Privacy Policy

Last Updated: June 29, 2026

Drip Works, Inc. ("Drip," "we," "us," or "our") provides a market and professional intelligence platform (the "Services"). This Privacy Policy explains how we collect, use, disclose, and protect personal information, and the choices and rights individuals have.

Please note that this Policy addresses two different groups of people:

Account Users: individuals who create an account, use the Services, or interact with us (for example, our customers and their authorized users). When we refer to "you," we generally mean an Account User.

Profiled Individuals: individuals whom our customers choose to track through the Services and about whom we compile information from publicly available and third-party sources. Profiled Individuals do not have a direct relationship with Drip, but have privacy rights described in Section 9, including the ability to opt out and request deletion.

Where a section applies specifically to one group, we say so.

1. Scope

This Policy applies to personal information we process through our websites, applications, and Services. It does not apply to third-party websites, products, or services that we do not control, including the public sources from which information originates and any separate tools you use for outreach.

2. Personal Information We Collect

2.1 Information from Account Users

When you create an account, purchase a subscription, or use the Services, we collect:

  • Account and contact identifiers: such as name, business email address, and the company you represent.
  • Authentication data: credentials and login information, managed through our authentication provider.
  • Billing information: subscription plan, transaction history, and payment information. Payments are processed by Stripe; we do not store full payment-card numbers.
  • Customer Data: the companies, individuals, accounts, topics, and trends you choose to track, and any notes, queries, or settings you provide.
  • Communications: information you provide when you contact us for support or otherwise correspond with us.
  • Usage data: information about how you access and use the Services, such as device and browser information, log data, feature usage, and diagnostic data.

2.2 Information We Compile About Profiled Individuals

For our People Intelligence and Account Intelligence offerings, we compile information about individuals' publicly available professional activities from public and third-party sources. This may include:

  • Identifiers: name and, where publicly available, social media handles. We do not collect or provide email addresses or telephone numbers for Profiled Individuals.
  • Professional and employment information: current or associated employer, role or title, and organizational affiliation.
  • Public professional activity: publicly available appearances, interviews, authored content, and similar professional activity, and links to the public sources where it appears.

We do not perform facial recognition and do not collect or process biometric identifiers. We do not collect sensitive personal information (such as government identifiers, financial account credentials, health, precise geolocation, or similar categories) about Profiled Individuals. The social media handles we provide are themselves publicly available.

2.3 Information Collected Automatically

When you visit our website or use the Services, we and our service providers may collect limited information through cookies and similar technologies necessary to operate and secure the Services. We do not use advertising cookies or third-party advertising/tracking technologies. See Section 6.

3. Sources of Personal Information

We obtain personal information from:

  • You: directly, when you register, subscribe, configure the Services, or communicate with us.
  • Publicly available and third-party sources: for information about Profiled Individuals and organizations, including public web sources, publicly accessible podcast feeds, the publicly accessible YouTube API, and publicly accessible RSS feeds (and, over time, licensed feeds and APIs).
  • Service providers: such as our authentication, hosting, and payment providers, in connection with operating the Services.

4. How We Use Personal Information

We use personal information to:

  • provide, operate, maintain, secure, and support the Services;
  • compile, synthesize, and deliver intelligence updates and Output to our customers;
  • process transactions, manage subscriptions, and communicate with Account Users;
  • develop and improve the Services, including refining the prompts, processing pipelines, and configurations used to generate Output, and creating aggregated and de-identified data;
  • respond to inquiries and provide customer support;
  • comply with legal obligations, enforce our agreements, and protect the rights, safety, and security of Drip, our users, and others; and
  • for other purposes disclosed at the time of collection or with consent.

We do not use Account User Customer Data to train our own foundation models, and we do not develop our own foundation models. Inputs and content may be processed by third-party AI providers to operate the Services, as described in Section 5.

5. How We Disclose Personal Information

We disclose personal information in the following circumstances:

  • Service providers / sub-processors: we share personal information with vendors that perform services on our behalf, subject to contractual protections. Our current sub-processors include:
    • Supabase: database and hosting;
    • Auth0 (Okta): authentication;
    • Stripe: payment processing; and
    • Third-party AI model providers: to process inputs and generate Output.
  • To our customers: the Services make compiled information about Profiled Individuals and organizations available to the customer that elects to track them, as part of delivering the Services.
  • Legal and safety: we may disclose information to comply with law, legal process, or government requests, to enforce our terms, or to protect rights, property, or safety.
  • Business transfers: in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to this Policy.
  • With consent: or at your direction.

