Effective date: September 1, 2026 · Last updated: September 29, 2026
Sprites AI is operated by Campfire Expeditions Inc. o/a Sprites AI, 350 Bay St., Floor 13, Toronto, ON M5H 2S6, Canada (“Sprites AI”, “we”, “us”). This policy explains what personal data we collect, how we use it, who we share it with, and the choices you have.
It applies to sprites.ai (including www.sprites.ai) and any related services (the “Service”). It does not apply to third-party platforms you connect to the Service; their own privacy policies govern those platforms.
We act in two different roles depending on the data involved.
As a controller for the personal data of our own users and website visitors: account registration details, login credentials, billing contacts, support communications, and usage of the Service. We decide how this data is used, as described in this policy.
As a processor for personal data that reaches us through the advertising, analytics, CRM, commerce, and content platforms our customers connect to the Service. This includes business contact records read from a customer’s CRM, campaign and audience metadata from advertising platforms, and content the customer creates in their workspace. We process this data only on the customer’s instructions under our Data Processing Addendum. The customer is the controller. If you are a data subject whose data appears in a customer’s connected system, contact that customer to exercise your rights; we will assist them in responding.
Account data. Name, business email address, password (stored hashed), company name, job title if provided, and profile details from Google or GitHub sign-in if you use them.
Billing data. Billing contact name and address, and payment method details handled by our payment processor, Stripe. We do not store full card numbers.
Usage data. Log data (IP address, browser type, device information, pages and features used, timestamps), diagnostic and error data, and interactions with the Service. Application logs are automatically redacted of personal identifiers such as email addresses and credentials before storage.
Communications. Support requests, emails, and messages you send us, including through shared Slack channels.
Website data. Cookies and similar technologies on sprites.ai as described in Section 9.
We do not collect special categories of personal data (health, biometric, political, religious, or similar), and we ask that you do not submit them to the Service.
When a customer connects a third-party platform (Google Ads, Meta Ads, LinkedIn Ads, TikTok Ads, Reddit Ads, Shopify, HubSpot, Google Analytics, Google Search Console, Google Business Profile, Google Merchant Center, WordPress, Webflow, Google Drive, OneDrive, and similar), the Service accesses that platform through the platform’s official API using OAuth or an access token authorized by the customer.
What we access: campaign structure, performance metrics, spend, targeting settings, creative assets, and content on the connected platform; business contact records from CRM platforms (read-only); analytics and search performance data; and files the customer explicitly selects from connected storage.
What we do not access or store: customer-match lists, hashed identifiers, or end-consumer personal data. Audience data remains within the advertising platforms.
How we handle it: campaign and platform data is fetched on demand when the customer or their approved automations request it. Working artifacts from these fetches (tool outputs and analysis files) are automatically deleted within 30 days. Data the customer stores in the Service (business profiles, strategy content, generated content, agent action history, and encrypted platform credentials) is retained for the term of the customer’s agreement and deleted within 30 days of termination.
Platform credentials. OAuth tokens and access tokens for connected platforms are encrypted at the application layer with AES-256-GCM before storage. Customers can revoke our access at any time from their own platform account settings, and access ends immediately.
Sprites AI’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically: we only use Google user data (from Google Ads, Google Analytics, Google Search Console, Google Merchant Center, Google Business Profile, and Google Drive) to provide and improve user-facing features of the Service that the user has requested. We do not use Google user data to serve advertisements, and we do not sell it. We do not transfer Google user data to third parties except to our subprocessors as necessary to provide the Service, as required by law, or with the user’s explicit consent. We do not allow humans to read Google user data unless the user has given consent, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymized for internal operations.
The same standards apply to data received from Meta, LinkedIn, TikTok, and other connected platforms under their respective platform policies.
As a controller, we use your personal data to:
Legal bases (GDPR and UK GDPR). Performance of a contract with you (account, billing, service delivery); our legitimate interests in securing and improving the Service, preventing fraud, and communicating with business customers; consent where required, for example for non-essential cookies or marketing emails; and compliance with legal obligations.
For data we process as a processor, the customer as controller is responsible for establishing the legal basis.
The Service uses third-party AI models to analyze data and generate recommendations and content.
