SpriteLight

Privacy

Last updated 26 August 2026

We don't store your sprites, we don't use cookies, and we have no way to identify you. The rest of this page explains exactly what that means.

Your sprites

When you generate a normal map, the image is sent to our service in Norway, held in memory while it is processed, and the result is sent back to your browser. The file is never written to disk. We keep no copy of it.

Your sprites are never stored, never shared, and never used to train our models. We couldn't train on them if we wanted to — nothing is kept. Your art is your art; we compute a normal map from it and forget we ever saw it.

When you drop a sprite on the front page, your browser holds it in session storage so it can be carried over to Studio. That copy never leaves your browser, it is deleted the moment Studio picks it up, and closing the tab clears it either way.

What we count

We want to know how many people use SpriteLight and how much they use it. Each time a normal map is generated, we write one line to our log: which model was used, the image dimensions, how long it took, and a code that stands in for you.

That code is a one-way hash of your network address and a secret only we hold. It cannot be turned back into your address, and it tells us nothing about who you are or where you are. The code is stable over time: if the same network comes back tomorrow, we can see that a returning visitor generated something — but not who, not where, and not anything else about them.

We changed this on 26 August 2026 — the code used to rotate daily. The reason is blunt: without it we cannot tell whether anyone actually comes back, and that is the one number that tells us if this service is worth running. What we gave up is the "two different strangers" property; what we kept is everything else — no cookies, no account, no address in any log, nothing sold or shared.

We have no accounts. We don't know your name, your email, or your country.

Cookies

None. SpriteLight sets no cookies and runs no tracking scripts. That is why you were never asked to accept anything.

Who else is involved

Microsoft Azure
Hosts both the website and the service, in the Norway East region, so your data stays within the EEA. Azure keeps ordinary server logs — times, addresses, status codes — as part of running the infrastructure.

That is the whole list — one company, and it's the one running the servers. There is no analytics provider and no ad network, and the typefaces are served from this site rather than from Google, so nothing about you reaches a third party just because a page loaded.

If you email us

Write to hello@spritelight.com and we keep your message so we can reply to it. It isn't used for anything else, and it doesn't go on any list.

Your rights

Under the GDPR you can ask to see, correct, or delete personal data an organisation holds about you. In our case there is very little to act on: no account, no name, and no email address unless you sent us one.

The visitor code in our logs cannot be traced back to a person from our side. If you want your entries deleted, email us your IP address and we can compute your code and remove them — that is the only way even we can find them.

Questions go to hello@spritelight.com.

Changes

SpriteLight is in free beta and still moving. If we start collecting something new, this page changes first and the date at the top changes with it.