Privacy Policy

Effective date: September 1, 2026 · Last updated: September 29, 2026

Sprites AI is operated by Campfire Expeditions Inc. o/a Sprites AI, 350 Bay St., Floor 13, Toronto, ON M5H 2S6, Canada (“Sprites AI”, “we”, “us”). This policy explains what personal data we collect, how we use it, who we share it with, and the choices you have.

It applies to sprites.ai (including www.sprites.ai) and any related services (the “Service”). It does not apply to third-party platforms you connect to the Service; their own privacy policies govern those platforms.

1. Our role: controller or processor

We act in two different roles depending on the data involved.

As a controller for the personal data of our own users and website visitors: account registration details, login credentials, billing contacts, support communications, and usage of the Service. We decide how this data is used, as described in this policy.

As a processor for personal data that reaches us through the advertising, analytics, CRM, commerce, and content platforms our customers connect to the Service. This includes business contact records read from a customer’s CRM, campaign and audience metadata from advertising platforms, and content the customer creates in their workspace. We process this data only on the customer’s instructions under our Data Processing Addendum. The customer is the controller. If you are a data subject whose data appears in a customer’s connected system, contact that customer to exercise your rights; we will assist them in responding.

2. Data we collect as a controller

Account data. Name, business email address, password (stored hashed), company name, job title if provided, and profile details from Google or GitHub sign-in if you use them.

Billing data. Billing contact name and address, and payment method details handled by our payment processor, Stripe. We do not store full card numbers.

Usage data. Log data (IP address, browser type, device information, pages and features used, timestamps), diagnostic and error data, and interactions with the Service. Application logs are automatically redacted of personal identifiers such as email addresses and credentials before storage.

Communications. Support requests, emails, and messages you send us, including through shared Slack channels.

Website data. Cookies and similar technologies on sprites.ai as described in Section 9.

We do not collect special categories of personal data (health, biometric, political, religious, or similar), and we ask that you do not submit them to the Service.

3. Data we process on behalf of customers

When a customer connects a third-party platform (Google Ads, Meta Ads, LinkedIn Ads, TikTok Ads, Reddit Ads, Shopify, HubSpot, Google Analytics, Google Search Console, Google Business Profile, Google Merchant Center, WordPress, Webflow, Google Drive, OneDrive, and similar), the Service accesses that platform through the platform’s official API using OAuth or an access token authorized by the customer.

What we access: campaign structure, performance metrics, spend, targeting settings, creative assets, and content on the connected platform; business contact records from CRM platforms (read-only); analytics and search performance data; and files the customer explicitly selects from connected storage.

What we do not access or store: customer-match lists, hashed identifiers, or end-consumer personal data. Audience data remains within the advertising platforms.

How we handle it: campaign and platform data is fetched on demand when the customer or their approved automations request it. Working artifacts from these fetches (tool outputs and analysis files) are automatically deleted within 30 days. Data the customer stores in the Service (business profiles, strategy content, generated content, agent action history, and encrypted platform credentials) is retained for the term of the customer’s agreement and deleted within 30 days of termination.

Platform credentials. OAuth tokens and access tokens for connected platforms are encrypted at the application layer with AES-256-GCM before storage. Customers can revoke our access at any time from their own platform account settings, and access ends immediately.

4. Google API Services User Data Policy

Sprites AI’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically: we only use Google user data (from Google Ads, Google Analytics, Google Search Console, Google Merchant Center, Google Business Profile, and Google Drive) to provide and improve user-facing features of the Service that the user has requested. We do not use Google user data to serve advertisements, and we do not sell it. We do not transfer Google user data to third parties except to our subprocessors as necessary to provide the Service, as required by law, or with the user’s explicit consent. We do not allow humans to read Google user data unless the user has given consent, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymized for internal operations.

The same standards apply to data received from Meta, LinkedIn, TikTok, and other connected platforms under their respective platform policies.

5. How we use personal data

As a controller, we use your personal data to:

  • Create and manage your account and workspace
  • Provide, operate, and secure the Service
  • Process payments and manage billing
  • Respond to support requests and communicate about the Service
  • Monitor performance, diagnose issues, and prevent abuse
  • Improve the Service using aggregated and de-identified usage data
  • Comply with legal obligations

Legal bases (GDPR and UK GDPR). Performance of a contract with you (account, billing, service delivery); our legitimate interests in securing and improving the Service, preventing fraud, and communicating with business customers; consent where required, for example for non-essential cookies or marketing emails; and compliance with legal obligations.

For data we process as a processor, the customer as controller is responsible for establishing the legal basis.

6. Artificial intelligence and your data

The Service uses third-party AI models to analyze data and generate recommendations and content.

  • We do not use customer data to train or fine-tune AI models. This includes campaign data, connected platform data, creative assets, prompts, and content created in the Service.
  • Our AI providers process data under API terms that do not permit training on customer inputs or outputs.
  • AI-generated output can be inaccurate. State-changing actions proposed by the Service (campaign changes, budget changes, publishing) pass through a server-enforced approval step before they are applied to a connected platform, and unattended automations can only perform change types the customer has pre-authorized.
  • We may use aggregated, de-identified usage data (such as feature adoption or error rates) to improve the Service. This data cannot be used to identify any customer or individual.

