Privacy Policy

How SpriteFuse handles account, generation, payment, and analytics data

2026/08/06

Scope

This Privacy Policy explains how SpriteFuse handles information when you use spritefuse.com, create an account, generate sprite assets, use a checkout, or contact support.

Information We Handle

Depending on how you use SpriteFuse, we may handle:

  • Account data, including your name, email address, account identifier, authentication records, and session information.
  • Generation inputs, including character descriptions, open-ended Move and adjustment text, optional reference images, and request identifiers.
  • Generation outputs and project data, including AI-generated images, processed frames, sprite sheets, previews, exports, quality-control metadata, job status, and project relationships.
  • Payment and Credit records, including the selected offer, provider customer or transaction identifiers, subscription state, payment status, Credit grants, refunds, disputes, and webhook audit records. SpriteFuse does not receive your complete payment-card number from a hosted checkout.
  • Support data, including the email address and information you choose to send us.
  • Usage and device data, including pages, product events, referrer, browser and operating-system information, IP-derived approximate location, and diagnostics when configured analytics services are active.

Why We Use Information

We use information to provide and secure the service, authenticate accounts, moderate generation requests, plan and generate sprite assets, store and export projects, apply limits, manage checkouts and Credits, respond to support, diagnose failures, prevent abuse, keep transaction and security records, and understand product use through configured analytics services.

AI and Infrastructure Providers

SpriteFuse sends only the information needed for each service function:

  • Waffo Pancake receives generation text for the mandatory Prompt Sift moderation step, hosts checkout, and processes billing events for Waffo-owned payments.
  • Creem continues to process billing events only for Creem-owned historical payments.
  • OpenRouter receives moderated character, Move, and adjustment text plus indicators about available reference or current artwork so an AI model can prepare a generation plan. SpriteFuse does not send the raw reference image to OpenRouter through this planning request.
  • fal.ai receives the compiled image prompt and, when needed, a short-lived signed link to reference or current artwork. fal.ai returns temporary generated media for SpriteFuse to process.
  • Cloudflare R2 stores new reference uploads and processed generation artifacts in a private bucket. Downloads use short-lived, owner-authorized signed links.
  • Supabase provides the PostgreSQL database used for accounts, project and job records, asset inventory, payment records, and Credits.
  • Vercel hosts and serves the SpriteFuse application and processes normal web requests and operational logs.

These third-party providers process data under their own terms, privacy policies, retention practices, and data controls. Their service locations and subprocessors may differ from ours.

Model Training

We do not use private generation inputs or outputs to train a SpriteFuse model. SpriteFuse currently relies on third-party AI providers rather than training its own generation model. Provider use, retention, and model-improvement practices are controlled by each provider's terms and data controls; this policy does not promise that every third-party provider follows SpriteFuse's internal practice.

Analytics

Configured analytics services load automatically on production pages:

  • Google Analytics 4 measures traffic and product usage.
  • Self-hosted Plausible Analytics measures aggregated traffic and configured product events.
  • Microsoft Clarity provides interaction analytics such as heatmaps and session recordings.

PostHog is not enabled in the current SpriteFuse production analytics set. The application template keeps an optional PostHog adapter, but it remains inert unless production configuration is supplied. We will update this policy before adding PostHog to the production provider set.

SpriteFuse product events are designed not to include prompts, uploaded images, email addresses, user IDs, payment IDs, or provider payloads. SpriteFuse does not provide an in-product analytics toggle. See the Cookie Policy for browser-level controls.

Storage, Security, and Access

New persisted generation assets use private application storage. SpriteFuse uses access controls, opaque asset references, short-lived signed download links, and other technical and organizational safeguards designed to reduce unauthorized access. No internet service can guarantee absolute security.

Do not send passwords, API keys, full card details, or unnecessary sensitive personal information in a generation request or support message.

Retention and Deletion

Retention varies by record and provider:

  • fal.ai generation requests are configured to use temporary provider storage while SpriteFuse copies usable output into private application storage.
  • Active project inputs and outputs are retained to provide project history, adjustment, and export until you delete the project or account, subject to cleanup completing successfully.
  • Project deletion removes inventoried private artifacts before the project database graph is removed. Active generation, legacy provider-hosted output, or a storage failure can delay deletion so the service does not falsely report that an artifact was removed.
  • Transaction, Credit, moderation, fraud-prevention, security, backup, and provider records may be retained after project or account deletion when reasonably needed for operations, dispute resolution, or legal obligations.

Providers may retain data under their own retention schedules. We cannot delete data that a provider is independently required or permitted to retain, but we can use available provider and application controls when handling a verified request.

Your Choices and Requests

You can use browser privacy settings or content blockers to limit analytics, use available project or account controls, or contact us to request access, correction, or deletion. Rights vary by location and may require identity verification. We may ask for an account email, Project ID, or Job ID; do not send passwords, API keys, or full payment-card details.

Changes

We may update this Privacy Policy as SpriteFuse or its providers change. We will post the revised policy and effective date on this page.

Contact

Privacy questions and requests can be sent to support@spritefuse.com.