Sprite Catch

Privacy Policy

Last updated: 9 September 2026 · Effective: 9 September 2026

Sprite Catch is a free app made by one person. It has no ads, and everything the app does is free to use. There is nothing in it to buy — no decoration, no feature and no subscription — and nothing ever has been bought from it. The app does have a currency, called Gems, and it is earned by using the app and cannot be bought with money: there is no way to top it up, no pack to buy, and nothing anywhere that turns money into Gems. It does collect a limited amount of information about how the app is used, so that it can be made better — you can turn that off. It can also ask you to answer a questionnaire about the games you play. Those answers are read by me and go nowhere else — nothing about you is sold to anybody, and nothing ever has been. This page explains what is collected, why, and what you can do about it. It covers the iPhone app, the Android app and the web version at spritecatch.com.

The short version. The collection tracker works without an account. Used anonymously, what is stored is a random identifier created on your device plus the sprites you have ticked off. The community side is different: posting, replying, reacting, following, messaging and trading require an account — signing in with Apple, signing in with Google, or using an email address and a password — so if you never sign in, none of it is available and none of it is collected. Reading the feed and looking at a public profile do not need an account, so anything you post is readable by someone who never signed in. If you sign in, add a display name or Fortnite tag, post a trade, write in the community feed, or message another collector, that is stored too — and because profiles are public by default, other collectors can see the public parts, and your profile has a web address anyone with the link can open. Making your profile private in Settings takes that back. Direct messages are private from other users, but not from me: I run the server. You can delete everything from inside the app, from the web version's own settings, from spritecatch.com/delete-account, or by emailing me.

Nothing about you is sold, and nothing ever has been. The app can offer you a questionnaire about the games you play in exchange for a decoration. Those answers are read by me, to work out what to build next, and they go nowhere else — not to game companies, not to studios, not to anybody outside the service. Earlier versions of this page described an ability to run a questionnaire whose answers were sold as market research: it was never used, and it has been taken out of the app. Section 2 has the detail.

Nothing in the app can be bought with money, and nothing ever has been. There is no shop open for money, nothing is for sale, and no payment information has ever reached me — not a card, not a billing address, not a name. The app was built able to sell profile decorations through the App Store; that was switched off before it ever opened, no decoration was ever put on sale and no purchase was ever made by anybody. On 1 September 2026 the ability was taken out of the app and off the server altogether — not switched off, removed: there is no longer any code in Sprite Catch that can charge you, ask the App Store for a price, or receive a payment. Putting it back would be a new version of the app and a change to this page first.

There is a currency, and it is earned rather than bought. Gems are given for using the app — trading with people, posting, keeping a daily streak, filling in your collection, being around a while — and they buy profile decorations from a small shop. No amount of money will ever produce a single Gem. There is nothing to top up, no pack, no bundle and no subscription, the App Store sells nothing for this app, and the number of Gems you have is worked out from what you have done rather than from anything you paid. Nothing that the app gives away at random — a reward box, the seventh day of a streak — can ever be bought with them either. What is kept about it is described in section 2: what you have spent them on, and when.

The web version is now a full version of Sprite Catch, and it has moved. It is at spritecatch.com; app.spritecatch.com is now only the page that tells people about the app. You can sign in there with the same account as the phone — with Apple, with Google, or with an email address and a password — and once you do, the web version does what the app does: your collection syncs to your account, and you can post, reply, react, trade, message other collectors, follow, block and report. Until you sign in, the sprites you tick off there are still saved in your own browser and never sent to me, and clearing your browser data deletes them with no copy anywhere for me to restore. Nothing here sets a cookie — not the web version, not any page of the website, with one exception named on the Cookies page: the Discord linking page, which runs Apple's and Google's own sign-in code so you can prove who you are, and their code is theirs. No advertising and no third-party analytics runs on any of it. What your browser does keep once you sign in — the token that keeps you signed in, your own profile, your own collection and a few display preferences — is listed in section 3, along with how to clear it. The Cookies page says the same thing on one screen, and is why there is no cookie banner. Visits are still counted so I can tell whether the site is being used, with no cookie and nothing stored in your browser for it; section 2 explains exactly how.

1. What this policy covers

Sprite Catch is made and operated by Mateo Duran, an individual developer based in Uruguay. For the purposes of the GDPR, I am the data controller. This policy applies to the Sprite Catch iPhone app, the Android app, the web version at spritecatch.com, and the public pages on spritecatch.com and app.spritecatch.com.

Privacy questions, access requests and deletion requests: privacy@spritecatch.com

2. What information we collect

The categories below describe what the service collects. Most of it is optional, and how much exists depends entirely on how you use the app: an anonymous collection tracker generates almost none of it.

Account information

Identifiers that let the service recognise you and restore your collection: a random device identifier the app generates for itself, a randomly generated account ID, and — if you choose to sign in — the identifier your sign-in provider returns, from Sign in with Apple or from Google. That identifier is meaningless outside the service: it identifies you to this app and to nothing else, and it is what lets you sign back in on a new phone and find your collection waiting.

Your username is different from all of those, because you choose it. It is the short handle other collectors type to find you — shown on your profile, used by search, and part of your profile's web address. Two things follow from your having picked it rather than the service: it can be recognisable, and if you reuse a handle you use elsewhere, somebody may connect the two. Pick one you are comfortable being public, and change it in Settings if you would rather not be findable under it. It can be changed once every fourteen days, and the service records when you last changed it so it can tell you when you may again.

The account ID is the random code that used to do that job. It still identifies your account to the service, and it is still what a support conversation quotes — but it is now shown only to you, in Settings, rather than on your profile. Older links and older versions of the app still work with it.

Signing in is optional for the collection tracker and required for the community features. Tracking your collection, scanning, exporting and keeping it in sync all work on the device identifier alone; posting, replying, reacting, following, messaging and trading do not, because that content belongs to a collector other people can find, and a device identifier cannot follow you to a new phone.

The device identifier is created by the app. It is not an advertising identifier, not Apple's or Google's, and it is not connected to your Apple ID or your Google account unless you sign in. On iPhone it lives in the Keychain, so it survives deleting the app; on Android it lives in the app's private storage, which the system erases on uninstall.

Signing in from a browser creates no device identifier at all. The one described above belongs to the two apps. The web version has never had one, cannot make one, and the server refuses to give it one — which is also why there is no such thing as a guest account on the web: you either sign in there or you are nobody, tracking a collection that stays in your own browser. What being signed in is, in a browser, is a token your browser holds; section 3 says what it looks like and signing out throws it away.

Turning notifications on creates a second identifier, and it is not mine. To deliver a notification at all, a phone has to be registered with the notification service its platform provides — Apple's on iPhone, Google's on Android — and that service issues a token for your device which the app stores so it knows where to send. On Android, from a future release, this also means Google's messaging service creates an identifier for that installation of the app. Both exist only while notifications are on, both go away when you turn them off or uninstall, and neither is an advertising identifier or can follow you into another company's app. Section 6 says exactly what each service receives.

The account also records the country your requests come from, so that I can see which countries the app is used in and decide which languages to translate it into. Four things about it are worth stating plainly, because they are what keep it as small as it is:

The account also records which version of Sprite Catch you use — the iPhone app, the Android app or the web version — so that I can tell whether a launch on a new platform is reaching anybody, and how many of the people already here are on each one. There are two of these and they answer different questions: the version you signed up in, and the version you last opened. It is the same shape of thing as the country above, and the same four things are what keep it small:

Contact information

There are three ways the app can end up with your email address, and all three are your choice.

If you sign in with Apple, Apple offers to share your address with the app, and the app asks for it. Apple's sign-in sheet lets you share your real address or hide it behind a private relay address that forwards to you; either way the choice is yours, made in Apple's screen rather than in mine, and Apple only offers it the first time you authorise the app.

If you sign in with Google, Google shows you which address it is about to share before you agree, and the app asks for that address and nothing else — not your name, not your profile picture, not your contacts, and nothing about your other Google activity. The app keeps the address only if Google confirms it belongs to you; an address Google has not confirmed is discarded on arrival. Unlike Apple's, Google's sign-in offers no way to hide the address behind a relay, so the address the app receives is the real one. Where you pick the account differs by phone — on iPhone it happens in your browser, and on Android, from a future release, in a chooser Google's own software draws inside the app — but either way it is Google asking, not me, which means Google learns that you signed in to Sprite Catch and handles that under its own privacy policy — see section 6.

If you choose instead to sign in with an email address and a password, you type the address yourself. The app then emails you a short code to confirm you can read that mailbox, and you pick a password. The code is good for a few minutes and is stored scrambled, so it cannot be read back out. Your password is never stored as you typed it: what is kept is a one-way scrambled version that can be checked against a later sign-in but cannot be turned back into your password — not by me, and not by anyone who ever ended up with a copy of the database. Nobody at Sprite Catch can see it, and I will never ask you for it.

An address is used for account and service purposes — sending you a sign-in code, reaching you about something important to your account, security, or a support conversation. It is not used to send you news or promotional email unless you separately turn that on in Settings → Privacy & Safety, and you can turn it back off at any time. Having your address and having permission to market to you are two different things, and the app treats them that way.

So that nobody can use the code screen to flood a stranger's inbox, or to guess their way into an account, the service keeps a short-lived count of recent attempts. That record holds a scrambled, shortened form of the network address the request came from — never the address itself — and it is erased within a couple of days.

Before a code is sent, the address is checked for whether mail can reach it at all. The service looks at the part of your address after the @ and asks the public internet directory whether that domain exists and is set up to receive email, and it recognises a handful of well-known misspellings of the big providers. Only the domain is looked up — the part of your address before the @ is not sent anywhere for this, and the directory it asks is Cloudflare's, which already runs everything else described in section 6. If mail could not possibly arrive, you are told so on the spot, with a suggestion where there is an obvious one, instead of waiting for a code that was never coming.

If a message that is sent comes back rejected — most often because the mailbox does not exist — the service records that the address bounced, with the reason and the date, and stops sending to it. It is worth saying plainly why that record exists, because it is the one thing on this page kept for the service's benefit rather than yours: email providers cut off a sender whose messages keep bouncing, and a sender who has been cut off cannot deliver anybody's sign-in code. The record holds the address, the reason and the dates and nothing else — no name, no account, no network address, and nothing about anything else in this policy. A temporary failure is forgotten within a day. A permanent one is kept for as long as it stays true, which for a mailbox that does not exist has no natural end; if an address of yours is being refused and you have fixed the cause, write to privacy@spritecatch.com and I will clear it.

The app asks for no other contact details: no real name, no phone number, no postal address. If you use the app without signing in, it holds no address for you at all.

Telling you when Android is ready

The website has a box you can type your email address into so that you hear when the Android app is released. It sits in the footer of the web version at spritecatch.com, and it is the one thing anywhere on the website that asks you for something with no account behind it. It works differently from everything else on this page, so it is worth being exact about.

What is stored is your email address, where on the site you typed it, and the language the page was in, along with the date. There is no account attached to it, because you do not need one — nothing links the address to a collection, to a profile, or to anything else this policy describes. Your network address is not stored: the count that stops one computer signing up thousands of addresses is worked out at the moment you press the button and is never written down beside your address.

It is used for exactly one email, on the day the Android app comes out. Your address is deleted as that email is sent, and the email itself says so. There is no second message, no newsletter, and nothing to unsubscribe from afterwards, because by then nothing of yours is left. If the release slips, or if the email is never sent at all, the whole list is erased automatically 30 days after the announced date — so this ends with an empty list either way, without depending on me remembering.

You can change your mind before then and I will take the address off the list — email privacy@spritecatch.com, or use the same box on the website, which offers to remove an address as well as add one. It is not shared with anyone: the only company that ever sees it is Cloudflare, which sends the email, and which is already described in section 6.

You should be 13 or older to use this box, and the page says so beside it. It is also the one thing here that is asked for outside the app, so the app's age question — described below — has no answer for it.

Signing in with Epic

You can sign in with your Epic Games account to have your Fortnite name confirmed. It is optional, it is not a way to sign in to Sprite Catch, and it does nothing on its own except put a verified name on your profile — which exists because this is a trading app, and “is this really the person they say they are” is currently answered by a name anybody can type.

It cannot see what you own in Fortnite, and neither can we. The only thing Epic offers an app like this one is your basic profile — who you are. There is no way for any app, at any level of access, to read your locker, your V-Bucks, your stats or your purchases, and Sprite Catch asks for none of those because none of them exist to ask for. Nothing this app does can grant, change or take anything in the game.

What is stored is the identifier Epic uses for your account, the display name it had when you linked it, and when you linked it. That name replaces the Fortnite name on your profile and becomes what other collectors see and search for, which is the point of it. Nothing else arrives: no email address, no friends list, no password. Sprite Catch never sees your Epic password — you type it on Epic's own website, in a window this app cannot read — and it never asks for one anywhere else. Anybody who does ask you for your Epic login is not us.

Epic is told you signed in. That is unavoidable and is what signing in means: to confirm who you are, Epic has to be asked, so Epic learns that an account of theirs was used to sign in to this app. The permission you are shown before it happens says what is being shared. Nothing about your collection, your locker, your messages or anything else in Sprite Catch is sent to Epic, then or ever.

This only happens because you asked for it, and you can undo it. Nothing about an Epic account is recorded before you finish signing in, and unlinking removes the record. The verified name stays on your profile after you unlink — it was your name, and removing a link is not a statement that it was wrong — and you can change it once the link is gone.

Linking your Discord account

Sprite Catch has a bot on Discord, and any server can add it. If you type /link or /login — in a server the bot is in, or in a direct message with the bot itself — you are offered a private link that connects that Discord account to your Sprite Catch account, and taking it stores the identifier Discord uses for your account, the username it had at the time, and when the link was made. One other thing reaches this app, and only from the Sprite Catch community server: whether you are one of the people helping run it, described further down. Nothing else does — not your messages there, not who else is in your servers, not your friends.

The roles below happen in the Sprite Catch community server and nowhere else. The bot is a guest in every other server: it asks for no permission to hand out roles there, and so it cannot, whatever happens to your standing.

This only happens because you asked for it. Being in the server does not link anything; clicking a link to the server does not either. The command has to be typed, and the page or screen it opens has to be finished. Nothing about your Discord account is recorded before that.

Finishing a link does five things on Discord's side, and four of them only in the community server. The app sends you a direct message from its bot confirming the link, which repeats your display name and account ID so you can see which collection it landed on, and says how many Sprites you had already marked with the bot; it gives your Discord account a Verified Collector role in the community server; it gives you the trader role matching your trading standing in the app — Bronze, Silver, Gold or Diamond — if you have earned one; it gives you a season role for any past season whose Sprites you have all mastered; and it gives your Sprite Catch account a profile decoration, which is a reward rather than anything stored about you. Disconnecting takes every one of those roles away again. The decoration is yours to keep.

None of that happens at all if your profile is private. A private profile keeps your collection and your trading record to yourself — that is what section 4 promises and what the app does when another collector tries to look you up — and a Discord role is that same information, shown to everyone in the server. So a private profile is given no trader role and no season role, and if you make your profile private after being given one, it is taken away the next day. Verified Collector, which says nothing about you except that you linked, is the only one that stays.

The trader role follows your trading standing, and it is checked once a day. That standing is worked out from the same trades, ratings and reports the app already shows on your public profile — it is the badge under your name, put on Discord — so a role you hold can go up, go down, or come off entirely as your record changes. Collectors with no trades yet get no role, and neither does anyone whose record carries a warning: a warning is never published to Discord.

The season roles work the other way round: they are earned once and kept. A season role says you have mastered every Sprite of a past season — the same achievement the app shows you — and because it is a record of something you did, it is not taken away if your collection changes afterwards. Going private does take it away, because that is a different question from whether you earned it.

Alongside both, the only thing stored on this side is which roles the server was last told to give you, so that a role which has not changed does not have to be set again. It is worked out from the collection and the trading record already described above; nothing extra is collected for either.

If you help run the community server, that is written down here, and it changes three things about your Sprite Catch account. The people who moderate and answer questions in the server wear a role saying so, and once a day the app looks at who is wearing one and records the name of it against the linked account — nothing else about the server, and nothing about anybody who is not wearing one. It exists because that job is telling people no, and the app hands the person being told no a one-tap public accusation with nothing behind it. So while you hold one of those roles: another collector cannot put a public scam warning on your profile; the automatic safety checks in section 4 will not act on you on their own, and a person has to look instead; and if your profile carries no mark of its own you are given the verified badge, which says the team vouches for you. Reporting you still works exactly as it does for anybody else — a report reaches me, it is read, and nothing about these roles stops it or counts against the person who filed it. That is deliberate: the point of the roles is that people trust the person wearing one, so being able to tell me when one of them is in the wrong matters more here than anywhere else. Losing the role in Discord takes all three back within a day, and so does disconnecting your account or deleting it.

Six things about the link are worth stating plainly:

Proving the account is yours works exactly the way signing in already does: in the app there is nothing to do, because you are already signed in; in a browser you sign in with Apple, with Google, or with a code emailed to you — described in the two sections above, and adding nothing to what they say. Signing in on that page does not leave you signed in. It makes the link and nothing else, and the browser is left holding no way into your account. And it never creates an account: an address with no Sprite Catch account behind it links nothing rather than quietly starting a new one.

Tracking your collection with the Discord bot

You do not need a Sprite Catch account to use the bot, and using it does not make you one. Typing /sprites in a server the bot is in, or in a direct message with it, opens a panel only you can see where you tick off the Sprites you have caught. Those ticks are saved against the identifier Discord uses for your account — that and nothing else. No Sprite Catch account is created, you get no profile, no Account ID and no place in the app's search, and nothing you do here appears anywhere in the app.

Three things are stored, and this is all of them: which Sprites you have marked caught or mastered; which servers you have used the bot in and roughly when you last did; and, if you open a trade room, the fact that a room exists between you and one other person and whether each of you has marked the trade finished. Nothing else about Discord is read or kept — not your messages, not who else is in those servers, not your other activity there, not anything the bot was not directly asked to do.

Other members of a server you have used the bot in can find you, and that is the point of it. Typing /whohas there lists the people who have marked the Sprite being looked for — by their Discord name, with what they have and what they are missing — so that two collectors who can help each other can find each other. It only ever looks at the server the command was typed in, it only lists people who have used the bot there, and your marks are never shown to a server you have not used the bot in. There is no search across servers and no way for a stranger to look you up from outside one. And if you have linked a Sprite Catch account and made your profile private, you are not listed at all — the same rule that keeps a private profile out of search, Discover and the "who has this" lists in the app, and off Discord's roles, applies here too.

If you have linked a Sprite Catch account, you can also be listed in a server you are simply a member of, without having typed anything there. This is new, and it is the one part of the bot that reaches you rather than waiting for you. The bot reads the member list of a server it has been added to, matches it against the Discord accounts that have linked, and adds those collectors to that server's list. It does this at most once an hour per server, it stores only that you are a member of that server and roughly when it noticed — not the rest of the member list, not who else is there, not anything about people who have not linked. Three things limit it, and they matter more than the mechanism: a private Sprite Catch profile is still never listed, so this cannot show a collection you have kept to yourself; it only ever affects servers the bot has been added to and you are in; and /spritecatch privacy hides you from any server's list, or deletes everything the bot holds, from inside Discord and without asking me. If you have never linked an account, nothing here applies to you at all — the bot only knows you if you have used it.

