Back to Home

Privacy Policy

Last Updated: July 19, 2026

1. Introduction

AI Flip Room ("we", "us", "our") respects your privacy. This Privacy Policy explains what information we collect, how we use it, and the choices you have. Where we rely on your consent for a specific activity — such as the optional "Help improve our AI" and "Showcase my designs" permissions, or non-essential analytics cookies — we obtain it separately through an explicit, opt-in action. Using the Service is not by itself treated as your consent to those activities.

2. Information We Collect

Account information.When you sign up, we collect your email address and (if you choose Google sign-in) your name and profile picture from Google. Authentication is handled by Clerk — we never see or store your password.

Payment information. Subscription payments are processed by Stripe. We receive a customer ID and subscription status from Stripe; we do not store credit card numbers, CVV codes, or other full payment details on our servers.

Uploaded images. Photos you upload to generate an AI redesign are temporarily processed on our servers and by our AI providers (Replicate, Google and Anthropic). They are deleted from our active servers within 24 hours (see Section 4 for backups and logs). AI Flip Room does not use your photos to train AI models.

Usage data.We collect usage data such as page views, generation counts, plan tier, and rough device type. Page views are recorded against a one-way code derived from your IP address rather than your name or account — pseudonymous, not anonymous, and treated as personal data. This data is used to operate and improve the Service. See "Cookies and tracking" below for details.

3. How We Use Your Information

  • Operate the Service and produce your AI generations
  • Process subscription payments and renewals
  • Send transactional email (sign-in codes, payment receipts, account notices)
  • Provide customer support when you contact us
  • Detect, prevent, and respond to abuse or violations of the Terms of Service
  • Improve the Service through analytics that are not tied to your name or account

4. Image Data — Specifics

We treat your uploaded room photos with extra care because they may show your home or client property:

  • When you upload a photo it is sent to Anthropic to detect the room type; when you click Generate it is sent to Google or Replicate to produce your redesign
  • Uploaded photos are deleted from our active servers and the inference cache within 24 hours. Residual copies may briefly persist in encrypted backups and error logs and are purged on a rolling basis (within 90 days); they are not accessed or used for any other purpose in the meantime
  • AI Flip Room does not use your photos to train AI models.Our AI providers process your photos only to produce your output, under their own terms — Replicate and Anthropic do not train on API inputs; Google processes the images we send through its Gemini image model under its own API terms
  • Generated images and training.If, and only if, you turn on the optional "Help improve our AI" setting (off by default), we use the images you generate— never your uploads — to train and improve our own AI models, on the legal basis of your consent. Before any generated images are used for training, we will screen out and exclude those that appear to depict an identifiable person or readable personal information (a face, name, address, document, or licence plate). You can withdraw consent at any time in your account settings, after which we exclude your images from all future training
  • We do not sell, share, or license your photos to third parties for marketing or dataset purposes

5. Third-Party Services

The Service relies on the following sub-processors. Each operates under its own privacy policy:

  • Clerk— authentication and account management (email, optional Google login)
  • Stripe— payment processing (subscription billing, no card data stored on our servers)
  • Replicate— AI inference (image generation; does not train on API inputs)
  • Google— AI inference (image generation for your interior redesigns, via the Gemini image model; processes the images we send under its own terms)
  • Anthropic— AI inference (automatic room-type detection when you upload a photo; does not train on API inputs)
  • Vercel— hosting, edge delivery, and privacy-friendly Web Analytics (no cookies, anonymous, no cross-site tracking)
  • Google Analytics (GA4)— site analytics (traffic and usage measurement; sets non-essential analytics cookies — see Section 6 for your choices)
  • Sentry— error and performance monitoring (captures error context, IP address, and browser/device info to diagnose crashes); United States
  • Namecheap Private Email— the inbox behind support@aifliproom.com
  • Meta (Facebook/Instagram)— advertising measurement. When you visit the site or complete a sign-up or purchase, we send Meta a pageview and conversion events (including a one-way hashed version of your email) so we can measure and optimize our advertising. You can opt out via our cookie banner and the "Do Not Sell or Share My Info" link; United States
  • Neon— managed PostgreSQL database (stores your account activity, generation history, and consent records); United States

Where these providers process your data outside your region (primarily in the United States), we rely on appropriate safeguards — the EU-US / UK Data Privacy Framework where the provider is certified, and Standard Contractual Clauses otherwise (see Section 10).

6. Cookies & Tracking

We use the following cookies and local storage:

  • Essential cookies set by Clerk to keep you signed in. These are necessary for the Service to work and are always active
  • LocalStorage for UI preferences such as the last selected style
  • First-party page-view count— cookieless and pseudonymous: we store one-way hashes of your IP address and browser (never the raw IP) together with the page you visited, on our own servers, to measure traffic and protect against abuse. The hashes are stable rather than anonymous — they let us tell repeat visits apart, though they cannot be reversed to identify you and are never linked to your name, email, or account. No cookie is set, and no cross-site or advertising identifier is created. Deleted after 14 months (see Data Retention)
  • Vercel Web Analytics— cookieless and anonymous; no personal identifiers, no cross-site tracking, no advertising profiles
  • Google Analytics (GA4)— sets non-essential analytics cookies to measure traffic, referrers, and which pages help people the most

Analytics cookies are non-essential.Google Analytics is the one analytics tool we use that sets cookies, to understand how people find and use the site so we can improve it. In the EEA, UK, and Switzerland, analytics cookies stay off until you accept them in our cookie banner. Everywhere else, analytics is on by default and you can turn it off at any time using the "Do Not Sell or Share My Info" link in the footer; we also automatically honor your browser’s Global Privacy Control signal. You can additionally block analytics cookies with any tracker-blocking browser extension. Our own first-party page-view count above sets no cookie and runs on the basis of our legitimate interest in measuring and securing our traffic, so it operates without a consent banner.

