Privacy Policy
Flipism is local-first. If you never sign in, your flips never leave your device.
The short version
-
Guest Flips and history stay on this device.
Your flips, options, and draw history are stored in a local database on your device. Diagnostics and usage analytics may still be sent.
-
Cloud sync needs sign-in and your confirmation.
Only after you sign in — with Google, or with an email address and password — and confirm sync do your flips get uploaded to your private account storage. Draw history always stays on this device.
-
The app collects diagnostics and usage analytics.
This happens whether or not you sign in. Device identifiers may include the Android advertising ID, when available. Details below.
-
We do not sell your data.
We do not serve ads, we do not build advertising profiles, and we do not share your content with advertisers.
1. Who we are
Flipism is provided by Xiaoyu Yin, operating under the studio name First App Studio ("we", "us"). First App Studio is a studio name, not a separate incorporated legal entity. You can reach us at mensaplus2016@gmail.com. For anything in this policy, that address is the fastest route to a human.
2. Using Flipism without an account (Guest mode)
You can use the core decision modes without registering. Ordinary Guest use keeps your content local. Starting a native purchase or restore can create an anonymous Firebase user ID and associate it with RevenueCat billing and entitlement metadata. This purchase identity is not a registered Flipism account and does not enable content sync. Without confirmed account sync, the following stay on your device only:
- the flips you create, and their names
- the options inside each flip, and their weights
- your draw history and results
- a random installation identifier used to scope the local database
This data lives in a local SQLite database. It is removed when you uninstall the app or clear its storage. We cannot recover unsynced content for you. Signing in and choosing to merge can back up your Flips, but not your draw history.
Native Premium does not require registration or cloud sync. Creating an account can preserve your purchase identity; to link a subscription to an existing account, sign in and restore purchases in the native app. Restore uses the Apple or Google Play account on this device and may move access from a previous Flipism identity. Restoring purchases does not restore or upload Flips or Draw History. To restore previously synced Flips, sign in to their Flipism account and explicitly choose account data; to upload local Flips, choose to merge and confirm sync. Draw History stays on the device.
3. What we collect when you sign in
Signing in is optional and always initiated by you. You can sign in with Google or create an account with an email address and password. Either way, we collect account identity data; content and sync-device data are stored only after you confirm sync:
| Data | Why | Where it goes |
|---|---|---|
| Email address | Identifies your account and is shown in the app so you know which account you are signed into | Firebase Authentication |
| Account ID (user ID) | The stable key that your synced data is filed under | Firebase Authentication, Cloud Firestore |
| Your flip names, option text, weights, and game modes | So your library is available on your other devices and can be restored | Cloud Firestore, under your account only |
| A device identifier generated by the app | Lets sync tell your devices apart so simultaneous edits are not silently overwritten | Cloud Firestore, under your account only |
Before your existing local flips are uploaded, the app asks you to choose: merge this device's data into the account, use the account's data only, or cancel the sign-in. Your local Flips are not uploaded until you confirm sync.
Other users cannot access your synced content. Server-side rules restrict access; authorized service operations and processors may handle it.
4. Diagnostics and analytics
Independently of sign-in, the app includes Google's Firebase Analytics and Firebase Crashlytics SDKs, which collect:
- App interaction events — that the app was opened, which screens were shown, session length
- Device and app information — device model, OS version, app version, language, coarse region
- Device identifiers, which may include the Android advertising ID when available
- Crash logs and diagnostics — stack traces and device state at the time of a crash
We use this only to understand whether the app is working and which features get used. We do not use it for advertising, we do not build profiles, and we do not sell it. The app does not contain ads or third-party ad SDKs.
Product analytics events exclude Flip names, option text and search terms. Crash reports contain diagnostic error details and may include data present in those errors. Separately, supported native release apps can automatically report unexpected handled sync and entitlement failures to Crashlytics when collection is enabled. These nonfatal events use allowlisted error categories/codes and restricted code-location frames, not raw error messages, account IDs, emails, tokens, document IDs or Flip content. Available cached queue counts (not Flip totals) and entitlement loading/error/data state may be included. Routine offline failures are omitted; repeated transport failures spanning at least five minutes may produce a bounded report. Reports are deduplicated and limited; delivery is not real-time or guaranteed, and this reporting is not supported on Web. The local support snapshot is separate and copied only on request.
Our first product events record only that a flip was created and its mode/source, that a draw completed and its mode, that Marketplace or a template category/mode was opened, that sign-in completed and its method, and that a marketplace template was adopted or a flip was edited or deleted. They do not contain template IDs, account IDs, email addresses, search terms, or any flip content.
Your control: Android lets you delete or reset your advertising ID system-wide under Settings → Privacy → Ads. Deleting it stops apps, including Flipism, from receiving it.
5. Device and browser integrity checks
Sensitive actions are protected by Firebase App Check. On Android, Google Play Integrity produces an attestation token that helps our backend confirm a request came from a genuine, unmodified Flipism install. On the web, Firebase App Check uses Google reCAPTCHA Enterprise to help protect against abuse and fraud. Google and the browser may process browser, network, and IP-address information and attestation signals for that purpose. These checks confirm an app or browser request, not your identity, and we do not use them to track you.
