Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

On by default: marketing, cookies, and ML-driven targeting of Dropbox users

2023–2024

LowStatus: OngoingProduct: Core syncYear: 2024

Dropbox uses cookies and machine learning to profile how engaged each user is — analyzing connected devices, storage used, file content, and sharing actions — to market premium services, with regional differences in what is on by default.

What happened

Beyond storing files, Dropbox runs marketing and personalization systems on top of account data. Its own privacy materials state that Dropbox uses 'machine learning, artificial intelligence, and algorithmic analysis' to gauge a user's activity and engagement — looking at factors such as how many devices are connected, how much storage is used, file content, and sharing actions — specifically to identify and market premium services to users likely to be interested.

Dropbox also sets cookies and similar technologies, including via third-party providers, to 'promote' its services, with a Cookies/CCPA preferences control in its site footer. Consent and default states vary by region: stricter regimes such as the EU and UK require consent-first handling, while users elsewhere are more likely to be opted in by default — a pattern Dropbox repeated explicitly with its 2023 third-party-AI toggle, where EU/UK/Canada users were opted out but most others were opted in. The result is profiling and marketing data use that many users do not expect from a 'file storage' product, governed by defaults that depend on where they live.

Impact

Users in less-protected jurisdictions carry a heavier default burden of profiling and marketing analytics, and few realize that file content, storage levels, and sharing behavior are inputs to machine-learning models aimed at upselling them. It illustrates how Dropbox monetizes behavioral signals around the files, and how privacy outcomes hinge on opt-out defaults most people never change.

Dropbox's Response / Official Position

Dropbox discloses these practices in its privacy policy and cookie documentation, provides cookie and marketing-preference controls and an unsubscribe option, and says it obtains consent where required; it states data is used to provide, improve, and promote its services.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

Because Dash can be downloaded and set up with 'no sales or IT required,' an individual employee can connect and index an organization's apps and browser history without administrator oversight — recreating the shadow-IT data-governance risk that earlier consumer Dropbox use posed to enterprises.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)Account Lockouts & Support Failures
Read documentation

Dropbox repeatedly assures users that AI features do not train on their data and that content is deleted within 30 days — but because these are revocable policy promises layered over server-side access rather than technical guarantees, security commentators remain skeptical that the assurances will hold.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)
Read documentation

Through 2025 Dropbox pushed Dash to general availability with self-serve sign-up and no IT required, marketing it as an AI assistant that indexes content across all of a user's connected apps — a model that, by design, reaches far beyond the files stored in Dropbox.

Privacy & Encryption ConcernsProduct Changes & User BacklashCurrent / Ongoing Issues (2024–2026)
Read documentation

Dash connects to Google Workspace, Microsoft 365, Slack, Notion and more, and routes queries through large language models — leaving users to trust Dropbox's contractual assurances that connected and indexed data is not used to train third-party AI models.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)Developer, API & Platform
Read documentation