Back to home

Privacy Policy

What ForgeSprite processes, why it is needed and how to manage your data.

Last updated: 2026-09-14

This policy covers ForgeSprite at forgesprite.com, Studio and our public tools. It explains what information is processed when you browse, sign in, create assets or buy credits. Contact support@forgesprite.com for privacy questions or requests. See also our Terms of Service.

1. Information we handle

  • Account and sign-in: Your account identifier, name, email, profile image, sign-in/session records and account preferences. Google supplies the profile information you authorize at sign-in; ForgeSprite does not receive your Google password.
  • Creative work: Project titles, prompts, conversations, uploaded references, generated assets, selected versions, edits, task status and export information. These let you return to and continue your work.
  • Purchases: Order and subscription identifiers, offer, amount, currency, payment/cancellation/refund status and credit transactions. Waffo Pancake and its payment partners handle payment details. Full payment card numbers and card security codes are not received or stored on our servers.
  • Support and operations: Messages you send us, related account/order/task identifiers, and records needed to diagnose errors, reconcile tasks or investigate abuse. Requests to our website and infrastructure can include IP address, browser/device information, timestamps and request metadata.

Provide only information needed for your task. Do not put payment card details, passwords, health information or other unnecessary sensitive personal data in prompts, images or support messages. If you upload information about another person, you must have an appropriate right to do so.

2. Why we use it

Where applicable law requires a legal basis, we rely on:

  • Providing the service you request: Account access, project storage, AI processing, editing and export are needed to perform our agreement with you.
  • Purchases and support: Payment confirmation, credit accounting, cancellation and resolving a service request are needed to perform that agreement. Handling fraud and disputes also supports our legitimate interest in a reliable service.
  • Security and necessary notices: Detecting misuse, diagnosing faults and communicating account, billing, security or policy changes support our legitimate interests, balanced against your rights.
  • Legal obligations: Records or disclosures required by applicable tax, payment, consumer-protection or other laws are processed to meet those obligations.
  • Optional uses: If we ask to use your private work publicly or for another purpose requiring consent, we will explain it and obtain that consent. You can withdraw consent for future use without affecting earlier lawful processing.

We do not sell personal information or share it for cross-context behavioral advertising. We do not run a marketing mailing list. Optional product analytics and masked public-page recordings are based on your consent; the controls and basic visit measurement are explained below.

3. AI requests and image processing

For AI planning, generation or generative edits, we send the prompt, relevant conversation/project context and necessary reference or selected images to third-party AI processing services. Depending on the task, this may include an uploaded image, a prior output or the image and selection used for an edit. We do not intentionally include your sign-in credentials or full payment details in these requests.

Third parties process those inputs to return a plan or image and may keep request data or logs for service operation, security, abuse prevention and their legal obligations. Their handling depends on the service and configuration in use. We do not promise zero retention or that every third party deletes an image immediately after processing. Contact us before submitting material with special confidentiality or data-location requirements.

ForgeSprite does not use your private projects to train its own AI models or place them in a public example gallery without your permission. This statement concerns our use of your work; it is not a promise about every third party's retention or processing practices.

Direct Studio pixel operations, such as rotate, crop and exact color replacement, run in our application backend without sending that operation to an AI model. Asking AI to plan an edit can still send the relevant project context for processing. The public PNG resizer processes the chosen image locally in your browser and does not upload that image.

Prompts and generated images may also be sent to content-safety processors to check compliance before delivery. We retain the review decision, policy version, request reference and content hash with the project; we do not duplicate raw images or prompts in these review logs. Authorized operators may investigate relevant records when handling reports or appeals.

4. Cookies, drafts and browser storage

Necessary cookies support sign-in, sessions and security. Blocking them can prevent account features from working. Browser storage also keeps creation drafts, preferences, request identifiers and pending references so you can continue after sign-in or avoid accidentally repeating a request.

Draft and request state can last for the browser-tab session. A pending reference may remain in this browser until it is uploaded or removed. We attempt to clear the pending local copy after a successful upload; an interrupted flow can leave it behind. You can clear this site's cookies and storage through your browser settings. Doing so may sign you out and remove unsent drafts or references, but does not delete projects already stored in your account.

Trying ForgeSprite without signing in creates a guest account linked to a session cookie. Prompts, projects and credit use are stored on our servers for that guest account. Signing in with Google from the same browser transfers this work and any unused guest credits to your account. Clearing the cookie before signing in can make the guest work inaccessible; it does not delete the stored records. We keep limited, pseudonymous promotion records to prevent repeated welcome-credit claims.

Visit measurement: Google Analytics 4 measures basic page visits with analytics storage denied by default. Before you allow optional analytics, Google receives limited, cookieless measurement signals rather than a persistent analytics cookie identifier. We send fixed page categories instead of private project URLs, query parameters or document titles. These signals can support aggregate or modeled reporting; they do not reliably identify every distinct visitor. Network requests still expose connection information such as your IP address to the receiving service.

Optional analytics: If you choose “Allow optional,” Google Analytics can use analytics cookies to measure visits across pages and sessions, and we send limited product events such as requesting a plan, confirming generation, receiving a result or exporting an asset. We do not send your account identifier, email, prompts, conversations, filenames, reference images or generated assets as analytics event data. Advertising storage, advertising user data, personalized advertising and Google signals remain disabled.

