Privacy Policy
Last Updated: September 7, 2026
Effective Date: September 7, 2026
Overview
Dropout is built on one promise: you can speak freely on your campus without it being tied to your name. This Privacy Policy is how we keep that promise honest — it tells you exactly what we collect, why, who ever touches it, and how to make it disappear.
Dropout ("Dropout," the "app," or the "Service") is operated by Sori Labs LLC ("we," "us," or "our") — an anonymous, campus-based social platform. The Service is offered only in the United States. We verify control of email addresses to help place people in campus communities. During beta, we also accept addresses outside supported university domains; email verification is not universal proof of university affiliation.
By creating an account, using the Service, or using our website (including the waitlist and the Suggestion Wall), you agree to the practices described here; if you do not agree, please do not use Dropout. Our guiding principle is minimalism: we collect as little personal information as we can while verifying account ownership and keeping the community safe.
1. Information We Collect
1.1 Information you provide
- Email address. Used to verify control of the address, place you in a campus community, sign in, recover your account and respond to account requests. During beta, we also accept addresses outside supported university domains. Your email is never shown to other users and is not used to derive your username.
- Password. Stored only as a salted Argon2 hash. Your password is processed when you sign up or authenticate; we do not store it in plaintext.
- Date of birth. Collected once, at sign-up, to confirm you meet the minimum age (see Section 8). We store your age, not your full date of birth, and displaying it on your profile is optional and off by default.
- Username and profile details. A pseudonymous username and optional profile information you choose to add. Major, graduation year, MBTI, gender and age have visibility controls; hidden values are withheld by the profile API. Display name, bio and avatar are public when provided.
- Content you create. Posts, comments, course reviews, events, club descriptions, votes, bookmarks, event reminders and other content or reactions you submit.
- Direct messages. If you message another student, we store the message content and who the conversation is between, so it can be delivered and shown to you both. Direct messages are not end-to-end encrypted. We do not read them routinely, but they are stored on our servers and can be accessed by our moderation team when a message or conversation is reported, when required to investigate abuse, or where the law requires it. Messages and message requests are screened with automated keyword and content-moderation tools when submitted. With your explicit permission, submitted message and message-request text is sent to OpenAI for this safety screening. Treat a direct message as private from other users, not as private from us.
- Personal safety preferences. Accounts you block and course reviews you choose to hide. Hiding an authorless review does not reveal its author.
- Reports and support requests. Information you provide when you report content or a user, or when you contact support.
1.2 Information we collect automatically
- Device, app and technical request information. Device and app information, IP addresses, user-agent information, request paths, response status and error details may be processed in application and hosting logs for troubleshooting, security and compatibility. These logs can contain account identifiers or information associated with a failed request.
- Usage data. First-party information about how the app is used (for example, which features are opened) to diagnose problems and improve the Service. This usage data is linked to your account ("Data Linked to You"); it is not sold or shared with third parties for advertising, and never used to track you across other companies' apps or websites. Service providers who process data strictly on our behalf (for example, hosting and email delivery) are not third-party advertisers.
- Push notification token. If you enable notifications, a device push token so we can deliver them.
- Randomly generated identifiers that are tied to your account for functionality and abuse prevention, not to your real-world identity.
1.3 Information we do NOT collect
- Real names. We do not require your legal name; information you choose to enter in optional profile fields or content may identify you.
- Phone numbers. We do not collect phone numbers.
- Precise location. We do not collect GPS or precise location data.
- Contacts. We do not access your address book or contact list.
- Cross-app tracking. We do not track your activity on other apps or websites, and we do not use third-party advertising trackers. We do not present an App Tracking Transparency prompt because we do not track you across other companies' apps or sites.
- Biometric or health data.
1.4 Information you provide on our website (no account needed)
Two parts of our website work without any account, and each collects the minimum it needs:
- Campus waitlist email. If your campus isn't live yet, you can leave your school email address on our waitlist page. We store the address and its school domain for exactly two purposes: counting demand for your campus, and sending you one email when it opens. If your campus is already live, we don't store the address at all. Waitlist addresses are never shown publicly, are never used for marketing lists, and are removed on request (see Section 6).
- Suggestion Wall posts. Feedback you post on our public Suggestion Wall — the title, details, and category — becomes public after a human on our team approves it. You may add an email address if you want a reply; it is visible only to our team, used only to respond to your feedback, and never appears publicly.
- A hashed identifier for Suggestion Wall records. When you post or vote on the Suggestion Wall, its database records a salted SHA-256 hash derived from your IP address for vote de-duplication and daily submission limits. Those records contain the hash rather than the raw address. Application and hosting systems separately process technical request information, including IP addresses, and may retain it in logs. Your browser also keeps a local list of items you've voted for so the wall remembers on revisit; that list stays on your device and is never sent to us.
2. How We Use Your Information
We use the information above to:
- Verify control of an email address, place you in a campus community, and confirm you meet the minimum age.
- Provide and operate the Service — authenticate you, display content, and run community features.
- Keep the community safe — enforce our Community Guidelines, run automated and human content moderation, and respond to reports (see our Safety & Community Guidelines).
- Maintain and improve the app — diagnose crashes and errors and understand aggregate usage.
- Communicate with you — send account and service-related notifications. You can opt out of non-essential notifications in Settings.
- Run our public website — tally waitlist demand and send the single campus-open email you asked for, reply to Suggestion Wall feedback when you leave an email, and de-duplicate votes and rate-limit submissions using hashed identifiers.
- Comply with law and enforce our Terms of Service.
We do not use your information to build advertising profiles, and we do not sell it.
