Flipism

Privacy Policy

Flipism is local-first. If you never sign in, your flips never leave your device.

Last updated: 12 September 2026 · Applies to the Flipism mobile app (com.firstappstudio.flipism) and web app.

The short version

1. Who we are

Flipism is provided by Xiaoyu Yin, operating under the studio name First App Studio ("we", "us"). First App Studio is a studio name, not a separate incorporated legal entity. You can reach us at mensaplus2016@gmail.com. For anything in this policy, that address is the fastest route to a human.

2. Using Flipism without an account (Guest mode)

You can use the core decision modes without registering. Ordinary Guest use keeps your content local. Starting a native purchase or restore can create an anonymous Firebase user ID and associate it with RevenueCat billing and entitlement metadata. This purchase identity is not a registered Flipism account and does not enable content sync. Without confirmed account sync, the following stay on your device only:

This data lives in a local SQLite database. It is removed when you uninstall the app or clear its storage. We cannot recover unsynced content for you. Signing in and choosing to merge can back up your Flips, but not your draw history.

Native Premium does not require registration or cloud sync. Creating an account can preserve your purchase identity; to link a subscription to an existing account, sign in and restore purchases in the native app. Restore uses the Apple or Google Play account on this device and may move access from a previous Flipism identity. Restoring purchases does not restore or upload Flips or Draw History. To restore previously synced Flips, sign in to their Flipism account and explicitly choose account data; to upload local Flips, choose to merge and confirm sync. Draw History stays on the device.

3. What we collect when you sign in

Signing in is optional and always initiated by you. You can sign in with Google or create an account with an email address and password. Either way, we collect account identity data; content and sync-device data are stored only after you confirm sync:

Data Why Where it goes
Email address Identifies your account and is shown in the app so you know which account you are signed into Firebase Authentication
Account ID (user ID) The stable key that your synced data is filed under Firebase Authentication, Cloud Firestore
Your flip names, option text, weights, and game modes So your library is available on your other devices and can be restored Cloud Firestore, under your account only
A device identifier generated by the app Lets sync tell your devices apart so simultaneous edits are not silently overwritten Cloud Firestore, under your account only

Before your existing local flips are uploaded, the app asks you to choose: merge this device's data into the account, use the account's data only, or cancel the sign-in. Your local Flips are not uploaded until you confirm sync.

Other users cannot access your synced content. Server-side rules restrict access; authorized service operations and processors may handle it.

4. Diagnostics and analytics

Independently of sign-in, the app includes Google's Firebase Analytics and Firebase Crashlytics SDKs, which collect:

We use this only to understand whether the app is working and which features get used. We do not use it for advertising, we do not build profiles, and we do not sell it. The app does not contain ads or third-party ad SDKs.

Product analytics events exclude Flip names, option text and search terms. Crash reports contain diagnostic error details and may include data present in those errors. Separately, supported native release apps can automatically report unexpected handled sync and entitlement failures to Crashlytics when collection is enabled. These nonfatal events use allowlisted error categories/codes and restricted code-location frames, not raw error messages, account IDs, emails, tokens, document IDs or Flip content. Available cached queue counts (not Flip totals) and entitlement loading/error/data state may be included. Routine offline failures are omitted; repeated transport failures spanning at least five minutes may produce a bounded report. Reports are deduplicated and limited; delivery is not real-time or guaranteed, and this reporting is not supported on Web. The local support snapshot is separate and copied only on request.

Our first product events record only that a flip was created and its mode/source, that a draw completed and its mode, that Marketplace or a template category/mode was opened, that sign-in completed and its method, and that a marketplace template was adopted or a flip was edited or deleted. They do not contain template IDs, account IDs, email addresses, search terms, or any flip content.

Your control: Android lets you delete or reset your advertising ID system-wide under Settings → Privacy → Ads. Deleting it stops apps, including Flipism, from receiving it.

5. Device and browser integrity checks

Sensitive actions are protected by Firebase App Check. On Android, Google Play Integrity produces an attestation token that helps our backend confirm a request came from a genuine, unmodified Flipism install. On the web, Firebase App Check uses Google reCAPTCHA Enterprise to help protect against abuse and fraud. Google and the browser may process browser, network, and IP-address information and attestation signals for that purpose. These checks confirm an app or browser request, not your identity, and we do not use them to track you.

5a. Subscription billing

Subscribe to Web Premium from the app. The Web billing disclosures apply to Web subscriptions. Paddle acts as Merchant of Record, with RevenueCat providing subscription entitlement infrastructure. Google Play purchases are available in limited testing; Apple purchase availability is pending verification. Applicable native purchases are processed by the original store; availability depends on your store account, region, and testing access. Apple and Google Play process store payments and transaction records under their own terms and privacy policies; RevenueCat provides entitlement infrastructure for these purchases.