Optional recordings: With the same permission, Microsoft Clarity records masked interactions on public pages to help us understand usability. All page content is masked by default. Workspace, account, administration, sign-in and query-bearing pages are excluded from recording. We do not use Clarity to identify you by your account or email.

Use “Privacy choices” in the website footer or your account menu to allow or reject optional analytics. Rejecting stops our optional event collection, stops Clarity and removes accessible first-party analytics cookies; basic cookieless visit measurement continues. Your choice is stored for up to 180 days. Recording may resume on a subsequent eligible page load after you opt in again. Sign-in and checkout sites have their own notices and controls when you visit them.

5. Who receives information

We share information necessary for these functions:

  • AI processing services: The task-related content described above, for planning and producing or revising assets.
  • Cloud hosting and storage: Cloudflare serves the website, stores private files and forwards support emails.
  • Authentication and support email: Google provides sign-in and the mailbox used to handle support messages.
  • Analytics: Google provides basic visit measurement and, with your permission, product analytics; Microsoft Clarity provides optional masked public-page recordings. See Google’s privacy information and Microsoft’s Privacy Statement.
  • Payments: Waffo Pancake and its payment partners process checkout, transactions, subscriptions and refunds. They may also use payment information for their own fraud-prevention and legal responsibilities.
  • Legal and security matters: We may disclose relevant records in response to a valid legal requirement or when reasonably necessary to protect rights, users and the service.

Authorized people administering ForgeSprite may access relevant records to provide support or investigate an incident. Project access in the application is restricted to the owning account; private access does not mean that no service provider processes the content. If a business transfer changes who handles personal information, we will provide any notice and safeguards required by law.

For services you interact with directly, see Google's Privacy Policy, Cloudflare's Privacy Policy and the notices presented by Waffo Pancake at checkout. This policy does not replace their notices for processing they undertake independently.

6. International processing

Our infrastructure and service providers may process information outside your country, including in the United States and China. Processing locations depend on the feature and provider configuration; ForgeSprite does not currently offer a choice of data region or a guarantee that data stays in your country.

Cross-border processing remains subject to applicable data-protection requirements. If you need information about the safeguards relevant to your data or an applicable transfer, contact support.

7. Retention and deletion

Our current retention practices are:

  • Accounts and saved projects: Kept while your account remains open so you can continue working. There is no automatic project-expiry timer. Archiving only hides an item; all stored versions remain until deletion is handled.
  • Drafts and pending references: Kept in browser storage as described above. Clearing local storage does not remove server-side copies.
  • Task, credit and payment records: Kept with the account to explain usage, delivery and billing. Closing an account may require separate retention of limited records for unresolved transactions, disputes, fraud prevention or an applicable legal obligation.
  • Analytics: Consent preferences last up to 180 days. Google Analytics event-level retention is configured to two months. Clarity session recordings are generally retained for 30 days; aggregate reports and any recordings retained using Clarity features may last longer under its service rules.
  • Support correspondence: Kept to follow up and establish how a request was resolved. You can include correspondence in an access or deletion request.

Deletion of account data and support correspondence is currently handled through support, not through an automatic cleanup schedule. We acknowledge privacy requests and aim to respond within 30 calendar days of receipt, or sooner if applicable law requires. We may ask for proportionate identity verification. If a request needs more time or we must retain particular records, we will explain the reason, expected timing and scope of the exception. We will not claim that an archived item has been deleted.

A completed deletion request covers eligible data held by ForgeSprite. Payment or processing services may have separate records they are legally required to retain. We will explain relevant limitations rather than promise deletion from systems outside our control. Export assets you need before requesting deletion. Canceling a subscription alone does not delete your account or projects.

8. Security

We use authenticated access to private projects and files, checks on account ownership, restricted administrative access and encrypted connections for public service traffic. We review security-sensitive changes and investigate reported issues. No internet service can guarantee absolute security; protect your sign-in account and avoid uploading unnecessary sensitive information.

If we identify a personal-data breach, we will assess its impact, take steps to contain it and notify affected people and authorities where required, within applicable deadlines. This includes the 72-hour supervisory-authority notification requirement where the GDPR applies and its conditions are met. It is not a promise that every incident is reportable or that all investigation can finish in 72 hours.

9. Your rights and choices

Depending on the law that applies to you, you can ask to access or obtain a copy of your personal data, correct inaccurate information, delete eligible data, restrict processing, receive portable data, object to processing based on legitimate interests or withdraw consent. You can also complain to your local data-protection authority. Exercising a right does not remove access to support or result in unlawful discrimination.

Email support@forgesprite.com from your account email, state the request and identify the account or project concerned. Do not send passwords or payment card numbers. We may verify account control before disclosing or deleting information. An export of project images is not necessarily a full export of all personal data; contact us for a broader access request.

10. Age, external links and updates

ForgeSprite is for people aged 18 or older. We do not knowingly collect children's information. If a child has supplied personal information, contact us so we can review and remove it as appropriate.

External links may lead to services with different privacy practices. Review their notices before providing information. We update the date on this page when the policy changes and provide additional notice or request consent for material changes where required. Questions and privacy requests can always be sent to support@forgesprite.com.