Privacy Policy
Last updated: 28 August 2026
Drum (“we”, “us”) operates Drum, a team chat application for software teams. This policy explains what we collect, why, and what you can do about it.
Drum is workspace-based. Your employer or whoever administers your workspace controls it, can see membership, and can remove you. Where they determine why and how your data is processed, they are the data controller and we act as processor on their behalf.
What we collect
You give us:
- Account — email address and password. Passwords are stored only as hashes, handled by our auth provider; we never see the plaintext.
- Profile — display name, username, and optionally an avatar image and a status message.
- Content — the messages, thread replies, and emoji reactions you send, and any files or images you attach.
- Workspace data — which workspaces and channels you belong to, and invites you send or accept.
- Beta interest — if you apply for early access, we store your email address so we can contact you about the beta.
Generated by using Drum:
- Delivery state — read markers and unread counts, so Drum knows what is new.
- Presence — whether you are currently online. This is transmitted live between connected clients and is not written to our database.
- Notification records — that you were mentioned, reacted to, or added to a channel.
- Device tokens — if you enable notifications on the iOS app, an Apple push token identifying that device installation. Deleted when you sign out.
- AI usage counters — token counts per workspace, for capacity and billing. Counts only; we do not retain prompt or response text in this record.
Only if you connect them:
- GitHub, Linear, Figma — OAuth access tokens plus the data those services return for items you reference (issues, pull requests, files). You choose to connect these; disconnecting removes the stored token.
We do not run advertising, we do not sell personal data, and we do not use third-party analytics or tracking SDKs in the mobile app.
How we use it
To operate Drum: deliver and display your messages, keep unread state, show who is online, send notifications you asked for, and run the integrations you connected. To keep the service secure and abuse-free. To contact you about the service — invitations and account email, not marketing.
Legal bases where GDPR applies: performing our contract with you, and our legitimate interest in a secure, functioning product. Where consent applies — such as push notifications — you may withdraw it at any time in your device settings.
Ringo, the AI assistant
Drum includes an AI teammate called Ringo. Ringo only sees what you send it. When you message Ringo or @mention it, the content of that conversation — and any channel messages it is explicitly asked to read — is sent to Mistral AI for processing.
We call Mistral's EU endpoint (api.eu.mistral.ai), so that processing takes place in the European Union.
Ringo is not passively reading your workspace. It fetches messages only when a request requires it, and only from conversations you can already see.
Who else processes your data
| Processor | What it handles | Where |
|---|---|---|
| Supabase | Database, authentication, file storage, realtime | EU (Ireland) |
| Cloudflare | Application hosting and edge delivery | Global edge |
| Mistral AI | Ringo requests only | European Union |
| Apple (APNs) | Push notification delivery to iOS devices | Global |
| Resend | Transactional email — invites, account mail | Per Resend’s terms |
| Klipy | GIF search, only when you open the GIF picker | Per Klipy’s terms |
| GitHub, Linear, Figma | Only if you connect them | Per their terms |
Each acts on our instructions under a data processing agreement.
File attachments
Files and images you upload are stored privately and are readable only by members of the channel or conversation they were shared in. They are served through short-lived signed links that expire, rather than permanent public addresses.
Anyone you deliberately forward such a link to can open the file until that link expires, so treat a shared link as you would the file itself.
How long we keep it
Messages and attachments are kept until deleted by you, by a workspace administrator, or until the workspace is deleted. Account records are kept while your account exists. Push tokens are removed at sign-out, and automatically when Apple reports the app uninstalled. Backups persist for up to 7 days.
Deleting your account
You can delete your account from Profile → Settings → Delete account in the app. This permanently removes your profile, your device tokens, your integration tokens, and your workspace memberships.
Messages you sent to shared channels remain visible but are attributed to a removed user.
Your rights
Depending on where you live you may request access, correction, deletion, export, or restriction of your data, and may object to processing. Contact contact@drum.chat and we will respond within 30 days.
If your workspace is administered by an employer, direct requests to them first; we will assist them in responding.
You may lodge a complaint with your local data protection authority (for example, Integritetsskyddsmyndigheten, IMY, in Sweden).
Security
Data is encrypted in transit (TLS) and at rest. Access to the workspace database is enforced by row-level security, so the database itself will not return a message from a channel you are not a member of. Passwords are hashed. Access to production systems is restricted to authorized personnel.
No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authority as required by law.
Children
Drum is a workplace tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
Changes
We will post any change here and update the date above. Material changes will be announced in the app or by email before they take effect.
Contact
Drum
Email: contact@drum.chat