Privacy Policy
Flippy: AI PDF & EPUB Reader · Effective September 13, 2026
Overview
Flippy is a PDF and EPUB reader for Android and iOS, with optional read-aloud, AI, and cloud sync features. Your privacy matters to us. This policy explains what data Flippy accesses, how it is used, and your choices. In short: your books stay on your device, there are no ads, we do not sell your data, and the only things that ever leave your device are the specific pieces of text (or reading data) needed to run a feature you chose to use.
Data Stored on Your Device
Flippy stores your library and everything you create locally on your device. This data stays there unless you choose to sign in and turn on Cloud Sync (free and optional; see the next section), and even then only the reading data listed there is uploaded — never your files. The read-aloud and AI features described further down are the other exception: when you use one, the specific text involved is sent away to be processed, as explained in those sections.
- PDF and EPUB files you import into the app (an EPUB is converted into pages on your device when you import it)
- Bookmarks, highlights, notes, and annotations you create, and drawings made with the draw tool
- Reading progress and statistics (current page per book, pages read, time spent, streaks, the dates you read)
- App preferences (theme, language, reading settings, voice and reading style, collections and tags)
- Your AI conversations — the questions you ask and the answers you get back are saved on your device so you can come back to them later, kept separately for each book. They are never uploaded, and they are deliberately not included in Cloud Sync. You can erase a book's conversation at any time with the "Clear chat" button in the AI panel.
- Saved study sets and My Words — flashcards and quizzes you save, and the personal dictionary of words you look up, are kept on your device and are not synced
- Downloaded read-aloud audio — if you choose to download a chapter for offline listening, the generated audio is saved in the app's private storage on your device and can be deleted at any time
- A copy of your top-up balance — if you buy a top-up pack, the app keeps a local copy of your remaining minutes and AI uses; the master record lives on our backend (see In-App Purchases)
Flippy's interface is available in 15 languages. Your language choice is stored on your device and travels with AI requests so that answers come back in your language.
This local data is stored in your device's app storage and is not accessible to us or any third party.
Cloud Sync (optional, free)
Cloud Sync is optional and free for all users — no subscription is required to sign in or sync. Nothing is uploaded until you sign in. If you choose to sign in, the following applies:
- Authentication: You sign in with your Google account through Google Sign-In and Firebase Authentication. We receive your name, email address, profile photo, and a Firebase user ID, which are used to show who is signed in and to file your synced data under your account. We do not see or store your Google password.
- Data synced: For each book in your library: its name and page count (so a second device can recognize the same file; the file itself is matched by a fingerprint computed on your device), your bookmarks and their notes, your highlights (including the highlighted passage, its color, and any note), your reading position, and which collection it belongs to. Plus your collections and your reading statistics (pages read, minutes, streaks, and the dates you read). This is stored in Google Firebase Firestore under your Firebase user ID and is written while you are signed in.
- Never synced: your PDF and EPUB files, your AI conversations, saved study sets, My Words, downloaded audio, and top-up balances. Only your reading data is synced.
- Signing out stops syncing and leaves your cloud data in place for the next time you sign in. Delete Account & Data in Settings → Cloud Sync deletes the reading data we hold for you in Firestore and signs you out; your local data is untouched. See Data Deletion below.
Free Week, Free Sample, and Paid Allowances
The read-aloud and AI features below are available with a Premium or Pro subscription, during the free week that starts when you first install the app, from a small free monthly sample, or from a purchased top-up pack. The data handling described in each section is the same in every case. When a free user's sample minutes run out, read-aloud continues in your phone's own built-in voice, which runs entirely on your device and sends nothing anywhere.
AI Read-Aloud
Flippy offers natural-voice text-to-speech powered by OpenAI's Text-to-Speech API.
- When you use this feature, the text of the page being read is sent via our backend to OpenAI's servers to generate audio. So that playback does not pause between pages, the text of the next page or two may be sent slightly ahead of when you reach it. If you ask Flippy to read an AI answer out loud, that answer text is sent as well. Downloading a chapter for offline listening generates its audio the same way, once, at download time.
