jsdrop.
DATA & PRIVACY

Know where your data lives.

What jsdrop stores, why, and who else sees it. We collect what the service needs to work, and nothing for advertising.

Drops

The code, title, description, tags, settings, and saved versions of your drops are stored on our servers so they can be edited, shared, run, and deployed. Public drops can be seen by anyone with the link, may appear on the Explore page, and are listed for search engines once someone has worked on them. Private drops are visible only to you and the editors you invite, and are never listed or indexed. Your browser also keeps a local copy of drops you open, so they load fast and keep working offline.

Running in your browser

Run executes a drop in your own browser. npm packages are downloaded from the npm registry, and the program’s own network requests go wherever its code sends them. While a server runs, its public tunnel URL passes requests from the internet to your tab.

Accounts, shared with HTMLDrop

You can use jsdrop without an account. jsdrop and HTMLDrop share one account system: signing in with Google stores your Google account ID, name, email address, and profile picture URL, plus sign-in times, and the same account works on both sites. Sessions use a random token in an HttpOnly cookie; only a hash of it is stored, and signing out deletes it. Drops you create while signed in belong to you and only you can delete them. To have your account and its drops deleted, contact us.

Guest drops

Drops created without an account are public, and anyone with the editor link can change them. The list of drops you have opened is kept only in your browser; you can hide drops from it at any time.

Deployed drops and environment variables

A deployed drop runs on our servers, and its recent output is available as logs to you and the editors you invite. Environment variables are stored encrypted, given only to the deployed drop, and never shown again or copied to forks.

Payments

Pro payments are handled by Stripe, and one subscription covers jsdrop and HTMLDrop. We store your Stripe customer ID and subscription status, never card details. Stripe processes payment information under its own privacy policy.

Custom domains

For a custom domain, jsdrop stores the domain name, the drop it serves, and its verification status, and requests a TLS certificate for it from Let’s Encrypt.

Analytics

jsdrop.com uses Google Analytics to count visits and see which pages are used, so we can improve the service. It sets analytics cookies in your browser. Advertising features are turned off. Analytics never runs inside running drops, embeds on other sites, deployed drops, or custom domains, and your code is never sent to it. You can turn it off for this browser with the button on this page.

View counts

To rank popular drops, jsdrop counts views of public drops, once per visitor per day. Only the totals are stored; the visitor identifier used to avoid double counting is held in memory for the day and never saved.

AI assistant

When you send a request from the assistant sidebar, the drop’s code and your recent requests in that session are sent to the provider you chose (Anthropic for Claude, OpenAI for Codex) under your own API key and that provider’s terms. Your key stays in your browser and passes through our server without being stored or logged. Environment variables are never sent.

Operational data

Who is editing a drop, cursor positions, and rate-limit counters are held in memory only. Our servers may keep short-lived technical logs to keep the service secure and running.

Made to be explored. Open the workspace and try it for yourself. Coming from Val Town, Replit, or Glitch? See how jsdrop compares.