This is a print-friendly report. Click Print and choose “Save as PDF” in the destination dropdown to download.

SaaSGuard Risk Report

Dropbox

dropbox.com

Generated May 4, 2026

Grade C

Score: 67 / 100

Executive summary

We analyzed Dropbox’s Terms of Service across 8 risk dimensions and found 7 flagged clauses across 5 categories. 1 material change detected in the recent crawl history.

Recent material changes

  • 3/4/2024 · severity 4

    Dropbox introduced Dropbox AI and quietly authorized sharing user file contents with OpenAI and other third-party AI providers. The update removed the prior guarantee that files wouldn't be shared with AI providers.

    Users storing tax documents, NDAs, financial records, or medical files in Dropbox — these can now be sent to OpenAI's infrastructure as part of AI feature processing, with OpenAI's separate retention policy applying.

Flagged clauses by category

Auto-renewal traps (1)

  • Severity 2 · minor

    We’ll automatically bill you from the date you convert to a Paid Account and on each periodic renewal until cancellation.

    Dropbox automatically bills you starting from the date you convert to a Paid Account and for each renewal period until you cancel.

    You will be charged automatically for renewals unless you actively cancel your subscription.

Surprise price hikes (1)

  • Severity 3 · notable

    We may change the fees in effect on renewal of your subscription, to reflect factors such as changes to our product offerings, changes to our business, or changes in economic conditions. We’ll give you no less than 30 days’ advance notice of these changes via a message to the email address associated with your account and you’ll have the opportunity to cancel your subscription before the new fee comes into effect.

    Dropbox may change subscription fees upon renewal to reflect business changes, and will provide at least 30 days' notice via email, allowing you to cancel before the new fee takes effect.

    Your subscription cost may increase upon renewal, and you must cancel within 30 days of notice to avoid the new price.

Termination friction (2)

  • Severity 4 · material

    We won’t provide notice or an opportunity to export Your Stuff before termination or suspension of access to the Services where Dropbox reasonably believes: you’re in material breach of these Terms, which includes, but is not limited to, violating our Acceptable Use Policy, doing so would cause us legal liability or compromise our ability to provide the Services to our other users, or we're prohibited from doing so by law. Once we suspend or terminate your access to the Services, you will not be able to access or export Your Stuff.

    Dropbox may terminate or suspend your access and prevent data export without notice if it reasonably believes you materially breached the terms, it would cause legal liability or compromise service, or if legally prohibited.

    You risk immediate loss of access and data if Dropbox believes you have violated the terms, even without prior warning.

  • Severity 3 · notable

    We’ll provide you with reasonable advance notice via the email address associated with your account to remedy the activity that prompted us to contact you and give you the opportunity to export Your Stuff from our Services. If after such notice you fail to take the steps we ask of you, we’ll terminate or suspend your access to the Services.

    Dropbox will give you reasonable advance notice via email to fix issues that prompted contact and allow you to export your data before terminating or suspending your access.

    You may lose access to your data if you do not resolve issues within the timeframe Dropbox provides.

Liability caps (2)

  • Severity 4 · material

    IF YOU USE THE SERVICES FOR ANY COMMERCIAL, BUSINESS, OR RE-SALE PURPOSE, DROPBOX, ITS AFFILIATES, SUPPLIERS OR DISTRIBUTORS WILL HAVE NO LIABILITY TO YOU FOR ANY LOSS OF PROFIT, LOSS OF BUSINESS, BUSINESS INTERRUPTION, OR LOSS OF BUSINESS OPPORTUNITY.

    Dropbox, its affiliates, suppliers, or distributors disclaim all liability for any loss of profit, business interruption, or business opportunity if you use the services for commercial, business, or re-sale purposes.

    You cannot recover any business losses from Dropbox if you use the service for commercial purposes.

  • Severity 4 · material

    OTHER THAN FOR THE TYPES OF LIABILITY WE CANNOT LIMIT BY LAW (AS DESCRIBED IN THIS SECTION), WE LIMIT OUR LIABILITY TO YOU TO THE GREATER OF $20 USD OR 100% OF ANY AMOUNT YOU'VE PAID UNDER YOUR CURRENT SERVICE PLAN WITH DROPBOX.

    Dropbox limits its liability to you to the greater of $20 USD or 100% of the amount you paid under your current service plan, excluding liabilities that cannot be limited by law.

    Your ability to recover damages from Dropbox is capped at a low amount, regardless of your actual losses.

Right to silently change terms (1)

  • Severity 3 · notable

    We may revise these Terms to better reflect: changes to the law, new regulatory requirements, or improvements or enhancements made to our Services. If an update affects your use of the Services or your legal rights as a user of our Services, we’ll notify you prior to the update's effective date by sending an email to the email address associated with your account or via an in-product notification. These updated terms will be effective no less than 30 days from when we notify you.

    Dropbox may revise the terms to reflect legal or service changes and will notify you at least 30 days before the update's effective date via email or an in-product notification.

    You must review and understand updated terms of service, as they will apply to your use of the service after the notice period.

Methodology

SaaSGuard uses an automated pipeline: a daily Playwright crawler captures each vendor’s public Terms of Service, Privacy Policy, and DPA. Google’s Gemini 2.5 Flash classifies each clause into one of 8 risk categories with a severity score (1–5). Clauses are cross-referenced against a curated database of real lawsuits and FTC actions via embedding-based similarity matching. Grades are computed from per-category max severity; full source code is available on request.

Built for educational and informational purposes. Not legal advice. Always have your own counsel review SaaS contracts before signing.

View live page →