Privacy Policy
Last updated: August 3, 2026
This Privacy Policy explains how Studiflip, Inc., doing business as StudiFlip (“StudiFlip,” “we,” “us,” or “our”), collects, uses, discloses, retains, and deletes personal information through the StudiFlip application, website, and related services (the “Service”).
Studiflip, Inc.
650 W 42nd St, Apt. 3123
New York, NY 10036
United States
1. Scope and Summary
Currently:
registration generally requires an accepted Purdue email domain;
the Service is intended only for users who are at least 18 years old;
profiles, listings, and marketplace content are visible only to signed-in users;
StudiFlip stores precise listing coordinates server-side but shows other users only a randomized approximate area or circle;
users communicate directly and arrange payments and transactions outside StudiFlip;
StudiFlip does not sell personal information or use it for cross-context behavioural advertising;
sendDefaultPii is disabled in Sentry and Session Replay is disabled;
uploaded images are processed to remove embedded metadata;
account-deletion requests are irreversible and are completed after a processing period of up to 30 days, subject to limited retention exceptions; and
messages may remain visible to the other participant after deletion under the name Deleted User.
Where StudiFlip changes a practice described in this Policy, it will update this Policy before or at the time the change takes effect.
2. Information You Provide
Account and eligibility information
We collect information such as:
email address;
username;
first and last name;
password hash;
verification and authentication records;
age confirmation;
campus or eligible-email information;
policy versions and acceptance records; and
account-recovery and support information.
Email verification confirms control of an eligible inbox. It does not verify identity, current enrollment, employment, age documents, background, qualifications, ownership, or trustworthiness.
Profile information
We may collect:
profile photograph;
username and name;
campus information;
account creation date;
follower/following or similar social counts; and
information you choose to include in your profile.
Profiles are visible only to signed-in users currently.
Product, service, housing, and other listings
We collect listing information such as:
title and description;
price or pricing basis;
category and condition;
photographs;
product, service, property, lease, rental, availability, and restriction information;
precise coordinates and address information selected for a listing;
draft, active, archived, disabled, and moderation status; and
communications relating to the listing.
Saved listings and activity
We collect saved or wishlisted listings and other actions needed to provide your account and marketplace features. We do not maintain a general search-history or recently-viewed-history feature currently unless the Service is changed and this Policy is updated.
Messages
We collect message content, participants, timestamps, and associated conversation information.
Messages are not end-to-end encrypted. Users cannot edit or individually delete messages currently. After account deletion, messages may remain visible to the other participant, but the sender is labelled Deleted User and the deleted profile is inaccessible.
Reports, blocks, moderation, and safety information
We collect:
reports concerning profiles, listings, conversations, conduct, or suspected violations;
report reasons and descriptions;
blocks and relationship restrictions;
moderator notes, decisions, warnings, suspensions, bans, and appeal communications;
evidence voluntarily provided to us; and
information reasonably necessary to investigate fraud, threats, safety issues, intellectual-property complaints, and legal requests.
StudiFlip also operates a dedicated route for an identifiable individual, or an authorised representative including a parent or guardian, to report an intimate visual depiction of that individual published without consent. Reports of this kind may be sent to [email protected]. We log each report with the action taken. The Terms of Service describe this process.
Subscription information
Apple, Google, and RevenueCat may process billing and purchase information. We receive information such as:
app-store account or customer identifiers;
subscription product and entitlement;
subscription status, renewal, expiration, and cancellation information;
webhook and reconciliation records; and
limited transaction information needed to provide access and support.
We do not receive your full payment-card number from Apple or Google.
Support, privacy, legal, and DMCA communications
We collect the information you include when contacting support, privacy, safety, legal, or copyright channels, including your identity, contact details, request, attachments, and our response.
Account-deletion information
We collect the deletion request, authentication information, request date, status, and any reason you voluntarily provide.
3. Information Collected Automatically
Device and app information
We may collect:
device type and operating system;
app version and language;
application state, technical identifiers, and device push token;
network and connection information;
feature and error context; and
security and authentication events.
IP and request information
Our infrastructure providers may process IP address, request time, URLs, headers, request method, response status, and security signals to deliver the Service, prevent abuse, enforce rate limits, and maintain reliability.
Request URLs recorded in infrastructure logs may transiently include search terms or filters you enter. These logs are used for delivery, security, and reliability, not to build a search-history feature.
