🛒
← Back

Privacy Policy

Last updated: 10 June 2026

This policy explains what information Flip ("we", "us") collects when you use the Flip web app at whattheflip.app, how we use it, and your rights under the EU General Data Protection Regulation (GDPR).

Who is responsible for your data

Flip is operated by an individual sole operator based in the Netherlands. For any questions about this policy or to exercise your data rights, contact: hello@whattheflip.app.

The short version

Flip does not have user accounts, does not use any analytics or tracking, and does not set advertising or tracking cookies. We collect almost nothing about you. The little we do store stays in your browser session and disappears when you close your browser.

What we collect

Flip stores a small amount of information to make the app work, using a single browser session cookie. This includes:

  • The products you add to your basket during your visit
  • Whether you have premium access (a simple yes/no flag)
  • The result of any basket analysis you run, and any related error message

This information is stored in a signed, server-side session cookie. The cookie is HttpOnly (it cannot be read by scripts in your browser), sets no explicit expiry, and is therefore deleted automatically when you close your browser. We do not link this information to your identity, because Flip does not ask for or store your name, email, or any account details.

What we do not collect

  • No accounts, names, passwords, or profiles
  • No analytics or usage tracking (no Google Analytics, Meta Pixel, or similar)
  • No advertising cookies or third-party tracking cookies
  • No location data, device fingerprinting, or behavioural profiling

Cookies

Flip sets exactly one cookie: a session cookie used only to remember your basket and app state during your visit. It is strictly necessary for the app to function and contains no tracking or advertising data. Because it is essential and stores no personal identifiers, it does not require a consent banner under GDPR/ePrivacy rules. It is automatically removed when you close your browser.

Third parties we share data with

To look up products and generate explanations, Flip sends certain information from our server (not from your browser) to the following services:

  • Open Food Facts — we send the barcode or product name you search for, to retrieve product and nutrition data. Open Food Facts is an open, non-commercial food database.
  • DuckDuckGo — used only as a fallback when Open Food Facts has no result; we send the product name to retrieve basic information.
  • OpenAI — we send product names, ingredients, and nutrition values to OpenAI's API to generate the AI health summary, alternative suggestions, and basket analysis. We do not send any personal information about you, because we do not hold any.
  • Replit — Flip is hosted on Replit, which processes standard server request data (such as IP addresses in routine server logs) as part of providing hosting.

These transfers contain product queries, not personal data about you. Each of these providers operates under its own privacy policy.

Legal basis for processing

Where any limited processing occurs, our legal basis under GDPR is our legitimate interest in operating the app and providing the service you have requested, and — for the strictly necessary session cookie — the necessity of that cookie for the app to function.

How long we keep your data

Session data (your basket and app state) exists only for the duration of your browsing session and is deleted when you close your browser. We do not maintain a database of users or retain personal information after your visit ends.

Payments

Flip does not currently process any payments or collect payment information.

Email and accounts

Flip does not currently collect email addresses or operate user accounts. You can use the app without providing any personal details.

Your rights

Under GDPR you have the right to access, correct, or erase any personal data we hold about you, to object to or restrict processing, and to lodge a complaint with a supervisory authority (in the Netherlands, the Autoriteit Persoonsgegevens). Because Flip does not store personal data beyond your temporary session, in practice there is little for us to hold — but you can contact us at hello@whattheflip.app with any request.

Children

Flip is not directed at children under 16 and we do not knowingly collect data from them.

Changes to this policy

We may update this policy as Flip evolves. The "Last updated" date at the top reflects the most recent change. Significant changes will be noted on this page.