive data from the Google services you grant access to, through the scopes shown on Google's consent screen. Our use, storage, and transfer of this data is governed by the Google API Services User Data section below.

How do we collect your data?

We collect data when you:

  • Visit our website (automatically through cookies and analytics)
  • Contact us via email or contact forms
  • Subscribe to our newsletter or updates
  • Create an account
  • Authorize Backdrop to access a third-party service such as Google via OAuth

We may also receive your data indirectly from:

  • Google Analytics (website usage data)

How will we use your data?

Backdrop collects your data to:

  • Analyze website performance and improve user experience
  • Respond to your inquiries and provide customer support
  • Send you updates or newsletters (only if you've opted in)
  • Ensure website security and prevent fraud
  • Provide and improve the features of our services

Legal basis for processing: We process your data based on:

  • Legitimate interests (website analytics and improvement)
  • Consent (marketing communications)
  • Performance of a contract (providing the services you request)

Google user data exception: Data received from Google APIs is used solely to provide and improve the user-facing features you authorize. It is not used for advertising, analytics beyond the authorized feature, or any other purpose outside the Limited Use requirements described in the Google API Services User Data section.

How do we store and secure your data?

Backdrop maintains a comprehensive information security program aligned with SOC 2 Type II, including the following administrative, technical, and organizational safeguards:

  • Encryption in transit: All data transmitted between your browser or device and Backdrop is protected with TLS 1.3.
  • Encryption at rest: Stored data is encrypted using AES-256.
  • Access controls: Role-based access control (RBAC) enforced on a least-privilege, need-to-know basis.
  • Authentication: Multi-factor authentication (MFA) is required for all remote administrative access to production systems.
  • Vulnerability management: Weekly automated vulnerability scans, annual third-party penetration tests, a 48-hour patch SLA for critical vulnerabilities, and a 30-day SLA for routine patches.
  • Logging and monitoring: Security logs are retained for 90 days with 24/7 automated alerting on suspicious activity.
  • Infrastructure: Hosted on SOC 2–certified cloud providers, including Amazon Web Services (AWS) and Google Cloud Platform (GCP).

Data storage locations

  • Website analytics data is processed by Google Analytics and stored on Google's servers.
  • Customer data and account information are stored on secure cloud infrastructure in the EU and US.

Data retention

  • Customer data and associated personal data: deleted or pseudonymized within 60 days following termination of your account or service, subject to legal retention obligations.
  • Google user data: retained only as long as needed to provide the authorized feature, and deleted or rendered inaccessible within a reasonable period after you disconnect your Google account or request deletion.
  • Website analytics (Google Analytics): 26 months (default retention period).
  • Technical logs: 12 months.
  • Security logs: 90 days.

We will delete your data when the retention period expires or when you request deletion, subject to legal requirements.

Google API Services User Data

Backdrop's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, data that Backdrop receives through Google APIs is:

  • Used only to provide or improve user-facing features that are prominent in the Backdrop user interface.
  • Not transferred to third parties except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users and protections at least as protective as this policy.
  • Not used or transferred for serving advertisements, including retargeting, personalized, or interest-based advertising.
  • Not read by humans, except: (a) with the user's explicit consent for specific user data; (b) as necessary for security purposes, such as investigating abuse; (c) to comply with applicable law; or (d) in aggregated or anonymized form used for internal operations and only in accordance with applicable privacy laws.

You can review and revoke Backdrop's access to your Google account at any time via your Google Account permissions page.

AI and sub-processors

Backdrop uses enterprise AI platforms — including Google Cloud Vertex AI and Amazon Bedrock — to power its AI features. These AI sub-processors are engaged under contractual terms that require:

  • Zero data retention (ZDR) by the AI platform
  • No training or fine-tuning of any AI model on customer data

Backdrop does not use customer data, including data received from Google APIs, to train its own AI models or any third-party AI models.

For Backdrop's full list of sub-processors and up-to-date information on our security program, see our Trust Center.

Marketing

We would like to send you information about our products and services that we think might interest you.

Marketing communications include: Newsletter, product updates, special offers

Opt-out: You can opt out of marketing communications at any time by:

We will never share your data with third parties for their marketing purposes without your explicit consent. We do not use information received from Google APIs for marketing purposes, and we do not sell personal information.

What are your data protection rights?

Under GDPR, you have the following rights:

  • Right to access: Request copies of your personal data
  • Right to rectification: Request correction of inaccurate or incomplete data
  • Right to erasure: Request deletion of your personal data under certain conditions
  • Right to restrict processing: Request limitation of how we process your data
  • Right to object: Object to our processing of your data under certain conditions
  • Right to data portability: Request transfer of your data to another organization

To exercise these rights: Contact us at support@getbackdrop.ai. We will respond within one month.

No fees: We do not charge fees for most requests, but may charge a reasonable fee for excessive or repetitive requests.

What are cookies?

Cookies are small text files stored on your device when you visit our website. They help us understand how you use our site and improve your experience.

For more information about cookies, visit allaboutcookies.org.

How do we use cookies?

We use cookies to:

  • Analyze website traffic and usage patterns (Google Analytics)
  • Remember your cookie preferences
  • Ensure website security

What types of cookies do we use?

Necessary Cookies

These cookies are essential for our website to function properly. They include:

  • Cookie consent preferences
  • Security tokens

Analytics Cookies

We use Google Analytics or other similar cookies to understand how visitors use our website. These cookies collect:

  • Pages visited and time spent on each page
  • How you arrived at our site
  • Device and browser information
  • Anonymized IP address

How to manage your cookies

You can control cookies through:

  • Our cookie banner: Use the settings to accept or reject different types of cookies
  • Browser settings: Configure your browser to block or delete cookies
  • Google Analytics opt-out: Use Google's opt-out browser add-on or other similar opt-out tools

Note: Blocking certain cookies may affect website functionality.

Privacy policies of other websites

Our website may contain links to other websites. This privacy policy only applies to our website. When you click on links to other websites, please read their privacy policies.

Changes to our privacy policy

We review and update this privacy policy regularly. Any changes will be posted on this page with an updated revision date.

How to contact us

If you have questions about this privacy policy or want to exercise your data protection rights:

Email: support@getbackdrop.ai

Ready to get started

Try Backdrop Free