- No PDF or EPUB files are uploaded. Only extracted text is transmitted.
- OpenAI processes the text and returns audio. OpenAI's use of this data is governed by OpenAI's API Data Usage Policies. Per their policy, data sent via the API is not used to train their models.
- Audio cache: so that re-reading a chapter does not generate the same audio twice, our backend keeps a copy of generated audio in Cloudflare's edge cache for up to 30 days. Each copy is filed under a one-way hash of the text together with the voice, speed, and reading style — not under your install token — so it is not linked to you. It does mean that audio of a page you listened to can exist on our infrastructure for up to 30 days, and that anyone who requests exactly the same text with the same settings would receive the same cached audio.
- The short voice-preview sentences in Settings are fixed sample lines, not text from your books.
AI Q&A, Summaries, Explain, Study Tools, and Define
Flippy uses Anthropic's Claude API to answer questions about your books, generate summaries, explain highlighted passages, create study materials (flashcards and quizzes) from chapters you choose, and define words.
- When you use these features, the text content of your book (the most relevant pages for your question, or the chapter you selected) is sent to Anthropic's Claude API along with your question.
- To work out which pages are the most relevant, Flippy may first send your document's table of contents together with a short one-line extract from each page. This step covers more of your document than the answer step, but it is used only to pick the right pages to read closely.
- If you ask about another book in your library while reading, the same table-of-contents-and-extracts step, and then the relevant pages, may be sent for that other book too.
- When you ask a follow-up question, the earlier turns of that conversation are sent along with it so the AI has context. Conversations are otherwise only stored on your device.
- Define: the selected word and your app language are sent via our backend to dictionaryapi.dev; when the dictionary has no entry, or the app is set to a non-English language, the definition is generated with Anthropic's Claude API instead. Definitions are cached on our backend by word alone for up to 90 days, never linked to your install.
- This data is processed to generate a response and is not stored by Flippy.
- Anthropic's use of this data is governed by Anthropic's Commercial Terms. Per their policy, data sent via the API is not used to train their models.
Help & FAQ Question Box
Settings → Help & FAQ includes a box where you can type or speak a question about the Flippy app itself. It first searches the built-in FAQ on your device. If you choose "Ask Flippy AI", your question is sent via our backend to Anthropic's Claude API together with a fixed description of the app, so it can answer. None of your books, reading data, or conversation history is sent — the box has no access to them. This is free for everyone and does not count against any allowance; to prevent abuse it is limited to 20 questions per day per install. Spoken questions are transcribed the same way as Ask Aloud (next section). Answers are generated automatically and may be wrong; the written FAQ and our support email are the authoritative sources.
Ask Aloud / Speak-to-PDF Voice Questions
Flippy lets you ask questions out loud — about your book, as a spoken follow-up in Explain or Study, or in the Help & FAQ box. This feature uses your device's microphone.
- The microphone is only active while you are recording a question (after you press the microphone button). Flippy never listens in the background.
- On iPhone and iPad, your speech is transcribed entirely on your device, using Apple's built-in speech recognition. Your voice recording never leaves your device — only the resulting text is used, and the recording is deleted straight afterwards. If your device cannot transcribe (for example, Dictation has never been enabled), Flippy tells you what to enable; nothing is uploaded.
- On Android, Flippy transcribes your speech on your device first, using Android's built-in speech recognition — on most modern devices this is what happens, and the recording never leaves your device. Only if on-device recognition produces no result is the voice recording sent via our backend to OpenAI's transcription API (Whisper). In that case the recording is used only to produce the transcript and is not stored by Flippy or our backend beyond the lifetime of that request.
- The transcribed question is then handled exactly like a typed question (see the sections above), and the spoken answer is generated with OpenAI's Text-to-Speech.
- OpenAI's handling of this audio is governed by OpenAI's API Data Usage Policies. Per their policy, data sent via the API is not used to train their models.
AI Explain Pictures
When you highlight a word or phrase and tap "Explain," Flippy generates a short, even-handed explanation of that term from the surrounding text (see the AI section above) and, where it helps, shows a picture.
