← Back to Dipper

Privacy Policy

Last updated: September 5, 2026

This policy covers everything Dipper offers: the website at dipperapp.com, the Dipper browser extension for Chrome and Safari, and the Dipper mobile app. It sets out every category of data we collect, why we collect it, how long we keep it, and every third party it is shared with.

What Dipper is

Dipper is an AI-powered price tracker. You choose the products you want to watch — by pasting a link into the app, or with one click from the browser extension while you are on the product page. On a schedule, Dipper retrieves those publicly available product pages, uses an AI model to read the current price, availability, and title, stores a price history, and notifies you when the conditions you set are met.

How Dipper works (data flow)

For transparency, and for compliance reviewers:

  1. You add a product URL to your account, from the app or the extension.
  2. On a schedule, we fetch that public page — directly, or through a third-party scraping API for sites that block automated access. We never log in, bypass paywalls, or touch non-public content.
  3. An AI model (Anthropic) reads the title, price, currency and availability from that page. Your data is not used to train AI models.
  4. We store a timestamped price history, and alert you — by email, in the app, or by push — when your rules are met.

The browser extension

The extension runs on the pages you visit so it can offer one-click tracking. This is the part of Dipper with the broadest access to your browsing, so here is precisely what it does.

What it reads on the page

When you open a page, the extension reads that page’s own content inside your browser to work out whether it is a product page. If it is, it pulls out the product title, price, currency, any member or club price, availability, image, brand, model, barcode (GTIN), and the page URL. This reading happens locally in your browser. If no product price is found, nothing is extracted and no card is shown.

What leaves your browser, and when

  • Before you connect a Dipper account: nothing about the pages you visit is sent anywhere. Every request below requires a connected account and is refused without one.
  • When you click “Track”: the product URL and the fields listed above are sent to Dipper’s servers to create your tracker, together with the alert rule you chose.
  • Automatically, for products you already track: when you open the page of a product that is already on your watchlist, the extension sends what it just read (URL, title, image, price, availability) so your watchlist shows the real photo and an up-to-date price — including for sites our servers cannot read. Our server ignores this for any URL you do not already track; it never creates a new tracker.
  • Automatically, on Amazon product pages: the extension asks our servers to look for cheaper alternatives, sending the product title, page URL, currency, brand, model, and barcode. The results are shown in the card on the page.
  • Once, when you install it: an anonymous ping containing only the extension version, your browser’s interface language, and the fact that this was a fresh install. It carries no account details and no page data.

What is stored on your device

The extension uses your browser’s extension storage to keep your Dipper sign-in token, an in-progress sign-in code while you approve it, your widget preferences (corner position, collapsed state, sites where you dismissed or muted the card), and a local count of how many products you have added. This data stays in your browser, is not readable by the websites you visit, and is removed when you disconnect your account or uninstall the extension.

What the extension never does

  • It does not collect your browsing history, and it does not send us the addresses of pages that are not product pages.
  • It does not read or transmit what you type, form fields, passwords, payment details, or the cookies of sites you visit.
  • It does not inject advertising, and it does not modify the pages you visit beyond adding its own dismissible Dipper card.
  • It does not download or run remote code — all of its code ships inside the package you install from the store.
  • It does not sell your data, and it shares nothing with advertisers, analytics services, or data brokers.

Location (optional)

The extension’s “find cheaper nearby” feature can ask your browser for your location. Your browser asks you first, and you can refuse — the search still runs, just without nearby results. If you allow it, the coordinates are sent to our server and passed to OpenStreetMap’s Nominatim service, which returns a city name. We use only that city name, to localize results and to group cached results for shoppers in the same city. We do not store your coordinates, and we never derive or store a street address.

