Privacy policy
Last updated: August 23, 2026.
1. Who we are and what this policy covers
This policy applies to Flipria's public website, the application (/app), the books our customers publish, and our API.
The data controller for the personal data described here (unless stated otherwise) is Neus Digital Technologies Ltd., with registered address at 8F China Hong Tower, 8-12 Hennessy Road, Wan Chai, Hong Kong, operator of Flipria.
2. What data we collect
- Account data: the name and email you give us when you sign up, managed with Supabase Auth in the eu-west-1 region (EU).
- Content: the documents you upload and the books you publish. They are yours; we use them only to provide the service.
- Billing data: once payment is enabled (Stripe, currently in beta), Stripe processes your card data directly; we never store it.
- Leads from your readers: the data your readers submit in your forms is processed on your behalf and under your responsibility; Flipria acts as processor.
- Technical data: IP address, user agent, pages viewed and reading time. In reading analytics these are stored only as a hash with a daily-rotating salt, so they are neither reversible nor linkable across days.
- Communications: if you write to us, we keep the content of your message so we can reply.
3. Legal bases for processing (GDPR)
- Performance of a contract: to create your account, host your books and provide the service.
- Legitimate interest: platform security, abuse prevention and aggregate usage analytics.
- Consent: for third-party measurement scripts inside a book (GA4, Meta Pixel) and for marketing email you have opted into.
- Legal obligation: where the law requires us to retain or disclose certain data, for example billing records.
4. Who we share data with
We use a small number of processors to run Flipria. None of them uses your data for their own purposes.
- Supabase (AWS, eu-west-1, Ireland): database, authentication and file storage.
- Anthropic and OpenAI (United States): process text from your documents only when you use AI features (document analysis, auto-transform, the AI agent, search embeddings), under standard contractual clauses.
- Resend: transactional email delivery (confirmations, double opt-in).
- Stripe: payment processing, once billing is enabled.
- Cloudflare: content delivery network and abuse protection.
5. International transfers
When a processor handles data outside the European Economic Area, for example in the United States, we rely on the European Commission's standard contractual clauses or another valid transfer mechanism to ensure an equivalent level of protection.
6. How long we keep your data
We keep your account data while it is active. If you delete it, your books, leads and associated analytics are permanently deleted within a reasonable period. Technical security logs are kept for the minimum time needed to detect and prevent abuse, normally no more than 12 months.
7. Your rights if you are in the European Economic Area or the UK
You can exercise the following rights by writing to hola@flipria.app:
- Access to the data we hold about you.
- Rectification of inaccurate data.
- Erasure (right to be forgotten).
- Restriction of processing.
- Portability: we give you your books (HTML/ZIP) and your leads (CSV) directly from the application.
- Objection to processing based on legitimate interest.
- Withdraw your consent at any time, without affecting the lawfulness of processing before the withdrawal.
- Lodge a complaint with the data protection authority in your country of residence.
8. If you live in California or another US state
The CCPA and CPRA give you the following rights over your personal information:
- Categories we collect: identifiers (name, email), commercial information (plan subscribed), internet activity (application usage) and, if you use the API, professional information.
- We do not sell or "share" (as defined by the CCPA/CPRA) your personal information to third parties.
- Right to know, delete, correct and limit the use of sensitive personal information: write to hola@flipria.app; we will verify your identity before responding, normally within 45 days.
- We do not discriminate against anyone who exercises these rights: the service and its pricing stay the same.
- You may authorize someone to submit the request on your behalf.
9. Children's privacy
Flipria is built for professional use. We do not direct the service at children under 16 in the EU or under 13 in the US, and we do not knowingly collect data from children of those ages. If you believe a child has given us data, write to us and we will delete it.
10. Security
Encryption in transit (TLS), per-organization isolation via row-level security (RLS) in the database, scope-limited API keys and an immutable audit log of administrative actions. No system is invulnerable; if we detect a breach that affects you, we will notify you as required by applicable law.
11. Cookies and similar technologies
Flipria's public website does not use analytics or advertising cookies. The application uses a technical session cookie needed to keep you logged in, and password-protected books use a signed unlock cookie. Full details are in our Cookie Policy.
12. Changes to this policy
If we make material changes, we will update the date on this page and, if the change is significant, notify you by email or with a notice inside the application.
13. Contact
Neus Digital Technologies Ltd., 8F China Hong Tower, 8-12 Hennessy Road, Wan Chai, Hong Kong. For any question or to exercise your rights: hola@flipria.app.