AI assistant connectors. You can connect Sprites to an AI assistant such as Claude or ChatGPT through our MCP connector (mcp.sprites.ai). You sign in with your Sprites account and choose the business the assistant may work on; the assistant then holds an access token for that account. Disconnecting Sprites in the assistant ends that access, and you can also ask us to revoke it at the address in section 12. When the assistant calls a Sprites tool we receive what it sends: the request written from your conversation (for example “audit my Google Ads account”), the channel, and your local date. We do not receive the rest of the conversation. We process the request like one made in the Sprites app, under the terms above, and return the result to the assistant, where it becomes part of your conversation under that assistant provider’s own privacy terms. The connector also records which tools were called and when, and card rendering errors, to operate and secure the connector; these records follow the application log retention in section 11.

7. Who we share data with

We do not sell personal data. We share it only with:

Subprocessors that help us operate the Service, each bound by written terms at least as protective as our commitments to customers:

ProviderLocationPurpose
Google CloudUnited StatesApplication hosting, compute, storage
VercelUnited StatesWeb application hosting
NeonUnited StatesDatabase hosting
CloudflareUnited StatesEdge network, DNS, security
Redis Cloud (Redis Ltd.)United StatesQueueing and ephemeral cache
SuperTokensUnited StatesAuthentication service
StripeUnited StatesPayment processing
LoopsUnited StatesTransactional email
AnthropicUnited StatesAI language models
OpenAIUnited StatesAI models (text and image generation)
Google (Gemini API)United StatesAI models (image generation)
Fireworks AIUnited StatesAI model inference
SentryUnited StatesError monitoring
PostHogUnited StatesProduct analytics for our own users
PipedreamUnited StatesIntegration connectivity (Google Drive, OneDrive, Google Business Profile)
Bunny.netSloveniaContent delivery and file storage

Customers receive at least 30 days’ advance notice before we add or replace a subprocessor and may object.

Connected platforms you choose to link, which receive data as necessary to perform the actions you or your workspace users approve.

Professional advisers, and authorities where required by law, to protect our rights, or in connection with a merger, acquisition, or sale of assets, in which case this policy will continue to apply.

8. International transfers

We are a Canadian company and our production infrastructure is in the United States. If you are in the European Economic Area, the United Kingdom, or Switzerland, your personal data is transferred to the United States. For customer data we process under a Data Processing Addendum, transfers are covered by the EU Standard Contractual Clauses (Module Two) and the UK International Data Transfer Addendum, supported by the security measures described in Section 10. For our own users’ account data, we rely on the same Standard Contractual Clauses with our subprocessors and on the safeguards described in this policy.

9. Cookies

sprites.ai uses essential cookies required for the site and app to function (authentication, session, security) and analytics cookies to understand how the site is used. Analytics cookies are set only with your consent where required by law. You can manage cookies through your browser settings; disabling essential cookies will prevent the app from working.

10. Security

Our security measures include encryption in transit (TLS 1.2 or higher) and at rest (AES-256), application-layer AES-256-GCM encryption of connected-platform credentials, secrets held in a dedicated secrets manager and never in code, centralized PII-redacted logging retained for 365 days, continuous dependency vulnerability scanning with automated security updates, container image scanning in the deployment pipeline, server-enforced human approval of state-changing agent actions, and point-in-time recovery of the production database. No system is perfectly secure; if you believe your account has been compromised, contact us immediately. If we confirm a breach affecting your personal data, we will notify affected customers without undue delay and within 72 hours of confirmation.

11. Retention

Account data is retained for as long as your account is active and deleted within 30 days of account closure, except where we must retain it for legal, billing, or dispute-resolution purposes. Customer workspace data is retained for the term of the customer’s agreement and deleted within 30 days of termination, with written confirmation on request. Working artifacts from connected-platform fetches are automatically deleted within 30 days. Application logs are retained for 365 days.

12. Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to restrict or object to certain processing, and to withdraw consent. We respond to verified requests within 30 days. If you are in the EEA or UK, you may also lodge a complaint with your local supervisory authority. If you are in Canada, you may contact the Office of the Privacy Commissioner of Canada. If you are a California resident, you have the rights described in the CCPA, including the right to know what personal data we collect and the right to delete it; we do not sell or share personal data for cross-context behavioral advertising.

To exercise any of these rights, email [email protected].

If your data reaches us through a customer’s connected platform, please contact that customer; we will support them in responding to your request.

13. Children

The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect personal data from children.

14. Changes to this policy

We will post any changes on this page and update the effective date. For material changes, we will notify account holders by email or in-app notice before the change takes effect.

15. Contact

Sprites AI (Campfire Expeditions Inc.)
350 Bay St., Floor 13, Toronto, ON M5H 2S6, Canada
Privacy and security contact: Siamak Freydoonnejad, Co-founder and CTO
[email protected]