A server can also give you one role for finishing a season. If that server's admins have chosen a role for it, completing the current season's Sprites gives you that role there, and no longer having them takes it back. It is one role, chosen by that server's own admins, and the bot cannot touch any other — it does not create, delete or reorder roles, and it can never give itself or anybody else a permission. Like every other role in section 3, a role is visible to everyone in the server, which is what a role is: it says you finished a season, and nothing else about you.

Two smaller things about that list. It marks which of the people on it have linked a Sprite Catch account, because that is what decides whether the two of you can finish the trade in the app and rate each other; it is the same single fact the Verified Collector role publishes in section 3, and it says nothing about which account, your name, your ID or your record. And it is drawn from the people who are in that server now — if you leave, you stop being listed there, and what the bot remembered about your being a member of it is deleted the next time somebody looks.

You can switch that off, and you can delete all of it, from inside Discord. Typing /spritecatch privacy shows what is stored, offers to hide you from that server's search while keeping your marks, and offers to delete everything the bot holds about you — the marks and every record of which servers you used it in — which takes effect immediately and cannot be undone. Deleting your Sprite Catch account deletes it too. It does not work the other way round: telling the bot to forget you leaves the collection in your app alone, because that is yours.

A trade room is a private conversation on Discord, not in this app. When two people agree to trade, the bot opens a private thread in a channel that server's administrators chose and adds the two of them to it. Everything said in there is on Discord, under Discord's rules and that server's moderators, and this app neither stores it nor reads it — Sprite Catch's own blocking and reporting tools do not reach into it, which is why the bot's opening message says so and points at both. The bot writes one message at the start listing what each of you could swap, and one at the end when either of you closes the room. Either of you can close it at any time, without the other agreeing. A trade agreed in a Discord room changes nothing about your trading record in the app; that only moves through the app's own rating step, which both people have to take.

If you link your account, what you marked with the bot comes with you. Running /link moves those ticks into your Sprite Catch collection, and the bot's own copy is deleted in the same moment — from then on there is one collection, and marking something on your phone or in Discord changes the same thing. Where the two disagree, the more recent mark wins. Disconnecting does not send your collection back the other way: the bot starts again with nothing, because publishing what you built in the app to Discord is not something disconnecting should do.

The server itself is told nothing about you. Adding the bot stores the server's identifier, its name, who added it and which channel trade rooms should open in — facts about the server, not about its members. The bot holds no permission to read messages, to see a member list, to give out roles, or to create or remove channels in any server but the community one.

Posting a picture of your collection to Discord

Once your account is linked, you can type /missing, /collection or /rating in a Discord channel and the app answers in that channel, where everyone in it can see it, with a picture: the Sprites you are still hunting, the ones you have caught, or your trading record in stars. The picture carries your display name and your friend code, so it says whose it is — it is the same image the app's own share button has always made, drawn on the server instead of on your phone.

It happens because you typed the command, and only then. Nothing posts on its own, nothing is posted when your collection changes, and there is no version of this that runs while you are not looking.

You can ask for another collector's, and only if their profile is public. Naming somebody or typing their Account ID draws their picture instead of yours — but only under the same rule that decides whether a stranger can look them up in the app or open their shareable web page in section 4. A private profile refuses, and the refusal is shown to the person who asked and to nobody else, so asking about somebody tells the channel nothing about them. Your own is the one exception: you may post your own picture whether your profile is public or private, because posting it is your decision about your own collection.

The picture then belongs to that conversation. It is drawn on demand at a web address that stops working after about an hour, but Discord copies it onto its own network as soon as the message appears and keeps that copy under its own rules — so a message you posted stays a picture of the collection you had at the time, even after your collection changes, and removing it is something you do on Discord. Nothing new is stored here to make it: it is drawn from the collection and the trading record already described above, and no record of having drawn it is kept beyond the ordinary server records described in section 13.

Your collection and the content you create

Which sprite variants you mark as owned, mastered, or as needing a rebuy — the point of the app — plus anything else you choose to add: a display name, a Fortnite tag, the character you design as your profile picture, a flag and a small badge you pick to sit beside your name, the saved looks described below, a short description you write for your profile, trade listings and their notes, posts and the photo you can attach to one, replies — including which reply a reply is answering, and who it was addressed to — reactions, likes (on a post or on a reply) and reposts in the community feed, direct messages and any photo or voice message you send in one, the groups you are in — their names, their pictures, who is in them and how far you have read — ratings and written reviews you leave after a trade, reports you file, and messages you send to support along with any photo — usually a screenshot of whatever went wrong, or of something you are claiming a reward for — you attach to one of those.

Every post and trade listing carries the language it was written in, so collectors looking for that language can find it, and other collectors can see it. Your phone works that out from the words you typed, before the post is sent — it uses the language recogniser built into iOS, nothing is uploaded to do it, and what leaves your phone is the answer ("Spanish"), never an analysis of what you wrote. When there is too little to go on — a few words, a link, a row of Sprites — nothing is guessed, and the label falls back to the setting below.

From a future release, the flag beside your name is one you pick, and it is public. You choose a country from a list, or none at all, and you can add one small badge beside it — a mark for the platform you play on, and a moderator's mark if you are one. It shows anywhere your name shows: the feed, a conversation, a profile, the website. Two things about it are worth saying plainly. It is chosen, never worked out — nothing about your internet address, your phone's settings or your phone's location has any part in it, and picking a flag says nothing about where you actually are. And it is a different thing from the country in section 2, which is recorded from your internet address, is seen by no other collector, and does not change because you picked a flag. You can change either the flag or the badge whenever you like, or take both off, and what you last chose is what is stored.

That setting is which language you read the community in. It narrows the feed, the trade board and the list of collectors who own a Sprite when you ask it to, it is the fallback label described above, and it decides which language an announcement written by me is sent to you in. Choosing one is optional — if you never do, the app uses the language it is already displaying itself in, and your feed shows every language, which is how it behaves for everybody until they say otherwise.

The profile description is a few lines about yourself, and it is optional and empty until you write one. Other collectors can read it on your profile if that profile is public — in the app or in the web version, which draws the same profile — and it is screened for banned content like every other thing a stranger can read. It is deliberately left off the shareable web page described in section 4.

From a future release you can also save a look: the whole of how you have your profile set up at that moment — the character you designed, the decorations you have on, the flag and badge beside your name — kept under a name you type, so you can put the lot back on later with one tap. Up to ten of them. Nothing new is worked out about you: a saved look is a copy of choices already described in this section, and giving it a name is optional. Nobody else can see one. A saved look is not on your profile, not on the shareable web page in section 4, never sent to another collector and never published to Discord — the only thing anyone else sees is the look you actually have on, which is what they would have seen anyway. Because they are yours alone, the names you give them are not screened the way something a stranger can read is. You can rename or delete one whenever you like, deleting one changes nothing about how you currently look, and they all go with your account (section 9).

The app also keeps a checklist of the codes Fortnite hands out. Fortnite publishes codes you type into its own Admin Panel for rewards, and Fortnite does not tell you which ones you have already entered — so the app lets you tick them off, and remembers the ticks against your account so they are still there on a new phone. What is stored is only which codes you ticked, nothing else: not when you ticked one, not whether the code actually worked, and nothing at all from Fortnite. A tick is a note to yourself — it redeems nothing, it is checked against nothing, and you can untick anything at any time. No other collector ever sees it: it is not on your profile, not on the shareable web page described in section 4, and never sent to anybody else. The list of codes itself is published by the app for everybody and is not about you.

Different from that, and worth keeping apart: the app has its own codes — a short word or two given out on a stream, in a Discord post or on a card, which you type into the Rewards screen to be handed a profile decoration, some Gems, or both. What is stored is which of those codes you used and when, and how many Gems that code paid you, because that record is what your Gems are counted from and what stops one code being used twice by the same account. These are the app's own codes and have nothing to do with Fortnite: they hand over things inside Sprite Catch, and the app still cannot grant, transfer or change anything in the game. A code is always free — there is no way to buy one, they are never sold or bundled with anything, and nothing they pay out can be bought with money. No other collector ever sees which ones you used, and all of it is deleted with your account (section 9).

Separately from the sprite collection, the app keeps a locker: a list of the Fortnite cosmetics — outfits, back blings, pickaxes, emotes and the rest — that you tell it you own, and which styles of each. What is stored is which items and styles you ticked and when you last changed each one, so the list survives a new phone and stays the same on every device you sign in on. The app is not connected to your Fortnite account and cannot see it. It has no way to check what you actually own and never tries; every tick is something you told it, the same way the code checklist above is. Your locker is private — it is not on your profile, not on the shareable web page described in section 4, and no other collector can see it. A future release may add a setting that lets you choose to show it on your profile; until you turn something like that on yourself, it stays private. The catalogue of cosmetics the app lists comes from a public Fortnite community database and describes the game, not you — we fetch it on our own servers, and nothing about you or your locker is sent there or to Epic Games.

From a future release you can fill that list in by pasting one, instead of ticking every item by hand. If you already keep your Fortnite locker on a community site, you copy the address of your locker page there and paste it into Sprite Catch. Four things about that are worth saying plainly. Your phone does the reading — the pasted text is decoded on the device, matched against a list of cosmetics the app publishes, and shown to you before anything is saved. The app does not visit that site, then or ever, so nothing about you reaches it and it is not told you use Sprite Catch. Only the cosmetics are kept: what is saved is the same list of items a tick would have made, and nothing about where it came from — the address you pasted is not stored, and the one other thing those links carry, the date the Epic account was created, is discarded without being kept or sent. It only ever adds, so importing cannot clear anything already in your locker. This is still not a connection to your Fortnite account: importing does not ask you to sign in to Epic and never asks for an Epic password, and the optional Epic sign-in described above confirms your name and nothing else — it cannot read a locker either.

Beside the locker the app keeps a wishlist: the cosmetics you tap a heart on because you want them. What is stored is which items you hearted and when. It is there for one purpose, and the purpose is a notification — once a day the app checks which of the things you hearted are in Fortnite's item shop, and if any are, it sends you one notification saying so. Nothing is sent until you heart something, that notification is never sent more than once a day, and there is a switch in Settings that turns it off without un-hearting anything. A wishlist is as private as the locker it sits beside: it is not on your profile, not on the shareable web page, and no other collector can see it. The list of what is in the shop is published by the app for everybody, is fetched from the same public community database, and is not about you — nothing about you or your wishlist is sent there or to Epic Games.

There is a second shop notification, and it is not about you at all. It tells you once a day what has gone into the item shop, whether or not you hearted any of it — the same sentence sent to everybody who asked for it, built from the public list of what is on sale. It needs nothing from you, it reads nothing about you, and the only thing stored is the fact that you switched it on: it is off unless you turn it on, which you can do when the Skins screen first offers it or at any time in Settings, and turning it off stops it. The wishlist notification above and this one are separate switches, so having one does not mean having the other.

You can also react to a Fortnite cosmetic — one of five faces, saying whether you like the look of it. What is stored is which item you picked a face for, which face, and when. Two things happen with it, and they are worth separating. Your own reaction is private in the same way your locker is: no other collector is shown that it was you, and it is not on your profile or on the shareable web page. The count is public — how many people picked each face for a given item is published for everybody and drawn on the shop screen, because that number is the whole point of reacting. You can change your reaction or take it back at any time, and taking it back removes it from the count.

One consequence is worth stating plainly rather than leaving to be discovered. If you delete your account, your reactions are deleted with it, but the public counts are not reduced. Once several people have reacted to an item, the number is a count of opinions and no longer points at anybody — nothing in it identifies you, and it cannot be traced back to you once your reaction row is gone. If you would rather not be part of a count at all, take your reaction back before you delete the account, which removes it from both.

All of it is optional except the collection itself, and each piece is stored so the feature it belongs to works — your collection survives a new phone, your conversation is there when you come back, your review counts towards the reputation other collectors see. Section 4 explains which of these are visible to other people.

Usage information

So that the app can be improved, it records how it is used: which screens are opened, which features are used, when a flow is abandoned, whether the scanner succeeded, along with your app version, device language, and the country your request came from.

Three limits on this are worth stating plainly, because they are what make it different from what "analytics" usually means:

You can turn this off in Settings → Privacy & Safety → Share Usage Data. When it is off the app stops producing this information at all, so nothing leaves your device — it is not collected and then discarded, it is never created. The rest of the app works exactly as before.

The web version produces none of this, signed in or not. Everything in this subsection is the two phone apps; the web version sends no usage events of any kind, and the only thing it counts is the visit described below. So the switch above has nothing to switch off there, which is why you will not find one.

Separately, the app can show promo cards — an invite to the community Discord, a link to Sprite Catch's own page on another service. They appear in the side menu and on the Rewards screen. Tapping one tells the server which card was tapped and nothing else: the request carries no account and no device identifier, and the server simply adds one to that card's running total. No record of who tapped exists anywhere.

The web version counts visits, and it does it without storing anything on your device. spritecatch.com records that a visit happened — the screen you arrived on, your language, the country the request came from, and which release of the site served it — so I can tell whether anyone is using it. It is deliberately the narrowest thing that answers that question, and four limits define it. Nothing is written to your browser: no cookie, no stored identifier, nothing added to what your browser already keeps for you. Instead, so that ten page loads from you are not counted as ten people, the visit is filed under a scrambled stand-in worked out from your IP address, your browser's description of itself, and today's date — and because the date is part of it, the stand-in is a different one tomorrow, so what is stored cannot be used to follow a browser from one day to the next, by me or by anyone else. It carries no account, and that is now a choice rather than a consequence: the web version has accounts, and this count deliberately does not send yours, so a visit is not attached to you even when you are signed in — and it holds nothing about which sprites you ticked off. And the screen is recorded as a category — that you opened a sprite's page, someone's profile, your messages or your settings — never the address, so whose collection you looked at, and whose conversation you opened, is not in it. Two honest consequences: two people sharing a connection and the same browser count as one, and one person on two networks counts as two. It is a count of visits, not of people, and it is not capable of becoming one without storing something on your device, which it does not do. There is no switch for it, because there is nothing in it tied to you to switch off; the app's Share Usage Data switch is separate and unaffected. The marketing page at app.spritecatch.com counts nothing at all — it is five files and no program, so there is nothing there that could.

Daily rewards

The app offers a small reward for coming back on consecutive days. To do that it keeps four things: how many days in a row you have claimed one, the longest run you have ever had, the date of the most recent claim, and how many Gems the streak has paid you in total.

Unlike the usage information above, this is kept against your account rather than against a scrambled stand-in — a streak that could not be tied to you would not be your streak. Three things follow, and each is deliberate:

The first six days of a streak each unlock a fixed, published decoration — a colour for your name, a look for the character you use as a profile picture. Every seventh day draws one prize at random from a small pool. Nothing about it costs money, nothing can be bought to change your chances, and Gems cannot be spent on it either — nothing the app draws at random can be paid into with anything. A prize you already hold is never drawn again — so every draw gives you something new until you have them all. The odds are shown in the app, on the screen that does the drawing.

A day that unlocks no decoration pays Gems instead. Past the first week, and once you have collected everything the seventh day can draw, there is nothing left for a day to hand over — so claiming one now adds a small number of Gems to your balance, and the app tells you how many before you claim and again afterwards. The amount gets smaller the more the streak has paid you, which is why the running total above is kept: it is what the next day's amount is worked out from, and it is the only reason that number exists. It is never a random amount, there is nothing to buy or spend to change it, and a day pays a decoration or it pays Gems — never both.

From a future release, a reward can also arrive as a box — given to you after a person has checked something you did, and opened by you to reveal one decoration out of a published set. The same things are true of it: nothing about it costs money, nothing can be bought to change your chances, nothing in it can be bought with Gems and nothing in it is ever put in the Gem shop, a decoration you already hold is never drawn again, and the whole set and your real odds are shown before you decide to open it. Nothing won this way can be traded or sold. What is kept is only which decorations you own and which box gave you one, which is part of the decorations described above and is not shared with anyone.

From a future release, opening a box also lets you choose. It shows you one decoration, and you can ask it to show you another a small fixed number of times — the app tells you how many before you start — and then keep whichever of the ones you were shown you like best. Every one of those extra looks is free and comes with the box: there is nothing to buy, nothing to earn, no way to spend Gems on one and no way to get more of them, and asking for another never takes away one you have already been shown. While you are deciding, the app keeps a short-lived note of which decorations it has offered you, so that closing the app and coming back brings you to the same ones rather than a fresh set. That note is kept only until you choose, and it goes when you do — it is deleted the moment you keep one, and with everything else if you delete your account.

Invites

You can invite friends by sharing your username, and unlock decorations as more of them join. Two things are kept for that: who invited you, if somebody did, and — worked out from that — how many people you have brought in.

This is the first thing in this policy that records a link between two accounts, so it is worth being exact about what that link is and is not:

The decorations this unlocks cannot be bought and nothing about it costs money. They are fixed and published, at set numbers of friends, and there is one more for entering somebody's code yourself — so both sides of an invite get something. One of them is a box, of exactly the kind described above: it opens into one decoration out of a published set, nothing can be bought to change the chances, a decoration you already hold is never drawn again, and the set and your real odds are shown before you open it. Nothing you win this way can be traded or sold.

An invite link is a page on this website that names nobody. It shows the username or account ID it was made for and an install button, and it says nothing else about the person who sent it — not their name, not their collection, not even whether their profile is public.

Playing the arcade

The Rewards screen has a small arcade on it — five short games, every one of them drawn by the app itself out of its own artwork and the sprites you already collect: flying the character you designed through a run of pipes, guessing which of two sprites is the commoner catch, naming a sprite as it fades in from its shadow, stacking blocks, and finding matching pairs. What is kept, separately for each game, is your best score and the date you set it, plus your best inside the current day, the current week and the current month. Not every game you play, not how many times you tried. Each of those is only rewritten when you beat it, so a hundred losing games in a row leave nothing behind at all, and there is no history of when or how often you played.

A finished run also says how long it took. That is used to check the score is one the game could actually have produced, and then it is thrown away — with one exception worth naming: in one of the five games the score simply is how quickly you finished, so a faster board is a higher number. Nothing else about a run is kept, and nothing about a run you abandon is sent at all.

The three shorter records exist because each game has a leaderboard for each of them (section 4). They are not a diary: a day's best is simply replaced the next time you play in a new day, and the same for the week and the month, so nothing accumulates and yesterday's number is gone the moment you start a run today. The day, week and month are counted in UTC, the same clock for everybody, so that two collectors are always being ranked against the same window.

One game a day is spotlit on the arcade screen. That is a signpost and nothing else: it is the same game for everybody, it is worked out from the date rather than from anything about you, and it changes nothing about what is stored, what is earned or who can see it.

Like a streak, and unlike the usage information above, each of those scores is kept against your account rather than against a scrambled stand-in — a high score that could not be tied to you would not be your high score. Unlike a streak, it is not yours alone: if your profile is public, your best score can appear on a leaderboard other collectors read. Section 4 says exactly what that shows and who is on it.

