No marketplace credentials
Flipinator does not ask for or store marketplace passwords, session cookies or one-time sign-in codes. Never send those details to support. Searches use sanctioned public marketplace capabilities and the structured location you choose.
Product-isolated accounts
A Flipinator account, session, search, Feed, device registration, purchase state and support context belong to Flipinator. Trusted host, signed token and the immutable product on the account must agree before authenticated work proceeds.
Passwordless sign-in
Email verification links or codes and configured Apple or Google identity can establish a session. Codes are short-lived and bound to their intended flow. Treat an unexpected sign-in message as sensitive and never forward it.
Device alerts
Browser and native push registrations contain provider-issued identifiers needed to reach the device. Sensitive notification configuration is protected at rest and is never returned as a raw token through normal account views. Permission and interruption remain controlled by the browser or operating system.
Billing boundaries
Approved payment providers and app stores handle payment credentials. Flipinator receives the identifiers, verified events and entitlement state needed to maintain access, not full card numbers. Webhook processing is authenticated, deduplicated and safe to retry.
Reporting a concern
For a suspected account issue, use the support form and begin the message with “Account security”. Include what you observed and when. Do not include passwords, codes, private keys, full payment data or exploit material that could harm other people.
For a potential technical vulnerability, identify the affected public Flipinator surface and a minimal safe reproduction. Do not access another person’s account, disrupt service, retain personal data or test against production in a way that creates risk.