3. How Your Anonymity Works
Dropout is built for pseudonymous posting within your campus community.
- To other users: your posts and comments appear under your username only. Your account email and profile fields marked hidden are not shown to other users. Information you put in public profile fields or content may identify you.
- Anonymity is not absolute. To operate the Service, prevent abuse, and comply with the law, we retain internal records (such as the account associated with content). We may access these records to investigate violations of our Terms or Guidelines.
- Legal requests. We may disclose information when required by valid legal process (such as a subpoena or court order), or where necessary to protect the safety of a person or the public. We respond only to lawful requests and disclose only what is legally required.
4. How We Share Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
We share information only with the service providers ("sub-processors") that operate the app on our behalf, and only as needed to run the Service. They are bound by contract to protect your information and use it only for us. Our current sub-processors include:
- Railway — application and database hosting (United States); processes stored app data, application traffic and technical logs, including IP addresses, user-agent information, request paths and response status.
- Sentry, when enabled on the server — error diagnostics and request metadata used to investigate failures. The mobile app does not include a Sentry SDK.
- Postmark — transactional email delivery, including verification and password recovery; receives the destination email address and email content.
- Expo, Apple Push Notification service and Google Firebase Cloud Messaging — deliver notifications on iOS and Android; process push tokens, delivery metadata and notification payloads. Depending on the feature, a payload may include message or event text.
- OpenAI — automated content moderation, only after explicit in-app permission. It receives text submitted in posts and poll options, comments, messages and message requests, display names and bios, course tips, club names/descriptions, and event titles/descriptions/locations to check for harmful content. We do not attach your account ID, email address or password. The text itself may contain personal information you include. If OpenAI is unavailable, we may use our local text filter and accept content that passes it; a local-only check does not send text to another provider. Permission is versioned and must be renewed if this disclosure changes; accepting the Terms or simply continuing to use the app does not grant this permission.
We may also disclose information: (a) to comply with law or valid legal process; (b) to protect the rights, safety, and security of our users, the public, or Dropout; and (c) in connection with a merger, acquisition, or sale of assets, with notice to you.
5. Data Retention
- Account data is retained while your account is active.
- When you delete your account (Profile → Settings → Delete Account), we invalidate sessions, erase profile and credential data, remove authored text from posts, comments and messages, delete account-linked course reviews and remove associated activity and personal safety preferences. Structural placeholders may remain so other people’s conversations continue to work. Certain records may be retained where we have a legal obligation, need to resolve disputes, prevent abuse, or enforce our agreements — for example, a minimal, append-only moderation/audit record.
- Backups and technical logs. Account deletion does not immediately remove every residual copy from any existing backups or provider-operated logs. Their retention follows the applicable backup and logging settings and provider policies.
- Waitlist signups are kept while your campus remains unopened — the address exists only so we can send the one campus-open email — and are removed on request at any time (see Section 6).
- Suggestion Wall posts are kept while they are on the wall; posts we decline or remove may be retained internally to handle repeat abuse. An email left with a post lives only as long as the post itself and is removed on request. The hashed identifier stored with a post or vote lives only as long as that post or vote.
6. Your Rights and Choices
Everyone:
- Delete your account and data — in the app, at Profile → Settings → Delete Account.
- Delete posts, comments and course reviews using their in-app controls. Cancel events you host. Contact support for other content requests.
- Edit your profile and manage visibility for major, graduation year, MBTI, gender and age. Display name, bio and avatar are public when provided.
- Manage notifications in Settings.
- Control OpenAI safety checks in Settings → Privacy → OpenAI safety checks. You may decline or withdraw permission and keep browsing. Submitting text that requires screening asks for permission. Withdrawal prevents subsequent checks; checks already in progress may finish, and text already sent cannot be recalled. Account deletion clears the stored permission record.
U.S. state privacy rights. Depending on where you live — California (CCPA/CPRA) and states such as Virginia, Colorado, and Connecticut with comparable laws — you may have the right to know the categories and specific pieces of personal information we collect, to access and delete it, to correct it, and to opt out of the "sale" or "sharing" of personal information. We do not sell or share your personal information, so there is nothing to opt out of, and we will never discriminate against you for exercising a privacy right.
To exercise any right that isn't already self-serve in the app, email support@dropoutsocial.com. We may need to verify the request against your account. For website data with no account attached — a waitlist signup or an email left with a Suggestion Wall post — write us from that email address; that's how we know the request is yours, and we'll remove it.
7. Security
We use reasonable technical and organizational safeguards to protect your information, including Argon2 password hashing, encryption of data in transit (TLS), and access controls that limit who can reach production data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Children's and Teens' Privacy
Dropout is intended only for users 18 years of age or older. A neutral date-of-birth gate runs at sign-up. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us information, contact us at support@dropoutsocial.com and we will delete it.
Because content on Dropout is anonymous and user-generated, any content that references a minor is moderated with heightened caution (see our Safety & Community Guidelines).
9. Where We Operate
Dropout is offered only in the United States as a campus-focused community. During beta, signup also accepts email addresses outside supported university domains. Our service providers may process data in locations covered by their service arrangements. The Service is not directed to, or intended for, users outside the United States.
10. Do Not Track
We do not track you across third-party apps or websites, so we do not respond differently to "Do Not Track" browser signals; there is no cross-site tracking to disable.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you in the app or by other means and update the "Last Updated" date above. Your continued use of Dropout after a change takes effect means you accept the updated policy.
12. Contact Us
Questions about this Privacy Policy or our privacy practices:
Sori Labs LLC Email: support@dropoutsocial.com
We aim to keep this policy clear and honest. If anything is unclear, email us and we'll explain.