5a. Subscription billing
Subscribe to Web Premium from the app. The Web billing disclosures apply to Web subscriptions. Paddle acts as Merchant of Record, with RevenueCat providing subscription entitlement infrastructure. Google Play purchases are available in limited testing; Apple purchase availability is pending verification. Applicable native purchases are processed by the original store; availability depends on your store account, region, and testing access. Apple and Google Play process store payments and transaction records under their own terms and privacy policies; RevenueCat provides entitlement infrastructure for these purchases.
| Processor | Data processed | Purpose |
|---|---|---|
| Paddle, for Web billing | Purchase email, name where provided, country, payment status, transaction, tax, refund, and invoice information | Payment, fraud prevention, support, tax/invoicing, accounting, and legal obligations |
| RevenueCat | Firebase user ID, subscription and product IDs, entitlement status, expiry, and transaction metadata | Entitlement delivery, support, and subscription status |
For native purchases and restores, and Web purchases, Flipism receives and stores the billing and entitlement metadata needed to associate a purchase with an anonymous purchase identity or registered account, such as Firebase user ID, subscription, product, or transaction identifiers, entitlement status, and expiry. Flip names, options, labels, and draw results are never billing attributes. Flipism never receives or stores full card details. Billing processors may retain their records after deletion of a Flipism account where law requires it.
5b. In-app feedback
When available, Send feedback lets you submit 1–1000 characters without registering. Only pressing Send submits your text, app version, platform and interface language. Please do not include personal or sensitive information. Feedback is a one-way suggestion box, not an email conversation; it does not include a reply address.
A separate anonymous Firebase Authentication identity is created on submission and reused to limit abuse. It is separate from your signed-in account and purchase identity and does not enable cloud sync. Feedback and its technical identifier are stored in Cloud Firestore through an App Check-protected server. Other app users cannot read them; authorized operators can review them. The app does not attach your Flips, draw history, email, or diagnostic report. Firebase and integrity providers may process network metadata as described above.
Include usage identifier is enabled by default and can be turned off before sending. When enabled and available under existing Analytics permissions, we attach the Analytics App Instance ID on mobile or GA4 Client ID on Web. This lets authorized operators link your feedback to existing usage events for troubleshooting, not to a complete activity recording. It does not add a registered account ID, email, Flip content, options, or draw results. These identifiers can change after data resets and are not permanent cross-device identities. If an identifier is unavailable, feedback can still be sent. Turning this option off omits the identifier from this feedback; it does not turn off Analytics or delete earlier records. The option does not override Analytics consent settings.
Feedback is scheduled for deletion after 180 days; the provider's asynchronous deletion can take additional time. This expiry applies to Firestore feedback records, not the anonymous Firebase Authentication identity. The anonymous identifier is not your registered account, so deleting that account or uninstalling does not immediately delete previously submitted feedback. Contact us about data rights using the address below. We process voluntarily submitted feedback to improve and support the app and use the technical identifier to prevent abuse.
6. What we never collect
- Precise or coarse GPS location
- Contacts, calendar, photos, files, or microphone input
- Full card details or complete payment credentials
- Health data
Guest content is not synced unless you sign in and choose to merge it.
7. Who we share data with
We do not sell personal data and we do not share it with advertisers or data brokers. The following providers process data as described above. RevenueCat handles native purchase and restore metadata now; Paddle processes Web billing:
- Google LLC — Firebase Authentication, Cloud Firestore, Cloud Functions, Firebase App Check, Firebase Analytics, and Firebase Crashlytics, under Google's terms as our data processor
- Apple and Google Play — store payment, subscription, cancellation, and refund processing under their own policies
- Paddle — Web Merchant of Record, payment, transaction, tax, refund, invoice, and purchase-support processing
- RevenueCat — native and Web subscription and entitlement processing using the billing metadata described above
Synced account content is stored on Google Cloud infrastructure, primarily in the United States. Paddle and RevenueCat process billing and entitlement data as described above. If you use Flipism from outside the United States, your data may be transferred there.
We may disclose data if legally required to do so, or to investigate abuse of the service.
8. Retention and deletion
Your synced data is kept while your account exists. You can delete it permanently from inside the app: Settings → Account & sync → Delete account and cloud data. That removes your synced flips, any legacy cloud draw records, and your Flipism sign-in identity. This account’s Flips and draw history on this device are removed when the app clears the deleted account's local data. Guest data, independent offline copies and data on other devices are not automatically erased.
If you have uninstalled the app, you can still request deletion — see the account deletion page.
Technical records retained after deletion
When an account is deleted, we retain deletion-prevention and deletion-recovery records containing your former account ID, timestamps and technical status. They contain no Flip content or email address.
This exists for a security reason. A device that was offline during the deletion can hold a still-valid cached credential, and without a deletion-prevention record it could re-upload the data you just deleted. Our servers use the record to reject those writes. Recovery records allow interrupted account deletion to finish. These records currently have no automatic expiry.
9. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict processing, and to complain to a supervisory authority.
In practice: your synced data is visible in the app on any device you sign in from, and deletion is available in-app and by request. For anything else, email mensaplus2016@gmail.com and we will respond within 30 days.
Our legal basis for processing account data is performance of our agreement with you (providing sync); for diagnostics and analytics it is our legitimate interest in keeping the app working.
10. Children
Flipism is not directed to children. It is rated for users 18 and over, and we do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Security
All traffic between the app and our servers is encrypted in transit with TLS. Access to account data is enforced server-side by security rules, not only by the app. Account deletion additionally requires you to confirm your identity again — through Google, or by entering your password. The app sends passwords to Firebase Authentication for sign-in and account creation. Passwords are not part of the local Flip database.
12. Changes to this policy
If we change how we handle data, we will update this page and the "last updated" date above. Material changes will also be surfaced in the app.
13. Contact
Questions, requests, or complaints: mensaplus2016@gmail.com