Product
Terms, privacy & compliance
4 documented issues affecting Terms, privacy & compliance, most severe first.
The 2022 phishing breach: 130 internal GitHub repositories stolen
A phishing campaign impersonating the CI provider CircleCI tricked Dropbox employees into handing over credentials and 2FA codes, letting attackers copy 130 of Dropbox's private source-code repositories.
The fine print that takes your day in court: Dropbox's arbitration clause and class-action waiver
Dropbox's Terms of Service require binding individual arbitration and waive your right to join a class action — so even after a breach or billing dispute, most users cannot sue Dropbox or band together in court.
Dropbox's transparency reporting centers on US legal process, but as a global service it also faces foreign-government and cross-border demands — an area where its disclosures are thinner and the CLOUD Act blurs jurisdictional lines.
A July 2011 terms-of-service and privacy-policy update used broad licensing language that many users read as Dropbox asserting ownership-like rights over their files, forcing the company to publicly clarify and walk back the wording.