FlipperBack to homepage

Privacy Policy

Last updated August 30, 2026
Google API Services User Data Policy
Flipper’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Every Google scope Flipper requests is read-only, and Google user data is never used to develop, improve or train generalized or non-personalized AI models.

Who we are

Flipper (“Flipper”, “we”, “us”) is a company-memory service operated from India by Arpit Damani. Flipper connects to the tools a team already uses, turns what it finds into a searchable, permission-aware body of company context, and answers questions about that context with citations back to the original source.

This policy explains what information Flipper processes, why, who it is shared with, how long it is kept and how you can get it back or delete it. It applies to the Flipper web application at app.flipperai.in, our website at flipperai.in, the Flipper API, and the Flipper MCP server used by AI assistants such as Claude and ChatGPT.

Flipper is a business product. In most cases an organization (the “customer”) is the controller of the information in its workspace and Flipper acts as its processor, handling that information on the customer’s instructions. If you use Flipper through your employer, your employer’s own policies also apply and questions about that data are best directed to your workspace administrator first.

The short version

  • We only read the sources you explicitly connect, and only with read-only permission.
  • Your content is used to answer your own team’s questions. Nothing else.
  • We do not sell data, we do not serve ads, and we do not use your content — or any Google user data — to train or improve any AI model, ours or anyone else’s.
  • Connected-source content is encrypted with AES-256-GCM before it is stored, and OAuth tokens are encrypted the same way.
  • You can export your entire workspace as JSON at any time, and delete it, at which point it is permanently purged after a 30-day recovery window.
  • Disconnecting a source stops all further access to it immediately.

Google user data we access

When a member of your workspace connects Gmail, Google Drive or Google Calendar, Flipper requests the narrowest Google OAuth scopes that let the feature work. Every Google scope Flipper requests is read-only: Flipper cannot send email, and cannot create, edit, move or delete any file, message or calendar event in your Google Account.

These are the only Google scopes we request, and this is the complete list of what each one is used for:

  • https://www.googleapis.com/auth/gmail.readonly — reads the message content, headers, labels and metadata of the connecting user’s Gmail mailbox. Used to turn email threads into episodes in your company brain, so that decisions, commitments and context agreed over email can be retrieved and cited later. Gmail is connected per person: each user connects their own mailbox, and no other member connects it on their behalf.
  • https://www.googleapis.com/auth/drive.readonly — reads file metadata and the contents of documents in the connected Google Drive. Used to index documents (specs, notes, plans, reports) into your company brain so they can be searched and quoted with a link back to the original file.
  • https://www.googleapis.com/auth/calendar.readonly — reads calendar events, their titles, descriptions, times and attendees. Used to give retrieved context a timeline and to relate meetings to the people and decisions that came out of them.
  • Sign-in only: email address, name and profile picture, when you choose “Continue with Google”. Used to create and identify your account. No Workspace content is read for sign-in.

How Google user data is used, stored and shared

Content retrieved from Gmail, Drive and Calendar is processed into episodes and facts: short, sourced statements that record what was said or decided, together with a link back to the original message, file or event. Episode content is encrypted with AES-256-GCM before it is written to our database, and the OAuth tokens that authorize access are encrypted with a separate key using the same algorithm.

Retrieved content is visible only inside the workspace that connected the source, and only to the members whose access permits it. Flipper carries source permissions and departmental grouping through to retrieval, so connecting a source does not flatten its access controls.

To generate embeddings and to synthesize facts and answers, the relevant excerpts are sent to the AI providers listed in the sub-processors section below. This transfer happens only to produce the user-facing features you asked for — search, answers and citations. Those providers process the data under their API terms and do not use API content to train their models. Workspaces that supply their own API key (BYOK) send that content directly under their own provider account instead.

Google user data is never sold, never used for advertising or profiling, never shared with data brokers, and never combined into any cross-customer dataset. It is never used to develop, improve or train generalized or non-personalized AI or machine-learning models.

No Flipper employee reads your Google user data. The narrow exceptions are: with your explicit permission for specific items, for example when you send them to us to debug a problem you have reported; where necessary for security investigations, to comply with applicable law, or to enforce our Terms; and where the data has been aggregated and anonymized so that it no longer identifies you or your content.

Limited Use commitment

Flipper’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The policy is available at https://developers.google.com/terms/api-services-user-data-policy.

Concretely, that means all of the following:

  • We limit our use of Google user data to providing and improving the user-facing features that are prominent in Flipper’s interface — search over your company context, sourced answers, and the memory browser that shows you exactly what was ingested.
  • We do not transfer Google user data except as necessary to provide or improve those features, to comply with applicable law, or as part of a security investigation. Any transfer in connection with a merger or acquisition would only occur after notice and with your explicit consent.
  • We do not use Google user data for serving advertisements of any kind, including personalized, retargeted or interest-based advertising.
  • We do not allow humans to read Google user data, except with your affirmative agreement for specific items, where necessary for security or to comply with the law, or where the data is aggregated and anonymized for internal operations.
  • We do not use Google Workspace API data to develop, improve or train generalized or non-personalized artificial intelligence or machine-learning models.

Revoking Google access

You can disconnect Gmail, Drive or Calendar at any time from the Connectors page in Flipper. Disconnecting stops all polling immediately and removes the stored credentials for that source.

You can also revoke Flipper’s access directly from your Google Account at https://myaccount.google.com/permissions, which takes effect immediately and independently of Flipper.

Disconnecting or revoking stops future access. Context that was already ingested remains in your workspace so that existing answers keep their citations. To remove that too, delete the individual items from the memory browser, or delete the workspace, which purges everything as described under Retention and deletion.

