legal

Security

last updated May 2026

Draftpile is designed for private material collection. This page explains the controls we use to protect owner workspaces, contributor links, and uploaded materials.

01Access control

Owner workspaces are protected by account authentication. Contributor pages are account-less by design, but each contributor receives a private link and must pass the invited-email gate before submitting materials.

Room slugs and workspace slugs are not authorization. Server-side checks decide access.

02Data isolation

Draftpile keeps workspace data isolated so one workspace cannot read or change another workspace’s rooms, contributors, files, or exports.

Production data access is enforced on the server and backed by database row-level security.

03Uploads & files

Uploaded files are stored in private storage and served through short-lived signed links. We validate file type and size before accepting materials.

Original filenames are kept as metadata; storage paths are generated by the system.

04Authentication

Draftpile supports owner sign-in with email and Google. Auth redirects are restricted to Draftpile-owned routes and domains.

External contributors do not need accounts, which keeps the collection flow simple while limiting what each link can access.

05Monitoring & response

We monitor errors, abuse patterns, and important security events so we can investigate issues quickly.

If you believe you’ve found a vulnerability, contact us through the contact page with enough detail for us to reproduce it.

06Limits

Draftpile applies rate limits and plan limits to sensitive actions such as uploads, exports, emails, and AI-assisted features.

These limits help protect customer data and keep the service reliable.

This is a product-design demo. The text below is placeholder and not legal advice. Questions? Contact us →
draftpile●─── ·
v0.1 · material collection rooms · 2026
“Messy materials in. Clean folder out.”
© 2026 draftpileone clean link to collect materials from anyone.