You can challenge somebody you already chat with. Finishing a game offers to send that score into one of your conversations, and the message composer can start one from scratch; either way what lands is a card that stays in the conversation and keeps a scoreboard on it. What is kept for one of those is who opened it, which game, which conversation, when — and one best attempt per person who plays it. Again not every attempt: a worse run writes nothing, so playing the same card ten times leaves one number behind.

Two things about that are worth being plain about. A challenge can only go into a conversation you already have, so nobody can be challenged by a stranger. And the number on the card is one you chose to put there — it is either the record you already hold at that game or a run you played on the card, and the app will never show a higher number than the one it already holds for you. So a private profile, which is off every leaderboard, still shows a score to the people in a conversation it played a challenge in, and only to them. A challenge run counts on the leaderboards exactly like any other run at that game, under the same rules as the rest of this section. Nothing is won by beating somebody: a run earns what it would have earned played alone, and the card itself pays out nothing at all.

From the version going out on 7 September 2026 somebody in a conversation can also ask it a question — a poll with a few answers to pick from. A poll is a message like any other, so everything in section 4 about where a message is stored, who can read it and how long it stays applies to the question and its answers. What I store beside it is each person's own pick: which answer they chose, on which poll, and when. Everybody in the conversation sees how many people chose each answer, and nobody — not the person who asked, not whoever runs a community — is shown who chose what. Your own picks are shown back to you and to nobody else. Whoever asked can end the poll early, and in a community room so can the people who run it; a poll can also end on its own after up to a week. If you delete your account, your picks are removed and the totals go down by exactly what you had chosen, the same way a reaction to an item in the shop is handled; a poll you asked goes with your messages.

Each game's screen also shows a short Friends list — collectors who follow you and whom you follow back, with their best score at that game. It publishes nothing a leaderboard does not: it holds only the accounts a leaderboard would already list, so a friend whose profile is private simply is not on it, and the app says nothing about them either way.

Playing earns you nothing today. The arcade was built with a way of handing out profile decorations for a score — reaching a number published on the screen before you play for it, or being first on one of a game's four leaderboards — and it is switched off. No decoration has ever been given out for a score, and none is being given out now; the games keep your records and rank them, and that is all they do. Nothing about the games costs money, and nothing that can be bought changes a score or a place on a board. If it is ever switched back on, this page changes with it, and what would return is the arrangement just described: a published number beside a published decoration, with no draw, no odds and no crate in it, and nothing won that could be traded or sold. The games pay no Gems either, and that is deliberate: a score is the one thing here a person can sit and repeat, so it earns nothing but the score.

Gems

Gems are the app's own currency. They are earned by using the app, or given by a code, and cannot be bought — there is nothing to top up, no pack, no bundle and no subscription, no amount of money produces a single one, and a code that pays them is itself always free and never sold. They buy profile decorations from a small shop.

How many you have is worked out, not stored. The number comes from things the app already knows about your account — how many different people you have completed a trade with, how much you have posted, the longest daily streak you have run, how much of your collection you have filled in, how long you have been here, and whether you have taken part in a creator-code campaign. There is one exception, and it is the daily reward described in section 3: what a streak has paid you on days with no decoration on them is written down, because it is the only part of the sum the app could not work out again afterwards. Nothing else new is recorded to make the number, and no overall tally of it is kept. A consequence worth saying plainly: because it is worked out from the current state of your account rather than banked, it can go down — un-marking sprites you had ticked off, or having a post taken down for breaking the rules, lowers it. Anything you have already bought stays yours.

What is kept is what you spent them on, and what was handed to you. When you buy a decoration the app records that this account bought that decoration, what it cost and when — and that record is what makes the decoration yours, so it stays after you reinstall. The same goes the other way: when you redeem one of the app's own codes, it records which code and how many Gems it paid, and that record is what those Gems are counted from. Three further numbers are kept against your account: anything I have handed you by hand (for example putting right something that went wrong), a one-off adjustment made when Gems were introduced so that a long-standing collector's whole history did not pay out at once, and the running total your daily streak has paid you. All of it is deleted with your account (section 9).

Nothing random can be paid into with them. A reward box, the seventh day of a streak — anything the app draws at random — can never be bought with Gems, and nothing that can be drawn is ever put in the shop. That is enforced by the app rather than remembered: a decoration that sits in any of those pools cannot be given a price at all.

The shop is the same for everybody, and everything in it is always in it — every decoration that has a price is on sale, all the time. Nothing in it is chosen for you, none of it depends on anything about you, and nothing about what you look at in it is recorded.

Buying a decoration — removed

There is nothing to buy, and there is no longer any way to buy. The app was once built able to sell profile decorations through the App Store. It was switched off before it ever opened; no decoration was ever listed, nobody ever bought anything, and no payment information ever reached me. On 1 September 2026 the ability itself was removed — from the app, from the server, and from this policy. Earlier versions of this page described what a purchase would involve, on the reasoning that the ability still existed and could be switched back on. It no longer exists, so the description has gone with it.

What this means for what is kept: nothing about payments is held, because none was ever taken. There are no purchase records, no transaction references, no refund messages from Apple and no record of anything bought — not held, not shared, and nothing for a deletion request to reach. The App Store is no longer a recipient of anything for this app (section 6). If decorations are ever sold for money again it will be a new version of the app, and this page will say so on the day, before it happens.

Questionnaire answers and rewards

The app can offer you something to do in exchange for a decoration for your profile — answer a short questionnaire, or open a link. These are always optional, always free, and skipping one costs you nothing but the decoration.

If you complete a questionnaire, the answers you choose to give are stored and I read them. Whatever you type into a free-text question is kept exactly as you wrote it. It is never shown back to anyone in the app, and it is deleted when you delete your account. Nothing is submitted until you tap through — closing a questionnaire sends nothing at all. Please treat a free-text box the way you would any other: don't put anything in it you would not want read.

Questionnaire answers are not sold, and none ever has been. What you answer is read by me, to work out what to build next. It goes nowhere else: not to game companies, not to studios, not to anybody outside the service.

Until 31 August 2026 the app carried the ability to run a questionnaire whose answers were sold as market research, and this page described it at length. It was never used — no such questionnaire was ever offered to anybody and no answer of yours was ever sold to anyone — and on that date the ability was removed from the app and from the server, together with the consent screen it would have shown. There is nothing left here to agree to, and nothing left to switch off. Section 13 records the change.

About the iOS tracking permission. While you are setting the app up, iOS asks whether Sprite Catch may track you, and you can put the same question to yourself at any time in Settings → Privacy & Safety → Tracking. Nothing in the app tracks you, and nothing reads your answer. There is no advertising identifier, no ad network, and nothing that follows you into another company's app or website. The permission was added on 1 August 2026 for the questionnaire described above; when that was removed the permission was deliberately kept, so that the choice is already yours before anything could ever need it. If anything ever does, this page will say so before it collects a thing. Saying no costs you nothing — every part of the app works exactly the same either way — and nothing is recorded by your answering at all.

Completing one of these is recorded against your account — which offer, and when. This is a different thing from tapping a promo card in the paragraph above, and the difference is deliberate rather than accidental: a promo tap is an anonymous counter, and this is not, because the service has to know who has already earned a decoration in order to give it to them once and to stop asking. Where a decoration came from is recorded too, so I can tell a reward apart from one I handed out by hand when somebody writes in asking why they have it.

The decorations themselves — which ones your account holds, and which ones you have chosen to show on your profile — are stored with your account. The artwork is mine, not yours: there is no way to upload a picture, and nothing in this feature asks for your photo library or your camera.

Achievements are still worked out on your device, from your own collection and the counters already on your profile, so for nearly all of them the service keeps no record of which ones you have earned. Two things about them are kept with your account. The first is your choice of which few to display: pinning an achievement to your profile stores that choice, so it follows you to a new phone and so other collectors see the ones you picked. The second is newer and applies to a small number of badges that no rule could work out — a badge for helping test the app, for being here early, for telling me about something broken. Those are handed out by me, one account at a time, so the service does record which of them your account has been given. Both are visible to anyone looking at your profile, which is what a badge is for.

Device and connection information

The service runs on Cloudflare. Like any web server, it logs standard request metadata — your IP address, the time of the request, your device's user agent — to route traffic, block abuse and defend against attacks. This is not used to build a profile of you and is not joined to your collection.

From 5 September 2026 the network address is also written down against your account, and kept for 90 days. Until that date it never was: it was scrambled into a form nobody can read back, and the address itself was thrown away. That changed, and it is worth being plain about why, because it is the one thing on this page that is stored for somebody else's benefit rather than yours. When child sexual abuse material has to be reported (section 6), the report is only useful if it says where the person was connecting from — without an address, the authorities have nothing to act on. A device and an email address do not answer that question.

It is recorded when you create an account, sign in, upload a photo or voice message, post, or send a message, and one record covers a whole hour of doing any of it, so using the app more does not write more. After 90 days the address is erased and only the scrambled form is kept — enough to tell that two things came from the same place, never enough to say where. If you delete your account, the addresses go with it (section 9). The one exception is a legal preservation, which is described in section 6 and stops that clock like every other.

Two things are unchanged. The short-lived count that protects the sign-in code screen still holds only the scrambled form and never the address itself, and the Android waitlist still stores no address at all.

Each request also carries the app's version and build number, so the server can tell an out-of-date release that it needs updating. That describes the release you installed, not you.

Age information

Both apps ask, and from 21 August 2026 answering is required. This used to be an iPhone-only question, and the Android app asked nothing — that is no longer true, and it changed for a reason worth stating plainly: by that date most accounts had never been asked at all, and the age is what decides an account's privacy defaults and which safety reminders it is shown. So the question is now put to everybody, on both apps, and — this is the part that changed — it has to be answered before the app continues, including by people who had already been using it for months without ever being asked. There is an explanation on that screen, behind the ⓘ, saying exactly what the answer is used for.

To set age-appropriate privacy defaults the app establishes whether you are over or under 13 — through Apple's Declared Age Range service where the device supports it, through Google Play's age range on Android where you agree to share it, or by asking how old you are if neither answers. Your date of birth is never asked for and never stored, on either app: a birthday identifies you far more precisely and would tell me nothing extra, because everything behind this is a comparison against a whole number of years. Apple's service reports a range rather than a birthday or a number, so on an iPhone that answers through it the app holds a result and never an age.

On Android, from the version going out on 9 September 2026, Google Play is asked first. Google holds an age range for a signed-in account — set by you, or by a parent for a supervised account, or established by Google in some other way — and Play can pass that range to an app. It only does so if you agree: the request puts Google's own screen in front of you, and saying no is a complete answer that costs you nothing. If a range comes back, the app takes it as the answer and does not ask you the question again; if none comes back, for any reason at all, you see the same age screen as before. What is stored is what was always stored — the lowest whole number of years the range allows, and no range, no birthday and nothing about how Google established it. Nothing new is sent to Google by this: the app receives an answer rather than reporting one, and it is used only to set the age-appropriate defaults described here, never for advertising, marketing or working out who you are. This exists because Brazil's Digital Statute of the Child and Adolescent requires an app that under-18s are likely to use to take the age range from the app store rather than only ask, and it is switched on everywhere rather than in one country because a rule that makes the answer better does not become worse by crossing a border.

From 2 September 2026 the app also works out whether you are 18 or over, and from 7 September 2026 that answer reaches me too. It comes out of the same question: on an iPhone, Apple's service is given both boundaries in the one request, so there is no second prompt and still no age; everywhere else it is the number you already gave. Until 7 September 2026 it stayed on your phone and decided one thing — whether you are shown the short safety note that appears above a conversation with somebody you have not spoken to before (section 3), which it still decides, on the phone, exactly as before. From the version going out on 7 September 2026 the same yes-or-no is also stored with your account, and on my server it decides exactly one thing: whether you can start, be invited into, or join a community its owner has marked for collectors aged 18 and over (section 11). Nothing else reads it. It is a yes or a no, never a date of birth and never a number on the accounts Apple answered for; it is shown to no other collector, and it is erased with your account (section 9). An account I was never told about is treated as under 18 on both sides: the note stays, and a community marked 18+ says no — and tells you that redoing the age check in Parental Controls is how to answer. Over or under 13 remains the only age result that changes how your account is treated everywhere else.

In the app version going out from 28 August 2026, the ages that screen offers start at 13, because the social side of Sprite Catch is a 13+ product, and under the list there is a button saying My age isn't listed. It opens an explanation and one offer: Safe Mode, a limited version of the app — the collection, the scanner, Rewards and your own profile, with the community, direct messages and news switched off. Choosing it records the account as under 13 and stores no number at all, because none was given. It can be switched off again from Parental Controls, where a parent can also set a passcode so that it cannot be.

The answer itself still takes nothing away. Whatever age you give, every part of the app still works — what an age changes is the defaults described below, never what you are allowed to do. The two things that do switch features off are both choices somebody makes: Safe Mode, chosen on that screen by a collector under 13, and Parental Controls, where a parent switches off the community, messages or news for a child of any age.

Where the app does ask — during setup, right after you choose a display name, or once over the app itself if your account predates this — the age you give is stored with your account, alongside the over/under-13 result, and both are sent to the server. Where the answer was My age isn't listed there is no number to store and none is invented: the account carries the under-13 result and nothing else. I keep the number to understand the ages of the people using the app, so that decisions about what it offers and how it behaves are made with that in mind. It is never shown to other collectors: it appears on no profile, no post, and not on the public web page, and no feature in the app displays it. You can redo the age check at any time from Parental Controls, and your age is erased with your account (section 9).

Some accounts hold an age nobody actually gave, and from 29 August 2026 those are asked again. Until 21 August 2026 the age list opened already resting on a value, and the button underneath it could be pressed without moving the list — so an account whose owner simply pressed straight through was recorded at that resting age rather than at a stated one. That is a large share of the accounts currently recorded as under 13, and the honest fix is not to quietly correct the number or to delete it, but to ask the question properly. Those accounts see the age screen once more, on the version that will not accept an answer until the list is moved. Nothing about the account changes while it is being asked, and nothing changes because of the answer either.

From 2 September 2026 that question is only put to accounts collecting as a guest. An account signed in with Apple, with Google or with an email address could be shown the screen but had no way to send the answer back — so the question came round again, and for some people it came round every few seconds. That is fixed by not asking: those accounts are left alone, the answer they last gave stays on their phone, and it reaches the server the next time they sign in. They keep exactly the protection they had while they were being asked — an age nobody gave is still not treated as an age anybody gave, so nothing is switched off for them on 1 October on the strength of it.

Accounts that did state an age under 13 are told what is coming, and when. Rather than a re-ask — an age somebody deliberately chose is an answer, and asking again would only be asking for a different one — the app shows a notice naming the date from which the community, direct messages and news will be switched off for that account, and saying what does not change: the collection, the scanner, Rewards, the arcade and your own profile. That date is 1 October 2026. It is held on the server rather than built into the app, so that if it moves, every installed copy of the app learns the new date instead of continuing to show an old one.

What happens on that date is that three switches move, and they are switches you can see. The community, direct messages and news are switched off using the same Parental Controls on the settings screen that a parent can already use for a child of any age — so they can be switched back on in that same place, unless a parent has set a passcode there, which is what a passcode is for. The app does not refuse to work: nothing on the server starts rejecting this account, and the collection, the scanner, Rewards, the arcade and your own profile carry on exactly as they are. It is applied once, and if you turn the three switches back on the app does not keep turning them off again.

The notice offers two answers and either one ends it. If the age is wrong you can redo the check there and then; if it is right you can say so, after ticking a box confirming the age on the account is your real age. When you confirm, the app records that you confirmed it and when — and that record is the whole reason it stops asking. It says only that the question was answered: it is not treated as proof that the answer is true, it is never shown to other collectors, it changes nothing about what your account can do, and it is erased with your account (section 9). You can still redo the age check whenever it stops being right, from Parental Controls.

The over/under-13 result has to reach the server: a protection that runs only on the device is one the device can be changed to skip, and the server cannot withhold things from a child's account without knowing which accounts those are. When the result is under 13:

What the age result does not do is switch features off by itself. The community feed, trades, other collectors' profiles and direct messaging are controlled by a person: a parent, on the Parental Controls screen (Settings → Parental Controls), where each one can be switched off independently and a 4-digit passcode keeps a child from switching them back — or a collector under 13, choosing Safe Mode on the age screen, which switches off all three at once and is undone on that same Parental Controls screen. The passcode and those choices are stored only on your device and never sent to the server.

3. What stays on your device

Several things people reasonably assume are collected, and are not.

Daily reward reminders. If you leave them on, the app asks your phone to remind you about an unclaimed reward — once in the afternoon and once before midnight. These are set by your phone, for your phone. No reminder is sent from a server, nothing about when you are reminded is recorded anywhere, and the app does not need to know your time zone to do it — your phone already does. They keep working with no signal, and they stop the moment you turn them off in Settings → Notifications, which is a switch stored on that device rather than on your account.

The screen scanner, on iPhone. The iPhone app can fill in your collection by photographing the Sprites screen in Fortnite. Those photos are never uploaded and never saved. Recognition runs entirely on your device against sprite artwork the app has already downloaded; the frames exist in memory for the length of one scan and are gone when you close the scanner. The only thing that leaves your device is the result you confirm — the same "I own this" mark you could set by tapping the sprite yourself. Nothing is marked without your approval.

There is one other place the camera is used, and that one does send the picture. When you claim a reward that a person has to check, you can photograph your proof rather than going hunting for a picture you took earlier — which is what you need if the thing you are proving is on a television. That photo is attached to your message and read by the small group who answer support, exactly like a photo you pick from your library, and it is covered by everything section 4 says about support photos. It is the only photo the camera takes that is ever sent anywhere, it is sent only when you press send, and the app resizes it first, which strips the details a camera records alongside a picture — including where it was taken.

The two apps reach the camera differently, and on Android the app never touches it. On iPhone the viewfinder opens inside Sprite Catch, and your phone asks you for camera permission the first time. On Android the app hands the job to your phone's own camera app and gets back only the one picture you chose to keep: Sprite Catch asks for no camera permission on Android and has none, so there is no way for it to open a camera you did not open yourself. Taking a photo is never the only way to answer either — picking one from your library sits beside it, and on both phones the app still asks for no access to your photo library to do that.

The microphone works the same way, and it is only ever the microphone. It is used for one thing — recording a voice message to send in a conversation — and it is off until you start a recording yourself, at which point your phone asks you the first time. There is no listening in the background, no recording while the app is closed, and no camera involved: a voice message is sound only. A recording you cancel, or one too short to be a message, is thrown away without leaving the device; the rest is in section 4. If you would rather not decide from inside a conversation, the same switch is under Settings → Privacy & Safety.

The warning on a photo somebody sends you. If your iPhone's own nudity detection is switched on — either you turned on Sensitive Content Warning, or a parent turned on Communication Safety in Screen Time — Sprite Catch uses it to cover a photo somebody sends you until you choose to see it, and on a child's phone it also asks before one is sent. The check is your iPhone's own, it runs entirely on your device, and its answer never leaves that device. No photo is uploaded for it, nothing is stored about what it decided, and I am never told that a photo was covered, or that anyone chose to look — that last part is not my choice but a condition Apple attaches to letting an app use the check at all, and it is what makes this a warning for you rather than a report about anybody. Two things follow that are worth being blunt about. It is switched off unless somebody switched it on, which most people have not — so a photo arriving with no warning has not been found to be fine, it has only not been checked. And it changes nothing about how the photo is stored or moderated: that is section 4, and it is the same for a photo that was covered and one that was not.