6. Cookies and Similar Technologies

We use only cookies and similar technologies that are strictly necessary to operate, secure, and provide the Services (for example, to keep you signed in). We do not use advertising cookies, third-party advertising networks, or cross-context behavioral advertising. We do not use analytics, retargeting, or other tracking technologies. Within the application, we use a first-party session and authentication cookie (named "__session__," which may be split across more than one cookie due to size) and first-party browser local storage that remembers your interface preferences. We may also use a first-party infrastructure or security cookie set at our domain to help deliver and protect the Services. We do not use these technologies for advertising, analytics, or profiling, and we do not sell or share information collected through them. You can control cookies through your browser settings, though disabling essential cookies may affect functionality.

Because we use only strictly necessary cookies and similar technologies, and none that require opt-in consent, we do not display a cookie consent banner. If we later introduce advertising, retargeting, or analytics technologies that require consent, we will update this Policy, provide the required notice, and offer an appropriate consent or opt-out mechanism before those technologies are used.

7. Data Retention

We retain personal information for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law.

  • Account User data: retained for the duration of the account and for up to 24 months thereafter, and as needed to meet legal, tax, and recordkeeping obligations.
  • Profiled Individual data: retained for no longer than necessary for the purposes described in this Policy or until we receive and process a valid deletion request, whichever is earlier, except where retention is required by law.

We may retain aggregated or de-identified information, which does not identify any individual, for legitimate business purposes.

8. How We Protect Personal Information

We maintain reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, use, alteration, loss, or destruction. We limit access to personal information to personnel and service providers who need it to operate, secure, and support the Services, and we require our service providers to protect personal information under appropriate contractual obligations. We use personal information only for the purposes described in this Policy, do not use it for advertising, and do not sell Account User Customer Data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. These practices correspond to the data-handling and security commitments in Section 7.6 of our Terms of Service.

9. Your Privacy Rights and Choices

Depending on where you live and applicable law, you may have the rights described below. These rights apply to both Account Users and Profiled Individuals.

9.1 California (CCPA/CPRA)

California residents may have the right to:

  • Know/Access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties to whom we disclose it;
  • Delete personal information we have collected, subject to exceptions;
  • Correct inaccurate personal information;
  • Opt out of the "sale" or "sharing" of personal information; and
  • Limit the use of sensitive personal information (note: we do not collect sensitive personal information about Profiled Individuals).

We will not discriminate against you for exercising these rights.

Categories of personal information. In the preceding 12 months, we have collected the categories described in Section 2 (identifiers; professional/employment-related information; internet or other electronic activity information; commercial/billing information for Account Users) and disclosed certain categories to the recipients described in Section 5.

9.2 Other U.S. State Privacy Laws

Residents of states with comprehensive privacy laws (such as Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and others as they take effect) may have the right to access, correct, delete, and obtain a portable copy of their personal information, and to opt out of targeted advertising, the sale of personal information, and certain profiling. Where required, you may also appeal a decision regarding your request by contacting us at team@joindrip.ai.

9.3 How to Exercise Your Rights

To exercise any of these rights, email team@joindrip.ai. You do not need a Drip account to make a request. We will:

  • take steps to verify your identity (and, for Profiled Individuals, to match your request to the information we hold) before acting;
  • respond within the timeframes required by applicable law;
  • honor requests submitted by an authorized agent where permitted, subject to verification; and
  • where we deny a request, explain why and how to appeal where applicable.

9.4 Specific Note for Profiled Individuals

If you have been tracked through the Services and wish to opt out and/or request deletion of the information we hold about you, email team@joindrip.ai with enough detail for us to locate your information (such as your name and, if available, the social handle or public profile at issue). We will process your request as described above, even though you do not have an account with us.

10. Data Broker Disclosure

Drip may qualify as a "data broker" under the laws of certain states because it collects and makes available information about individuals with whom it does not have a direct relationship. Where required, Drip registers as a data broker and honors applicable opt-out and deletion mechanisms.

  • California: Where required, Drip registers as a data broker with the California Privacy Protection Agency. California residents may exercise deletion rights as described in Section 9 and, where applicable, through the state's deletion mechanism (DROP) once operational.
  • Other states (e.g., Vermont, Texas, Oregon): Where these states require data-broker registration, Drip registers as required and honors the applicable opt-out and deletion mechanisms.

11. Children's Privacy

The Services are intended for business use and are not directed to children. We do not knowingly collect personal information from children under 18. We do not knowingly "sell" or "share" the personal information of individuals under 16. If you believe we have collected information from a child, contact us at team@joindrip.ai and we will take appropriate steps.

12. U.S.-Based Service; International Users

The Services are operated from the United States and intended for users and customers in the United States. If you access the Services from outside the United States, you do so on your own initiative and are responsible for compliance with local law.

13. Changes to This Policy

We may update this Policy from time to time. We will post the updated Policy with a new "Last Updated" date and, where required by law, provide additional notice. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.

14. Contact Us

If you have questions about this Policy or our privacy practices, contact us at:

Drip Works, Inc.
910 D St. #150206, San Rafael, CA 94901
Email: team@joindrip.ai (privacy@joindrip.ai for privacy requests)