Privacy Policy
Last updated: July 16, 2026
What we store
Your account email and name; the buyer price sheets you import (device models, prices, deduction rules); your deal log (devices bought/sold, amounts, buyer names, invoice details); your app settings; and scan results for listings that matched your numbers. API keys you add (Apify, Sickw) are encrypted at rest with AES-256-GCM and are only decrypted server-side to make requests on your behalf.
What we don't store
Card numbers never touch our servers — Stripe handles checkout entirely. We don't sell or share your data with advertisers, and we don't train AI models on your data.
Service providers
We rely on: Supabase (database and login), Vercel (hosting), Stripe (payments), Resend (transactional email), and Anthropic (the text of a price sheet you import is processed by the Claude API to extract prices — API inputs are not used for model training). Marketplace scanning and IMEI checks go through your own Apify and Sickw accounts under their privacy policies.
Cookies
Only the session cookie that keeps you signed in. No tracking or advertising cookies.
Access and deletion
Your data is yours. Email support@flipcommand.app to get a copy of your data or to delete your account — deletion removes your buyer sheets, deals, settings, and encrypted keys.
Changes
Material changes to this policy will be posted here with a new "last updated" date. Questions: support@flipcommand.app.