SpriteBrew

Privacy Policy

Last updated: October 4, 2026

SpriteBrew (“we”, “us”, “our”) is a pixel art sprite sheet generator built by George Albanese. This policy explains what data we collect, why, where it is kept, and how to delete it.

1. Your account

You sign in through Clerk, our authentication provider. Clerk holds your email address and, if you sign in with GitHub, the name, username and profile photo GitHub shares with us.

When an account is created, we check whether its email address belongs to a known disposable email service, to limit abuse of the free signup bonus.

We keep your token balance for as long as your account exists, and a log of your token credits and debits for 90 days.

We also keep small records that run the free tier and bonuses, for as long as your account exists: your signup grant, your daily login streak, how many free generations you have used, which one-time bonuses you have claimed, and whether your signup email matched our list of disposable email services.

2. What you create

When you generate, your prompt, the style and size you chose, and any image you upload (a character to animate or a reference image) are sent to Retro Diffusion, which creates the art. We do not send them your name, email address or account id.

Each finished generation is saved to your account: the image in Cloudflare R2 storage, and a gallery entry in Cloudflare KV with the first 300 characters of your prompt, the style and the date. Both stay until you delete them.

While a generation runs and for up to an hour after it finishes (about a day if we owe you a refund for it), we keep a job record, including the result. A copy of the record is deleted after one day.

An image you upload travels with its job through our processing queue and is removed from the queue when the job finishes. If a job runs into problems, its message, with your image, can move to a second queue that checks the result was delivered or your tokens were refunded. The message is removed from that queue once that check is done, which normally takes no more than a few hours.

To find and fix failures, we record each generation's progress (when it started, whether it finished, any error message, the style and size, and any tokens refunded along with your token balance after the refund) with your account id. These records are deleted when your account is deleted. Logs from our processing service, which also carry your account id, are deleted after 7 days.

The sprite slicer, preview, export tools and pixel editor run in your browser. Files you open in them are not uploaded to us.

Some things are kept only on your device, in your browser: a list of your recent generations (up to 50, each with its prompt and a small preview, and full images for up to the 10 most recent), your Animate settings and saved templates, editor drafts, and a copy of your token balance. Deleting a generation from your gallery does not remove it from this list. Clearing your browser data removes these. It does not delete anything saved to your account.

3. Payments

Token packs are paid through Stripe. You enter your card details on Stripe's checkout page; we never see or store your card number.

When you open a checkout, we record your account id, the time, your IP address, your browser's user agent, and your consent to receive the tokens right away. We keep this record for 400 days as evidence in case a payment is disputed, whether or not you complete the purchase. We also send your account id, IP address and the time of your consent to Stripe with the checkout.

When a payment succeeds, we keep a record of it (your account id, the pack, the tokens, the amount and Stripe's payment ids) and mark your account as a paying account. These records have no set expiry.

If a payment is refunded, we take back tokens from your balance and keep a record of the refund. If that leaves your balance below zero, your account cannot generate until we lift the block by hand, so contact us to resolve it. If a payment is disputed (a chargeback), we take back its tokens and permanently stop the account from generating. Neither step deletes your account or your data. For refunds and disputes we keep evidence about the purchase, including a copy of the checkout record above, for 400 days from the refund or dispute. We also keep, with no set expiry, how many refunds you have had, the date of the last one, a record of any dispute and any block on the account. We may add the email address and card fingerprint used for the payment (a code Stripe uses to recognize a card, not the card number) to fraud-prevention lists in our Stripe account.

Stripe keeps its own records of your payments, as the law requires.

4. Newsletter, waitlist and feedback

If you subscribe to the newsletter inside the app, we add your account email address to our mailing list at Resend and give you a one-time token bonus. Ask us at any time and we will remove you.

If you join the Pixel Pass waitlist, we keep your email address until you ask us to remove it.

If you send feedback through our feedback form, it is collected by Tally. If you email us, we keep the conversation.

5. Services we use

  • Clerk (clerk.com): sign-in and account management.
  • Retro Diffusion (retrodiffusion.ai): creates the art from your prompts and uploaded images.
  • Stripe (stripe.com): payments.
  • Cloudflare (cloudflare.com): hosts the site, runs our processing queue, and stores the data described above (KV, R2, D1 and logs).
  • Resend (resend.com): sends the newsletter if you subscribe, and a daily operations report to our own inbox that includes shortened generation-job identifiers and failure and refund details.
  • Tally (tally.so): the feedback form.

Each service's own privacy policy applies to the data it handles.

We use Cloudflare Web Analytics to count page visits. It does not use cookies. We add no advertising scripts and no tracking cookies. Clerk sets the cookies that keep you signed in.

6. What we don't do

We do not sell or rent your data, and we do not share it with anyone for their own marketing. We do not track you across other websites.

We do not use your prompts or images to train AI models.

7. Deleting your data

You can delete generations from your gallery, one at a time or using Clear all. The gallery shows your 50 most recent generations, and Clear all includes older generations saved to your account. For very large histories, you may need to refresh and clear again, or contact us for help. Deleting removes the image and its gallery entry. A temporary record of the job, which also holds the image, expires on its own about an hour after the generation finishes.

To delete your account and everything tied to it, email [email protected] from your account's email address. We delete your account, balance and history, images, newsletter subscription and generation records, and email you when it is done. If you write from another address, we first confirm with your account email.

We keep a record that you asked and that we deleted your data. Payment, refund and dispute records, and the fraud-prevention entries described in section 3, may be kept where we need them to handle disputes or prevent fraud. Stripe keeps its own payment records. Operations reports already emailed to our own inbox, which name jobs only by shortened identifiers, are not deleted. Backups clear themselves within 30 days, and logs within 7 days.

You can also ask us for a copy of your data.

Clearing your browser data removes only what is on your device (see section 2).

8. Contact

For privacy questions or data requests, email [email protected].

9. Changes to this policy

We update this policy when SpriteBrew changes how it handles data, and change the date at the top. Significant changes are noted on the site.