Privacy Policy
Last updated: September 5, 2026
This policy covers everything Dipper offers: the website at dipperapp.com, the Dipper browser extension for Chrome and Safari, and the Dipper mobile app. It sets out every category of data we collect, why we collect it, how long we keep it, and every third party it is shared with.
What Dipper is
How Dipper works (data flow)
For transparency, and for compliance reviewers:
- You add a product URL to your account, from the app or the extension.
- On a schedule, we fetch that public page — directly, or through a third-party scraping API for sites that block automated access. We never log in, bypass paywalls, or touch non-public content.
- An AI model (Anthropic) reads the title, price, currency and availability from that page. Your data is not used to train AI models.
- We store a timestamped price history, and alert you — by email, in the app, or by push — when your rules are met.
The browser extension
The extension runs on the pages you visit so it can offer one-click tracking. This is the part of Dipper with the broadest access to your browsing, so here is precisely what it does.
What it reads on the page
When you open a page, the extension reads that page’s own content inside your browser to work out whether it is a product page. If it is, it pulls out the product title, price, currency, any member or club price, availability, image, brand, model, barcode (GTIN), and the page URL. This reading happens locally in your browser. If no product price is found, nothing is extracted and no card is shown.
What leaves your browser, and when
- Before you connect a Dipper account: nothing about the pages you visit is sent anywhere. Every request below requires a connected account and is refused without one.
- When you click “Track”: the product URL and the fields listed above are sent to Dipper’s servers to create your tracker, together with the alert rule you chose.
- Automatically, for products you already track: when you open the page of a product that is already on your watchlist, the extension sends what it just read (URL, title, image, price, availability) so your watchlist shows the real photo and an up-to-date price — including for sites our servers cannot read. Our server ignores this for any URL you do not already track; it never creates a new tracker.
- Automatically, on Amazon product pages: the extension asks our servers to look for cheaper alternatives, sending the product title, page URL, currency, brand, model, and barcode. The results are shown in the card on the page.
- Once, when you install it: an anonymous ping containing only the extension version, your browser’s interface language, and the fact that this was a fresh install. It carries no account details and no page data.
What is stored on your device
The extension uses your browser’s extension storage to keep your Dipper sign-in token, an in-progress sign-in code while you approve it, your widget preferences (corner position, collapsed state, sites where you dismissed or muted the card), and a local count of how many products you have added. This data stays in your browser, is not readable by the websites you visit, and is removed when you disconnect your account or uninstall the extension.
What the extension never does
- It does not collect your browsing history, and it does not send us the addresses of pages that are not product pages.
- It does not read or transmit what you type, form fields, passwords, payment details, or the cookies of sites you visit.
- It does not inject advertising, and it does not modify the pages you visit beyond adding its own dismissible Dipper card.
- It does not download or run remote code — all of its code ships inside the package you install from the store.
- It does not sell your data, and it shares nothing with advertisers, analytics services, or data brokers.
Location (optional)
Information we collect
- Account: your email address, a hashed password, and an optional name.
- Tracked content: the product URLs you add, the product data and price history retrieved from them, and the alert rules you set.
- Extension data: exactly as described in the section above.
- Location: optional, coarse, and only for nearby results — see the section above.
- Usage: counters (for example checks performed, Smart Track and “find cheaper” evaluations) used to enforce plan limits.
- Notifications: your email address for alert emails, and, in the mobile app, a device push token if you enable push notifications.
- How you found us: any utm_source, utm_medium, and utm_campaign parameters and the referring site present when you sign up, so we can tell which channels bring people to Dipper.
- Billing (if you subscribe): a PayPal customer and subscription identifier and its status. Card details are handled entirely by PayPal — Dipper never sees or stores your card number. Subscriptions bought through our former provider, Lemon Squeezy, are still serviced under the same terms.
- Technical: a single authentication cookie (a signed session token) and standard server logs, which include your IP address, browser user-agent, and request timestamps.
Cookies, analytics & advertising
- Essential: one cookie keeps you signed in to the website. The site cannot work without it.
- Advertising: while we are running ads, the dipperapp.com website loads Google’s advertising tag (gtag.js), which sets Google advertising cookies and reports sign-up and purchase conversions to Google Ads so we can tell which ad clicks worked. This runs on the website only — the browser extension and the mobile app load no advertising or analytics scripts at all.
We do not show ads inside Dipper, we do not sell your data, and we do not share it with data brokers.
Service providers we share data with
Everyone who receives user data, and what they get:
| Anthropic | Page content, product titles and search queries, for AI extraction and web search. Not used for training. |
|---|---|
| Vercel | Hosting. Handles every request, including IP addresses and logs. |
| Neon | The database: your account, trackers and price history. |
| ScrapingBee | Product URLs, to fetch sites that block our servers. |
| PayPal | Whatever you enter at its checkout, if you subscribe. |
| Email provider | Your email address and the message, to deliver alerts. |
| Expo | Your device push token and the notification text. |
| OpenStreetMap | Coordinates, only when you opt in to nearby results. |
| Ad conversions on the website, and the domain of a site you track, for its icon. |
These providers are in the US and the EU, so using Dipper transfers your data there. We share only to run the service, we sell nothing, and we may disclose data where the law requires it or to protect our users.