etrobeads
  • Gallery
  • Prism
  • Tutorials
  • English
  • Svenska

Privacy

Local-first, with clear account boundaries.

Effective date: 2026-08-24

Local browser use stays private by default. Account, Prism cloud, and paid features add server-backed data only when you choose to use them.

In one paragraph

RetroBeads is local-first by default. Images are processed in your browser, and local projects stay on your device unless you explicitly choose a Prism project backup. A backup can include project data and, when available, a normalized working image; the original full-resolution upload stays local. My Beads sync and public pattern publication are separate, explicit account features. When you make an account, we store what that account needs. And so we can tell whether the site and app are working for people, we use a simple visitor counter on both the website and the app. It counts visits — it stores no cookies, and it can't tell who you are. We don't sell your data, we don't run ad trackers, and we don't record your screen.

What stays in your browser

  • Local source images, conversion work, projects, and preferences by default; explicit Prism project backups, My Beads sync, and public pattern publication are separate choices.
  • Local backups, local imports, and client-side PDF exports.
  • Your theme choice on this site, stored in localStorage.

What account and cloud features may store

When you use account or Prism features, they may store:

  • Your account identifier, email address, session data, and provider metadata through Supabase Auth.
  • Privacy, Terms, and account-age acknowledgement versions with acceptance time.
  • Project metadata, derived pattern data, and an optional normalized working image when you explicitly choose Back up project or Update backup in Prism. The original full-resolution upload stays local; My Beads sync and public pattern publication are separate features.
  • Security, rate-limit, and operational logs needed to run the service and reduce abuse.
  • Billing and entitlement records if you buy a paid feature through a Merchant of Record.

What we avoid

  • No sale of personal data.
  • No ad pixels, heatmaps, fingerprinting, or session replay.
  • No server-side conversion of your images in the planned account flow.
  • No retention of original full-resolution uploads as cloud originals.

How we count visits

So we can tell whether the site and app are actually working for people, we use a simple, privacy-friendly visitor counter on both the website and the app.

What it does: counts visits to a couple of pages — the app's front door and the Prism plan page. It stores no cookies and can't link a visit to a person.

What it never sees: This visit counter does not receive your images, patterns, projects, file names, or anything you make. Optional project backups, My Beads sync, and public pattern publication are disclosed separately.

Being straight with you: like every website, the counter works over the internet, so rough things like your country can be estimated from your connection. That's why we call it privacy-friendly, not invisible. We don't try to identify you, and we don't keep a record of who you are.

Providers we use

RetroBeads uses Cloudflare for hosting and private cloud file storage, and Turnstile for bot checks. Account data uses Supabase. Paid features use a Merchant of Record and secure payment provider for checkout, payment, tax, receipts, and cancellation flows.

Your choices and rights

You can use RetroBeads locally without an account. Account controls provide access to a machine-readable export and ordered account deletion. If Prism access ends, existing cloud projects enter a 90-day lockbox where you can read, restore, export, or delete them but cannot add new cloud writes; remaining cloud data is deleted when that window ends. Account deletion removes controlled cloud objects and public output before Auth ownership is erased. Billing records may be pseudonymized and retained only as required for tax, refunds, disputes, accounting, or bounded reconciliation.

Language preference cookie

The rb_www_locale cookie stores your language choice (English or Svenska) for one year. It is set only when you use the language switcher, contains no tracking data, and never leaves this domain. SameSite=Lax and Secure.

Questions

For privacy questions, account-data requests, or deletion help, email inforetrobeads@gmail.com.

etrobeads© 2026 RetroBeads. A small tool for makers.
ChangelogPrismPrivacyTerms