← App Prototypes
App Prototypes 2026-08-27

Drop Watch

Track whether the data brokers on your California deletion request actually met their deadline, and draft the complaint the moment one doesn't.

Drop Watch
Prototype

DropWatch

Track whether the data brokers on your California deletion request actually met their deadline, and draft the complaint the moment one doesn't.

Date: 2026-08-27 Form factor: web app Status: Prototype

What it is

DropWatch is a compliance tracker for California's DROP platform, the state's centralized system for requesting that data brokers delete your personal information. You log the brokers tied to your request, and the app tracks each one's 45-day access-and-response clock, flags the ones that missed it, and adds up the penalty they're supposed to owe for missing it. A third tab turns an overdue broker into a complaint you can copy and file.

Who it serves

A California resident who filed a DROP deletion request back in January 2026 and, now that brokers are actually required to act on it, has no easy way to tell which of the 600-plus registered brokers complied and which did nothing. This tool assumes you're willing to check a broker's people-search page yourself and log what you found; it isn't a fully automated opt-out service like DeleteMe or Optery, and it doesn't pretend to be.

Why it could be profitable

The free tier tracks a handful of brokers by hand. A paid tier ($4–6/month) would import the full CPPA registry automatically, send a reminder before each broker's deadline, and auto-file complaints instead of requiring a copy-paste. The math behind the complaint feature is what makes it worth paying for: brokers that miss a deletion request owe $200 per request per day, and most consumers have no idea that clock is even running.

The trigger for this idea is specific and recent: DROP's deletion mandate took effect August 1, 2026, roughly 450,000 Californians had already filed requests through the platform, and more than 600 data brokers are on the hook to act on them. That's a real enforcement window, not a hypothetical one. What's less certain is whether people will track this themselves instead of just paying DeleteMe or Optery to handle the whole thing — those services already run broad opt-outs for $100–200 a year, and neither one currently markets a dedicated DROP compliance clock or complaint generator, which is the gap this fills for now. If they add it, and it wouldn't take much, the standalone version stops being interesting.

Form factor & scope

Lives as a web app. The natural next step is a browser extension or scheduled check that visits a broker's people-search page automatically instead of asking the user to look and report back, but that's out of scope here. This prototype demonstrates the compliance dashboard, the broker directory, and the complaint generator against a curated set of 20 real, CPPA-registered brokers.

How to run it

  1. Open index.html in any modern browser. Sample data is embedded in the page as an inline JSON block rather than loaded with fetch, since fetch can't read a local file over file:// in Chromium-based browsers without a server; sample-data.json still ships alongside as the canonical copy of that data.
  2. On My brokers, see the 10 tracked brokers sorted by urgency, from overdue down to verified deleted. Click a row to log a check-in ("still appearing" or "verified deleted").
  3. Switch to Broker directory to search the full 20-broker list and track one that isn't tracked yet.
  4. Switch to File a complaint to see the generated complaint text for every broker that's overdue or still showing your data, with the accrued penalty estimate, and copy it to your clipboard.

What's in this prototype

  • A compliance dashboard for 10 tracked brokers, each with a deadline, a status badge, and a days-remaining or days-overdue count computed against the current date.
  • A summary bar totaling brokers tracked, brokers verified deleted, brokers needing attention, and total estimated penalty exposure.
  • A check-in flow that lets you mark a broker "verified deleted" or "still appearing," which is what moves it into the complaint queue.
  • A 20-broker directory (10 tracked, 10 not) drawn from real CPPA-registered data broker names, searchable by name or category.
  • A complaint generator that fills in broker name, CPPA-style registration reference, deadline, days overdue, and penalty math into copyable text.
  • sample-data.json with all 20 brokers and a fixed DROP submission date; broker names are real, but the request and compliance status attached to each is simulated demo data representing one hypothetical user, not a claim about how these companies have actually behaved.

Roadmap

  • Pull the live CPPA broker registry instead of a hand-curated list, since it updates as brokers register and deregister.
  • Automate the check-in step by fetching a broker's people-search result instead of asking the user to look and report.
  • Email or push reminders a few days before a broker's deadline, and again the day it's missed.
  • One-click filing to the CPPA's actual complaint intake instead of copy-paste text.
  • Aggregate anonymized compliance data across users to name which brokers are chronically late, which is worth more than any individual complaint.

