Privacy Policy
Last updated: July 10, 2026
Overview
Spritely ("the Service"), operated by Red Road Studio, LLC ("we", "us", or "our"), a company based in Georgia, United States, is committed to protecting your privacy. This policy explains what information we collect, how and why we use it, who we share it with, and the choices and rights you have. It applies to visitors and account holders worldwide, including in the European Economic Area (EEA), the United Kingdom, and California.
For the purposes of the EU and UK General Data Protection Regulation (GDPR / UK-GDPR), Red Road Studio, LLC is the data controller for the personal data described here. The third parties listed below act as our processors or, where noted, as independent controllers.
Information We Collect
Account Information
When you create an account, we collect your email address. Passwords are securely managed by our authentication provider (Supabase) and are not directly accessible to us. This information is used to authenticate you and operate your account.
Google Sign-In
If you sign in using Google, we receive your name, email address, and profile photo from Google. This information is used solely for authentication and displaying your profile within the Service. We do not use it for advertising.
API Keys
If you create API keys for programmatic access, we store a hashed (non-reversible) version of the key along with a short prefix for identification.
Prompts and Generated Images
When you generate a sprite, the text prompt you submit and the images the Service produces are:
- Sent to third-party AI providers (see the table below) so they can generate the requested image. For reference-based or image-to-image features, any reference image you provide is sent as well.
- Stored on our servers. Generated images are uploaded to our storage provider (Supabase Storage), and the associated prompt (including any refined/expanded version of it), generation settings, and file metadata are recorded in our database. Thumbnails of generated sprites and their prompts are also written to an internal activity log we use for debugging, abuse prevention, and support.
- May also be cached in your browser (for example in IndexedDB) so your recent work loads quickly. This local cache is in addition to — not instead of — the server-side copy described above.
An earlier version of this policy incorrectly stated that generated images were kept only in your browser and not on our servers. That was not accurate, and this section corrects it.
Usage and Billing Data
We record how you use the Service to calculate billing, enforce limits, and prevent abuse. This includes the number and timestamps of generations, associated costs, your account balance and transaction history, and — for each logged request — technical metadata such as your browser user-agent string.
Device, Network, and Location Data
Our hosting provider (Vercel) processes your IP address to deliver the Service and derives a coarse, IP-based location (country and region) which we use to:
- Enforce U.S. export-control and sanctions law by blocking access from embargoed territories; and
- Apply rate limiting and protect the Service from abuse.
We do not use this for precise geolocation or advertising.
Google User Data
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- We only request basic profile information (name, email, profile photo) via Google Sign-In.
- We do not transfer Google user data to third parties, except to our authentication provider (Supabase) for the sole purpose of managing your account session.
- We do not use Google user data for advertising or any purpose unrelated to providing the Service.
- We do not allow humans to read Google user data unless required for security purposes, to comply with applicable law, or with your explicit consent.
How We Use Your Information
- Providing the Service: generating sprites, storing your work, and operating your account
- Authentication: verifying your identity and maintaining your session
- Billing: tracking usage and processing payments
- Safety and compliance: preventing abuse, enforcing rate limits, and complying with export-control and sanctions law
- Analytics and improvement: understanding how the Service is used so we can improve it — only where you have consented to analytics cookies (see Cookies below)
- Communications: sending you transactional messages, and marketing only if you have opted in
Legal Bases for Processing (EEA / UK)
If you are in the EEA or UK, we rely on the following legal bases under the GDPR / UK-GDPR:
- Performance of a contract — to create your account, generate and store your sprites, and provide the Service you request.
- Legitimate interests — to secure the Service, prevent fraud and abuse, apply rate limits, keep basic error logs, and maintain records, balanced against your rights.
- Consent — for non-essential analytics and session-replay cookies and for marketing communications. You can withdraw consent at any time (see Cookies and Marketing below).
- Legal obligation — to comply with tax, accounting, export-control, sanctions, and other applicable laws.
Third-Party Services We Share Data With
We rely on the third-party providers below to operate the Service. Most act as our processors; payment and sign-in providers act as independent controllers for the data they collect. Each has its own privacy policy, which we encourage you to review.
| Provider | Purpose | Data it receives |
|---|---|---|
| Supabase | Authentication, database, and file storage | Email, hashed password, account and usage records, prompts, and generated images |
| Replicate | AI image / animation generation | Your prompts and any reference images you provide |
| Google (Gemini AI models) | AI image generation and asset planning | Your prompts and any reference/source images |
| Anthropic (Claude) | Internal asset planning and admin analytics | Prompt text and generation metadata used to plan assets |
| Stripe | Payment processing | Email and payment/transaction details (card data is handled by Stripe; we never receive or store it) |
| Google Analytics 4 | Product analytics (only with your consent) | Usage events, device/browser data, and your account identifier (your Supabase user id) |
| Vercel | Hosting, edge delivery, and Vercel Analytics | IP address, coarse (country/region) location, request metadata; Vercel Analytics events load only with your consent |
| Sentry | Error monitoring and session replay | Error diagnostics and technical context; session replay (a masked recording of your session) loads only with your consent |
| Google Sign-In | Optional OAuth sign-in | Your name, email, and profile photo (only if you choose to sign in with Google) |
Payments
Payments are processed by Stripe. When you make a purchase, Stripe creates a customer record keyed to your email address. Your full card details are entered into and handled by Stripe directly — we never receive or store your card number. Stripe processes this data as an independent controller under its own privacy policy.