AI assistant connectors. You can connect Sprites to an AI assistant such as Claude or ChatGPT through our MCP connector (mcp.sprites.ai). You sign in with your Sprites account and choose the business the assistant may work on; the assistant then holds an access token for that account. Disconnecting Sprites in the assistant ends that access, and you can also ask us to revoke it at the address in section 12. When the assistant calls a Sprites tool we receive what it sends: the request written from your conversation (for example “audit my Google Ads account”), the channel, and your local date. We do not receive the rest of the conversation. We process the request like one made in the Sprites app, under the terms above, and return the result to the assistant, where it becomes part of your conversation under that assistant provider’s own privacy terms. The connector also records which tools were called and when, and card rendering errors, to operate and secure the connector; these records follow the application log retention in section 11.
We do not sell personal data. We share it only with:
Subprocessors that help us operate the Service, each bound by written terms at least as protective as our commitments to customers:
| Provider | Location | Purpose |
|---|---|---|
| Google Cloud | United States | Application hosting, compute, storage |
| Vercel | United States | Web application hosting |
| Neon | United States | Database hosting |
| Cloudflare | United States | Edge network, DNS, security |
| Redis Cloud (Redis Ltd.) | United States | Queueing and ephemeral cache |
| SuperTokens | United States | Authentication service |
| Stripe | United States | Payment processing |
| Loops | United States | Transactional email |
| Anthropic | United States | AI language models |
| OpenAI | United States | AI models (text and image generation) |
| Google (Gemini API) | United States | AI models (image generation) |
| Fireworks AI | United States | AI model inference |
| Sentry | United States | Error monitoring |
| PostHog | United States | Product analytics for our own users |
| Pipedream | United States | Integration connectivity (Google Drive, OneDrive, Google Business Profile) |
| Bunny.net | Slovenia | Content delivery and file storage |
Customers receive at least 30 days’ advance notice before we add or replace a subprocessor and may object.
Connected platforms you choose to link, which receive data as necessary to perform the actions you or your workspace users approve.
Professional advisers, and authorities where required by law, to protect our rights, or in connection with a merger, acquisition, or sale of assets, in which case this policy will continue to apply.
We are a Canadian company and our production infrastructure is in the United States. If you are in the European Economic Area, the United Kingdom, or Switzerland, your personal data is transferred to the United States. For customer data we process under a Data Processing Addendum, transfers are covered by the EU Standard Contractual Clauses (Module Two) and the UK International Data Transfer Addendum, supported by the security measures described in Section 10. For our own users’ account data, we rely on the same Standard Contractual Clauses with our subprocessors and on the safeguards described in this policy.
sprites.ai uses essential cookies required for the site and app to function (authentication, session, security) and analytics cookies to understand how the site is used. Analytics cookies are set only with your consent where required by law. You can manage cookies through your browser settings; disabling essential cookies will prevent the app from working.
Our security measures include encryption in transit (TLS 1.2 or higher) and at rest (AES-256), application-layer AES-256-GCM encryption of connected-platform credentials, secrets held in a dedicated secrets manager and never in code, centralized PII-redacted logging retained for 365 days, continuous dependency vulnerability scanning with automated security updates, container image scanning in the deployment pipeline, server-enforced human approval of state-changing agent actions, and point-in-time recovery of the production database. No system is perfectly secure; if you believe your account has been compromised, contact us immediately. If we confirm a breach affecting your personal data, we will notify affected customers without undue delay and within 72 hours of confirmation.
Account data is retained for as long as your account is active and deleted within 30 days of account closure, except where we must retain it for legal, billing, or dispute-resolution purposes. Customer workspace data is retained for the term of the customer’s agreement and deleted within 30 days of termination, with written confirmation on request. Working artifacts from connected-platform fetches are automatically deleted within 30 days. Application logs are retained for 365 days.
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to restrict or object to certain processing, and to withdraw consent. We respond to verified requests within 30 days. If you are in the EEA or UK, you may also lodge a complaint with your local supervisory authority. If you are in Canada, you may contact the Office of the Privacy Commissioner of Canada. If you are a California resident, you have the rights described in the CCPA, including the right to know what personal data we collect and the right to delete it; we do not sell or share personal data for cross-context behavioral advertising.
To exercise any of these rights, email [email protected].
If your data reaches us through a customer’s connected platform, please contact that customer; we will support them in responding to your request.
The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect personal data from children.
We will post any changes on this page and update the effective date. For material changes, we will notify account holders by email or in-app notice before the change takes effect.
Sprites AI (Campfire Expeditions Inc.)
350 Bay St., Floor 13, Toronto, ON M5H 2S6, Canada
Privacy and security contact: Siamak Freydoonnejad, Co-founder and CTO
[email protected]