Sources

Requirements

DropWatch — Requirements

Goals

  • Give a consumer who filed a California DROP deletion request one place to see which registered data brokers have met their deadline and which haven't.
  • Turn a missed deadline into a filing-ready complaint with the penalty math already done.
  • Make it clear at a glance where attention is needed, without requiring the user to track 20+ individual dates in their head.

Primary user

A California resident who submitted a deletion request through the state's DROP platform in early 2026. They're privacy-conscious but not a lawyer, and they're willing to spend a few minutes checking a broker's site themselves. They want a place to log what they found, understand what's overdue, and act on it, not a black-box service that claims to handle everything invisibly.

Functional requirements

  • FR1: The dashboard must list all tracked brokers with a status badge, next deadline date, and days-remaining or days-overdue count.
  • FR2: Days-remaining and days-overdue must be computed live against the current date, not hardcoded.
  • FR3: The dashboard must sort brokers by urgency by default: still appearing and overdue first, then due soon, then on track, then verified deleted.
  • FR4: A summary bar must show total brokers tracked, brokers verified deleted, brokers needing attention, and total estimated penalty exposure across overdue and still-appearing brokers.
  • FR5: Penalty exposure for a broker must be calculated as $200 times the number of days since its response deadline passed, and only applies once that deadline has passed.
  • FR6: A user must be able to log a check-in on any tracked broker, marking it "verified deleted" or "still appearing," with an optional note.
  • FR7: Marking a broker "still appearing" after its deadline has passed must move it into the complaint queue.
  • FR8: The broker directory must list all 20 sample brokers, tracked and untracked, each with name, category, and a CPPA-style registration reference.
  • FR9: The directory must be searchable by broker name or category.
  • FR10: A user must be able to track an untracked broker from the directory, which adds it to the dashboard with a computed first deadline.
  • FR11: The complaint tab must list every broker currently eligible for a complaint (overdue or still appearing past deadline).
  • FR12: Each complaint entry must generate letter text that includes the broker's name, registration reference, deadline, days overdue, and estimated penalty owed.
  • FR13: A user must be able to copy a generated complaint letter to the clipboard with one action.
  • FR14: All broker and user data must load from an inline JSON script block embedded in index.html (mirroring sample-data.json) rather than via fetch, since fetch against a local file is blocked in Chromium-based browsers without a server.
  • FR15: Status badges must pair color with a text label, not rely on color alone.

User stories

  • As a DROP filer, I want to see which of my tracked brokers are overdue at a glance, so that I know where to focus first.
  • As a DROP filer, I want to check a broker's people-search page myself and log what I found, so that the tracker reflects reality instead of guessing.
  • As a DROP filer whose data is still showing up after the deadline, I want a complaint already drafted with the right numbers in it, so that filing takes minutes instead of research.
  • As a DROP filer, I want to see my total penalty exposure across every noncompliant broker, so that I understand the scale of what's owed, not just one broker at a time.
  • As a DROP filer, I want to search the broker directory and add one I hadn't been tracking, so that my dashboard reflects every broker that has my data, not just the ones I started with.
  • As a DROP filer, I want a broker I've verified as deleted to visibly drop out of the "needs attention" list, so that the dashboard only asks me to act on what still needs it.

Non-functional requirements

  • The app must run entirely client-side from index.html, with no build step and no server dependency beyond serving static files.
  • No user data leaves the browser; there's no backend in this prototype.
  • The layout must remain usable at mobile width (single-column below 720px).
  • Status and urgency must be distinguishable without relying on color perception alone.
  • Newly tracked brokers and logged check-ins persist only for the current page session; there's no localStorage or backend in this prototype.

Out of scope (for the prototype)

  • Live integration with the CPPA broker registry or the actual DROP system.
  • Automated verification of a broker's people-search page; check-ins are self-reported by the user.
  • Actual submission of a complaint to the CPPA; the letter is generated text only, meant to be copied.
  • User accounts, authentication, or cross-device sync.
  • Email, push, or SMS reminders.

Open questions

  • Would a user actually check a broker's site by hand often enough to keep this useful, or does the product only work once automated verification exists?
  • Is the $200-per-day penalty something the CPPA will actually enforce broker-by-broker, or mostly a ceiling that gets negotiated down in practice? That affects how much weight the complaint feature can credibly carry.
  • If DeleteMe or Optery add a compliance-clock feature to their existing opt-out service, is there still a reason for a standalone tracker to exist?

More from App Prototypes