Diagnostics
We use Sentry for error and performance monitoring. sendDefaultPii is disabled, and Session Replay is disabled. Diagnostic events are linked to the account identifier of the signed-in user, so an error report can be traced to the account that produced it.
Sentry may still receive limited technical context associated with an error, such as device, app, network, transaction, URL, or feature information. We do not promise that diagnostic information can never include contextual data related to the action that produced an error. We configure and use diagnostics for reliability and security, not advertising.
Website data
Our website and infrastructure may use essential cookies or similar technologies for security, session operation, load balancing, and fraud prevention. We do not use advertising cookies, advertising pixels, or cross-site behavioural tracking currently.
Before introducing any advertising, analytics, or attribution technology on the website, we will update this Policy and, where required, implement consent and opt-out controls.
Advertising identifiers and tracking
Currently, StudiFlip does not access IDFA or GAID, use advertising or attribution SDKs, sell personal information, conduct cross-app tracking, or profile users for targeted advertising.
4. Location Information
Listing location
When creating a listing, a user may choose a location through address search, a map pin, or foreground device location.
We may store:
precise latitude and longitude;
address line, city, region, postal code, and related address fields; and
approximate display and distance information.
Precise coordinates are kept server-side and are not shown to other users. Other signed-in users see a randomized approximate area or circle. The circle is not the exact address, pickup point, property entrance, or meeting place.
Device location
If you choose “use my location” or a similar feature, the app may request foreground location permission. Background or “always” location is not required for the intended launch functionality.
You may deny location permission and select a location manually.
Maps providers
Google Maps and Google Places may process listing coordinates, location text used to set or resolve a listing location, device and network information, and map interactions under Google’s terms and privacy practices.
When you view a listing map or otherwise interact with a map in the Service, the listing coordinates required to render it, device and network information, and information about your map interactions are transferred to Google. When a listing location is set or resolved, the coordinates you select and, where you enter one, the location text you enter may also be transmitted to Google’s Maps and Places services, including from StudiFlip’s servers. Google processes that information under its own terms and privacy policy and for its own purposes, and not solely on StudiFlip’s instructions.
Precise meeting details
Users may voluntarily share a meeting point or address in chat. Do not share a dorm-room number, home address, access code, or other sensitive location unless necessary and you understand the risk.
5. Images and Metadata
Uploaded images are processed to remove embedded metadata, including location metadata, before the sanitized image is used through the Service.
We may store raw uploads temporarily for processing, security, or troubleshooting. Raw or rejected files are deleted or isolated according to operational retention rules. Sanitized images may be stored through AWS S3 or related infrastructure.
Image moderation may be performed using AWS image-moderation services and human review. Screening is imperfect and does not guarantee that every prohibited image will be detected.
6. How We Use Information
We use personal information to:
create, authenticate, secure, and maintain accounts;
confirm control of an eligible email inbox;
display profiles and listings to signed-in users;
provide product, service, housing, search, save, map, distance, chat, reporting, and blocking features;
manage subscriptions and listing limits;
process uploaded images and remove metadata;
screen, review, investigate, and moderate content and conduct;
prevent fraud, spam, abuse, cheating, prohibited transactions, and account evasion;
respond to support, privacy, legal, safety, and intellectual-property requests;
maintain, debug, secure, and improve the Service;
comply with law and valid legal process;
protect users, StudiFlip, and the public; and
establish, exercise, or defend legal claims.
We do not use private messages, reports, privacy requests, legal communications, or identifiable profile/listing content in advertising. We will not use identifiable listing photos, profile photos, names, or usernames in advertising without separate permission.
7. How We Disclose Information
Other users
Signed-in users may see information that you make available through profiles, listings, service offers, housing listings, and messages, including your name, username, profile photo, campus, listing content, approximate listing area, and other information you choose to disclose.
Other users are not shown the exact stored listing coordinates through the ordinary listing display.
Service providers
We may disclose information to providers that help operate the Service, including:
Railway and related hosting infrastructure;
PostgreSQL and Redis infrastructure;
AWS S3 for file storage;
AWS image-moderation services for image screening;
Cloudflare for delivery, security, and abuse prevention;
Google Maps and Google Places for maps and address functions;
RevenueCat, Apple, and Google for subscriptions and entitlements;
Sentry for error and performance monitoring;
Centrifugo or equivalent realtime communications infrastructure, self-hosted by StudiFlip;
push-notification infrastructure, including the Apple Push Notification service, Firebase Cloud Messaging, and OneSignal as the push-delivery provider, for delivering device notifications; and
Microsoft, our transactional email provider, for verification, account, support, and service messages.