Advertising. We use the Meta Pixeland Meta’s Conversions API to measure the performance of our Facebook and Instagram ads — this records pageviews and conversions (sign-up, purchase) and shares a one-way hashed email with Meta. In the EEA, UK, and Switzerland this stays off until you accept it in our cookie banner; everywhere else it is on by default and you can turn it off with the "Do Not Sell or Share My Info" link in the footer, and we honor your browser’s Global Privacy Control signal. We do not sell your data, and we use no other advertising or cross-site trackers.

7. Data Retention

  • Uploaded room photos: deleted from active servers within 24 hours (residual backup/log copies purged within 90 days)
  • Generated images: retained as part of your generation history per plan tier (Free 7 days / Pro 30 days / Agency 90 days)
  • Account data (email, plan, usage counters): retained while your account is active
  • Billing records (Stripe): retained as required by law (typically 7 years)
  • Server and error-monitoring logs: retained up to 90 days for security and abuse prevention
  • Page-view analytics: for each page view we store the page address, the time, and two one-way codes — one derived from your IP address together with your browser’s user-agent string, one from your IP address alone. Neither can be reversed to reveal your IP, but both are stable, so they let us tell repeat visits apart without knowing who you are. No name, email, or account id is attached. Deleted after 14 months.
  • Share-button analytics: the page address and which network was chosen, with no identifier of any kind. Deleted after 14 months.
  • Consent records (which permissions you granted and when): retained after account deletion as a legal-basis audit trail, in de-identified form (no name or email attached)
  • Anti-abuse marker: after account deletion we keep a one-way cryptographic code derived from your email for up to 24 months, in a separate table linked to nothing else (no name, account id, or images). It cannot be reversed to reveal your email and serves one purpose only — detecting when a new sign-up matches a previously deleted account, so free-plan limits cannot be reset by deleting and re-creating accounts. Legal basis where GDPR applies: our legitimate interest in preventing abuse (Art. 6(1)(f)). It is deleted automatically after 24 months, never used for marketing or profiling, and never shared. You may object by contacting us using the details in the Contact section below; absent evidence of abuse, we will delete it.

8. Your Rights

Regardless of where you live, you can:

  • Access— request a copy of the personal data we hold about you
  • Correct— ask us to update inaccurate information
  • Delete— close your account and have associated data deleted (a few narrow records may be retained — see Section 7)
  • Export— request your data in a portable format
  • Object / Restrict— opt out of, or restrict, any non-essential processing
  • Withdraw consent— turn off the optional "Help improve our AI" permission, or change your cookie choices, at any time in your account settings; withdrawal is as easy as giving consent and applies going forward

If you are in California, you also have the rights to know, delete, and correct your personal information, and to opt out of its "sale" or "sharing". We do not sell your personal information for money. To the extent analytics could be treated as "sharing" under California law, you can opt out at any time using the "Do Not Sell or Share My Info" link in the footer, and we automatically honor the Global Privacy Control signal.

To exercise any of these rights, email support@aifliproom.com. We will respond within 30 days.

9. Children's Privacy

The Service is intended for adults — you must be 18 or older to use it (see our Terms of Service). We do not knowingly collect personal information from anyone under 18, and never from children under 13. If you believe a minor has provided us with personal information, please contact us and we will delete it.

10. International Transfers

AI Flip Room is operated from infrastructure provided by Vercel, Replicate, Google, Anthropic, Clerk, and Stripe, primarily based in the United States. Your information may therefore be transferred to and processed in the United States and other countries. Where we transfer personal data out of the EEA, UK, or other regions with data-transfer restrictions, we rely on the safeguards in our providers' data processing agreements, including the EU-US and UK Data Privacy Framework where the provider is certified and Standard Contractual Clauses (with the UK Addendum where applicable). You may request more information about these safeguards by emailing support@aifliproom.com.

11. Data Security & Breach Notification

We use industry-standard security measures, including TLS encryption for all data in transit, encrypted storage at rest with our infrastructure providers, and limited internal access on a need-to-know basis. No system is 100% secure; we cannot guarantee absolute security. In the event of a personal-data breach, we will notify the competent supervisory authority within 72 hours where required by law, and affected users without undue delay where the breach is likely to result in a high risk to their rights.

12. Business Transfers

If AI Flip Room is involved in a merger, acquisition, financing, reorganisation, sale of assets, change of corporate form, or relocation or re-incorporation of our business in another country or jurisdiction, your personal data may be transferred to the successor or acquiring entity as part of that transaction. That entity will remain bound by this Privacy Policy, or by a policy at least as protective of your rights, and we will notify you of any change in the entity responsible for your data (the data controller). This does not reduce any rights you have under applicable law.

13. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last Updated" date at the top reflects the most recent revision. For material changes we will give reasonable advance notice via email or an in-app notice before the change takes effect.

14. Contact

Our Privacy Officer is accountable for our compliance with this policy and with applicable privacy laws, including Canada's PIPEDA and Quebec's Law 25. For any question or request about this policy or your data — access, correction, deletion, or a complaint — contact them at support@aifliproom.com.