Other connected sources

Beyond Google, Flipper can connect to Slack, Notion, Jira and Trello. These are workspace-level connections made once by an owner or administrator, and they are read with the narrowest permissions each provider offers. The same handling applies to them as to Google data: encrypted at rest, scoped to the connecting workspace, used only to serve that workspace, never sold and never used for model training.

Each connected provider processes data under its own agreement with your organization. Connecting a source in Flipper does not change your relationship with that provider.

Information you give us directly

  • Account information: your name, email address and profile picture, handled through our authentication provider.
  • Workspace information: your workspace name, the roles and groups you configure, invitations you send, and the answers given during onboarding, which are used to shape how context is organized for your team.
  • Support communications: the messages, screenshots and diagnostic details you choose to send us.
  • Provider API keys, if you bring your own: stored encrypted and used only to make requests on your workspace’s behalf.
  • Technical and usage information: IP address, browser and device type, pages viewed, feature usage, token counts, and error and performance logs. We use Google Analytics on our marketing website; you can opt out with Google’s browser add-on or by blocking the script.

How we use information

  • To provide the service: ingest the sources you connect, build your company brain, and answer questions with citations.
  • To enforce access: decide what each person and each agent token is permitted to retrieve.
  • To keep an audit trail: record who connected, retrieved, corrected, exported or deleted what, so your administrators can review it.
  • To meter usage: count tokens against your plan limit and, where applicable, bill accurately.
  • To secure the service: detect abuse, investigate incidents, and prevent unauthorized access.
  • To support you: respond to the questions and problem reports you send us.
  • To comply with the law and to establish, exercise or defend legal claims.

How we do not use information

  • We do not sell or rent personal information, and we have not done so in the past twelve months.
  • We do not serve advertising, and we do not share your content with advertising networks.
  • We do not train AI or machine-learning models on your content, and we do not permit our providers to do so.
  • We do not use one customer’s content to answer another customer’s questions. Workspaces are isolated.
  • We do not build cross-customer profiles or aggregate datasets from customer content.

Sub-processors

Flipper relies on the following providers to operate. Each is bound by its own terms and processes data only to deliver its part of the service.

  • Render — application hosting and deployment (United States).
  • Supabase — managed PostgreSQL database storing your workspace, episodes and facts.
  • Upstash — managed Redis backing the ingestion job queue.
  • Clerk — user authentication and session management.
  • Cloudflare — DNS, TLS and network protection for flipperai.in.
  • Amazon Web Services (S3) — object storage for original source files, where a workspace enables it.
  • Google (Gemini API) — fact synthesis and answer generation. API content is not used to train Google’s models.
  • Anthropic (Claude API) — fact synthesis and answer generation. API content is not used to train Anthropic’s models.
  • OpenAI — text embeddings used for semantic search. API content is not used to train OpenAI’s models.
  • Google Analytics — aggregate traffic measurement on our marketing website only. It does not run inside the Flipper application and never sees your company context.

Security

Connected-source content and OAuth tokens are encrypted with AES-256-GCM before storage, using keys held separately from the database. All traffic to Flipper is served over TLS. Access to production systems is restricted to the people who need it and is logged.

Inside the product, retrieval is access-aware: departmental groups constrain what each member can see, agent tokens carry their own scoped grants, sensitive material can be held for review, and every answer shows its sources so nothing arrives without provenance. Administrative actions are written to an audit log.

No system is perfectly secure. If we become aware of a breach affecting your information, we will notify affected customers and, where required, the relevant authorities, without undue delay.

Retention and deletion

We keep workspace content for as long as the workspace is active, because that content is the product: removing it would remove the answers your team relies on.

Individual facts and episodes can be corrected, retracted or deleted from the memory browser at any time. Retracted items are excluded from retrieval and retained only so that the history of a correction stays auditable.

A workspace owner can delete an entire workspace. Deletion is immediate in effect — ingestion stops, no member or agent can read the workspace, and a banner shows the scheduled purge date — and reversible for 30 days. After 30 days a scheduled job permanently purges the workspace and its contents. Backups age out on their own cycle shortly after.

Before deleting, an owner can export the whole workspace as a single JSON file, including episodes, facts, their sources, sensitivity and provenance. Audit records and records we must keep for legal, tax or accounting reasons are retained for as long as the applicable law requires.

Your rights

Depending on where you live, you may have the right to access, correct, export, delete or restrict the processing of your personal information, to object to certain processing, and to withdraw consent. Residents of the EEA and UK have these rights under the GDPR; residents of India have comparable rights under the Digital Personal Data Protection Act, 2023; residents of California have rights under the CCPA, including the right not to be discriminated against for exercising them.

Most of these are self-service in Flipper: export and deletion are one action each in the application, and the memory browser lets you see and correct exactly what has been stored about any person or topic. For anything else, or if you use Flipper through your employer and they cannot help, write to us at the address at the bottom of this page. We will verify your identity before acting and will not charge you for a reasonable request.

If you believe we have not handled your request properly, you may complain to your local data protection authority.

International transfers

Flipper is operated from India and our infrastructure and sub-processors are located primarily in the United States. Using Flipper therefore involves transferring information across borders. Where required, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, together with the technical measures described above.

Children

Flipper is a workplace product and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.

Changes to this policy

We may update this policy as the service changes. The date at the top of this page always reflects the current version. If a change materially affects how we handle your information — in particular any change to the Google scopes we request or how Google user data is used — we will notify workspace administrators by email before it takes effect, and where the law requires it we will ask for your consent.

Contact

Questions about this document, or a request about your data, can be sent to heyflipperai@gmail.com. We aim to respond within 30 days.