Your activity list. The Activity screen — new followers, reactions, replies, trade matches, message alerts — is stored only on your device. The server keeps no copy and no record of what you have read. The list is capped, old entries are discarded, and deleting the app removes it.

The collectors you were just looking at. The search screen opens onto a short list of the people this phone has recently been in front of — whose profile you opened, whose post you read or reacted to, whose conversation you answered — so getting back to somebody does not mean remembering their name. That list is built and kept on your device and is never sent to me: I have no record of whose profile you read, and nobody on it is told they are on it. It holds about twenty names at a time and the oldest drop off; it belongs to the account you are signed in to and does not follow you into another one; blocking somebody takes them off it at once; and the list carries a Clear button, with any single name removable on its own. Signing out puts it away with the account it belongs to, starting over or deleting the app removes it, and your phone may clear it by itself to reclaim space.

The web version, until you sign in. You can use spritecatch.com without an account, and used that way it is the same promise it has always been: the sprites you tick off are saved in your own browser and never sent to me, along with a display preference or two. Nothing identifies you, because there is nothing to identify. Clearing your browser data, using private browsing, or switching browser or device loses that collection permanently — there is nothing for me to restore, because I never had it. Visits are counted, in the narrow way section 2 describes, and that counting stores nothing on your device either.

The web version once you sign in, and what your browser then keeps. Signing in is the point at which the web version stops being local and starts being your account: your collection syncs to the server, exactly as the app's does, and everything sections 2 and 4 describe applies to what you do there. Your browser keeps a working copy so the site is quick and survives a reload, and this is all of it:

None of that is a cookie. The web version sets none, and neither does any written page of the website — the single exception anywhere is the Discord linking page, which runs Apple's and Google's own sign-in code and is described on the Cookies page. None of it is an advertising identifier, and none of it is readable by anybody else's website. It lives in your own browser's storage, for your own browser, and clearing your browser data removes every bit of it — the Cookies page explains how. Doing that while signed in signs you out, and loses nothing except any marks that had not reached the server yet — the collection itself is on the server by then, and so are your conversations, which come back the next time you sign in. Doing it while signed out is, as above, permanent.

The one thing the web version can send me without an account is an email address, and only if you type one into the Android box described in section 2; it is stored apart from all of this, it is attached to nothing here, and it is deleted on release day.

The web version can build a link that carries your collection into the iPhone app. Your collection is encoded after the # in that link, and browsers never send that part to any server — so it reaches your phone without ever reaching me. The flip side is that anyone you send the link to can read the collection in it, and the links do not expire. It contains only which sprites you ticked: no name, no account, nothing else about you.

4. What is public and what is private

This section describes both apps. The Android app used to be collection-only, and this page used to say so. That stopped being true during the August 2026 parity work: the Android app now has the same community surfaces as the iPhone app — the feed, trades, direct messages with photos and voice messages, trade reputation and reports — so everything below applies to it as well. Two things are still iPhone-only, and neither is a community feature: signing in with Apple, and buying a decoration.

A new profile is public by default, so collectors can find you and match trades, and posting a trade, writing a post or replying to one turns a public profile back on, telling you before you confirm. Public means anyone using the app can see — and reading does not need an account, so that includes people who never signed in — your display name, Fortnite tag, the character you designed as your profile picture, the description you wrote for your profile, any decorations you have chosen to show on it, the achievements you pinned to it and which achievements you have earned, your collection, trade listings and notes, posts and the photos attached to them, replies — which reply each one answers, and how many likes it has — reactions, likes and reposts, and your trade reputation — the star rating from completed trades, together with written reviews and any scam marks other collectors have left. Other collectors can also search for you by your username, your display name or your Fortnite tag, and can search the text of recent posts. Search covers public profiles and posts and nothing else — never your direct messages. You can go private at any time in Settings, which hides you from search, from Discover, from trade matching and from the "who has this" lists.

Your profile also gathers what you have written. A collector's profile has a Posts tab listing everything that collector has posted, newest first, and anyone who can see the profile can read it — which, as above, includes people who never signed in. Nothing new is stored for it and nothing appears there that was not already public in the feed; what changed is that it is in one place instead of scattered through a timeline, so assume that anything you post can be read as a list of everything you have posted. A private profile withholds that list exactly as it withholds the rest of the profile, a post you delete disappears from it the moment it disappears from the feed, and someone you have blocked cannot reach it at all.

From 4 September 2026 your trading record travels with your posts. The star rating from your completed trades — and the warning an account carries once enough scam marks have been left on it — now appears beside your name on your posts and your replies, not only on your profile. Nothing new is stored and nobody new can see it: it is the same record the paragraph above already describes as public, shown where somebody is actually reading rather than one tap away. The reason for moving it is that the feed is where people decide whether to start a trade, and a warning that only exists on a screen nobody opened first is a warning that arrives too late. Two things about how it is drawn are worth saying plainly. It is not shown on your own posts — everyone else sees it and you do not, because it is there to inform a reader and you are not the reader; your own record is on your Account Standing screen, where it comes with a reason and a way to appeal. And it changes nothing about what your posts do: a post from an account carrying a warning is still readable, still repliable and still reportable by anybody, and choosing not to see those accounts in the trading feed remains a filter you switch on yourself.

From 1 September 2026 a post can carry a photo, and a photo in the feed is public in a way a photo in a message is not. The feed changed on that date: it was only about Sprites — the ones you had caught and the ones you were hunting — and it now has a general Fortnite and Sprite Catch half alongside the trading one, where a post can be words, a picture, or somebody else's post you have passed on. A photo you send in a message goes to one person. A photo you put on a post goes to everyone, including people who never signed in, because reading the feed needs no account. It is stored on the server the way a message photo is, it is not on the public web profile page and it is not indexed by search engines, but treat putting one on a post as publishing it. The photo is stripped of the details a camera records with it, such as where it was taken, before it leaves your phone — the same as a message photo, and the web version does the same thing in your browser before anything is sent. Choosing one uses the picker iOS runs outside the app, which hands over the single image you pick and nothing else, so this feature by itself asks for no access to your photo library.

From 2 September 2026 a photo you attach to a post is checked before it is published, and that check is the one thing in this app that sends a picture to another company. When you pick a photo for a post, it is sent to Google's Cloud Vision service, which answers how likely it is to be explicit or graphic, and nothing else. If the answer is a confident yes the upload is refused: you are told the photo cannot be posted, you can pick another, and nothing is stored or shown to anybody. Everything about the boundary here is deliberate and worth reading, because it is narrower than it sounds. From 6 September 2026 it happens to three pictures and to nothing else: a photo on a post, a community's picture, and a group's photo. Not a photo in a direct message, not a photo attached to a support ticket, not a voice message, not anything you write. Until that date it was post photos alone, and the next paragraph is about why the other two joined them. A photo you send to one person is still not sent to Google, and is not going to be. Google is asked one question and is not asked to recognise anybody: the request asks for the explicit-content answer and for no other kind of analysis, and in particular it never asks Google to detect or match a face. Google handles it as a service provider, does not keep it and does not use it to train anything. The picture is not kept on my side either. What is written down is the five scores that came back, a fingerprint of the file, and whether it was refused — never a copy of the photo, and a refused photo is never stored at all. And if Google cannot be reached, or answers with an error, the photo is published rather than held back: a failure on their side is not allowed to stop you posting. Two things this is not. It is not a check for illegal images of children — it cannot do that, it is never treated as though it could, and reports remain how that reaches me. And it does not decide anything about you: a refusal is about one picture, it is not a strike, it is not recorded against your Account Standing, and it does not restrict your account in any way.

From 6 September 2026 the same check also looks at the picture you put on a community and the photo you put on a group, and there it does refuse. The line is not public against private — it is that a picture like that is shown to people rather than sent to them. It is drawn next to a name in a list, for everybody in that place, whether or not they opened anything: a community's picture is public to every signed-in collector browsing for one, and a group's photo is in the list of every person in that group, up to 255 of them in a community room. Nobody there chose to look at it. So when you set one, it is sent to Google the same way a post photo is, asked the same single question, and if the answer is a confident yes it is turned away — you are told, the picture you had before stays exactly as it was, and you can pick another. Two things are worth being exact about. It is checked at the moment you make it the picture, not when it is uploaded, which is what keeps every ordinary photo sent inside that group away from Google. And a picture that is turned away is not kept, not shown to anybody, and not held against you: as above, a refusal is about one picture and is never a strike, a mark on your Account Standing, or a restriction on your account.

On posts, today it still refuses nothing. There the check is running and every answer is being written down, but it is set to record rather than to act while I find out how it behaves on real photos, so right now no photo is being turned away from the feed by it. That is the one difference between the two: a refused post throws away something you wrote, and a refused community picture costs you picking a different one. This page will say plainly on the day the feed half starts refusing too.

The measure that stops keeping an account's photos now covers posts as well as messages. Section 4 describes it below: where the problem is the pictures themselves, I can stop keeping an account's photos altogether. Until this date that covered messages only. It now also covers a photo attached to a post — the picture is discarded rather than stored, and the post carrying it reaches nobody, though its author still sees it in their own feed. A photo attached to a support ticket is still always kept, and that remains the one exception, for the reasons given there.

You can tag any collector with a public profile in a post, not only the people who follow you. Until 1 September 2026 a tag only worked if that collector followed you, and it silently did nothing otherwise. Tagging someone puts their name in your post, gives readers a way to open their profile, and sends them a notification unless they have turned mentions off in Settings — that switch has always been there and is what this widening leans on. Tagging cannot reach a private profile, and it cannot reach somebody who has blocked you or whom you have blocked.

Who follows a public profile, and who that profile follows, are lists anybody can open. The two numbers have always been on it; from 4 September 2026 the names behind them can be read as well, by anyone who can open that profile — and since reading needs no account, that means anybody at all. Each row shows what a collector row anywhere else in the app shows: the display name and username, the character used as a profile picture, any decorations chosen for it, the official mark where an account carries one, how much of the collection has been caught and mastered, and the trading record shown beside a name everywhere else. Following somebody has never been private — they are told when you do it, and it is what puts their posts in your feed — but until now the list itself could only be read by the person it belonged to.

Only public profiles are on either list, which is the rule the leaderboards below follow and it is here for the same reason: a list of names a stranger can read holds only accounts that already agreed to be found. Going private takes you off every copy of both lists, exactly as it takes you off search, Discover, the owner lists and the boards, and an account belonging to somebody under 13 starts private (section 11), so it is never on one unless that has deliberately been changed. The two numbers count the follows themselves, so they can be larger than the names shown. A collector you have blocked is not on your copy of a list and you are not on theirs. And the lists carry nothing about whoever is reading them: they never say whether you follow any of those people back.

A handful of accounts carry an official mark beside the name — the person who makes the app, moderators who help run it, accounts the app itself runs, and collectors the team has vouched for. It is put there by hand and nothing in the app can give it to an account on its own: it cannot be bought, won, equipped or asked for, which is the whole point of it. It exists so you can tell a real one from somebody who copied the name, and it is shown wherever that account's name appears. It gives that account no power over yours and no access to anything of yours.

The language a post or a trade listing was written in is shown with it, so a reader can tell before answering whether the conversation that follows will be one they can have. It is worked out on your phone from the words in that post, so it describes the post rather than you — writing in English labels it English whatever language you read the app in. Your language is never written beside your name anywhere else. Your setting does decide one thing beyond that: whether you are among the names another collector sees when they narrow a list of the people who own a Sprite to the language they read, so that a first message is one you can both read. Nothing else about you is shown there that a public profile does not already show. The country your requests come from, described in the same section, is not public: it is not on your profile, not on the web page below, and never shown to another collector.

Your profile description is shown on your profile — in the app, and in the web version, which draws the same profile. It is not on the shareable web page below and not on any of the written pages on spritecatch.com. Anyone who can open your profile can read it, and opening a profile needs no account in either place, so write it as something a stranger will see.

Collectors who follow you can also see the sprites you caught in the last week, read out of your collection when they open that screen. The Share My Catches switch turns that off. What you have caught is never public on its own — a private profile keeps your collection to yourself — and which sprites you marked as needing a rebuy is never shown to anyone, either way.

Collectors you are talking to can also see when you were last using the app — drawn as "Online" while you have it open, and otherwise as how long ago it was. This is the same "last active" time that has always been shown on a public profile and used by the "active this week" filters — the one on the trade board, and the one on the Trading feed; what is new is that on the messaging screens it is now accurate to the minute rather than to the hour, and that there is a switch for it. Only the most recent time is kept — there is no history of when you have opened the app, just the last time you did — and it records that you were there, never what you were doing. Opening a conversation in the web version counts exactly the same way: it makes you "Online" to the person you are talking to, under the same switch, because it is the same account doing the same thing from a different screen.

In a conversation, the person you are talking to is also shown while you are typing — the indicator every messaging app draws. It is passed between the two of you as it happens and never written down: there is no record of when you were typing, of what you were typing, or of a message you started and did not send. It follows the same switch as the time above, in both directions, so a collector who has turned that off neither shows this nor sees it.

Separately from that, and never shown to anybody: while the app is open it holds a live connection to the server so that messages arrive as they are sent rather than when you next look. The web version does the same while a messaging screen is open, and closes it when you leave. The service notes that this connection is open, and forgets it when the app is closed. It is one flag with a time on it, it exists only so the server knows whether there is anything to deliver a message to, and it is not shown to other collectors, not used for the "Online" time above, and not kept as a history. It is erased with your account (section 9).

The Show When I'm Active switch, in Settings → Privacy & Safety, turns it off, and it works both ways on purpose: with it off nobody is told when you were last active, and you are not told about anybody else either. It also takes you out of every "active this week" filter — on the trade board and on the Trading feed — because a list of people who were around this week would otherwise say the thing you asked not to show. Accounts under 13 start with it off, alongside the private profile described in section 11. Switching it off stops the time being shown, not noted at all: the service still records when it last saw you, because that is how an abandoned anonymous account is recognised as abandoned (section 9) and how I can tell how many people are still using the app. What it stops is any other collector being told.

On a public profile, "your collection" means which sprites you have and which of them you have mastered, not only how many of each. Another collector sees both as a comparison against their own — what you have that they are missing, what they have that you are missing, and what you have finished that they have not — and the app shows the same comparison in a conversation with you. It is worked out from the collections themselves; nothing extra is collected for it, and going private takes it away along with the rest.

The leaderboards

Each of the arcade games in section 2 has four leaderboards — the best today, the best this week, the best this month, and the best of all time — which is twenty in all. Within a game they are the same list drawn four ways: the same people, the same information beside each name, ranked on a different one of the scores section 2 describes. A place on one of them earns nothing, for the reason section 2 gives. A game's boards are its own: a score at one game never appears on another's, and the games are not added up or compared anywhere.

Each lists the fifty highest scores, and beside each one it shows what a collector row anywhere else in the app shows: the display name, the character used as a profile picture, any decorations chosen for it, and the official mark where an account carries one. Plus the score. Nothing else travels with it — not your collection, not your streak, not how many people you have invited, and not the country your requests come from.

Only public profiles are on them. Go private and you can still play, still beat your own record and still see it; you simply are not listed, and the app says that is why rather than leaving you to wonder. A leaderboard is a published list of names, so it holds only accounts that already agreed to be found. This matters most for the people who never chose it: a profile belonging to somebody under 13 starts private (section 11), so those accounts are off the boards unless they have deliberately made their profile public. Being off the boards costs nothing beyond the listing itself.

A challenge card is the other place a score is shown, and it is a much smaller one: it sits inside a single conversation, it is seen only by the people in that conversation, and it shows the game, who opened it, and one number for each person who has played it. It is the one place a score belonging to a private profile can be seen by somebody else — and only because that person sent it there, or played the card themselves. Section 2 describes it. The short Friends list on each game's screen holds only accounts that are on the leaderboards anyway, under the rule in the paragraph above, so it shows nothing this section has not already described.

They are read in the app and in the web version, and nowhere else — not on the shareable web page below, and not on any of the written pages on spritecatch.com. A collector you have blocked is not on your copy of one and you are not on theirs, which is why the numbering can skip a place. And an account I have flagged for scamming is taken off every one of them, because a leaderboard is somewhere the app puts a name forward.

The web version added one board of its own, and it can be read without an account. It ranks public collectors against each other — by collection, by mastery, by completed trades, by the star rating those trades left, and by an overall score built from those — and each row shows the same things a public profile already shows: the handle, the display name, the Fortnite tag if you set one, the avatar, and the counts. Nothing new is stored about anybody to build it; it is those published numbers, sorted. The rule that decides who is on it is the same one as above and is the whole of its privacy: a private profile is not ranked, an empty collection is not ranked, an account carrying a scam warning is not ranked, and making your profile private in Settings takes you off it. A profile that starts private because the account is under 13 (section 11) is therefore off it from the beginning without anybody having to do anything.

Your profile as a web page

Every public profile has a shareable web address — spritecatch.com/u/<your username> — showing what another collector sees in the app, minus written reviews, scam-report text, the description you wrote, the character you designed, the official mark described above and which sprites you have mastered, all of which stay inside it. It still says how many you have mastered, as it always has — just not which. The page draws the app's own mascot for everybody rather than your character, so no choice you made about how you look leaves the app. No account is needed to open it, so treat it as public to the whole internet. Two things limit it: search engines are asked not to index it, and a private profile shows nothing at all. Going private takes the page down within minutes; deleting your account removes it.

That address used to contain a random code and now contains the username you chose, and that is a real difference. A random code was unguessable and told a stranger nothing; a handle you picked may be guessable, may be memorable, and may be one you already use somewhere else. The page itself shows no more than it did — but who can find it, and what it says about you before it is opened, is now partly your choice. The old code-based address still works, so nothing already shared has broken.

The same address can also be shared as an invite, and that version of the page deliberately shows nothing about you at all — not your name, not your collection, not even whether your profile is public. It carries only the handle or code the link was built from and an install button, and that is all, which is why it works the same whether your profile is public or private. See Invites in section 2.

The web version can look a profile up the same way, by username or by account ID, under the same public/private rule, and it can do it without an account. It shows more than the shareable page above does — it is the profile as the app draws it, so it includes the description you wrote, your reviews and your character — because it is the app, in a browser, rather than a card built for sharing. The public/private rule is the only thing deciding what it shows, and a private profile shows nothing there either. What you type into the search box is sent to the server to be answered, and I do not log who looked up whom.

Your posts on the web

The web version shows the real feeds, live, and a reader does not need an account to see them. The community feed, the trading feed, replies, reactions, likes and public profiles are the same ones the app shows, arriving the same moment they arrive in the app, under your real handle and display name. So a post you write in the app is readable in a browser by somebody who never downloaded anything and never signed in, and deleting it removes it from both at once. This is the same publicness section 4 has always described — it is not a new audience so much as a second door on to the same one — but it is worth stating plainly, because the honest test for anything you post is now "would I put this on a web page", and the answer to that has not changed since the day your profile got a web address.

