Privacy
Local-first, with clear account boundaries.
Effective date: 2026-05-20
Local browser use stays private by default. Account, Prism cloud, and paid features add server-backed data only when you choose to use them.
In one paragraph
RetroBeads is local-first. Your images, your patterns, your projects — they're made right here in your browser. They don't get uploaded, and we never see them. When you make an account, we store just what that account needs. And so we can tell whether the site and app are working for people, we use a simple visitor counter on both the website and the app. It counts visits — it stores no cookies, and it can't tell who you are. We don't sell your data, we don't run ad trackers, and we don't record your screen.
What stays in your browser
- Local-only source images, conversion work, projects, and preferences.
- Local backups, local imports, and client-side PDF exports.
- Your theme choice on this site, stored in localStorage.
What account and cloud features may store
When you use account or Prism features, they may store:
- Your account identifier, email address, session data, and provider metadata through Supabase Auth.
- Privacy, Terms, and account-age acknowledgement versions with acceptance time.
- Cloud project metadata, derived pattern data, and a capped normalized working source asset when you choose cloud sync.
- Security, rate-limit, and operational logs needed to run the service and reduce abuse.
- Billing and entitlement records if you buy a paid feature through a Merchant of Record.
What we avoid
- No sale of personal data.
- No ad pixels, heatmaps, fingerprinting, or session replay.
- No server-side conversion of your images in the planned account flow.
- No retention of original full-resolution uploads as cloud originals.
How we count visits
So we can tell whether the site and app are actually working for people, we use a simple, privacy-friendly visitor counter on both the website and the app.
What it does: counts visits to a couple of pages — the app's front door and the Prism plan page. It stores no cookies and can't link a visit to a person.
What it never sees: your images, your patterns, your projects, your file names, or anything you make. Those never leave your browser.
Being straight with you: like every website, the counter works over the internet, so rough things like your country can be estimated from your connection. That's why we call it privacy-friendly, not invisible. We don't try to identify you, and we don't keep a record of who you are.
Providers we use
RetroBeads uses Cloudflare for hosting and private cloud file storage, and Turnstile for bot checks. Account data uses Supabase. Paid features use a Merchant of Record and secure payment provider for checkout, payment, tax, receipts, and cancellation flows.
Your choices and rights
You can use RetroBeads locally without an account. With an account, you may request access, export, correction, or deletion of account-backed data. Cloud projects and normalized source assets are deleted with the project or account unless a legal retention rule applies. Billing records may need limited retention for tax, refund, dispute, and accounting reasons.
Language preference cookie
The rb_www_locale cookie stores your language choice (English or Svenska) for one year. It is set only when you use the language switcher, contains no tracking data, and never leaves this domain. SameSite=Lax and Secure.
Questions
Reach the maintainers through the project channel that brought you to RetroBeads. A dedicated support and data-request contact will be published before public account collection opens broadly.