Last updated September 1, 2026
Privacy Policy
This policy explains the information Flipper processes through its web and iOS apps to provide album-collection, community, and listening features.
Information we process
- Account information, including your email address, username, and account identifier. Supabase handles authentication credentials.
- Profile and collection information you provide or create, such as your bio, avatar, preferred streaming services, stacks, saved albums, ratings, reviews, notes, follows, and play or skip activity.
- Support requests and feedback you submit, including your message and the page, app, browser, device, and technical context sent with it.
- Safety information, including accounts you block, reports you submit or receive, and records of moderation decisions. Reports can include the reason and optional details supplied by the reporter.
- Usage and operational information such as page paths and query strings, which can include search terms; referrers; timestamps; authentication status; play, skip, save, and follow activity; and diagnostic information when an error is reported.
Public information
Your username, avatar, bio, public stacks and their albums, reviews, and some community activity can be visible to other people. Private stacks and personal album notes are not public. Review visibility is controlled by the related album and profile views, not by a separate private-review setting.
How we use information
- To create and secure accounts and maintain your session.
- To provide your profile, library, stacks, reviews, notes, follows, and listening features.
- To show public profile and stack content where you choose to make it public.
- To understand app usage, respond to feedback, diagnose failures, and improve the service.
- To enforce our Community Guidelines, prevent unwanted interactions, investigate reports, and document moderation decisions.
- To calculate album and community popularity. Account deletion keeps only approved date-bucketed totals that cannot be tied back to the deleted account.
Service providers and external services
Flipper uses Supabase for authentication, database, and file-storage services, and Vercel for application delivery and privacy-focused web analytics. Flipper also records its own page-view and diagnostic data. We query Spotify, Apple Music, and Odesli to find album metadata and streaming links. When you choose a streaming link, you leave Flipper for that service, whose privacy practices apply. We do not sell personal information or use it for targeted advertising.
Cookies and similar storage
Supabase authentication uses cookies to keep you signed in. Flipper can use browser session storage to restore account navigation and uses Keychain storage in the native iOS app to preserve its session. Vercel Web Analytics does not use third-party advertising cookies. Flipper does not use advertising identifiers or track you across other companies’ apps and websites.
Retention and security
We retain account and collection information while your account is active or as needed to operate the service. Feedback is retained while it is useful for support and product improvement. Reports are visible only to authorized moderators and are retained while needed to review and enforce our rules. Minimal moderation records can be retained for safety, audit, and abuse-prevention purposes. Flipper targets deletion of operational error logs after 30 days. Analytics records can be retained for historical service measurement; account-linked analytics are anonymized when the account is deleted. We use access controls and row-level database policies to limit access, but no online service can guarantee absolute security.
Data export and account deletion
In Settings → Account, you can download a CSV of your saved albums, ratings, reviews, notes, and stack names. You can also permanently delete your account after confirming your current password. Deletion removes your email, profile, avatar, saved albums, ratings, reviews, notes, follows, identifiable activity, and stacks that nobody else follows.
If another person still follows one of your public stacks, that stack remains as an ownerless community stack. Its owner identity and description are removed. Flipper also retains date-and-album aggregate popularity counts without an account, profile, stack, free-text, or event identifier.
Your choices and requests
You can update your profile and streaming preferences in Flipper and control whether stacks are public. You can block another account from its profile and manage blocked accounts in Settings. Blocking is not disclosed to the blocked person. You can use the export and deletion tools described above, or request access, correction, or help by contacting support@flipper.fm. Available rights may depend on where you live. See Support for additional help.
Changes and contact
We may update this policy when our practices change. The latest version will appear here with its updated date. For privacy questions, email support@flipper.fm. Our Community Guidelines explain the standards for public content.