What still needs an account is writing, and everything private. Posting, replying, reacting, boosting, trading, messaging, following, blocking, reporting and marking somebody all require you to be signed in. So do the lists that are not public in the app either — who owns a particular sprite, your own conversations, your own settings. Direct messages are never on the web at all, in the sense that matters: they are behind your sign-in, exactly as they are behind it in the app, and the paragraphs below apply to them identically wherever you read them.

An earlier version of this page described a fixed sample of about twenty real posts, published on the old web page with every author's name replaced by an invented one. That page is gone: no page of the web version shows that sample any more, and nothing reads the file it was built from. Section 13 records it. Nothing about it survives into what is described above, which is the live feed under real names.

Direct messages and groups

Private from other users — not private from me. No other collector can read them. But I run the server, so I can access anything stored on it, including messages, attached photos and voice messages, and I may review that content where I need to: investigating a report, dealing with abuse or a safety problem, answering a support ticket, or fixing a bug. Written messages are also screened automatically for banned content, the same way public posts are, and there is a safety program that can read whole conversations looking for strangers approaching children — though that program has been switched off since 30 August 2026, so no program on my server is reading your conversations as conversations today. Both are described under Moderation and safety below. A voice message is not — nothing listens to it or writes down what was said, which is the other half of the same promise: no machine of mine turns your voice into words, and no machine of anyone else's does either. It is reviewed only if it is reported, and then by me.

Before your first conversation the app shows you the safety rules — don't share where you live or go to school, don't send pictures of yourself, people can say they are someone they are not — and asks you to tick a box saying you have read them. That you have done so is stored on your account rather than on the phone, so that reinstalling the app or signing in somewhere new does not put you through it again; the date is all that is kept. It takes nothing away: you tick through it, and reporting and blocking are never behind it.

A short version of it appears again above each conversation with somebody new, and from 2 September 2026 you can turn it off. Closing it asks whether you mean this conversation or all of them, and offers the rules again; whichever you pick is remembered on the phone and nowhere else — no part of it reaches my server, and it is not part of your account. Turning it off comes back on from Settings → Privacy & Safety → New Chat Reminders, which is the row that also says what it is. Collectors of 18 and over are not shown it at all, worked out as described in section 4. None of that touches anything: reporting, blocking and closing a conversation stay in the ⋯ menu at the top of every chat, identically at every age and whether the note is on or off.

You can record a voice message instead of typing one. The app asks your phone for the microphone the first time, and your phone asks you — say no and everything else works as it did. Recording runs only between the moment you start it and the moment you stop — on iPhone by holding the record button, or after deliberately locking it so you can put the phone down; on Android by starting and then sending or cancelling. Either way nothing is sent until you choose to send it, and a recording you cancel never leaves the device at all. A sent voice message reaches the conversation you sent it to and nobody else — one collector, or everybody in that group — and it is deleted from my server after 30 days, unless the child-safety preservation in section 6 has stopped that clock — longer than the conversation needs and much shorter than a written message, because a recording of somebody's actual voice is not a screenshot. Your own phone keeps its copy of anything you have played, so an older message still plays for you after mine has gone.

You can delete a conversation — from the Chats list or from inside the conversation itself. It leaves your app, and your copy of the messages and photos in it goes with it. What it does not do is reach into the other collector's app: a conversation belongs to two people, and one of you deleting it cannot take the other's copy away — that would hand anyone who had just been reported a way to erase what they said. So the messages remain on the server as the other side's, until they delete the conversation too or delete their account. If they write to you again the conversation comes back, carrying only what is sent from then on.

You can also close a conversation, which is a different thing and reaches both of you. Deleting clears your own copy and the next message brings the conversation back; closing ends it. Neither of you can send anything into a closed conversation — no message, no photo, no voice message, no trade confirmation — and both of you keep everything that was already said. It is meant for the ordinary end of a trade, or for deciding you no longer want one, without having to block somebody to make the messages stop. The other collector is told: a line appears in the conversation for both of you saying it was closed and by whom, and both apps show it as closed from then on. I store when it was closed and which of you closed it, because that second fact is what decides who can undo it — only the collector who closed a conversation can reopen it, and the other has no way to, not even by asking to chat again. If you both close it at different times, it is whoever closed it last. Closing takes nothing else away: they are still on your feed and in search, you are still on theirs, and you can still report them or mark them as a scammer from inside the closed conversation. There is no notification for it — nobody needs a banner about a door that shut — and it does not delete anything. Whose list a closed conversation sits in, and where, is still yours to choose: it moves to Archived on your phone, and you can move it back.

A conversation can have more than two people in it. A group carries a name and, if somebody sets one, a picture — both chosen by the people in it and visible to all of them. Since 6 September 2026 that picture is checked for explicit content before it becomes the group's photo, and can be turned away; section 4 describes that check, including the fact that it is the one thing here that sends a picture to Google, and that it does not touch the photos sent inside the group. What I store alongside it is who is in the group, when each person joined, whether they have muted it, and how far each of them has read. The thing worth being blunt about is the reach: anything you send to a group — a message, a photo, a voice message — goes to everybody in it, which can be up to thirty-one other collectors rather than one, and up to 255 of them in a community room. Everything else on this page still applies to it, including that I can read what is stored on my server.

Anyone in a group can add other collectors to it, so a group can grow to include people you have never met. Nobody can remove anybody else from a group — leaving is always your own decision there, and when you leave, the conversation carries on for everyone still in it. If you are the last one out, the group and its messages are deleted. Communities work differently on that one point, and the section below says how.

Who can add you is your choice, and a stranger never simply appears in your list. Collectors you follow, or already have a conversation with, can add you to a group straight away; you can turn that off in Settings so they have to ask first. Someone you do not know always has to ask, whatever that setting says, and the invitation waits in Chats until you answer it. Until you accept, you are not in the conversation and cannot read any of it. When you do accept, you see the group from that moment forward — never what was said before you arrived. A community room is the one place that can work differently, because a room is somewhere you walk into rather than somewhere somebody puts you; the section below says exactly when, and what it can never do.

Deleting your account does not delete the group. Your messages, your photos and your voice messages in it are deleted with everything else, and your place in it goes; the conversation itself belongs to the other people in it and stays theirs. If you were the last member, it goes too.

Communities

A community is a public place, and that is the point of it. Anyone can start one, and by default anyone can find it and walk in. From the version going out on 7 September 2026, what is public about it is public to anyone who has its link, signed in or not: its name, what it is for, its picture, how many people are in it and how joining works. Every community has a web address — spritecatch.com/communities/ followed by its id — that shows exactly that and nothing else, so a link somebody pastes into a Discord server reads the same as the card inside the app; a community that is not listed in Find a Community still has that page, but it asks search engines not to index it. Who is in it is different: the member list is shown only to a signed-in collector who opens the community in the app, and never on the web page. If you would rather not appear on a list like that, the answer is not to join, and leaving takes you off it. From the same version the directory can also show you which of the people you follow are in a community — a count and a few of their faces on its card, and a short "suggested for you" list of communities where people you follow already are. It reads nothing new: who is in a community was already visible to anyone who opened it, and who you follow was already yours. Nobody is told that they appeared on your card. Three more things arrive with the same version. A want can be posted into a community you are in: it is the same post on the same board, with one more place it is listed — the community's own Wanted list, which only people in that community can open — and leaving the community does not take the want off the board. Inside a community you are in, the app can tell you how many of its members hold a Sprite you are missing and how many are missing one you own, and name them beside each Sprite; that is the same comparison the trading feed already makes for one collector at a time, made for the community's members at once, and it reads only collections that are public — a member whose profile is private is counted in neither number and named nowhere — and is shown to members only. And a post in the feed can point at a community its author is in: readers see a card with the community's name, purpose, picture and size and a Join button that does exactly what it does in the directory, and a post about a community that has since been closed keeps its words and loses the card. Because the picture really is public to all of them, since 6 September 2026 it is checked for explicit content before it becomes the community's picture and can be turned away — the same check, described in section 4.

From the version going out on 7 September 2026, whoever starts a community can mark it for collectors aged 18 and over. The mark is part of what is public about the community — it is drawn on its card for everybody browsing — and it is the one place in the app where the 18-or-over answer described in section 3 decides anything: my server refuses to let an account it does not know to be an adult start such a community, be invited into it, or join it, and says so rather than failing quietly. That is the server's decision off the answer it holds, never the app's off a number on the phone. It removes nobody who is already in — marking a community afterwards changes who may join from then on, and the room is told — and it permits nothing: the Terms, the rules and every way of reporting are the same inside a community marked 18+ as anywhere else.

What I store is the community itself, who is in it and when each of them joined, what each person is allowed to do there, and which of its rooms each person has joined. A community holds an Announcements channel everybody in it is in, and any number of smaller rooms people join for themselves — nobody is ever put into one. Everything above about a group applies to each of those rooms, because that is what they are.

A community's rooms can be set to keep their past messages for people who join later, and from 7 September 2026 that is how a new community starts. It is the one exception to the rule in the section above, and it is here for an ordinary reason: somebody who writes down what their community is for should not have to post it again every few days for whoever has arrived since. Whoever runs the community turns it on and off, for all of its rooms at once, in the community's settings.

Turning it on never reaches backwards, and that is the part worth being exact about. It takes effect from the moment it is switched on and no earlier, so anything said in a room before that moment stays visible only to the people who were already in it — nobody who joins afterwards can read it, and there is no setting anybody can turn on that changes that. Turning it back off means new members are once again shown a room only from the moment they arrive. Two things are untouched either way: a room you have cleared off your own list stays cleared, and none of this changes who is allowed into the room in the first place. A community that existed before that date has this switched off until somebody turns it on. The room itself is told when it changes, so nobody's messages quietly start being read by a wider group than they were written for.

From a future release, somebody can invite you into a community — and an invitation does not put you in one. It is an offer: I store that it was made, who made it and when, and you are sent a notification saying so if you have notifications switched on. Joining is still something you do yourself, and until you do you are in none of its rooms and on nobody's member list. What an invitation actually does is stand in for the community's own front door — if it is one that would otherwise ask somebody to approve you, or one only invited people can enter, the invitation is that approval, given in advance. Turning one down leaves nothing behind at all: the offer is deleted, the person who sent it is not told, and you can still walk into that community yourself later if it is open. An invitation you simply ignore looks exactly the same to them, which is deliberate. Nobody can invite you if either of you has blocked the other, and being invited is not something anybody but you and the person who sent it can see.

The person who starts a community can hand out the ability to run it, and people who can run it can take somebody out. This is the one place in the app where a decision like that is made by another collector rather than by me, so it is worth being exact about what it is and what it is not. Being removed ends your place in that community and all of its rooms, and stops you joining it again unless whoever removed you undoes it. You are told — the community stays visible to you, saying that you were removed and which of a short list of reasons was given. The reasons are a fixed list I wrote; nobody can type a sentence onto your screen.

Being removed from a community takes nothing else away. It is not a warning on your account, it does not touch your posting, your messages or your trading, and it changes nothing anywhere else in the app. It specifically does not close any door to reporting: you can still open that community, see who runs it, and report them — and you can write to support if you think it was a mistake. Nobody who runs a community can hide anything from you, ban you from the app, or reach anything outside their own community.

What a community keeps a record of. Every time somebody uses one of those powers — handing out the ability to run it, taking it back, removing somebody, letting somebody in, turning somebody down, inviting somebody, changing the settings — I record who did it, to whom, and when, including the times it was refused. Turning an invitation down is the one thing in that list I keep no record of, because it is your decision about yourself rather than a power somebody used over you. That record is mine and is not shown to anybody in the app. It exists so that a power one collector holds over another can be looked at afterwards, which is the only thing that makes handing it out reasonable at all. It is deleted along with everything else when either person deletes their account.

The person who started a community can close it, and nobody else can — not a moderator, and not anybody they have handed anything to. It is the only way a community ends from inside the app, and it cannot be undone. Everyone in it loses it and all of its rooms, at once and without being told: there is nothing anybody else could do about it, and a notice would only be an announcement of somebody else's decision. Nothing is erased. What was said in its rooms is kept exactly the way every other message on this page is kept — it stops being reachable, which is not the same thing — so a report about something that happened there can still be looked at afterwards, and your own messages in it go when you delete your account, along with everything else of yours.

From the version going out on 7 September 2026 the person who started a community can also hand it to one of its moderators, by typing its name to confirm; they stay in it as a moderator, the community itself and everything said in its rooms are untouched, and the Announcements channel is told in one line who runs it now. If instead they delete their account without closing or handing it on, the community carries on and passes to whoever they had made a moderator longest ago; if there was nobody, it is closed rather than deleted, because deleting it would take other people's conversations with it.

Communities are off when Community or Messages is off in Parental Controls, and both of those are already what they sound like. Nothing about a community is exempt from the rest of this page: what is said in its rooms is stored the way every other message is, and I can read it.

You can delete a request to chat — one you sent, once it has been answered or has gone quiet, from the list of them in the app. It clears your copy of that list, and where the request never got an answer it takes the request back as well: it leaves the other collector's app and they can no longer accept it. Unlike deleting a conversation, then, this one does reach them — but only the ask, never a chat: a request somebody accepted leaves the conversation it opened exactly where it is, for both of you. Because taking a request back also closes it, you cannot ask that collector again for a day. The record that you sent it stays on the server, and that part is deliberate. It is what limits how many times one person can be asked, and what holds someone's answer of "not again today" — so a delete that erased it would turn tidying your own list into a way around both.

You can unsend a single message — hold it and choose Unsend. This one does reach the other collector's app: the message disappears from both conversations, and neither of you can open it, read it or see its photo again. What it leaves behind on both sides is a line saying a message was unsent, so the other person can see that something was taken back rather than finding a silent gap in a conversation they were reading. A voice message in it is deleted outright.

What unsending does not do is erase it from the server. The words stay, and since 24 August 2026 so does the photo. Both are kept where neither of you can reach them and I still can. That is deliberate, and it is the same reason deleting a conversation cannot reach your copy: without it, unsending would be a way for someone who has just scammed you to strip what they promised out of your app before you could report them — and when the thing they sent was a picture, the picture is usually the whole of what happened. This is a change from what this page said before, which was that an unsent photo was deleted for good; that was true until 24 August 2026, and photos unsent before then really are gone. A kept photo is read for the same narrow reasons kept words are, listed above. It is never shown to the other collector, never published and never used for anything else, and deleting your account removes it along with everything else (section 10).

Your reading copy is kept on the device you read it on, and your conversations follow your account. Messages, the photos in them and any voice message you have played are saved on the device, so a conversation opens instantly, works offline, and does not have to be fetched from the server every time you look at it. A message you write that does not reach the server — you were offline, or the connection dropped — is kept there too, so that it is still waiting to be sent when you come back rather than quietly disappearing. Signing in on a new phone, or on the web, brings your conversations with you: opening one downloads it from the server, and there is a button at the top of it that loads the rest, back to the first thing either of you said. This is a change from what this page said before, which was that everything above the last message stayed on the phone it arrived on and was not downloaded onto a new device. That was true of the apps until 6 September 2026 — never of the server, which has kept every message throughout — and what it meant in practice was that changing phone left you looking at your own conversations with the words missing. The saved copy is still deliberately left out of device backups: the server is what your history survives on. You can see how much space it is using on the device in your hand, and delete all of it, under Settings → General → Storage. That clears that device only: it does not close a conversation, delete your account, or reach the other collector's copy — and because the conversation is on the server, opening it again downloads it again.

I access message content when there is a reason to, not as a routine — but I am not going to promise you a technical limit that does not exist. Nothing you send is encrypted in a way that would stop me reading it. One other company handles it: if the person you are writing to has notifications switched on, the notification that tells them about your message carries the message, so it passes through Apple's push service on its way to their phone — the same route every notification on an iPhone takes, and the reason the message is waiting for them rather than being fetched when they tap. Nobody else receives it. Please do not put anything in a display name, Fortnite tag, trade note, post or message that you would not want a stranger to read.

Support conversations

When you write to support, the ticket is read and answered by me — and, since 9 September 2026, with the help of a scheduled assistant that works the queue alongside me and is described in full a few paragraphs below. It is never published, never shown to other collectors, and never used to decide what you see in the app. You can attach a photo to a message, which is what most people do when something is broken: a screenshot says in one picture what a paragraph struggles to. It is stored with the ticket, and it is not published anywhere. Who can open that photo depends on why you sent it. On an ordinary ticket — a bug, a suggestion, a question, an appeal — it is readable by you and by that same small group and by nobody else, and nothing automatic looks at it. On a ticket claiming a reward, where the picture is the whole proof and the assistant is what settles the claim, the assistant can open it too; that is the one kind of support photo it may ever see, and the paragraph below says why. Photos are optional — a ticket with no picture works the same way — and the app resizes the one you send before it goes, which also strips the details a camera records with a photo, such as where it was taken. You can pick a photo from your library or take one on the spot; either way it is the same picture going the same place, and nothing is sent until you send it.

The app asks to see your recent photos, and that is all it does with them. When you attach a picture anywhere — a message, a support conversation, a reward claim — the app shows the most recent ones on your phone in a strip, so picking a screenshot does not mean hunting through a whole library. Those pictures are read on your phone to draw that strip and for nothing else: the app reads the full picture only for the one you tap, sends nothing until you press send, and never adds anything to your library or removes anything from it. It does not look at, index or upload the rest. You can refuse and lose nothing important — the picker that has always been there is one tap away in the same place, and it hands over only what you choose without the app seeing your library at all. iOS also offers to share selected photos only: the app treats that as a yes, shows what you shared, and gives you a way to change the selection.

There is one exception to being answered, and it is about repetition rather than about you. If somebody writes in again and again about something I have already answered in full, I can set that person's tickets aside for a while so the queue is not one collector deep while everybody else waits. Nothing else changes for them, and I mean nothing: they can still open tickets on the same daily limit, the automatic reply still answers what it can, the conversation still stays open at their end for the usual thirty days, and nothing anywhere in the app is deleted, hidden, restricted or held against them. Their tickets are stored exactly as everyone else's are. What I keep is a note to myself — the account, why, the date, and the date it ends. It always ends — three months is usual and a year is the longest — because writing to support is what I ask you to do when you think something has been done to your account quietly, and I am not willing to close that door for good. And it never covers a report about somebody's safety: a ticket filed through Report someone reaches me in the ordinary order whoever sent it.

Support does not pass through Discord, and never has. An arrangement for volunteer moderators to answer part of the queue from a private staff channel was described here in August 2026 and then dropped; it was never actually switched on, no ticket ever reached that channel, and the connection between support and Discord has since been removed from the app altogether. Nothing you write to support has ever reached Discord or a moderator — it comes to me and to nobody else. See section 13.

An automatic reply answers some questions straight away. A lot of what arrives is a question the app's own help already answers — how to unfollow somebody, how to get a profile frame, how to move a collection to a new phone — and waiting a day for me to type that out helps nobody. So the first message of a new ticket is checked for a handful of phrases, and if it matches one of the questions I have written an answer to, that answer is sent back within seconds. There is no artificial intelligence in this one and nothing about it is sent anywhere to be read: it is a list of words and a list of answers, both written by me, on the same server that already holds the ticket. (The scheduled assistant described below is a separate thing, and it is not this.) It is not a chatbot you talk to — it looks at one message once, when the ticket is opened, and never again.

