Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

Upgrade nagware: relentless upsell prompts, badges, and emails

2019–2026 (ongoing)

LowStatus: OngoingProduct: Dropbox app (free and paid tiers)Year: 2021

Users have long complained that Dropbox badgers them with upgrade prompts, full-page upsell interstitials, in-app badges, and marketing emails — pressure that hits not only free accounts but, by users' accounts, paying Professional customers too.

What happened

A recurring grievance across Dropbox's forums, Hacker News, and tech commentary is that the product nags users to upgrade. Free Basic users report stacks of windows asking them to upgrade that are 'hard to get rid of,' repeated even after declining, plus a steady stream of marketing emails some describe as 'alarmist alerts' thinly disguised as account notices.

The complaint is not confined to free users. Paying customers have objected that upsell interstitials interrupt their workflow — one widely cited account described leaving Dropbox after a full-page 'Dropbox Business' upsell appeared on a paid account, calling it 'wrong' to disrupt a paid, professional workflow for an ad. Over the years Dropbox layered in 'badge' notifications, in-app prompts, and email campaigns that users found difficult to fully silence.

While some design analysts have praised Dropbox's upgrade prompts as relatively unobtrusive, that framing sits in tension with the volume of user complaints, which span from roughly 2019 through the mid-2020s and treat the constant prodding as a degradation of the product experience rather than a neutral monetization feature.

Impact

Persistent upsell pressure is a low-severity but corrosive form of product change: individually minor, cumulatively it makes the app feel like adware and erodes goodwill, particularly among paying users who feel they should be exempt. The nagware reputation has been a recurring reason cited by users who migrated to OneDrive, Google Drive, or self-hosted tools, and it reinforces the perception that Dropbox optimizes for conversion over user experience.

Dropbox's Response / Official Position

Dropbox has not issued a single formal response to the 'nagware' criticism; its support channels typically point users to notification and email-preference settings to reduce prompts. The upgrade prompts, badges, and marketing emails have remained a standard part of the free and entry-level experience.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

In an 8-K filed May 26, 2026, Dropbox disclosed that co-founder Drew Houston would step back as CEO after 19 years, with the Board appointing Ashraf Alkarmi — its General Manager, Core — as Co-Chief Executive Officer effective that date, ahead of Alkarmi becoming sole CEO and Houston moving to executive chairman 'following a transition period.' The handoff arrives as AI upends the software era Dropbox grew up in and the company's revenue sits near flat.

Product Changes & User BacklashCurrent / Ongoing Issues (2024–2026)
Read documentation

Dropbox's Q1 and Q2 2026 results both kept total reported revenue growth under 1% year-over-year, the company refinanced debt and repurchased hundreds of millions of dollars in stock over the same six months, and the period closed with a co-CEO handoff, a new product chief, and a routine, tax-related insider stock disposition reported by the Motley Fool.

Pricing & Business PracticesCurrent / Ongoing Issues (2024–2026)
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation