Privacy Policy
Last updated: 23 August 2026 · version 2026-08-22
Flip Kitchen AI ("Flip Kitchen", "we", "us") is a free kitchen design tool operated from Canada — designing costs nothing; paid extras only improve the experience. This policy explains what information the site collects, why, where it is stored, and what control you have over it. We have tried to describe what the software actually does rather than reserve every right a lawyer could imagine.
If you only want the short version: the design tool needs a free Google sign-in; your saved designs are private; your Render Studio images are only shared with us if you explicitly turn that on; and you can get a copy of your data or delete the whole account whenever you want.
1. Information we collect
Account information
Using the design tool, and talking to Emma, require an account. We use Google Sign-In (or Sign in with Apple in the app); Google gives us your account identifier, email address, display name and profile picture, and we never see or store your password. The rest of the site — the home page, the guides, the Learn and Spotlight articles, the showroom — stays open to read with no account.
We ask you to sign in for two honest reasons rather than one: your designs, quotes and renders have to belong to someone in order to come back to you on another device; and the 3D model library and catalogue are the part of this product most worth copying, so we do not serve them to anonymous automated traffic.
Your acceptance of these documents
The first time you sign in — and again whenever we materially revise this
policy or the Terms of Use — the designer shows you a summary and asks you to
accept before you start. We record that you accepted: which version, the date,
your account email, a shortened description of the browser you used, and the
network portion of your IP address (for example 203.0.113.0/24, not
your full address). That record exists so we can show, if we are ever asked,
that you were told what we do with your data. It is deleted with your account.
Design data
When you save a design, we store the design itself: room dimensions, walls, cabinets and SKUs, colours, countertops, appliances, notes and any name you give it. If you use the room-scanning feature, the resulting floor plan measurements are part of that design data. Saved designs are private to your account. They are not published, sold, or used to train third-party AI models.
Render Studio images
Render Studio sends a screenshot of your 3D kitchen, plus the design settings behind it (door colour, cabinet layout summaries, and similar), to an AI image provider to produce a photorealistic render. That transfer is necessary to generate the image you asked for.
Separately, we ask whether you are willing to let us keep a copy of your renders and their settings so our team can review real output and improve image quality. This is off unless you turn it on. You are asked once, and the current state is always shown as a line directly under the render, which you can click at any time to change. Your answer is recorded against your account, not just in that browser, so it follows you to another device and survives clearing your browser data — and so that we can show what you chose if it is ever questioned. When it is on, the render, a thumbnail and the design settings are stored in our archive; when it is off, nothing is kept. Archived renders are only viewed by Flip Kitchen staff, and may be used to evaluate and improve our own rendering pipeline — including as training material for it. They are never published, sold, shown to other users, or handed to a third party for training. If you have not turned sharing on, your renders are not kept and are never used this way.
3D Photos (the Blender renders you take with the camera button) work differently: the full-resolution image is held in a private staging area for about two hours so you can download it, and is then deleted. The exception is images generated by our own staff accounts, which we keep as training material for our rendering pipeline — those are our images, not yours.
Messages and submissions
If you use the contact form, post in the community section, or submit a design question or problem report, we receive what you send us — including any screenshots automatically attached to a design question (top view, elevations and 3D views of the design you were working on). A design question is delivered into our own team workspace, which runs as a separate application of ours on the same hosting; it does not go to another company.
Purchases
Membership and GH Coin are optional — a complete design costs nothing. If you do buy something, the payment itself is handled by PayPal on the website and by Apple in the app: card numbers and banking details never reach us. What we keep is the record we need to give you what you paid for — the transaction reference, what was bought, when it renews or expires, and your coin balance and its history.
The FlipKitchen iOS and Mac app
The app is the same account and the same design store as this site, with two things a browser cannot do. Camera and LiDAR: scanning a room runs entirely on your device — the camera feed is never uploaded, and what leaves the app is the measured floor plan (walls, openings, appliance positions), which becomes design data exactly like a design you drew by hand. Photos: if you photograph a kitchen for Modify Photo, that photo is sent to our AI provider to produce the edited image you asked for, and renders you choose to save are written to your photo library. The app asks for camera and photo access the first time it needs each, and both can be revoked in iOS Settings at any time.
Records we keep of what happened
Three things leave a record, kept in our file storage rather than the database, and none of them keeps the thing itself:
- Images the AI generated for you. We keep the date, the feature, the model, and a fingerprint of the image — a one-way checksum of the exact file we handed you. Not the picture. That fingerprint is what lets us confirm, later, whether a particular image came from us; it is also why we do not stamp a visible mark on your renders.
- Typed conversations with Emma, our assistant — what was asked and what it answered. Talking to Emma by voice is not recorded at all: the audio goes straight from your browser to the speech provider and never reaches us, and we do not ask for a transcript of it.
- What our own staff do to accounts — adjusting a coin balance, locking an account, changing a membership, deleting a design. The staff member is named; the customer they acted on is stored as a one-way digest rather than an address, because this record exists to hold us accountable, not to be a second copy of our customer list.
Usage analytics
We record coarse usage events: page views, which buttons and catalogue items get clicked, saves and exports. Each event carries a random per-tab identifier that is discarded when you close the tab, plus the page path. We do not use advertising cookies, we do not build cross-site profiles, and we do not sell any of this.
Local storage on your device
The designer keeps a lot of state in your own browser — your current design, preferences, language, keyboard shortcuts, your sign-in session, and recent Render Studio images. This lives in your browser's local storage and IndexedDB, not on our servers, and clearing your browser data clears it. If you turn on "Auto-save to folder", renders are written as ordinary image files into a folder on your computer that you pick; we cannot read that folder or anything else on your device.
2. Why we use it
- To run the designer and give you back the design, quote or render you asked for.
- To save and reload your work, and to keep you signed in for a session.
- To answer your messages, quotes and support questions.
- To understand which features get used, so we know what to improve.
- To improve render quality — only using renders you have agreed to share.
- To keep the service working and to prevent abuse.
3. Service providers
Flip Kitchen is a small operation built on third-party infrastructure. These providers process data on our behalf:
| Provider | What it handles | Where |
|---|---|---|
| Vercel | Website hosting, serverless functions, and the database behind the designer's command log | United States / global edge |
| Redis (via Vercel Marketplace) | Accounts, sessions, saved designs, projects, coin balances, messages, community posts, tickets | United States |
| Cloudflare R2 | 3D Photo staging, voice messages, showroom files, and the Render Studio archive (only if you opt in) | Global |
| Sign-In; Gemini models for AI rendering, photo editing and design assistance | United States | |
| OpenRouter | Routing for AI image generation and for Emma, the chat assistant. Providers are pinned to ones that do not retain or train on what passes through | United States |
| Notion | Internal record of usage events and contact-form leads. Conversations with Emma are no longer copied there | United States |
| Resend | Sending the emails the site owes you — contact-form replies and Team Up match notices | United States |
| PayPal | Payments and subscriptions, if you buy anything. Card details go to PayPal, never to us | United States / global |
| Apple | Sign in with Apple and in-app purchases in the iOS and Mac app | United States |
| WeCom (企业微信) | Where support tickets reach our team, so a ticket you file is visible to us there | China |
If you use an export feature to send a design to your own Google Drive or Notion workspace, that transfer happens because you asked for it and lands in an account you control.
Because these providers operate in the United States and elsewhere, your information may be processed outside Canada and may be subject to the laws of those countries.
4. What we do not do
- We do not sell your personal information.
- We do not publish your saved designs or show them to other users.
- We do not use your designs or renders to train third-party AI models.
- We do not run advertising trackers or share data with ad networks.
5. How long we keep things
- Saved designs: until you delete them or ask us to close your account.
- Sign-in sessions: about 8 hours, then you sign in again.
- Shared renders: kept while they are useful for improving the product; you can ask us to delete yours at any time.
- 3D Photos: about two hours in the staging area, then deleted — download the ones you want to keep. Images generated by our own staff accounts are kept as training material.
- Contact messages and support tickets: kept as business records. If you delete your account, your contact messages go with it, and your support tickets keep only their text — your name and any screenshots you attached are removed, so the defect history other people worked on survives without you in it.
- Records of generated images and Emma conversations: about 13 months, and deleted with your account.
- Records of staff actions: about 13 months. These outlive a deleted account, holding only the one-way digest described above.
- Designer command log: what you typed at the design assistant is kept for 180 days and then deleted. It carries no account and only a one-way hash of your address, which is also why we cannot pick your rows out of it on request.
- Usage events: kept in aggregate reporting; individual rows are not tied to a named person.
- Your acceptance of this policy: for as long as the account exists, then deleted with it.
- Messages you send other members: about a year from the last message in that conversation, then they expire on their own.
- In-app notifications: about six months.
- Purchase and coin records: kept as financial records for as long as tax and accounting rules require.
6. Your choices and rights
Everything on this list that you can do yourself lives in one place: Settings → Privacy & data. Signed in, that page shows what you accepted and when, and deletes the account. In the designer it is in the account menu at the top right, under Privacy Policy. For a copy of your data, email us — see below.
- Render sharing: turn it on or off any time from the line under the render in Render Studio.
- Delete a design: from your saved designs or projects list.