Five things about it are worth stating plainly, because they are the reasons it is safe to have. Its replies are labelled — an automatic one says so on the message, so you always know whether you are reading me or a machine. It never decides anything about your account. It cannot warn you, suspend you, lift a warning, hand out a decoration, change a setting or touch your collection; the only thing it can do is send one of the answers I wrote. Whole kinds of ticket never reach it at all: appealing a warning, reporting someone for a scam or for safety, claiming a reward, anything with a photo attached, and anything from an account carrying a warning — those go straight to a person, by design, because they are decisions a person should make. So does anything mentioning money, a refund, a ban or your own account, whatever else is in it. And when nothing matches, it says so and hands the ticket over; the ticket stays open and waits for a person, exactly as it would if none of this existed. A ticket you attached a photo to is the one it does not write to at all — it is passed on without a word, because those tend to arrive in bulk and a form letter would only get in the way. Either way the app confirms on screen that your message was sent, and nothing is waiting on a reply from a machine.

A ticket the automatic reply answers is then closed, and that is worth knowing before it happens rather than after. Those answers are complete, so the conversation has nothing left in it — but it does mean you cannot write again in that same thread. The reply says so at the bottom and tells you what to do instead: open a new ticket, and it comes to me. Nothing about that loses anything you sent, and every message either of us wrote stays in the app for you to read.

There is one kind of support conversation where the photo is the point rather than an extra. Some rewards ask you to do something outside the app — using a creator code in Fortnite's item shop is the first of them — and since nothing here can check that for you, the app asks you to send a screenshot of it and I look at the picture myself. That conversation records which reward you are claiming, so that I can give it to you once and the app can stop offering it. Three things follow from it being a screenshot of another app: it may show your name or tag in that game, so send only the part that shows what you did; it is read by me and by the scheduled assistant described below, and by nobody else; and it is never sent to Epic Games — the only thing this app ever asks Epic is whether an account you chose to link is yours, which section 2 describes. Claiming is entirely optional — the reward is a decoration for your profile, nothing in the app is behind it, and ignoring it costs you nothing.

The scheduled assistant

Since 9 September 2026 an assistant works through the queues on a schedule, and it reads what is in them. This is the one genuinely new thing on this page, so it is set out plainly rather than folded into a sentence somewhere. Support is one person in one time zone, and the cost of that has always been paid by whoever was waiting: a reward claim sent on a Friday could sit until Monday, and a review somebody had been marked with unfairly stayed on their profile until I got to it. So every few hours a session of Claude, made by Anthropic, PBC, opens the same queues I do and works them.

What it reads. Three things, and nothing else: the messages on a support ticket; the screenshot on a ticket claiming a reward; and a conversation that the safety measures further down this section have already singled out. It reads one of those at a time, by name, because a queue handed it that one — it cannot search, cannot browse and cannot go looking through anybody's messages. Anthropic processes what it is shown on my behalf, as a service provider: it does not keep it and does not use it to train anything. Section 6 names them alongside everybody else who handles information for me.

What it does not read, and these are the limits rather than the defaults. A voice message is not read by it, and nothing anywhere turns one into words — the promise made further up this section is exactly as absolute as it was. A photo on a support ticket that is not a reward claim is not readable by it at all: a screenshot of a bug, a picture attached to an appeal, anything else you send me stays between you and me, and that is enforced rather than intended. It is never asked to recognise a face and cannot be. And it is not given a conversation because somebody reported it or because it felt like looking — only the safety measures below put one in front of it.

What it can do, and what it deliberately cannot. It can do the things that would otherwise be waiting for me: give you a decoration you claimed, write you an answer, close or set aside a ticket, and take down a review or a scam mark where an appeal holds up. Everything on that list is something I can undo in under a minute, and that is the test for being on it. It cannot restrict your account. It has no way to ban, mute, hide or shadow anybody: where it thinks an account should be paused it records that as a request, and whether anything happens is decided afterwards by the same unchanged rules that decided it before — which still refuse to overturn a decision a person made, and still make anything decided this way expire on its own. It cannot delete an account or anything in one, and a report about somebody's safety is never answered or closed by it: those reach me, always, and the app refuses to let it answer one at all.

Its replies say so, and there is a record of what it opened. A reply it writes on a support ticket is labelled Automated reply, exactly as the automatic answer above is, so you are never guessing whether you are reading me or a machine. A message it sends in a conversation carries no such label — there is nowhere to put one — but it comes from the Sprite Catch Team account and never from a person's. And each time it opens a ticket, a claim screenshot or a conversation, a line is written down saying which one it opened and when — not a copy of it, the same way the safety records described in section 9 keep what was looked at rather than the thing itself. That record exists so that this is reviewable rather than something you have to take my word for.

If any of this is not something you want, support is not the only way to reach me: the address in section 14 goes to a person and to nothing else.

Moderation and safety

Because people can post, trade and message, the app has to be moderated. Text posted publicly or sent in a message is screened automatically before it sends. Web addresses are refused everywhere except inside a conversation two collectors have already agreed to have — not in a post, a display name, a profile description, a trade listing, a group's name, or the note attached to a message request — and tapping one in a conversation shows you where it goes, and a warning that nobody has checked it, before anything opens. The app has no browser of its own: a link you choose to follow opens in your phone's browser, outside Sprite Catch, and nothing about the visit comes back here. Photos attached to messages are looked at automatically as of 29 August 2026, which is a change from what this page said before — until that date they were never scanned on my server, only stored as sent and moderated when somebody reported them. What changed is described a few paragraphs below, under the safety program, which looks at pictures only for the small number of accounts something else has already singled out, and looks for one account showing different faces to different children. And from 5 September 2026 there is a second, separate check that does run on every photo sent in a conversation or a group, as it is sent. It asks one question — whether the picture is sexual and whether the person in it appears to be a child — and it exists because of the one thing this app is obliged to report, described in section 6. It runs on Cloudflare's own service, the same network that already runs everything else here; no photo of yours goes to another company, and in particular a message photo is still never sent to Google. It cannot recognise a face and is not allowed to learn how. It never looks at a photo attached to a support ticket, and it never touches a voice message. Today it turns nothing away: it is recording its answers rather than acting on them while I find out how it behaves on real photos, and this page will say plainly on the day that changes. What it writes down is two words about the picture and a fingerprint of the file — never a copy of it, and never a description. Separately, since 25 August 2026 a photo can be covered with a warning before you see it, and that one is still your own iPhone's check running on your own device and telling nobody, including me: section 3 explains it, and it does not change what is stored here or who can read it. You can block another user, and report a user, trade, post or message; I review reports and can remove content, reset a collection or reputation, and suspend or delete accounts that break the Terms. To do that I may need to read any content stored on the server, including a private message, whether or not it was the thing reported — context usually sits around it.

From 29 August 2026 one of the reasons you can pick when reporting an account is that they appear to be under 13. The community is a 13+ part of the app, and until now there was no way to tell me about an account that clearly is not — so the only thing that ever established an age was the account's own answer. What a report of this kind does is put the account in front of me to look at; it is a message about somebody, not a finding about them, and it is treated that way. It never restricts an account on its own, and it is deliberately not weighted like a report of harassment or of a scam, because "report them as a child" is free to file, impossible to disprove, and would otherwise be an easy way to push somebody to the top of a queue out of spite. As with every other report, what is stored is that you filed it, against whom, and anything you wrote with it.

Being blocked does not stop you reporting someone, and from 29 August 2026 it no longer takes the conversation away from you either. A block still hides the two of you from each other everywhere else — profiles, posts, trades, search — and it still stops anything further being sent between you, in either direction. What changed is which side loses the conversation. If you block somebody, their conversation disappears from your list, because that is what you asked for. If somebody blocks you, the conversation stays where it was and you can still read what was said in it; you simply cannot reply, and Report sits where the message box used to be. The messages were sent to you and are already on your phone, so this hands you nothing new about the other person — it stops someone who takes your sprite and blocks you from also deleting, from your side, the thing you would report them with. For the conversations that genuinely do disappear — the ones you blocked away, and ones you had already deleted — the app still keeps a list of who they were with, the other collector's name and picture only and never the messages, so a block is never a way out of a report or a public scam mark.

Closing a conversation is not blocking, and neither is a way out of a report. The two are easy to confuse because both stop the messages, so the difference is worth stating: a block hides the two of you from each other everywhere — profiles, posts, trades, search — while closing a conversation touches nothing but that conversation. You still see each other, you can still follow each other, and the whole transcript stays on both phones. What closing adds that blocking does not is that it is mutual and mutually visible: it stops you writing too, and both of you are told it happened. Reporting, and marking somebody as a scammer with the conversation as evidence, work inside a closed conversation exactly as they do in an open one — for the same reason being blocked no longer takes the transcript away.

From 1 September 2026, blocking one of the moderators no longer hides you from them. Until that date it hid everything: your profile, your posts, the replies under them and your name in search all disappeared from the one account with a button to act on any of it, while every other collector went on seeing the lot — so blocking a moderator was a way of switching off, for yourself, the only moderation that happens inside the app. Three things bound the change, and each is a limit in the app rather than a promise about anybody's behaviour. It runs in one direction only: your side of the block is untouched, so a moderator you have blocked is still gone from your feed, your search and your profile, and blocking one is still how you stop seeing them. It covers reading and nothing else — the block still refuses a follow, a message request and a reply from them, in either direction, so being visible to a moderator is not the same as being reachable by one. And it applies only to the few accounts I have granted that permission to, not to anyone wearing a mark: what they can see is still only what you have already posted in public, and everything in the paragraph below about what moderating does and does not include is unchanged.

Moderation runs both ways. If I put a warning on your profile and you think it is wrong, appeal it from inside the app (menu → Support); I read the appeal alongside whatever the decision rested on, reply either way, and take the warning off if I got it wrong. What I will not do is have the same argument for ever: if you appeal a decision, get an answer, and then keep re-filing the same appeal, I may set your tickets aside for a while rather than keep replying — see Support conversations in section 4 for exactly what that does and does not mean. It changes nothing about your account, and it always ends.

From 4 September 2026 every decision a moderator makes is sent to me as it happens, and a decision can name more than one thing. Nothing new is collected by either half. On the first: the record of what the moderators do has existed since the day they got the power, and it lived only in the operator tools I have to go and open — so a decision I would have questioned could sit unread for a week. Each one now reaches my phone as it is made: who acted, whose account it landed on, and what they said it was for. Attempts that were refused are sent too, which is the half that matters most, because somebody repeatedly reaching for an account they are not allowed to touch is the clearest sign I gave the wrong person the power. The moderator's private note is not in it — that stays in the operator tools, where it always has, and the rule that it never reaches a phone is one I would rather keep whole than make an exception to for my own. On the second: a moderator taking something down used to have to pick a single reason for it, so a post that was both an attempt to sell Sprites for money and the sixth copy of itself that hour was filed as one or the other. It can now carry several, and you are shown all of them on your own Account Standing screen rather than whichever one happened to be picked. What is on that screen is unchanged in every other respect: still the categories and never anybody's free text, still nothing about your messages or your photos, and still nothing that arrives as a notification — a decision is there when you look.

Selling Sprites for real money is now something you can report in as many words. It has always been against the Terms and has always been something I act on; what it did not have was its own reason in the report form, so anyone reporting it had to file it as a scam or as spam and hope the description was read. It is treated as a trading complaint rather than as an abuse report, which is a statement about how it is ranked in my queue and not about how seriously it is taken.

From 2 September 2026 you can see how your own account is doing, and why. Settings → Account Standing shows a colour and a sentence — good, something to watch, limited, restricted — together with a list of what has been decided about your account: what happened — a post or a reply removed, posting paused, a scam mark filed — what it was for, roughly when, and when it stops counting. Almost everybody who opens it will read “good standing”, and being able to say that is most of why it exists. Most of what lands on that list is a decision a person made: a post a moderator removed, a pause a moderator applied, or a scam mark a moderator filed with the evidence they had. Two things can add to it without a person: being reported by several separate people for something serious, and an automatic check for one narrow thing — asking different collectors for gift-card codes or free V-Bucks, which is against the rules and is how a lot of money gets taken from children here. Each says on the screen which of the two it was. A single ordinary report, or a scam mark from one other collector, does not put anything there on its own. Nothing on it is permanent — every entry stops counting after a set time, on its own, and an account that stops goes back to good standing without asking anybody. As standing falls the app pauses things in steps: first nothing at all, then posting and replying, then also starting new chats and posting trades. Anything paused comes back by itself, and the screen says when. It is yours alone: nobody else can see it, there is no way for another collector to look it up, and it does not appear on your public profile or your web profile. The notes a moderator writes for me are not shown to you; what you see is the category and the date. If you think something on it is wrong, the appeal path is the one described above.

One thing that screen deliberately does not tell you. The sentence under each level says your posts may reach fewer collectors and your messages may not send a notification. That wording is the same for everyone at that level, whatever is actually true of your account — it describes the policy rather than reporting your own settings, because as described above the measures that hide content are not announced to the account they apply to, and a screen that varied would announce them.

Some public posts are held back to protect the person who wrote them. A post that says how old the writer is and asks strangers for a relationship — or that hands out an address, a phone number or an account name somewhere else alongside something like that — is kept out of the feed automatically. It is not refused and it is not deleted: the writer still sees it in their own feed exactly as they wrote it, and it simply reaches nobody else. The fact that a post was held, and which of those patterns it matched, is stored with the post so that I can review it and put it back if the app got it wrong. This is aimed at one thing only — a child broadcasting to strangers how old they are, what they look like and where they live — and it is deliberately narrow: talking about where you live so two of you can work out a time to trade is not this, and is not affected.

A moderator's scam mark now says what it is for, and yours does not. From 2 September 2026, when one of the moderators marks an account, the profile carries a short line naming what they say they saw — that they watched it happen, that the account was selling for real money, that a trade went one way, that somebody was pretending to be another collector or to be Sprite Catch, or that other collectors reported it to them and it is second-hand. The same line is shown above a conversation with that account, because a trade happens in the conversation rather than on the profile. Two things about it. The words come from a short fixed list the app translates, plus whatever the moderator chose to publish in the public review they wrote — which was already on that profile under their name; the private note they wrote for me is not part of it and never will be. And a mark from an ordinary collector does not do this: those are counted rather than quoted, and only once several different people have left one does a profile carry a warning at all, for the reason described just below. If a moderator's mark on your profile is wrong, the appeal path is the one above.

A mark you left is yours to take back. If you marked someone as a scammer by mistake, or the two of you sorted it out afterwards, you can take your own mark off their profile from inside the app — open their profile and undo it. It comes off, it stops counting against them, and the report that went with it is withdrawn from my queue. There is no time limit on that. What it cannot do is remove anyone else's mark or a warning I put there myself: the first belongs to whoever left it, and the second is what appealing, just above, is for.

The reporting tools get abused too — most often by someone just marked as a scammer marking everyone back, which puts public warnings on people who did nothing. Where I see that, I can withdraw that account's ability to file: its reports are then discarded rather than stored and affect nobody. Because that pattern is fast and the damage lands on other people's profiles, it can also be applied automatically, when what an account files has a shape a real report does not: filing far more in a day than anyone reporting a real problem ever does, or filing against the app's own account, which is not something a report can be about. If you have a problem with the app itself, or with something I have done, write to me through Support (menu → Support) — that reaches me, and a report filed against my account does not. From 2 September 2026 the same protection covers the handful of accounts allowed to moderate the feed, and it works differently in the half that matters. A public scam mark aimed at one of them is discarded and never lands, because the reliable answer to being paused is to mark whoever paused you and a few annoyed collectors would otherwise put a public scam warning on the account the app asked to police them — but an ordinary report against a moderator is written down and reaches me exactly as any other report does, and filing one costs you nothing. A moderator abusing what I gave them is precisely the thing I need to be told about. Whichever way it happens, a person can see it, review what was filed, and undo it. The same applies to the feed — an account that keeps posting spam, scams or abuse can have its posts and replies withdrawn, still stored and still shown back to its author, but seen by no one else. And the same applies to messaging: an account that keeps sending abuse or harassment in private can have its chat requests and messages withdrawn the same way — still written, still shown back to the sender in their own copy of the conversation, but delivered to nobody and never notified to anyone. And where the problem is the pictures themselves, I can stop keeping an account's photos altogether: what it sends in a message is discarded instead of stored, and any message carrying one reaches nobody, though the sender's own phone still shows it back to them. Since 1 September 2026 it covers a photo attached to a post in the same way, which it did not before — the feed gained photos on that date, and a measure aimed at pictures that stopped at the private half of the app would have missed the public one. A photo attached to a support ticket is always kept, including from an account this has been applied to — a support photo is seen by the person who sent it and by me, by the scheduled assistant in section 4 where the ticket is claiming a reward, and by nobody else; it is usually the screenshot I asked for to settle a reward claim, show me a bug or appeal a decision, so throwing it away would take away their way of showing me something rather than take away anybody's way of being shown it. The measure is the only one here that keeps less rather than hiding more, and it cuts both ways: there is nothing left for me to look at afterwards, and nothing to put back if I lift it. It is also the only one that reaches backwards: unless I choose otherwise it takes the pictures that account has already sent as well, in messages and on tickets both — the messages stay and still read as conversations somebody sent a picture in, the pictures themselves are gone, and there is nothing to restore. Anything else sent before one of these decisions is untouched, and lifting one does not deliver what it held back. I keep a record of each such decision — the account, date, reason, and how much it covered — so it can be reviewed and undone. None of these measures is announced to the account it applies to, deliberately: naming it just tells the person to start again with a new account. If you think one has been applied to you, contact support and I will tell you, and undo it if I was wrong. The pause described in the next paragraph is the exception, and it is announced on purpose.

One caveat on the sentence above, added on 5 September 2026: the only case where I might not answer you is the repeat-tickets one described under Support conversations in section 4. It changes nothing about your account, it always ends, and it never covers a report about somebody's safety.

From 29 August 2026 a small number of trusted collectors can moderate the feed, and I am no longer the only person who can take a post down. Until now every one of the decisions above was mine alone, which meant the feed was only ever tidied as fast as one person noticed. So a few people I choose by hand can now, from inside the app, remove a public post — or a single reply under one, from 2 September 2026, which leaves the post and every other reply where they are — and pause the person who wrote it from posting for a while. Four things bound what that gives them, and each is a limit in the app rather than a promise about their behaviour. They see nothing you have not already made public — a moderator reads the feed like any other collector, with the single exception described just above (from 1 September 2026, blocking one does not take you out of it), and none of this reaches your private messages, your photos, your collection or your account details. They cannot do anything silently: the measures above, the ones that work by never telling you, stay mine alone, and the only thing a moderator can do to your account is the pause below, which says plainly that it happened. Nothing they do is permanent or unreviewable — a post they remove is kept exactly as your own deleted posts are, and I can put it back. And a record is kept of everything they do: who acted, on whom, when, why, and anything they wrote about it, including the attempts the app refused. That record exists so their decisions can be reviewed, and it goes when either account is deleted. Being able to moderate is something I grant and can withdraw; it is not something an account can earn, buy or ask for.