Analytics and Error Monitoring
Where you have consented to analytics cookies, we use Google Analytics 4 and Vercel Analytics to understand how the Service is used. This analytics is pseudonymous, not anonymous: events can be associated with your account identifier (your Supabase user id), including through Google Analytics' server-side Measurement Protocol.
We use Sentry for error monitoring so we can detect and fix defects; basic error reporting may operate on the basis of our legitimate interest in keeping the Service working. Sentry also offers session replay, which records a reconstruction of your session. Session replay is treated as a non-essential, analytics-class technology and loads only if you have consented to analytics cookies. When it is active, it is configured to mask all text content and block media by default to reduce the personal data captured, though masking cannot be guaranteed to be perfect.
Cookies and Similar Technologies
We group cookies and similar technologies into the following categories:
- Strictly necessary — required for the Service to function and always on. These include Supabase authentication/session cookies and Google Sign-In OAuth cookies, and a first-party cookie that records your analytics-cookie choice. They cannot be switched off.
- Analytics — Google Analytics 4 and Vercel Analytics. These are not essential and load only with your consent.
- Error monitoring & session replay — Sentry session replay. Also non-essential; loads only with your consent.
When you first accept our Terms and Privacy Policy, you are asked whether to allow analytics cookies. The box is unticked by default — nothing in the analytics or session-replay categories loads unless you opt in. You can change your choice at any time here:
Your choice is stored in a first-party cookie on this device and, if you are signed in, is also recorded against your account. Changing it here updates this browser immediately. Signed-in users can also manage this from the Privacy & communications settings in their account.
Marketing Communications
We will always send you transactional and service messages related to your account (for example, security notices, receipts, and important changes to the Service); these are necessary while you hold an account and are not optional. We send marketing and promotional messages only if you have given explicit, opt-in consent. You can withdraw that consent at any time from the Privacy & communications settings in your account, using the unsubscribe link in any marketing email, or by contacting us — without affecting your ability to use the Service. This mirrors Section 15 of our Terms of Service.
Data Security
We implement industry-standard security measures including:
- HTTPS encryption for all data in transit
- Password management delegated to our authentication provider
- Secure session management via HTTP-only cookies
Data Retention
We keep your account data, prompts, and generated images for as long as your account is active. To be transparent: we do not currently run an automated purge, so stored prompts and images are retained until you delete your account or ask us to delete them, or until we no longer need them for the purposes described here or to meet a legal obligation. To request deletion, contact us at the address below.
International Users and Data Transfers
We are based in the United States, and our providers are located in the United States and other countries. If you are in the EEA or the UK, your personal data will be transferred to and processed in the United States. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum (IDTA), together with any additional measures required.
EEA/UK users: an EU/UK representative under Article 27 GDPR will be identified here where required.
Your Rights
Depending on where you live, you may have some or all of the following rights over your personal data:
- Access — obtain a copy of the personal data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure — ask us to delete your data ("right to be forgotten")
- Restriction — ask us to limit how we process your data
- Portability — receive your data in a portable format
- Objection — object to processing based on our legitimate interests
- Withdraw consent — withdraw analytics or marketing consent at any time
The Service does not yet include a self-service tool to export or delete your data. To exercise any of these rights, email us at aidan@andrsnn.com. We will respond within 30 days. We may need to verify your identity before acting on a request. Exercising your rights is free and will not lead to any discrimination in the Service you receive.
If you are in the EEA or UK and believe we have mishandled your data, you also have the right to lodge a complaint with your local data protection supervisory authority (in the UK, the Information Commissioner's Office). We would appreciate the chance to address your concern first.
California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act, as amended by the CPRA.
Categories of personal information we collect: identifiers (such as email address, account id, and IP address); commercial information (purchases and transaction history); internet and network activity (usage events, browser user-agent, and coarse location); and user content (prompts and generated images). We collect this for the business purposes described in this policy.
We do not sell your personal information. We do not exchange it for money. However, allowing analytics cookies (such as Google Analytics) can be considered "sharing" personal information for cross-context behavioral analytics under California law. You can opt out of this at any time by turning off analytics cookies using the control in the Cookies and Similar Technologies section above; if you leave analytics cookies off, no such sharing occurs.
You also have the right to know what we collect, to access and delete your personal information, to correct it, and to not be discriminated against for exercising these rights. To make a request, contact us at aidan@andrsnn.com.
Children's Privacy
The Service is not directed to children. You must be at least 13 years old to use it. If you are in the European Union, the United Kingdom, or another jurisdiction that sets a higher digital age of consent, you must be at least 16 years old (or have verifiable parental/guardian consent), consistent with Section 3 of our Terms of Service. We do not knowingly collect personal information from children below these ages; if you believe a child has provided us data, contact us and we will delete it.
Changes to This Policy
We may update this policy from time to time. Material changes will be communicated by posting a notice on the Service or via email, and — where the change affects how we use your data — you may be asked to review and accept the updated policy.
Contact
Red Road Studio, LLC is the controller of your personal data. For privacy-related inquiries or to exercise your rights, contact us at aidan@andrsnn.com.