These providers process information under their own terms and our arrangements with them.
This list describes the providers used to operate the Service as at the date of this Policy. StudiFlip does not use analytics, attribution, or advertising software development kits, does not access advertising identifiers, and does not operate an SMS or text-message channel. If we add a provider that receives personal information for a new purpose, we will update this Policy.
For the two providers that handle messages to you: OneSignal delivers push notifications over the Apple Push Notification service and Firebase Cloud Messaging and processes your device push token, a user identifier, device type and operating system, notification content, and IP address; Microsoft delivers transactional email and processes your recipient email address, verification and two-factor codes, and notification content.
Legal, safety, fraud, and enforcement disclosures
We may preserve or disclose information where we reasonably believe it is necessary to:
comply with a valid subpoena, court order, warrant, or other legal process;
respond to an emergency involving a risk of death or serious physical injury;
report apparent child sexual exploitation as required by law;
investigate or prevent fraud, threats, abuse, prohibited activity, or security incidents;
enforce our agreements and protect our rights and property; or
establish, exercise, or defend legal claims.
We do not routinely share user information with Purdue University. We may respond to a lawful request from Purdue or another institution, property manager, rights owner, or authority where permitted or required by law and appropriate under our policies.
Business transfers
Information may be disclosed as part of a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or due-diligence process, subject to appropriate protections.
8. No Sale or Targeted-Advertising Sharing
StudiFlip does not sell personal information for money and does not share personal information for cross-context behavioural advertising currently.
We do not use data brokers, advertising networks, or advertising SDKs.
Before introducing any advertising, analytics, or attribution technology in the Service, we will update this Policy and, where required, implement consent and opt-out controls.
9. Communications
Transactional and service communications
Currently, we send only account, verification, security, listing, message, subscription, moderation, legal, support, and other service-related communications.
These communications are necessary to operate the Service and generally cannot be opted out of while maintaining an active account, although device-notification permissions may be changed through your device settings.
If we change the categories of transactional or service messages we send, we will reflect that change in this Policy.
Marketing communications
StudiFlip does not send promotional email or promotional push notifications currently. Before activating marketing communications, we will implement legally required consent, preference, and unsubscribe controls and update this Policy where necessary.
Acceptance of this Privacy Policy is not consent to marketing.
10. Retention and Account Deletion
General retention criteria
We retain information for as long as reasonably necessary to provide the Service, secure accounts, maintain records, comply with law, prevent fraud, investigate safety matters, resolve disputes, enforce our agreements, and support accounting or subscription reconciliation.
Account deletion process
You may request deletion:
in the StudiFlip app; or
through the external deletion page or by emailing [email protected] from the email associated with the account.
After the request is authenticated and processed:
the account becomes inaccessible;
the request cannot be cancelled or reversed;
the registered email may not be reusable during processing;
account information is restricted for up to 30 days for compliance, fraud, safety, investigation, and legal purposes; and
associated information is then permanently deleted from active systems, subject to the limited exceptions below.
Deleting the StudiFlip account does not cancel an Apple or Google subscription.
Messages after deletion
Users cannot delete individual messages. After account deletion, messages may remain in the other participant’s conversation, but the sender is displayed as Deleted User and the deleted profile is inaccessible.
Reported messages and related evidence may be retained separately when reasonably necessary for safety, fraud prevention, disputes, legal process, or enforcement.
Information we may retain
We may retain limited information after account deletion where reasonably necessary, including:
policy-acceptance and contract records;
subscription, entitlement, accounting, tax, refund, and store-reconciliation records;
banned-account identifiers or hashes;
fraud, security, moderation, report, and enforcement records;
legal, privacy, support, DMCA, or law-enforcement correspondence;
evidence subject to a complaint, dispute, preservation request, subpoena, or legal hold;
records needed to prevent repeat abuse; and
de-identified or aggregated information that no longer reasonably identifies you.
Backups and provider systems
Deleted data may remain temporarily in encrypted or access-restricted backups until normal rotation, expected to be approximately 30 days. We take reasonable steps to prevent restored deleted data from returning to active use.