From 2 September 2026 the moderators can read that record too, for one collector at a time, and they can undo their own decisions. Until now each of them could act and none of them could see: two could pause the same person without either knowing, and none of them had any way to lift a pause once it was applied. So a moderator looking at a collector can now see whether that account is currently paused, what for, until when and which of us applied it, together with the list of decisions already made about it — and can lift a pause or take back a scam mark they filed themselves. Three limits on that, and each one matters more than the feature does. It is the decisions and never the words: the categories, the dates and who acted, and never the private note a moderator wrote for me, which still goes to me and to nobody else. It reaches nothing else about you — not your standing screen, not your messages, not your photos, not your collection, not your account details, and nothing about the silent measures further up this section, which stay mine. And a moderator can only take back their own mark, never somebody else's. Undoing goes on the record like anything else, and where a moderator says the decision was wrong rather than merely finished, the entry on your Account Standing screen is marked as removed and stops counting. This is the same information those accounts could already act on, read by the same accounts, and it is a new group of people able to read a record about you — so it is written down here rather than left as an implementation detail.

If your posting is paused, you are told so, and told why and for how long. This is the one measure on this page that is deliberately visible. It lasts between an hour and seven days, or until I lift it, and while it runs the app shows you a locked box in place of the one you write posts in, carrying the reason it was applied — chosen from a short fixed list, so what you read is the app's own wording in your own language and never something a moderator typed about you. If a moderator did write a private note, it goes to me and is never shown to you or to anyone else. A pause stops new posts and new replies and nothing else: your collection, your trades, your conversations and everything already posted are untouched, and it does not follow you to another account. It is meant to be the opposite of the silent measures above — something you can see, understand and, if it is wrong, appeal through Support (menu → Support).

A post you delete stops being visible immediately, but I keep a copy for 90 days. When you delete one of your posts, or a reply, it goes from the feed, from search, from your profile and from your own screen right away — nobody in the app can reach it again, including you. What happens underneath is that it is hidden rather than erased: I can still read it, and only I can, for 90 days from the moment you delete it. After that it is erased for good, automatically, along with the reactions and replies that went with it. One thing outlives it, and it is a number rather than anything anybody wrote: how many reactions your posts have collected in total is part of what your own profile shows and what the achievement badges count, and deleting a post no longer takes that total back down. Nothing about the post is kept in it and nothing about who reacted — just the running count, which is yours, which you can already see, and which goes when your account does.

The reason is that the posts most worth looking at are often the ones taken down a few minutes later — a scam offer, a threat, someone posting another person's details — and until this change, deleting one also destroyed the only evidence of it, including for reports already filed about it. Deleting a post is still the way to take back something you wish you had not said, and it still works instantly for everyone else. It just is not a way to remove something from my view before I have had a chance to look at it. The same 90 days apply when I take a post down myself. Deleting your account is different and is not affected by this: that erases your posts outright, including any that were waiting out these 90 days (section 9).

Some of that checking happens on your own phone. As well as the screening above, the app can recognise — on your device, as you send — a few specific things a message asks a stranger for: how old they are, whether they are a girl or a boy, a picture of themselves, to carry on the conversation somewhere else like Snapchat or Discord, and to meet up or get on a call. When it recognises one, your phone tells the service only which of those kinds it was, and which conversation it was in. Your phone sends the message itself nowhere for this, nothing is scored on it, nothing is kept about how you write, and messages that match none of them — nearly all of them — leave no record at all. That is a statement about this check, on your phone; what a message stored on my server can be read for is described just below and in section 4. Asking one person one of those questions is ordinary and means nothing on its own; the same questions put to several different people is the pattern this exists to catch, and reaching that point can hold an account's messages back automatically for 24 hours, exactly as described above. Only the first three of those kinds can ever add up to that; the other two are recorded for me to read beside something else and never count towards it on their own. It never refuses to send anything, and a person reviews every case afterwards and can undo it. It exists because this app is used by children.

Your phone also warns you about messages you receive, and this half involves the service not at all. When a message arriving in one of your conversations asks for a picture of you, asks you to move to another app, or asks to meet or call, the app puts a short note under it saying so. That reading happens on your own device, on a message already sitting on it, and the answer is drawn on the screen and thrown away: nothing about it is sent to me, nothing is stored, and I have no way of knowing that any of it was ever shown to you. It is a caution about a message, not a judgement about the person who sent it.

Your phone also checks a post before you send it. As you write a post or a reply, the app reads what you have typed — on your own device, before anything is sent — and tells you either that the word list below is going to refuse it, or that it breaks one of the feed's rules: offering sprites for real money, gift cards or free V-Bucks, arranging in-game gifting, or moving someone off the app to finish a trade. If it reads as though you are accusing another collector of scamming you, it offers to file a report instead, because that is the thing that actually reaches me and a post is not. None of that reading is sent anywhere. What you typed, what was pointed out to you, and how often, reach me nowhere and are stored nowhere — including everything you thought better of and deleted before sending. It never sends anything on your behalf and it decides nothing about your account. When you do send the post, it is screened on my server exactly as described above; this is the same check run early, so that you find out before you have written a paragraph rather than after.

The safety program described next is switched off, and has been since 30 August 2026. It ran for a single day, from 29 August 2026. No program on my server reads a whole conversation today. Photos are a different matter since 5 September 2026 — the per-photo check described above under “a second, separate check” does run, on every picture sent in a conversation, and it is not this program. Everything else in this section is unaffected, and some of it does read written words: the word list below still screens each message as it sends, the check further down still holds back a public post that puts a child at risk, reports and blocks still work, and I still read what is reported to me. I have not removed the program — it is still built into the service and I can switch it back on — so it is described here in full, and this page will say so plainly on the day it runs again. What follows is what it does while it is running.

What it does when it is running: it reads written words on my server. The screening above is a word list: it looks at one message at a time and can only catch what somebody actually typed. It cannot tell the difference between a collector asking for a picture of your locker, which is how a trade is agreed here, and a stranger asking for a picture of you. So, while it is running, a few times an hour the program reads whole conversations — both sides, the way a person would — along with public posts, replies, and the note attached to a message request, and writes down what it thinks is going on and why. It looks at a small number of accounts each time, chosen because something about them stands out: they have opened conversations with several people who do not know them, somebody has reported them for something serious, or your phone's own check above has flagged them. It is there for one thing — strangers approaching children — and it exists because the pattern it looks for takes weeks to notice by hand and minutes to run.

It reads the pictures too, and this is the part that changed on 29 August 2026. Until then it read only writing. It also looks at photos sent in conversations — but only the photos of the same small number of accounts it was already looking at, and never a photo attached to a support ticket, which is still read by a person and by nothing else. That this program is not a per-upload check is still true of this program, and no longer true of the app: the separate check added on 5 September 2026, described earlier in this section, does look at every photo sent in a conversation. They are different things and this page keeps them apart on purpose.

What it is looking for in a picture is a pattern across conversations, not a face. It answers a short list of questions about each photo — is there a real person in it or is it a screenshot of the game, roughly how old they look, whether the picture is sexual — and then compares the answers between conversations. An account sending a picture of one person to one collector and a picture of a different person to another, each presented as themselves, is the thing this exists to notice. It is the commonest way an adult gets a child's trust in an app like this one, and it has happened here. It cannot recognise a face and it is not allowed to learn how. Nothing here builds a faceprint, nothing measures anybody's features, and no picture is matched against a picture of a named person: that would be biometric information about a child, which is a different kind of thing entirely and is not something this app collects. The one exact comparison it makes is whether the same image file was sent to several people, which is what a stolen photo looks like and which says nothing about who is in it.

A voice message is still not touched at all — nothing turns your voice into words, which is a promise made elsewhere on this page and this does not go near it. And none of this ever blocks or changes a message, or a photo, as you send it.

What it can do on its own is hold an account's messages back for seven days, the same silent measure described above and no other. It is deliberately hard to reach: the program being sure is not enough on its own, and something independent — a report somebody filed, or your phone's own check — has to point the same way before anything happens at all. Everything else it finds is written down for me to read and nothing more. It can never delete anything, never make a decision permanent, and never overturn one I have made. The seven days run out by themselves whether or not anyone looks.

A person reviews what it decides, and can undo it. Every judgement it makes is stored with its reasons and the messages it was looking at, and I read them; where I agree, the decision becomes mine, and where I do not, I remove it. As with every measure in this section it is not announced to the account it applies to — for the same reason, that naming it just tells someone to start again with a new account. If you think this has happened to you, write to me through Support (menu → Support) and I will tell you, and undo it if it was wrong. You are entitled to ask a person to look at any decision made about you this way, and that is how.

What it writes down about a photo is a description, never the photo. No copy is made and no picture is moved anywhere: it reads the one already stored, keeps a short line about what it saw and a fingerprint of the file, and that record is deleted with your account like everything else. Where a picture looks like it may be child sexual abuse material, even that line is withheld — the record says only that a person must look, and a person does.

The program runs on Cloudflare's own service, on the same network that already runs everything else here, described in section 6. While it is running, your messages and your photos are sent to it to be read and are not stored there, not used to train anything, and not given to anyone else.

5. Why we use information

Nothing about you is sold. Your collection, your posts, your messages, your questionnaire answers and your usage information are not sold, are not used for advertising, and are not used to build a profile of you across other companies' services.

6. Who we share information with

Everybody named here handles information for me, or is a company you have your own relationship with. Nobody buys anything about you, because nothing about you is for sale.

Handled on my behalf. These three process information as service providers and do nothing else with it:

The Android app adds one thing, and it is the notification service described above. There is still no analytics SDK, no advertising SDK, no crash reporter and no advertising identifier in it, and Android's automatic cloud backup is deliberately switched off so nothing — not your sign-in, not your collection — is copied into your Google Drive. The trade is that turning notifications on means Google's messaging service holds an identifier for your installation for as long as they stay on. Nothing else about the Android app reaches Google beyond distributing it and a sign-in you chose to start. The web version adds nobody at all — no third-party script, font or CDN beyond Cloudflare, and that survived it becoming a full version of the app: nothing on any page of it is loaded from another company, and every request it makes for your data goes to my own server. The same is true of every page on spritecatch.com and of the marketing page on app.spritecatch.com, except the linking page described below: the typefaces these pages use are served from the website, not fetched from Google (see section 13).

Signing in to the web version with Apple or with Google sends you to Apple or Google, and that is the point. Instead of running their software on my page, the browser takes you to appleid.apple.com or accounts.google.com, you sign in there, and they send you back with proof of who you are. So it is a visit to their own site, made by you, under their own privacy policy — the same thing that happens on the iPhone today — and what they receive is that you signed in to Sprite Catch and when. The proof they hand back reaches nobody but you and me. Google returns it in the part of the web address that browsers never send to a server, so it arrives in your browser having passed through nothing. Apple insists instead on posting it to the address it was given, which is my own server; that server does one thing with it, which is hand it straight back to your browser the way Google's arrives, and the checking happens afterwards. Either way it goes to no third party, and nothing of Apple's or Google's is left running on the page afterwards.

A photo you put on a post from the web goes to Google Cloud Vision exactly as one from the app does, and nothing about that is different for being uploaded in a browser: same one check, same question asked of it, same nothing kept. Photos you send in a conversation from the web are not sent there, the same way they are not from the app.

A community or promo link is a link, not an integration. Links to the community Discord, or to Sprite Catch's pages on services like TikTok or YouTube, embed nothing and send nothing about you with the click. Clicking through to the community server tells Discord nothing about your account here. If you join or follow, you become that service's user there and its privacy policy applies, not this one — including its minimum age. Sprite Catch's reporting and blocking tools do not reach into other services.

Discord Inc. is the one place that changes, and only if you ask it to. Typing a command means Discord tells this app which Discord account typed it, and which server it was typed in — and nothing else about you there. Everything the bot does is an answer to a command somebody typed; it holds no permission to read messages and no way to see who else is in a server. Once you finish the link, the app tells Discord these things back: the private reply you see on your own screen, a direct message to you confirming the link — which carries your display name and account ID — an instruction to give your Discord account the Verified Collector role, and, if your profile is public, an instruction to give it the trader role matching your trading standing and a role for any past season you have mastered. Those roles are visible to everyone in the server, and they are re-checked once a day for as long as the link exists, so a change to your standing is sent to Discord too. A private profile sends neither of the last two.

Three commands send Discord a picture, and each one is a message in a channel. Typing /missing, /collection or /rating sends Discord an image of the collection or the trading record it names — yours, or a public collector's you asked about — carrying the display name and username that collector's public profile already shows. Discord copies that image onto its own network and keeps it under its own rules, which is what makes the message readable to the channel later. Nothing else about the exchange changes: no email address, nothing about what you write or read anywhere in this app, and nothing at all unless you type a command. Discord is not working on my behalf here — it is a company you have your own relationship with, under its own privacy policy, and I cannot remove things from its systems for you. Section 2 describes what is stored on this side, when a picture is refused, and how to undo the link.

The bot sends Discord two more kinds of message, and both are things you asked for. A collector search shows its answer only to the person who typed it, so it tells the channel nothing about anybody. A trade room is a private thread the bot opens for two named people and writes two messages into — what the two of you could swap, and the fact that it closed. Both name Discord accounts and the Sprites involved; neither carries an email address, an Account ID, or anything about what you write or read anywhere in this app. Everything either of you then says in that thread is on Discord and never reaches this app, so it is not mine to store, to read, or to delete for you — and Sprite Catch's blocking and reporting tools do not reach into it either.

The linking page runs two pieces of sign-in software, and only the one you tap. If you finish the link in a browser rather than in the app, the page offers Sign in with Apple and Sign in with Google, and each is drawn by that company's own code loaded from that company's own address — which is the only way either sign-in can work, on any website. Tapping one tells that company you are signing in to Sprite Catch, exactly as the same button does in the app. Neither is analytics, neither is advertising, neither follows you anywhere, and using the app instead loads neither. Every other page on spritecatch.com still loads nothing from anybody.

A copyright complaint is passed on to the person it is about. If somebody tells me that a post, a photo or a message here copies work they own, handling it means handing details to a stranger in both directions, so it is worth stating before you ever send one. The complaint is forwarded to the collector whose content it names, carrying the complainant's name and contact details. If that collector disputes it, the law requires their reply to carry their real name, postal address and phone number, and that reply is forwarded to the complainant in full. Neither step has an anonymous version. The terms set out the whole procedure.

I may also disclose information where I am legally required to, or where it is genuinely necessary to investigate abuse of the app.

Child sexual abuse material is the one thing I am obliged to report, and it goes to the National Center for Missing & Exploited Children. United States law requires any service like this one to report apparent child sexual abuse material to NCMEC's CyberTipline as soon as it knows about it, and NCMEC may pass a report to law enforcement. A report carries what the law asks for: where the material is held, the account or accounts it involves, the messages around it, the sign-in details and timestamps I have, and — for anything on or after 5 September 2026 — the network addresses described in section 2. It is not something I can decline to send, there is no version of it that leaves the account out, and — because the same law expects the person it concerns not to be warned — it is not announced to them, in the app or anywhere else. Nothing else in this app is ever handed to NCMEC, and this is the only reason anything here is ever sent to a law enforcement body without a court order compelling it. Where this page says elsewhere that something is seen by you and by me and by nobody else — a voice message, a support photo, a direct message — read it as being about other collectors, and about companies other than the ones section 6 names as handling information on my behalf, which is what it has always meant: it was never a promise that a legal obligation could be refused, and this paragraph and the one below it are the exception it was always subject to.

When that happens, the ordinary deletion promises stop applying to that account. The same law requires the material and the account records around it to be preserved for at least one year after a report — longer if the authorities ask, and longer if I decide to keep it, which the law expressly allows. So for as long as a preservation like that is running, nothing about the account is erased on its usual schedule: not the 30 days after a deletion request, not the 30 days a voice message otherwise gets, not the clean-up that removes an abandoned upload after a day. Section 9 says what that means in practice. You can still delete your account and it still disappears from the app the moment you do; what waits is the erasing.

7. Where information is processed

Cloudflare's network is global and requests are served from wherever is nearest to you, so your information may be processed outside your own country, including in the United States. Where information originating in the European Economic Area or the United Kingdom is transferred, Cloudflare relies on the European Commission's Standard Contractual Clauses.

8. Legal bases (GDPR)

9. How long information is kept

An anonymous account inactive for a long period may be deleted to keep the database clean.

Logging out is not a deletion. It ends the session on that device and stops that device receiving notifications; nothing held about you is erased, and it is all there again when you sign in. Logging out also offers to clear the collection marked on that phone, which removes it from the phone only — the copy kept for your account is untouched.

What happens when you delete your account. It stops being reachable straight away: you are signed out, and your profile, posts, listings, conversations and follows disappear for everyone else the moment you confirm. Erasing the data itself happens within 30 days. The gap is review — deletions are checked by hand, because an account being abandoned to escape a scam warning should not be handed a clean start automatically, and because a deletion made by mistake is worth being able to undo. If you sign back in during that window the account comes back as you left it, and the app tells you that is what happened.

One thing survives a deletion: a single anonymous record that an account was deleted, and the date it happened. It holds nothing else — no name, no code, nothing that links back to the account it counts — so I can see how many collectors leave without keeping anything about who they were.

One more thing survives, and only in one case. If an account is erased while it is carrying a scam warning or a suspension, I keep a scrambled one-way fingerprint of the sign-in it used. It is not the sign-in, it cannot be turned back into it, and it cannot be matched against anything else I hold or anything anyone else holds — it is useful for exactly one comparison: whether a new account is the same person coming back. That is its only purpose, and what it restores is the warning or suspension a human decided on, never marks left by other collectors. An account erased without any of that is recorded nowhere. A fingerprint is discarded after a year.

Since 5 September 2026 there is also a short line about each photo sent in a conversation or a group that the check described in section 4 looked at — two words about what it saw and a fingerprint of the file, never the picture and never a description of it, and never anything that could match a face. It is kept with the moderation records above.

Network addresses are kept for 90 days, and then the address itself is erased automatically while the scrambled form described in section 2 stays. Deleting your account removes them outright, along with everything else.

And one situation stops the clocks on this whole list. If a report has been made to NCMEC's CyberTipline about an account, as section 6 describes, United States law requires the material and the records around it to be kept for at least one year, and it can run longer than that — the authorities can ask for longer, and the law lets me keep it longer on my own judgement. While that is running, nothing belonging to that account is erased on any of the schedules above — not the 30 days after a deletion request, not a voice message's 30 days, not the daily clean-up of an upload nobody ever sent, and not an unsend. It has no maximum here, because the law does not set one and only the authorities asking can say when it ends; when it does end, the ordinary schedules resume and everything that was waiting is erased. Because the conversation is what a report is about, this reaches the other person in it too: their messages in that conversation are held for the same period, and if they have asked for their account to be deleted, the erasing waits with everything else. Nothing in the app looks any different to either of them while it lasts, and nothing extra is collected to do it — what is held is what was already there.

What survives it, permanently, is a short record that the preservation happened: which account, why, when it started, when it ended, and the reference number of the report. That record is kept even after the account is erased, because it is the only proof that the law was followed and it is what an authority asking later is answered from. It holds no message, no photo, and nothing anybody wrote.