- Delete your account: on the website, go to Settings → Privacy & data → Delete my account; in the app it is Settings → Delete account. Either way you type DELETE to confirm, and it happens immediately — you do not have to ask us and wait. This erases the account itself along with your saved designs, cloud projects, renders, archived photos, records of the images we generated for you, your conversations with Emma and your sign-in sessions — on our servers and on the device — and it cannot be undone. Your contact messages go too, and your support tickets keep their text with your name and attachments stripped out. Questions and answers you posted in the community stay up with your name removed, so replies other people wrote are not destroyed with them.
- …including copies other people hold. Your details do not only sit in your own records. A designer who made a kitchen for you has your address on their copy of the project; anyone who added you to their address book has your name and email in it; a Team Up room carries your display name on every message you sent. Deleting your account clears you out of those too — the designer keeps the design and the quote, and loses your contact details; the room keeps the conversation, and loses your name. We tell you how many such records were cleared when it is done. Can't sign in, or would rather we did it? Email us and we will do the same thing.
- Get a copy of your data: email us and ask, and we will send it to you — within 30 days, at no charge. You get a machine-readable file containing your account record, your saved designs and projects, your preferences, your coin history, your community posts and your acceptance record — everything we hold that is about you.
- Access, correction, deletion: email us and we will retrieve, fix, or delete the information we hold about you.
- Local data: clearing your browser's site data removes everything the designer kept on your device.
Under Canadian privacy law (PIPEDA) and comparable rules elsewhere, you have the right to access and correct your personal information and to withdraw consent. We will act on a request within 30 days, and we do not charge for it.
7. If you are in the European Union or the United Kingdom
The GDPR (and the UK GDPR) give you a specific set of rights, and require us to say plainly why we are allowed to handle your information at all. Our legal bases are:
- Performance of a contract (Art. 6(1)(b)) — running the designer, saving your work, producing your quotes and renders, keeping you signed in. This is most of what we do, and it is not something you opt into separately: it is the service you asked for.
- Consent (Art. 6(1)(a)) — only for genuinely optional things, and only the ones we ask about explicitly: keeping a copy of your renders so we can improve image quality, and sending you push notifications. You can withdraw either at any time without losing anything else, and withdrawing does not undo what was lawful before you did.
- Legitimate interests (Art. 6(1)(f)) — keeping the service up and preventing abuse, understanding which features get used through coarse, non-identifying event counts, and protecting our catalogue and 3D models from bulk automated copying. We have weighed these against your interests; none of them involve profiling you or building a picture of you across other websites.
Your rights: access, rectification, erasure, restriction, portability, objection (including objection to anything we do on the legitimate-interest basis above), and withdrawal of consent. Email info@flipkitchen.ca and we will answer within one month. There is no automated decision-making that produces legal or similarly significant effects about you.
Transfers out of the EEA and UK. Flip Kitchen is operated from Canada and its infrastructure is mostly in the United States, so your information is transferred out of the EEA. Canada holds an adequacy decision from the European Commission for commercial organisations; transfers to our United States providers rest on the Standard Contractual Clauses contained in those providers' data processing terms, which apply to our use of them.
If you think we have got this wrong, you can complain to your national data protection authority (in the UK, the Information Commissioner's Office). We would rather you told us first so we can fix it, but that right is yours regardless.
We have not appointed an EU representative under Art. 27, and the reason is that we do not offer this service in the EU: we price in Canadian dollars, we supply and install in Ontario, and the French on this site is for Quebec. The site loads anywhere, which is not the same thing. If you are in the EU and have used it anyway, the rights above are still yours and the email address above still reaches the person who decides — we would simply rather say what our position is than leave you to guess it.
8. AI-generated images and AI assistance
Renders, photo edits and redesign images produced by Flip Kitchen are generated by AI. They are interpretations of your design, not photographs of a real kitchen, and we say so wherever they are produced. We deliberately do not burn a visible watermark into your images — they are yours to use — and instead keep a fingerprint of each one, as described above, so the question "did Flip Kitchen generate this?" still has an answer. Emma, the chat assistant, is also an AI — you are not talking to a person, and it can be wrong. Nothing either of them produces is a construction document; anything that matters should be checked by a human before you order or build.
9. Security
Traffic is encrypted in transit. Admin tools are restricted to our own accounts and re-checked on the server, not just hidden in the interface. Render archive uploads and downloads use short-lived signed links rather than a public bucket. No system is perfect, and we do not claim otherwise — if a breach affects you, we will tell you.
10. Children
Flip Kitchen is meant for homeowners and trade professionals and is not directed at children under 13. We do not knowingly collect their information.
11. Changes
If we change this policy we will update the date and version above. When a change is material, the version changes too, and the designer asks you to read and accept the new version the next time you open it — so a material change reaches you rather than sitting on a page you have no reason to revisit. Cosmetic edits do not trigger that, because being asked to re-accept for a typo would only teach everyone to click through without reading.
12. Contact
Questions, or a request about your data: info@flipkitchen.ca.