Information we collect

  • Account: your email address, a hashed password, and an optional name.
  • Tracked content: the product URLs you add, the product data and price history retrieved from them, and the alert rules you set.
  • Extension data: exactly as described in the section above.
  • Location: optional, coarse, and only for nearby results — see the section above.
  • Usage: counters (for example checks performed, Smart Track and “find cheaper” evaluations) used to enforce plan limits.
  • Notifications: your email address for alert emails, and, in the mobile app, a device push token if you enable push notifications.
  • How you found us: any utm_source, utm_medium, and utm_campaign parameters and the referring site present when you sign up, so we can tell which channels bring people to Dipper.
  • Billing (if you subscribe): a PayPal customer and subscription identifier and its status. Card details are handled entirely by PayPal — Dipper never sees or stores your card number. Subscriptions bought through our former provider, Lemon Squeezy, are still serviced under the same terms.
  • Technical: a single authentication cookie (a signed session token) and standard server logs, which include your IP address, browser user-agent, and request timestamps.

Cookies, analytics & advertising

  • Essential: one cookie keeps you signed in to the website. The site cannot work without it.
  • Advertising: while we are running ads, the dipperapp.com website loads Google’s advertising tag (gtag.js), which sets Google advertising cookies and reports sign-up and purchase conversions to Google Ads so we can tell which ad clicks worked. This runs on the website only — the browser extension and the mobile app load no advertising or analytics scripts at all.

We do not show ads inside Dipper, we do not sell your data, and we do not share it with data brokers.

Service providers we share data with

Everyone who receives user data, and what they get:

AnthropicPage content, product titles and search queries, for AI extraction and web search. Not used for training.
VercelHosting. Handles every request, including IP addresses and logs.
NeonThe database: your account, trackers and price history.
ScrapingBeeProduct URLs, to fetch sites that block our servers.
PayPalWhatever you enter at its checkout, if you subscribe.
Email providerYour email address and the message, to deliver alerts.
ExpoYour device push token and the notification text.
OpenStreetMapCoordinates, only when you opt in to nearby results.
GoogleAd conversions on the website, and the domain of a site you track, for its icon.

These providers are in the US and the EU, so using Dipper transfers your data there. We share only to run the service, we sell nothing, and we may disclose data where the law requires it or to protect our users.

Affiliate links

Some links Dipper shows to other stores — including the cheaper alternatives found by “find cheaper” — may carry an affiliate tag, such as an Amazon Associates tag. If you buy after following one, we may earn a commission at no extra cost to you, and the retailer can tell the visit came from Dipper. Affiliate tagging never changes the price you pay.

Chrome Web Store Limited Use

Dipper’s use of information received from Google APIs, and of all data the extension obtains from the pages you visit, adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Specifically: we use that data only to provide and improve the price-tracking features that are visible to you in the product; we do not sell it; we do not transfer it to anyone except the service providers listed above, or where the law requires it; we do not use it for advertising, ad targeting, or credit assessment; and no human reads it except with your consent, to investigate a security problem or abuse, or to comply with the law.

Third-party retailer sites

When Dipper retrieves a product page, it accesses content the retailer makes publicly available to any visitor. Dipper is independent and is not affiliated with, endorsed by, or sponsored by the retailers it tracks. Those retailers have their own privacy policies covering your visits to their sites.

Data retention & deletion

We keep your account, trackers, and price history for as long as your account is active. Deleting a tracker deletes its price history. You can request a copy of your data, or the deletion of your account and everything in it, at any time by emailing support@dipperapp.com; we action verified requests within 30 days. Server logs are kept for a short period for security and debugging. Uninstalling the extension removes everything it stored on your device, but it does not delete your Dipper account — ask us if you want the account removed too.

Your rights

Depending on where you live (for example under GDPR or CCPA/CPRA), you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. We do not sell or share personal information as those laws define it. Contact us to exercise any of these rights; you will never be treated differently for doing so, and you may complain to your local data-protection authority.

Security

Passwords are hashed (bcrypt), data is encrypted in transit (TLS), the extension’s sign-in token is kept in your browser’s extension storage and the mobile app’s in the operating system’s secure store, and access is scoped to your account. No method of transmission or storage is 100% secure, but we take reasonable measures to protect your data.

Children

Dipper is not directed to children under 16 and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.

Changes to this policy

We may update this policy; material changes will be reflected here with a new “last updated” date, and we will tell you in the app or by email when the change affects how we handle your data.

Contact

Questions about privacy, or a request about your data? Email support@dipperapp.com.