Processor Data processed Purpose
Paddle, for Web billing Purchase email, name where provided, country, payment status, transaction, tax, refund, and invoice information Payment, fraud prevention, support, tax/invoicing, accounting, and legal obligations
RevenueCat Firebase user ID, subscription and product IDs, entitlement status, expiry, and transaction metadata Entitlement delivery, support, and subscription status

For native purchases and restores, and Web purchases, Flipism receives and stores the billing and entitlement metadata needed to associate a purchase with an anonymous purchase identity or registered account, such as Firebase user ID, subscription, product, or transaction identifiers, entitlement status, and expiry. Flip names, options, labels, and draw results are never billing attributes. Flipism never receives or stores full card details. Billing processors may retain their records after deletion of a Flipism account where law requires it.

5b. In-app feedback

When available, Send feedback lets you submit 1–1000 characters without registering. Only pressing Send submits your text, app version, platform and interface language. Please do not include personal or sensitive information. Feedback is a one-way suggestion box, not an email conversation; it does not include a reply address.

A separate anonymous Firebase Authentication identity is created on submission and reused to limit abuse. It is separate from your signed-in account and purchase identity and does not enable cloud sync. Feedback and its technical identifier are stored in Cloud Firestore through an App Check-protected server. Other app users cannot read them; authorized operators can review them. The app does not attach your Flips, draw history, email, or diagnostic report. Firebase and integrity providers may process network metadata as described above.

Include usage identifier is enabled by default and can be turned off before sending. When enabled and available under existing Analytics permissions, we attach the Analytics App Instance ID on mobile or GA4 Client ID on Web. This lets authorized operators link your feedback to existing usage events for troubleshooting, not to a complete activity recording. It does not add a registered account ID, email, Flip content, options, or draw results. These identifiers can change after data resets and are not permanent cross-device identities. If an identifier is unavailable, feedback can still be sent. Turning this option off omits the identifier from this feedback; it does not turn off Analytics or delete earlier records. The option does not override Analytics consent settings.

Feedback is scheduled for deletion after 180 days; the provider's asynchronous deletion can take additional time. This expiry applies to Firestore feedback records, not the anonymous Firebase Authentication identity. The anonymous identifier is not your registered account, so deleting that account or uninstalling does not immediately delete previously submitted feedback. Contact us about data rights using the address below. We process voluntarily submitted feedback to improve and support the app and use the technical identifier to prevent abuse.

6. What we never collect

Guest content is not synced unless you sign in and choose to merge it.

7. Who we share data with

We do not sell personal data and we do not share it with advertisers or data brokers. The following providers process data as described above. RevenueCat handles native purchase and restore metadata now; Paddle processes Web billing:

Synced account content is stored on Google Cloud infrastructure, primarily in the United States. Paddle and RevenueCat process billing and entitlement data as described above. If you use Flipism from outside the United States, your data may be transferred there.

We may disclose data if legally required to do so, or to investigate abuse of the service.

8. Retention and deletion

Your synced data is kept while your account exists. You can delete it permanently from inside the app: Settings → Account & sync → Delete account and cloud data. That removes your synced flips, any legacy cloud draw records, and your Flipism sign-in identity. This account’s Flips and draw history on this device are removed when the app clears the deleted account's local data. Guest data, independent offline copies and data on other devices are not automatically erased.

If you have uninstalled the app, you can still request deletion — see the account deletion page.

Technical records retained after deletion

When an account is deleted, we retain deletion-prevention and deletion-recovery records containing your former account ID, timestamps and technical status. They contain no Flip content or email address.

This exists for a security reason. A device that was offline during the deletion can hold a still-valid cached credential, and without a deletion-prevention record it could re-upload the data you just deleted. Our servers use the record to reject those writes. Recovery records allow interrupted account deletion to finish. These records currently have no automatic expiry.

9. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict processing, and to complain to a supervisory authority.

In practice: your synced data is visible in the app on any device you sign in from, and deletion is available in-app and by request. For anything else, email mensaplus2016@gmail.com and we will respond within 30 days.

Our legal basis for processing account data is performance of our agreement with you (providing sync); for diagnostics and analytics it is our legitimate interest in keeping the app working.

10. Children

Flipism is not directed to children. It is rated for users 18 and over, and we do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Security

All traffic between the app and our servers is encrypted in transit with TLS. Access to account data is enforced server-side by security rules, not only by the app. Account deletion additionally requires you to confirm your identity again — through Google, or by entering your password. The app sends passwords to Firebase Authentication for sign-in and account creation. Passwords are not part of the local Flip database.

12. Changes to this policy

If we change how we handle data, we will update this page and the "last updated" date above. Material changes will also be surfaced in the app.

13. Contact

Questions, requests, or complaints: mensaplus2016@gmail.com