- To find pictures, the highlighted term (or a short related search phrase the AI suggests based on it) is sent directly from the app to Wikipedia and Wikimedia Commons to look up public images and their descriptions, which are shown as captions. For a person or place, Wikimedia Commons may be searched for several photos of that subject.
- These are standard public search requests, made directly from your device; no account, login, or personal data is involved, but Wikimedia's servers see your IP address the way any website you visit does.
In-App Purchases
Flippy offers optional Premium and Pro subscriptions and one-time top-up packs of extra natural-voice minutes and AI uses. All purchases are processed by Apple (App Store) or Google (Google Play). We never see or store your payment details; billing, receipts, and refunds are handled entirely by the respective store.
- Subscriptions: to confirm a subscription is active, the app sends your App Store or Google Play purchase receipt to our backend, which checks it with Apple or Google. The receipt contains no name, email, or payment details; the verification result is cached for up to 24 hours.
- Top-up packs: when you buy a pack, the app sends the store's purchase token (Google Play) or signed transaction (App Store) to our backend, which verifies it with Google or Apple and then credits your balance. Our backend keeps a purchase ledger keyed to your install token: the pack bought, the store's order or transaction ID, the platform, the quantity, the date it was credited, whether it was a test purchase, and running counts of the minutes and AI uses you have drawn from it. It contains no name, email, or payment details. Because packs never expire, the ledger is kept without a time limit (see Data Deletion). The balance is tied to the device install it was bought on: the hashed device identifier described below lets it survive a reinstall on the same device, and "Restore" simply re-reads the ledger. It cannot be moved to another device, account, or person.
- If a top-up purchase is refunded or reversed by the store, we may remove the corresponding credit.
Our Backend, Analytics, and Advertising
There are no ads inside Flippy. We do not display ads, sell your data, or include any third-party advertising or analytics SDKs (no Meta/Facebook SDK, no Google Analytics, no crash reporting SDKs).
Flippy uses a small backend service we operate (a Cloudflare Worker) to route read-aloud, AI, transcription, dictionary, and purchase-verification requests to their providers. This proxy lets us keep our API keys server-side so they aren't extractable from the app, and lets us apply usage limits. The backend receives:
- An anonymous install token — a random ID created the first time the app contacts our backend. It is stored on your device, and our backend keeps a record of it alongside the date it was created, your platform, the app version, and the IP address it was created from. It is used to apply the free sample and rate limits per install so a single device can't run up unexpected charges, to hold your top-up balance, and to count unique installs in the anonymous event counters described below. It is not linked to your name, email, or any account.
- A hashed device identifier — a one-way SHA-256 hash of an app-scoped identifier (on Android, the app-scoped Android ID; on iOS, a random ID the app keeps in the device Keychain). The raw identifier never leaves your device. The backend stores only the hash, next to the install token it was first seen with, and uses it solely to recognize a device that has already used Flippy, so that uninstalling and reinstalling the app does not reset the free week or free sample — and so that a purchased top-up balance is not lost on reinstall. It is not linked to your name, email, account, or advertising identifier, and it is never shared with anyone.
- The text of your AI question (or highlighted term) and the book content you're asking about (only for AI Q&A, summary, Explain, Define, and study-tool requests; only for as long as it takes to forward the request).
- The page text you've asked Flippy to read aloud (only for read-aloud requests; the generated audio may be cached as described above).
- The text of a question you ask in the Help & FAQ box (only for as long as it takes to forward it).
- On Android only: your voice recording when you ask a question by voice and it could not be transcribed on your device (only to forward it for transcription; see the voice section above). On iPhone and iPad, voice recordings are never sent to the backend.
- Your App Store or Google Play purchase receipt or transaction when the app verifies a subscription or credits a top-up pack (see In-App Purchases).
- Your IP address, as is standard with any HTTPS request. It is recorded once alongside your install token when that token is first created, and it appears in our backend's short-term request logs. Cloudflare may also retain it in standard request logs (typically days, not months).
