sprite.click
Log in

Your information

Privacy policy

This policy describes how sprite.click collects, uses, stores, and shares personal data.

Effective 23 July 2026 · Version 2.0

Data controller and contact

The publisher and data controller responsible for this service is:

  • Controller and publisher: Mathias Larsen
  • Application: sprite.click
  • Developer organization: Tripox Consulting
  • Country: Denmark
  • Data-protection email: privacy@sprite.click

Use that email for privacy questions, access or deletion requests, objections, complaints, and any other data-protection inquiry. The inbox accepts messages from outside the organization and is monitored by the controller. Include “Data protection request” in the subject when the request concerns personal data. No data protection officer has been appointed; Mathias Larsen handles these matters directly.

Data processed

  • Account and sign-in: an internal account ID, username, account timestamps, and the name, email address, profile photo, and provider identifier supplied through Google and Neon Auth. Registration is closed and only existing Google-based sprite.click accounts can sign in.
  • Collection: the Sprite IDs marked collected or mastered and the latest update time. Changes may be made on sprite.click or through a connected ChatGPT account at your request.
  • Sharing choices: whether the profile is public, whether the available account name or Google profile photo is displayed, and whether registered Epic friends may view the detailed collection. All sharing choices are off by default.
  • Epic connection: the Epic account ID, display name, encrypted access and refresh tokens, and token expiry for an Epic account linked by a signed-in sprite.click user.
  • Epic friends: when the Friends page is opened, Epic friend account IDs are temporarily compared with Epic accounts registered on sprite.click. The fetched Epic friends list is not retained.
  • ChatGPT connection: the registered OAuth client, granted scopes, connected resource, account reference, expiry times, and hashed authorization credentials. Collection data is disclosed or updated only when the connected user invokes the relevant tool.
  • Technical requests: Vercel and other infrastructure providers may process IP address, browser or device details, requested URL, timestamps, and related diagnostics to deliver and secure the service.

Purposes and legal bases

  • Performance of the service (GDPR Article 6(1)(b)): authenticate accounts, store collection progress, identify registered Epic friends, and provide user-authorized ChatGPT collection access.
  • Optional sharing (Article 6(1)(a)): publish the collection profile; display the account name or profile photo; or disclose the detailed collection to registered Epic friends. Each choice is separate and can be withdrawn at any time without deleting the private collection. Withdrawal does not affect processing that was lawful before it was withdrawn.
  • Security and reliability (Article 6(1)(f)): prevent authentication abuse, protect credentials, investigate errors, and keep the service reliable. You may object to processing based on legitimate interests where the GDPR gives you that right.

sprite.click does not sell personal data, serve advertising, use analytics, or make solely automated decisions that produce legal or similarly significant effects.

Public profiles

If public sharing is enabled, anyone with the profile URL can see the chosen username, collection totals, and which Sprites are collected, mastered, or missing. Displaying the account name and available profile photo requires separate opt-ins. Email addresses, Epic account IDs, Epic friend information, sign-in details, invitations, timestamps, and connected-app details are not displayed. Turning public sharing off makes the profile unavailable without deleting collection progress.

Epic Games and registered friends

A user must first sign in with an existing Google-based sprite.click account before linking Epic Games from Friends. After linking, that Epic account can authenticate the same existing sprite.click account; Epic cannot create or register a new sprite.click account. Account linking, sign-in, and registered-friend matching use the basic_profile and friends_list permissions.

A registered match may display the Epic display name. The sprite.click username is displayed only when that person has enabled a public profile. sprite.click does not receive Fortnite inventory data, retain the fetched Epic friends list, create separate friendships, or enable collection sharing merely because two accounts are Epic friends.

Detailed collection sharing with registered Epic friends is a separate setting on Profile and is off by default. When enabled, an Epic friend who is also registered on sprite.click can see the Sprites the account holder reported as collected or mastered and use them in a private comparison. Turning the setting off prevents later friend-list requests from returning that collection information. This choice is independent of the public-profile setting.

Recipients and service providers

  • Neon: application database and Neon Auth.
  • Google: identity provider for existing Google accounts and Google Workspace for messages sent to privacy@sprite.click.
  • Epic Games: optional account linking, basic account information, token issuance, and the requested Epic friends list.
  • Vercel: hosting, delivery, scheduled maintenance, and operational request processing.
  • OpenAI / ChatGPT: collection information returned or updated when a user connects sprite.click and invokes its tools. OpenAI handles prompts and ChatGPT account data under its own relationship with the user.

These providers may use subprocessors to provide their services. sprite.click does not disclose the Epic friends response to other registered users.

Locations and international transfers

The production Neon application database and Neon Auth used by sprite.click are configured in AWS eu-central-1 in Frankfurt, Germany.

Epic account linking and friends requests, Vercel delivery and logs, Google sign-in and email, OpenAI / ChatGPT, support access, backups, and provider subprocessors may involve processing outside the EEA, including in the United States. Depending on the recipient and destination, transfer safeguards may include an adequacy decision or the European Commission's Standard Contractual Clauses. Information about safeguards applicable to personal data may be requested at privacy@sprite.click.

Retention and deletion

  • Account, profile, collection, sharing choices, and the Epic connection are kept while the sprite.click account exists, unless they are removed earlier.
  • The encrypted Epic OAuth state cookie used during account linking lasts no more than 10 minutes.
  • ChatGPT authorization codes last five minutes, access tokens one hour, and refresh tokens up to 180 days. Stored credentials are hashes; expired records are cleaned during OAuth maintenance and use.
  • Infrastructure and connected-service providers may keep operational logs or backups according to their own retention schedules.

Deleting a sprite.click account removes its profile and collection, Epic link and encrypted credentials, and ChatGPT authorization records. It does not delete the person's Google, Epic Games, OpenAI, or ChatGPT account, and provider logs or backups may remain for their applicable retention periods.

Your choices and rights

  • Change the username, public-profile choices, Epic-friend collection-sharing choice, displayed name, or email from Profile.
  • Download a JSON copy of account, collection, sharing, Epic connection, and connected-access data. Secret tokens, token hashes, encryption material, and one-time authorization codes are excluded for security.
  • Withdraw public-profile, name, photo, or Epic-friend collection-sharing consent without deleting the private collection.
  • Delete the sprite.click account and account-linked data described above.
  • Request access, correction, erasure, restriction, or portability, and object to legitimate-interest processing where applicable.
  • Lodge a complaint with the relevant supervisory authority. In Denmark, this is Datatilsynet.

Use the controls on Profile or contact privacy@sprite.click to exercise a right. Identity verification may be required before a request is completed.

Cookies and browser storage

sprite.click uses essential Google/Neon authentication cookies. Linking an Epic account uses a short-lived encrypted state cookie to protect the OAuth flow from request forgery. The collection interface may use local browser storage as a cache while signed-in progress synchronizes. No optional advertising or analytics cookies are currently used.

Policy changes

This page will be updated when sprite.click materially changes how it processes personal data. The version and effective date above identify the current notice. Questions and data-protection requests can be sent to Mathias Larsen at privacy@sprite.click.

sprite.click

Keep track of every Fortnite Sprite and the ones you have mastered.

Portions of the materials used are trademarks and/or copyrighted works of Epic Games, Inc. All rights reserved by Epic. This material is not official and is not endorsed by Epic.

Explore

Home

Project

About and publisherDisclosure

Legal

Privacy policyTerms of serviceprivacy@sprite.click
© 2026 sprite.click · Published by Mathias Larsen, Denmark