Third-party providers may retain limited records under their own legal, security, billing, or backup requirements.
11. Your Choices
Depending on the feature, you may:
edit profile information;
create, edit, archive, or delete listings;
save or unsave listings;
block users;
report content or conduct;
deny foreground location permission and select a location manually;
change camera, photo, location, and notification permissions in device settings;
manage subscriptions through Apple or Google;
request access, correction, or deletion; and
appeal certain privacy or moderation decisions by email.
Users cannot individually delete messages currently.
12. Privacy Rights
Depending on where you live and whether an applicable law applies, you may have the right to request:
confirmation that we process your personal information;
access to personal information;
correction of inaccurate information;
deletion;
a portable copy of certain information;
an appeal of a denied request; and
information concerning categories of collection and disclosure.
StudiFlip does not sell personal information or use it for targeted advertising, so there is no sale or targeted-advertising opt-out to exercise currently.
Submitting a request
Send requests to [email protected]. We may require you to verify control of the registered email or provide information reasonably necessary to authenticate the request.
We will acknowledge your request promptly and will respond within 45 days of receipt of a verifiable request. Where reasonably necessary, we may take one extension and will tell you about the extension within the original 45-day period. Where an applicable law sets a shorter or different period, we will meet that period.
Requests are generally free, although we may decline or charge a reasonable fee for manifestly unfounded, excessive, or repetitive requests where law permits.
Appeals and authorized agents
You may appeal a denied privacy request by emailing [email protected] and stating that the message is an appeal.
We will decide an appeal and tell you the outcome in writing within 45 days of receipt of the appeal.
Where applicable law requires, an authorized agent may submit a request. We may require proof of authorization and direct identity verification from the user.
Browser privacy signals
Some browsers transmit “Do Not Track” signals. Because there is no common standard for interpreting them, the Service does not currently respond to Do Not Track signals.
Because StudiFlip does not sell personal information or share it for cross-context behavioural advertising, Global Privacy Control signals do not change our processing currently.
13. Sensitive Information
Precise geolocation, account credentials, message content, and certain safety information may be considered sensitive.
StudiFlip treats precise geolocation, account credentials, and message content as sensitive information. We process precise location only to provide the map, distance, and listing functions you ask for and to support security and safety. Where applicable law requires consent before sensitive information is processed for a given purpose, we will obtain that consent before processing it for that purpose.
We use precise location to provide user-requested maps, distance, and listing functions and to support security and safety. We do not show the exact stored listing coordinates to other users.
If the device offers Face ID, fingerprint, or similar authentication, the biometric template is controlled by the device platform. StudiFlip receives only the authentication result and does not receive the biometric template.
14. Security
We use administrative, technical, and organizational safeguards designed for the nature of the Service, including:
password hashing;
hashed verification codes;
TLS for network communication;
access controls;
rate limiting;
secure mobile credential storage;
moderation and account controls;
logging and diagnostic monitoring;
image sanitization; and
backup and deletion procedures.
No system is completely secure. You are responsible for protecting your email, password, device, and verification codes. Where notification is required by applicable law, we will notify affected individuals and the relevant authorities without unreasonable delay following discovery of a breach of security of personal information.
15. Children and Age
The Service is limited to people who are at least 18 years old. We do not knowingly collect personal information from a person under 18 through an authorized account.
If you believe an under-18 person has created an account, contact [email protected]. We may suspend and delete the account.
16. United States Scope
The Service is intended for users in the United States and is initially focused on the Purdue community in Indiana. We do not intentionally market the Service to the European Union, United Kingdom, or other non-U.S. markets currently.
Some global providers may process information in other locations. Their contractual and legal safeguards may apply.
17. Changes to This Policy
We may update this Policy to reflect product, provider, legal, security, or operational changes. We will update the date above and may provide Policy by email, in-app Policy, or another reasonable method.
Where required, we will obtain additional consent or acknowledgement.
18. Contact
Account and deletion support: [email protected]
Privacy requests: [email protected]
Safety and abuse: [email protected]
Reports of an intimate visual depiction published without consent: [email protected]
Legal and law-enforcement requests: [email protected]
DMCA notices: [email protected]
Studiflip, Inc.
650 W 42nd St, Apt. 3123
New York, NY 10036
United States
Telephone: (765) 409-2412