Legal
Privacy Policy
What Flogit touches, what stays on your computer, and the few things that leave it. Written to match what the software actually does.
Effective 18 July 2026 · last updated 20 July 2026
Flogit is a browser extension that helps Vinted sellers manage their own shop — inventory, sales, offers, pricing, and creating listings. This policy explains exactly what data Flogit touches, what stays on your computer, and the few things that leave it. It is written to match what the software actually does; where a term is technical we say plainly what it means.
Who we are. Flogit is operated by José Luis Fernandes de Sousa, Amoreiras Square, R. Carlos Alberto da Mota Pinto nº17, 3rd Floor A – Escritório 317, 1070-313 Lisboa, Portugal. For any privacy question, or to exercise the rights below, contact us at privacy@flogit.app.
The short version
- Almost everything Flogit knows about your shop stays on your own computer — your inventory, sales, orders, buyer offers, market estimates and your private cost/expense notes are stored locally in your browser and are never sent to us.
- We do not collect your email, and there is no account. There is nothing to sign up for and no password. If you buy a plan, your Gumroad licence key is stored on your own device and identifies your plan; we only ever store a one-way hash of it.
- A few things leave your device, and only when you use the feature that needs them: the text of a listing you ask AI to help with, a market search term, and — if you use photo autofill or phone upload — the photos of the item you are listing. Phone-upload photos are deleted as soon as your computer picks them up.
- We do not use analytics, trackers, or advertising SDKs. None.
- We never see, store, or transmit your Vinted password or your Vinted login session.
1. What stays on your device and is never sent to us
Flogit keeps the working data of your shop in your browser's own storage (chrome.storage.local and a local database). This data is not transmitted to Flogit's servers, to Vinted, or to anyone else. It includes:
- Inventory — your items, and any SKU, purchase price, quantity, or notes you add.
- Sales and orders — order history, cost-of-goods and per-order notes you enter.
- Market estimates — the comparable-listing prices Flogit computes for you and its record of which comparable listings have come and gone over time.
- Buyer offers and negotiation data — offers received, conversation-read markers, and records used to flag repeat low-ballers (which may include a buyer's public Vinted username).
- Your private ledger — any purchases and expenses you record in Flogit.
- Dispute-evidence photos — if you capture item photos as evidence, the image files are stored locally in your browser (IndexedDB) and are never uploaded.
Because this data lives in your browser profile, clearing the extension's storage or removing the extension deletes it. It is not backed up to us.
2. How Flogit reads your Vinted data
Flogit reads your Vinted shop through Vinted's own website, from within the Vinted tab, using the login session you already have open in your browser. Concretely:
- Flogit never handles your Vinted password.
- Flogit never reads, copies, or transmits your Vinted login cookie. That cookie is attached by your browser only to requests to Vinted itself; Flogit's requests to its own backend deliberately send no cookies.
- Reading your Vinted data (items, orders, offers) happens locally in the page and is used to populate the on-device data described in Section 1.
3. What leaves your device, and where it goes
Flogit's backend runs at api.flogit.app (hosted on Cloudflare). Requests to it go through the extension's background worker, which attaches either your licence key (if you have a plan) or an anonymous device identifier, so the backend can apply the right monthly allowance. The following — and nothing else — is sent off your device:
3.1 Your licence key, or an anonymous device id — to apply your plan
If you have bought a plan, your Gumroad licence key is sent so we can confirm the plan with Gumroad. We store only a one-way hash of it, never the key itself. If you have no licence, the extension sends a random identifier generated on your device — it is not derived from you, your browser or your Vinted account, and it exists only to keep one browser's free monthly allowance separate from another's. You can erase it at any time by clearing the extension's storage.
3.2 Listing text — when you use AI writing help
When you ask Flogit to improve a listing or suggest a price, the relevant text is sent to our backend and on to Anthropic (the "Claude" AI provider) to generate the suggestion. Depending on the feature this text may include: the item's title, description, brand, category, size, condition and price, and — for negotiation help — the listing and offer prices and the text of the buyer/seller messages in that conversation. This is used only to produce the suggestion you asked for.
3.3 A search term — for market comparisons
When Flogit estimates a resale value, it may send a search phrase (built from the item's title and brand) to our backend, which queries the eBay Browse API. Only the search phrase is sent — no identity or account information.
3.4 Item photos — only if you use AI photo autofill
If you use the feature that reads your photos to fill in a new listing, the photos of the item you are listing are sent to our backend and on to Anthropic to detect the item's attributes (category, colour, and so on) and draft the listing. These photos:
- are sent only when you click to run the feature — never automatically, never in the background;
- are used only to generate that listing's details, in that moment;
- are not stored on our servers after the request is handled, and are not used to train any AI model;
- are the photos you chose to publish on Vinted anyway.
If you never use photo autofill or phone upload (Section 3.5), no image ever leaves your device through Flogit.