The backend does not store the contents of your questions or book pages beyond the lifetime of each request. Per install, it keeps only small operational records: how much of the free monthly sample has been used (kept for about 40 days), daily request counts used for rate limiting (kept for one day), the top-up ledger described above, and one small preference — the Reading style you choose for read-aloud (Auto, Natural, Narrator, Lively, or Calm), kept for up to 400 days after you last set it so the voice can follow it. It does not receive bookmarks, highlights, notes, reading history, or any data that identifies you.
The backend also keeps small, anonymous daily counters of certain in-app events so we can understand how Flippy is used, improve the app, and detect abuse of free features. Examples: the app being opened (counted at most once per day per install, so we can see how many devices actively use Flippy), the local hour and weekday when the app is opened (counted, never linked to an install), a book being imported, the upgrade screen being viewed, a purchase or top-up completing, a trial reminder being shown, or a monthly usage limit being reached. Only the name of the event is counted — never the content of your documents, questions, notes, or anything that identifies you — and the counters roll off after 90 days.
Notifications
Reading reminders, and the reminders sent the day before and the day after your free week ends, are generated and scheduled entirely on your device using the operating system's local notifications; no push service or server is involved. The name of your last-read book, your monthly listening totals, and the date your free week ends are stored locally to personalize them and never leave your device. The playback controls shown in your notification bar while listening are local too. You can turn reminders off anytime in Settings or in your device's notification settings.
Third-Party Services
Flippy integrates with the following third-party services. Except where noted, each is contacted only when you explicitly use the corresponding feature:
- Google Sign-In and Firebase Authentication — for signing in to Cloud Sync (free and optional)
- Google Firebase / Firestore — for storing your synced reading data
- OpenAI Text-to-Speech and Whisper transcription APIs — for AI Read-Aloud, for speaking AI answers out loud, and (Android only) for transcribing voice questions that your device could not transcribe locally (routed via our backend; see the backend section above)
- Anthropic Claude API — for AI Q&A, summaries, AI Explain, study tools, some definitions, and the Help & FAQ question box (routed via our backend)
- dictionaryapi.dev — for in-app word definitions (routed via our backend; cached by word alone, never linked to your install)
- Wikipedia / Wikimedia Commons — for the images and captions shown in AI Explain (contacted directly from the app; only the highlighted term or a related search phrase is sent; no account or API key involved)
- Apple App Store and Google Play — our backend contacts Apple's and Google's servers to verify subscription receipts and top-up purchases
- Cloudflare Workers and Cloudflare's cache — our own backend proxy that holds our API credentials, applies usage limits, and caches generated read-aloud audio for up to 30 days
- cdnjs (a public Cloudflare CDN) — Flippy loads the open-source library it uses to draw PDF pages from this public CDN. This happens every time the app starts, not only when you use a particular feature. Only the ordinary information carried by any web request is involved, such as your IP address; none of your documents, questions, or reading data is sent.
Each service is subject to its own privacy policy. Apart from the CDN noted above, no data is shared with these services unless you actively use the corresponding feature.
Children's Privacy
Flippy is not directed at children under the age of 13. We do not knowingly collect personal information from children.
Data Deletion
You can delete all your data at any time:
- Local data: Uninstall the app or clear app data from your device settings. (Because of the hashed device identifier, reinstalling later will not restart the free week or free sample, and any top-up balance will still be there.)
- AI conversations: Use "Clear chat" in the AI panel to erase the conversation for a single book, or uninstall the app to remove all of them. They are only ever stored on your device.
- Cloud data: Use "Delete Account & Data" under Settings → Cloud Sync. This deletes the reading data we hold for you in Firestore and signs you out. The sign-in record itself (your Google account's name, email, and photo as held by Firebase Authentication) may remain with our authentication provider — email us at the address below and we will remove it for you.
- Backend records: the install-token record, the hashed device identifier, usage counters, and the top-up ledger are not linked to your name or email, so we cannot find them from your email address alone. Email us from the app (Settings → Help & FAQ → Contact support) and we will work with you to identify and delete them. Note that deleting the top-up ledger forfeits any unused top-up balance.
Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated effective date.
Contact Us
If you have questions about this privacy policy or your data, contact us at:
flippypdf@gmail.com