BITRASTERPIXEL STUDIO
Open BitRaster
>>Legal

Privacy Policy

Last updated 27 August 2026. Published by Build Tuit LLC. Questions about anything here go to hello@tuit.dev.

This describes what BitRaster Pixel Studio collects and why. It is written from the software’s actual behaviour rather than from a template.

Using the Service without an account

Browsing this site, downloading the desktop application, opening a drawing somebody has shared with you, watching someone draw through a link, and using the editor itself do not require an account, and we store no personal data about you when you do them. Artwork made in the editor without one stays on your device and is never uploaded. The sections below describe what we hold once you have an account.

What stays on your device

The editor keeps a recent copy of your open and recently closed projects in your browser’s storage, or in the desktop application’s, so that a reload does not lose your work. Where a project has been saved to a file, the location of that file may be recorded instead of a copy of its contents. A history of the edits that made each drawing is kept alongside it, so a timelapse can be exported without having pressed Record - in full for a drawing you have saved, and covering the recent past for one you have not. You can turn that off in Settings, which also discards what it has kept. Your theme, font and font size are stored the same way, as is the arrangement of the app’s own panels and which of its built-in tabs you have closed. All of that is deleted when you clear your browser data. The one part of it that does reach us is the edit history of a drawing that lives in your account, which is sent so that it survives the device and is described under “What we store” below; everything else in this paragraph stays here. Saving a drawing to a file also puts that history into the file, and so does copying one out of your account onto your disk - so the file carries the whole history to wherever you send it, and it is worth knowing that includes the layer names you typed and work you later removed. Turning the timelapse off for a drawing, or clearing it, is what leaves it out.

When you share a drawing by link

Making a share link stores the link itself - its address, whether sharing is currently on, how much it gives away, the length you chose for a timelapse, and your display name or username, which is shown on the page as the artist. Your email address is never used for this. The name is recorded when the link is made and is not looked up again afterwards, so changing it later does not change what an already-shared page says.

The address itself contains the drawing’s name as it was when the link was made. That is worth knowing before you share something whose title you would rather not circulate: a name in an address travels wherever the link does, into chat previews and browser histories, and is visible to anyone who sees the link without opening it. It is recorded once for the same reason the artist name is, so renaming the drawing afterwards leaves the old name in the address until you generate a new URL. A drawing whose name we cannot write into an address gets one made only of random characters.

What a visitor receives is prepared by us from your drawing rather than served straight from your stored files, and the difference matters: your reference image, the file locations and export folders stored in your project, and the internal identifier of the piece are removed before anything leaves our servers. At the first step of the ladder your layers are flattened into one as well; at the second your layer, tag and palette group names are replaced with placeholders. We keep the prepared copies so the page loads quickly, they are refreshed whenever you change the drawing, and they are deleted when you delete it.

One of those prepared copies is a preview picture - the first frame of the drawing on a plain background - which is what a chat app, a forum or a social network shows when someone pastes the link. It is prepared at every step of the ladder, because it is what the link looks like rather than something the recipient is being given. It carries no name, no account and no other detail, and like the rest it is refreshed when you change the drawing, stops being served when you turn sharing off or replace the link, and is deleted when you delete the piece. Anyone those services pass the link to sees that picture without opening anything, which is worth knowing before sharing a drawing you would rather people came to deliberately.

Opening a shared drawing needs no account, and we do not ask visitors for one, set any identifier for them, or count them. Keeping a copy does need an account, and the copy is made on our servers into your own portfolio - the drawing itself never passes through the browser of the person taking it.

When you broadcast

While you are broadcasting, the edits you make are relayed through our servers to whoever has the watch link, along with a copy of the drawing for them to start from. Both are held only for as long as the session needs them and are deleted shortly after it ends. Your reference image is never included, and the file locations and export folders stored in your project are never included either. If you chose to hide layer names, they are replaced before anything leaves your device rather than hidden at the other end.

Watching needs no account, and we do not ask viewers for one. We count how many people are watching so that you can see it, using a temporary identifier created for each viewing tab and discarded afterwards; it is not linked to any account and does not tell us who is watching.

What we store

  • Account. Sign-in is handled by our authentication provider, which holds your email address and any profile details from the sign-in method you chose. We store the account identifier it gives us - not your password, which we never see.
  • Usage and credits. Your credit balance and rolling spend, so generation costs can be governed.
  • Preferences. Your theme, font and font size, so the web and desktop apps agree. Nothing else from the editor is synced.
  • Your pieces. For each generated sprite: the prompt, the mode, tier and model provider used, the pipeline settings and version, the dimensions, and references to the stored images.
  • Share links. For a drawing you have shared: the link’s address, whether sharing is currently on, how much it gives away, the timelapse length you chose, and the artist name and the drawing’s name shown on the page, both recorded when the link was made. Alongside it we keep the prepared copies a visitor is served, described under “When you share a drawing by link”. Nothing here exists until you make a link; turning sharing off stops it working immediately and keeps the address, and generating a new URL keeps a record of the old address so it can never be handed out again.
  • Images. Both the raw model output and the processed sprite, held in private storage and served to you through short-lived links.
  • Edit history of pieces in your portfolio. For a drawing that lives in your account, we store the sequence of edits that made it, in pieces, so that its history survives the device it was drawn on and can be played back or exported as a timelapse. It is held in the same private storage as your images and is deleted when you delete the drawing. This applies only to drawings in your portfolio - one that lives only on your device stays there.
  • Waitlist. If you submit your email address to the waitlist, we store that address and the date. It is not linked to an account.
  • Feedback you send us. If you use Help ▸ Feedback to report a bug or make a suggestion, we store what you wrote and the date. If you are signed in, your account is recorded with it so we can follow up and thank you - unless you tick Send this anonymously, in which case it is not, and we have no way to work out afterwards who sent it. If you are signed out, nothing identifies you unless you choose to type a name or address in the optional field. We use it to fix and improve BitRaster, and nothing else.

Third parties

Prompts and any source images you supply are sent to the model provider handling that generation - currently OpenAI and Google - and are subject to their terms and retention practices in addition to ours. Authentication is handled by Clerk. Hosting, the database, and file storage are provided by Vercel and Neon. We do not sell your data, and we do not use advertising or behavioural tracking.

What is public

Nothing you make is listed anywhere. There is no public gallery, and what you save to your account is yours alone unless you deliberately share a link to a drawing, start a broadcast, or invite somebody into a document. All three are described in this policy, all three are begun by you, and all three are ended by you. Your prompts are never shown to anyone.

A shared drawing is reachable by its link and by nothing else: the page carries instructions telling search engines not to index it, it appears in no sitemap, and the address cannot be guessed. That makes it unlisted rather than private - anyone the link is passed on to can open it, so treat giving it out as the act of publishing that it is.

Retention and your choices

We keep your account data while your account exists. You can delete individual pieces, revoke a share link or a watch link at any time, and request deletion of your account and its contents by contacting us at hello@tuit.dev. Depending on where you live you may have rights to access, correct, export, or erase your personal data, and to object to certain processing; contact us to exercise them.

Children

The Service is not directed to children under 13, and we do not knowingly collect their personal data.

Read the Terms of Service

BitRaster Pixel Studio
ReferenceConvertTermsPrivacy