Last updated 27 August 2026. Published by Build Tuit LLC. Questions about anything here go to hello@tuit.dev.
This describes what BitRaster Pixel Studio collects and why. It is written from the software’s actual behaviour rather than from a template.
Browsing this site, downloading the desktop application, opening a drawing somebody has shared with you, watching someone draw through a link, and using the editor itself do not require an account, and we store no personal data about you when you do them. Artwork made in the editor without one stays on your device and is never uploaded. The sections below describe what we hold once you have an account.
The editor keeps a recent copy of your open and recently closed projects in your browser’s storage, or in the desktop application’s, so that a reload does not lose your work. Where a project has been saved to a file, the location of that file may be recorded instead of a copy of its contents. A history of the edits that made each drawing is kept alongside it, so a timelapse can be exported without having pressed Record - in full for a drawing you have saved, and covering the recent past for one you have not. You can turn that off in Settings, which also discards what it has kept. Your theme, font and font size are stored the same way, as is the arrangement of the app’s own panels and which of its built-in tabs you have closed. All of that is deleted when you clear your browser data. The one part of it that does reach us is the edit history of a drawing that lives in your account, which is sent so that it survives the device and is described under “What we store” below; everything else in this paragraph stays here. Saving a drawing to a file also puts that history into the file, and so does copying one out of your account onto your disk - so the file carries the whole history to wherever you send it, and it is worth knowing that includes the layer names you typed and work you later removed. Turning the timelapse off for a drawing, or clearing it, is what leaves it out.
Making a share link stores the link itself - its address, whether sharing is currently on, how much it gives away, the length you chose for a timelapse, and your display name or username, which is shown on the page as the artist. Your email address is never used for this. The name is recorded when the link is made and is not looked up again afterwards, so changing it later does not change what an already-shared page says.
The address itself contains the drawing’s name as it was when the link was made. That is worth knowing before you share something whose title you would rather not circulate: a name in an address travels wherever the link does, into chat previews and browser histories, and is visible to anyone who sees the link without opening it. It is recorded once for the same reason the artist name is, so renaming the drawing afterwards leaves the old name in the address until you generate a new URL. A drawing whose name we cannot write into an address gets one made only of random characters.
What a visitor receives is prepared by us from your drawing rather than served straight from your stored files, and the difference matters: your reference image, the file locations and export folders stored in your project, and the internal identifier of the piece are removed before anything leaves our servers. At the first step of the ladder your layers are flattened into one as well; at the second your layer, tag and palette group names are replaced with placeholders. We keep the prepared copies so the page loads quickly, they are refreshed whenever you change the drawing, and they are deleted when you delete it.
One of those prepared copies is a preview picture - the first frame of the drawing on a plain background - which is what a chat app, a forum or a social network shows when someone pastes the link. It is prepared at every step of the ladder, because it is what the link looks like rather than something the recipient is being given. It carries no name, no account and no other detail, and like the rest it is refreshed when you change the drawing, stops being served when you turn sharing off or replace the link, and is deleted when you delete the piece. Anyone those services pass the link to sees that picture without opening anything, which is worth knowing before sharing a drawing you would rather people came to deliberately.
Opening a shared drawing needs no account, and we do not ask visitors for one, set any identifier for them, or count them. Keeping a copy does need an account, and the copy is made on our servers into your own portfolio - the drawing itself never passes through the browser of the person taking it.
While you are broadcasting, the edits you make are relayed through our servers to whoever has the watch link, along with a copy of the drawing for them to start from. Both are held only for as long as the session needs them and are deleted shortly after it ends. Your reference image is never included, and the file locations and export folders stored in your project are never included either. If you chose to hide layer names, they are replaced before anything leaves your device rather than hidden at the other end.
Watching needs no account, and we do not ask viewers for one. We count how many people are watching so that you can see it, using a temporary identifier created for each viewing tab and discarded afterwards; it is not linked to any account and does not tell us who is watching.
Prompts and any source images you supply are sent to the model provider handling that generation - currently OpenAI and Google - and are subject to their terms and retention practices in addition to ours. Authentication is handled by Clerk. Hosting, the database, and file storage are provided by Vercel and Neon. We do not sell your data, and we do not use advertising or behavioural tracking.
Nothing you make is listed anywhere. There is no public gallery, and what you save to your account is yours alone unless you deliberately share a link to a drawing, start a broadcast, or invite somebody into a document. All three are described in this policy, all three are begun by you, and all three are ended by you. Your prompts are never shown to anyone.
A shared drawing is reachable by its link and by nothing else: the page carries instructions telling search engines not to index it, it appears in no sitemap, and the address cannot be guessed. That makes it unlisted rather than private - anyone the link is passed on to can open it, so treat giving it out as the act of publishing that it is.
We keep your account data while your account exists. You can delete individual pieces, revoke a share link or a watch link at any time, and request deletion of your account and its contents by contacting us at hello@tuit.dev. Depending on where you live you may have rights to access, correct, export, or erase your personal data, and to object to certain processing; contact us to exercise them.
The Service is not directed to children under 13, and we do not knowingly collect their personal data.