3.5 Photos you send from your phone — only if you use phone upload
If you use phone upload — the QR code that lets you photograph an item with your phone and have the pictures appear in the listing form on your computer — those photos necessarily pass through our servers, because that is the only way to get them from one device to the other.
We hold them as briefly as we can:
- they are stored in Cloudflare R2 (EU), and deleted the moment your computer collects them — normally within a few seconds;
- anything not collected is erased automatically when the link expires, 15 minutes after you open it, whether you collected it or not;
- the link's address is a random 128-bit value that acts as its only key. It is shown only on your own screen, and reading the photos back additionally requires the same device that opened the link — so someone who photographed your QR code could add pictures to your form, but could never see what you uploaded;
- they are not used to train any AI model and are not sent to Anthropic unless you separately choose to run photo autofill on them;
- the phone shrinks each photo before sending it, so we never receive the original full-resolution file.
You start this flow deliberately, one session at a time. If you never open the QR, nothing is ever uploaded.
3.6 Vinted Pro credentials — only if you connect Vinted Pro
If you connect a Vinted Pro account, the API keys you provide are sent to our backend and stored encrypted; the signing key is decrypted only inside our server to sign requests to Vinted's Pro API on your behalf. Do not use this feature unless you have a Vinted Pro account and intend to.
4. The personal data we hold, and for how long
We keep the minimum needed to run the service:
| Data | Why | Where | Retention |
|---|---|---|---|
| Licence key hash | To confirm your plan with Gumroad and apply its allowance | Cloudflare D1, as a one-way hash — the key itself is never stored | Until the licence is removed or stops being valid |
| Anonymous device id | Only if you have no licence: to keep one browser's free allowance separate from another's | Generated on your device; the backend only sees it as an opaque string | Yours to erase by clearing the extension's storage |
| Monthly usage count | To apply your plan's allowance | Cloudflare D1, against the hash/device id above | Per calendar month |
| IP address | Abuse/rate-limiting on the free allowance only | Cloudflare D1 (rate-limit counter) | ~24 hours |
| Phone-upload photos | Only if you use phone upload: to carry the pictures from your phone to your computer | Cloudflare R2 (EU) | Deleted on collection; 15 minutes maximum |
| Encrypted Vinted Pro keys | Only if you connect Pro | Cloudflare D1 (encrypted) | Until you disconnect Pro |
There is no name, no email and no account — none of the above identifies you as a person. We could not contact you if we wanted to.
We do not store your inventory, sales, prices, offers, photos (beyond the minutes described in Section 3.5), or ledger on our servers — those stay on your device (Section 1). Our server keeps standard operational error logs (via Cloudflare) that do not contain this data.
5. Who we share data with (sub-processors)
We do not sell your data and we do not share it for advertising. We use these service providers strictly to run the features above:
- Cloudflare — hosting, database and (for phone upload) short-lived photo storage for
api.flogit.app. - Gumroad — receives your licence key to confirm the plan it grants.
- Anthropic — processes listing text and (if you use photo autofill) item photos to generate suggestions. Anthropic does not use data submitted through its API to train its models. See Anthropic's privacy policy.
- eBay — receives only the market search phrase for resale comparisons.
6. Fonts
The interface uses the "Outfit" font, which is bundled inside the extension — it is not fetched from Google or any other server, so displaying Flogit makes no font-related network request and reveals nothing to a third party.
7. Your choices and rights
- Nothing to delete, in most cases. We hold no account and no email. Removing the extension, or clearing its storage, erases your licence key and device id from your device — after which nothing on our side points to you.
- Remove your licence at any time in Settings → Plan → Deactivate. The key stays valid on Gumroad, so you can use it on another device.
- On-device data is under your direct control: remove the extension, or clear its storage, to erase everything described in Section 1.
- Disconnect Vinted Pro at any time; this deletes your stored Pro credentials.
- Questions or requests — email privacy@flogit.app. Note that without an account we may be unable to link a request to any specific record.
Depending on where you live (for example, the EU/UK under the GDPR), you may also have the right to object to or restrict processing, to data portability, and to lodge a complaint with your data-protection authority. Our legal basis for processing your licence key is performance of the service you asked for; for the device id and IP-based rate-limiting it is our legitimate interest in preventing abuse of a free allowance.
8. Children
Flogit is not intended for use by anyone under 16, consistent with Vinted's own minimum age. We do not knowingly collect data from children.
9. Changes to this policy
If we change how Flogit handles data, we will update this page and its "last updated" date. Material changes — in particular any new category of data that leaves your device — will be announced in the extension before they take effect.
10. Contact
José Luis Fernandes de Sousa Amoreiras Square, R. Carlos Alberto da Mota Pinto nº17, 3rd Floor A – Escritório 317 1070-313 Lisboa, Portugal Email: privacy@flogit.app