And one last one, in a narrower case still. If mail to your address ever bounced, the note saying so — the address, the reason and the date, described in section 2 — is not removed with the account. It is a record that a particular string of characters cannot receive email, held so that nothing tries again and damages this service's ability to send to anybody; most of the addresses on that list never belonged to an account in the first place, and erasing one would simply mean the next person who typed it bounced all over again. It is linked to nothing else here. Ask and I will clear it.

A warning can also follow the phone, with nothing kept at all. If an account carrying a scam warning or a suspension is still here and a new account is started on the same device, the new one is given the same warning. No deletion is involved and nothing extra is stored to do it — it is a comparison against an account that already exists. The same two limits apply: only a warning or suspension a person decided on carries, never marks left by other collectors, and the new account is labelled as having inherited it so that a human reviewing an appeal can tell the difference. Two people sharing one phone can be caught by this. If that is you, say so from the app's Support menu and it will be lifted.

10. Your choices and rights

Inside the app, in Settings:

Wherever you live, you can also ask me to see a copy of everything stored about you, correct anything wrong, delete your account and its data, export it in a portable format, or restrict or object to processing. Email privacy@spritecatch.com and include your username, or your account ID (Settings → Account), so I can find the right account. I respond within 30 days, there is no charge, and nothing about the app works worse because you asked.

Deletion has its own page — spritecatch.com/delete-account — covering how to do it in the app and how to ask me if you have already uninstalled. The web version's settings delete an account the same way the app's do, on the same 30-day hold, and signing back in during it still brings the account back.

If you are in the EEA or the UK you also have the right to complain to your national data protection authority.

California residents

Californian users have the rights to know, delete and correct set out above, and will never be discriminated against for exercising them. I do not use personal information for cross-context behavioural advertising.

I do not sell anything, and I never have. Nothing about you — not your collection, your posts, your messages, your email address, your usage information, and not your questionnaire answers either — has ever been sold or shared as the CCPA/CPRA define those terms, and nothing about you is sold or shared today. Until 31 August 2026 this page described one thing that could have become a sale: a questionnaire whose answers were sold as market research. It was never offered, no answer was ever sold, and the ability has been removed from the app and the server.

Do Not Sell or Share My Personal Information

There is nothing to opt out of. Sprite Catch does not sell or share personal information as the CCPA/CPRA define those terms, so there is no sale for this right to stop and no switch you have to find. The heading is kept because this page has carried it since 1 August 2026 and somebody looking for it should find an answer rather than a missing anchor.

If you would like that confirmed in writing for your own records, or you want to be certain nothing about you is held for any such purpose, email privacy@spritecatch.com. Say which account (your friend code is enough) and you will get an answer within 15 business days. You do not need an account or a password to ask, and an authorised agent may ask on your behalf. You will not be charged, refused any feature, or given a worse version of the app for asking.

Under 16. The CCPA requires opt-in rather than opt-out for consumers aged 13 to 16, and a parent's consent below 13. Nothing is sold or shared about anybody of any age, so neither threshold has anything to apply to here.

Sprite Catch does not respond to a browser Global Privacy Control signal, because there is no sale or sharing anywhere in the app or on the website for such a signal to stop.

11. Children

Sprite Catch is not directed to children under 13, and the App Store and Google Play listings are rated accordingly. I do not knowingly collect personal information from children under 13. Because the app works anonymously, asks for no real name, and never asks for or uses the phone's location, an under-13 user who simply tracks their collection is providing very little about themselves: a display name they choose, the country their requests come from — worked out from the internet address, never finer than the country, and shown to no other user — and, where Apple's age service does not answer, the age they enter during setup.

From the version going out on 28 August 2026, the app offers that user the collection tracker on its own. The ages on the setup screen start at 13, and the button under them saying My age isn't listed leads to Safe Mode: the collection, the scanner, Rewards and their own profile, with the community, direct messages and news switched off. It is offered, never imposed — nothing about an age switches a feature off by itself — and a parent can switch it off again, or lock the same restrictions behind a passcode, on the Parental Controls screen.

The social features — public posts, trades, and direct messages with photos — do let users communicate with strangers. Text is screened automatically, and users can block and report one another. A safety program that reads written conversations and looks at photos on the server — looking for strangers approaching children, and in particular for one account showing different faces to different children — ran for a day from 29 August 2026 and has been switched off since 30 August 2026; while it is off, no program on the server reads a whole conversation. Section 4 describes in full what it does when it runs: it is not a check on every picture, it cannot recognise a face and does not try, and a person reviews everything it decides. A separate check, added on 5 September 2026, does look at every photo sent in a conversation or a group — it asks only whether the picture is sexual and whether the person appears to be a child, it runs on Cloudflare's own service so no photo goes to another company, it cannot recognise a face either, and today it turns nothing away. Section 4 describes it. Web addresses are allowed inside an accepted conversation (with a warning in front of every one), and moderation is no substitute for a parent's involvement. A parent can switch each of them off and lock the choice behind a passcode, on the Parental Controls screen, and a collector under 13 can switch all of them off for themselves by choosing Safe Mode; the app does not switch them off by itself. Both apps have these features, and both have the Parental Controls screen.

Once the app has established that an account is under 13, the server also collects no usage information from it and keeps no email address for it. Both are enforced on the server rather than on the device, so they hold whatever the app is asked to do. An account whose age was never established is treated the same way as an under-13 one for this purpose. Nothing about any account, of any age, is sold. iOS's own "allow tracking" request is still put to every account, including a child's, and on every one of them it applies to nothing — the questionnaire it was added for is gone, nothing in the app tracks anybody, and no part of the app reads the answer, so answering it either way collects nothing. It is asked of everyone rather than hidden from children because hiding it made an app that genuinely implements the permission look to Apple like one that does not. On an Apple Account set up as a child's, iOS declines to show the request at all, which is Apple's decision and not mine.

The arcade is not on that list either, for the same reason. An under-13 account can play every game in it and can keep a best score at each, exactly like any other. Nothing about those scores is shared with anyone or sold to anyone, nothing random or paid is attached to them, and the one place they could be seen by other people — the leaderboards in section 4 — hold only public profiles, which an under-13 profile is not unless it has been deliberately made one.

Invites are deliberately not on that list, and it is worth saying so plainly rather than leaving it to be inferred. An under-13 account can share its username and unlock the decorations described in section 2, the same as any other. Nothing about it is shared with anyone or sold to anyone: what is recorded is who invited whom, it is shown to nobody but the person it belongs to, there is no money in it and nothing random about it, and the invite page itself names nobody. A parent who would rather their child did not take part can simply have them not share it — nothing in the app is behind it.

The web version now has the social features, and this section reaches them — but not everything in this section does, so read the next paragraph. Signed out, it is still what it was: a collection tracker that asks for no name, no age and no account, with no way for anyone to contact anyone. Signed in, it is the app in a browser, and every protection in this section that lives on the server comes with the account rather than the device — so an under-13 account keeps its private profile, is still not on a leaderboard, is still asked for no email address, still has no usage information collected about it, and is still never offered the questionnaire, whether it is signed in on a phone or in a browser.

What does not reach a browser is Safe Mode and the parental passcode, and that is worth being blunt about. Those are settings on the phone they were set on — held on that device, enforced by that app — which is what lets a parent lock them behind a passcode in the first place. A browser is not that device and never sees them. So if you have switched the community, direct messages or news off on your child's phone, that does not switch them off for the same account signed in at spritecatch.com; the way to prevent that is the ordinary way you would prevent a browser from reaching any website, on the device or on the network, and it is not something I can do from inside the app. The age itself is not the gap — the server's protections above follow the account everywhere. What does not follow it is the lock you set.

One thing on the website asks for an email address with no account behind it — the Android box described in section 2 — and the protections in this section cannot reach it. They are enforced against an account, and that box has none — so the honest position is that it asks you not to use it if you are under 13, says so on the page beside it, and holds no way of checking. A parent who finds their child's address on that list can have it removed by emailing me, and either way the whole list is erased within 30 days of the release date. Nothing else about that address is used for anything, and it is never sold.

Contacting support is deliberately not restricted: it stays reachable whatever the parental controls are set to, because a child must always be able to tell me something is wrong. The automatic reply described in section 4 is produced on the same server and sends nothing anywhere else. Since 9 September 2026 one other thing reads what arrives: the scheduled assistant in section 4, which works the queue alongside me. A report about somebody's safety is never answered or closed by it — the app refuses to let it — so a child who writes to me about another person still reaches a person, every time, which is the promise this paragraph has always been about. It is never shown a voice message, and never shown a photo on a ticket that is not claiming a reward. It can answer an ordinary question about how the app works and nothing more: there is no artificial intelligence in the support reply — it is a list of written answers matched against a list of phrases — it cannot decide anything about an account, its replies say they are automatic, and anything about safety, a warning, money, or a photo goes straight to me. A child who writes in about their safety always reaches a person. Two other things in the app use an outside service and it is worth being exact about both: the safety program in section 4 reads messages and posts, and it never reads a support ticket; and the scheduled assistant does read one, on the terms just given. From 2 September 2026 one more thing on that list uses an outside service: a photo attached to a public post is checked for explicit content before it is published, by Google's Cloud Vision. That check covers posts only — never a direct message, never a support ticket — it is asked one question and never asked to recognise a face, and a refusal turns away the picture without recording anything against the child who sent it.

If you are a parent or guardian and believe your child has entered personal information — a real name in the display name field, a Fortnite tag, a message or a photo — email me and I will delete the account and its data promptly.

12. Security

All traffic between the app and the server is encrypted with HTTPS/TLS, and data at rest is encrypted by Cloudflare. Requests are authenticated with a signed token kept in the iOS Keychain on iPhone and in the app's private storage on Android. If you set a password, it is stored only as a one-way scrambled version designed to be slow to attack, never as the password itself, and the sign-in screen limits how often anyone can guess. That said, no system is perfectly secure and I cannot guarantee absolute security — one more reason the app collects as little as it can.

13. Changes to this policy

9 September 2026 — an assistant now works through the support and safety queues on a schedule, and it reads what is in them. This is a new company seeing information about you, so it is the change on this page to actually read. Support has always been one person, and what that cost was paid by whoever was waiting: a reward claim sent on a Friday could sit until Monday, and an unfair review stayed on somebody's profile until I got to it. From today a session of Claude, made by Anthropic, PBC, opens those queues every few hours and works them. What it is shown is three things and only when a queue hands it one: the messages on a support ticket, the screenshot on a ticket claiming a reward, and a conversation the safety measures in section 4 have already singled out. It cannot search, cannot browse, and cannot go looking. This retires a sentence this page used to make. The claim screenshot was described here as read by me and nobody else, and a support photo as having two readers; both are now true only of a ticket that is not claiming a reward, and saying so is the point of this paragraph. What has not moved: a voice message is still read by nothing and turned into words by nothing; a photo on any other kind of ticket is still readable only by me; nothing is ever asked to recognise a face; and a report about somebody's safety is never answered or closed by it — the app refuses to let it, so those still always reach a person. It cannot restrict your account: it has no way to ban, mute or hide anybody, and where it thinks an account should be paused that is recorded as a request and decided afterwards by the same unchanged rules as before. Anthropic does not keep what it is shown and does not use it to train anything. A record of what it opened is kept and is described in section 9; section 4 has the whole of it and section 6 names them.

9 September 2026 — announcements from Sprite Catch are written in your language, and have a switch of their own. Until now, a notification I write myself — a new feature, a new version, something worth knowing about the app — went out in English to everybody. Only the app's own built-in wording is translated on your phone; mine is not, so it was sent exactly as I typed it. From today the language setting in section 2 — or, if you never picked one, the language the app is already displaying itself in — decides which of the nine translations you are sent. Nothing new is collected to do it: it is the same setting that already narrows the feed and the trade board, used for one more thing, and no new fact about you leaves my servers. Alongside it, these announcements move out of the Fortnite News switches in Settings and get one of their own, App news, which starts on. That is a real change for one group of people: an announcement from me used to ride the Game updates & events switch, so turning that off stopped mine along with Fortnite's. From today it stops only Fortnite's, and the new switch is what stops mine — it appears in Settings with the next app release, and turning notifications off in your phone's own settings has always stopped every one of them.

9 September 2026 — the account now records which version of the app you signed up in, and which one you last opened. Section 2 describes both. Sprite Catch reached Google Play today, and there was no way to tell how many people were joining on Android, or how many of the people already here were using it — so from today two more facts are kept with the account: which of the three versions created it, and which of the three you most recently opened. Each is one of three words, neither keeps any history, and no other collector ever sees either. Nothing new is asked of you and nothing new leaves my servers: every request the app makes already says which app it is, and this keeps the answer — once, for the first one, and overwritten in place for the second. The signup one is blank for every account that existed before today, with one exception: where the only device an account had ever registered for notifications was an Android one, it has been marked as an Android signup, because that could only have been true on Android. The last-opened one is blank for everybody until the next time they open the app.

9 September 2026 — on Android, Google Play can now answer the age question for you. Sprite Catch arrived on Google Play today, and with it a change to how the age in section 3 is established: before showing you the age screen, the Android app asks Google Play for the age range held for your account, and Google asks you whether to share it. Agreeing means you are not asked again; declining, or Google having nothing to share, means the same screen you would have seen anyway. Nothing new is collected and nothing new is sent anywhere — the app receives an answer instead of asking for one, and what it keeps is the same single number of years it always kept. It is required of apps that children and adolescents are likely to use by Brazil's Digital Statute of the Child and Adolescent, and it is on for everybody because a better-sourced answer is not worse elsewhere. Google's own rules, and mine, allow that range to be used for one thing only: giving you an age-appropriate experience. Section 3 has the detail.

7 September 2026 — whether you are 18 or over now reaches my server, and a community can be marked for adult collectors. Section 3 said on 2 September that this answer stayed on your phone and told me nothing; from the version going out today that is no longer so. The app sends the same yes-or-no it already worked out — still no date of birth, still no number for the accounts Apple's service answered — and it is stored with your account for one purpose: a community's owner can now mark it for collectors aged 18 and over, and the server refuses to let anybody it does not know to be an adult start, be invited into or join one. That is the whole of what the answer does. Nothing else reads it, it is shown to nobody, and everything the safety note above a new conversation did with it on the phone is unchanged. An account that never gave the answer is treated as under 18 and told how to give one. The mark itself is a label everybody can see in the community list, not a filter; it permits nothing — the same rules and the same reports apply inside such a community as anywhere else — and marking a community that already has members removes none of them. Sections 3 and 11 carry the detail.

7 September 2026 — polls, a community's own want board, a community card on a post, the people you follow on a community's card, handing a community on, and a web page for every community. Six smaller things, going out in the same version, and one of them collects something new. A poll is a question asked in a conversation; what is new is that I store each person's own pick, which is shown to nobody but them — everybody sees the totals, and the picks go with your account (section 4). A want can now be posted into a community you are in, where every member sees it; it is the same want as on the board, with one more fact beside it. A post can carry a community, so that the people reading it can join from it; that is a pointer to something already public and nothing new about you. A community's card can show you which of the people you follow are in it, read from two things that were already yours to see. The person who started a community can hand it to a moderator. And every community has a web page that anyone can open, signed in or not, showing its name, what it is for, its picture, its size and how joining works — the four facts this page already made public to every signed-in collector, now reachable by a link — and never who is in it. Sections 4 and 11 carry the detail.

7 September 2026 — a community's rooms can now be set to keep their past messages for people who join later. Section 11 describes it. Until today, every group and every community room showed you only what was said after you arrived; that is still true of a group chat, and a community's rooms are now the exception, at the choice of whoever runs the community. Nothing new is collected, and nobody can be shown anything from before the setting was turned on: what changes is how far back a member of a room can scroll, it only ever applies forwards from the moment it is switched on, and a room you have cleared off your own list stays cleared. A community created from today starts with it on, because a brand-new community has nothing said earlier to disclose; every community that existed before today starts with it off.

7 September 2026 — from a future release you can be invited into a community, and being invited is something I store. Section 11 describes it. It is one new fact about you — that a particular collector offered you a place in a particular community, and when — and it is kept until you accept it, turn it down, or the community closes. Nothing new leaves my servers and nobody new can read anything: an invitation is visible to you and to the person who sent it, the record of it being sent joins the record every other community power already writes, and turning one down is recorded nowhere. The one thing that reaches outward is the notification telling you an invitation is waiting, which goes through the same notification service every other one does and can be switched off in Settings with them.

7 September 2026 — signing in with Epic has shipped, and the sentences elsewhere on this page that said the app never talks to Epic Games have been narrowed. Section 2 has described it since 4 September as something a future release would do; that release is out, so it is written in the present tense now. Nothing new is collected and nobody new can read anything — what is kept is still the account identifier, the display name it had when you linked it, and when you linked it, exactly as section 2 already set out. What changed is a promise this page makes in five other places, about three different features, and it has been narrowed rather than left standing: the locker import, the codes checklist and the reward claim queue each still make no call to Epic and send it nothing, but the app as a whole does now contact Epic — once, on our own servers, when you choose to link, to ask whether the account is yours. It still cannot see what you own, still cannot change anything in the game, and still never asks you for an Epic password.

7 September 2026 — a reply can answer another reply, and a reply can be liked. A thread used to be a flat list, so an answer to the ninth reply landed at the bottom under eleven unrelated ones. A reply can now be written under another one — in the web version straight away, and in the iPhone and Android apps from their next release — which means two more things are kept about it: which reply it is answering, and, when it was aimed at somebody further down that conversation, who it was addressed to — drawn beside it as a name everyone can already see. Replies can also be liked, the same one tap a post takes: the number is shown to everybody and who left it is shown to nobody. Nothing here is new in kind, no new recipient can read anything, and none of it is used to work out anything about you — it is the same feed, one level deeper. One behaviour is worth stating plainly because it is a choice rather than a detail: deleting a reply does not delete the replies to it — what other people wrote stays and moves to the top of the thread — and the same is true when a moderator takes one down or an account is deleted. Sections 2, 3 and 8 describe it.

6 September 2026 — a day of your streak that unlocks no decoration now pays Gems, and one number is kept to work out how many. Past the first week, and once the seventh day's pool is collected, a daily reward had nothing left to give and said so. It now adds a small number of Gems instead, which the app tells you before you claim and again afterwards. The amount gets smaller the more the streak has paid you over time, so a running total of what it has paid is kept against your account — a fourth number beside the current run, the best run and the date of the last claim, and the only reason it exists is to work out the next day's amount. Nothing new is collected about you, nobody new can read anything, and nothing here can be bought: Gems are still earned only, and this is a reward being given rather than anything being recorded. The seventh day's random draw has not changed, and a prize you already hold is still never drawn again. Sections 2 and 3 describe it.

6 September 2026 — from a future release you can save up to ten looks, and they are yours alone. A look is the whole of how your profile is set up at one moment — your character, your decorations, your flag and badge — kept under a name you type so you can put it back on in one tap. It is a new thing an account holds, which is why it is written down here before the release rather than after it. Nothing new is collected and nobody new can read anything: a saved look is a copy of choices this policy already describes, and it is not on your profile, not on the shareable web page in section 4, never sent to another collector and never published to Discord. The one thing worth saying on its own is that the name you give a look is not screened, unlike everything a stranger can read — because nobody but you can read it. Section 3 describes them.

6 September 2026 — from a future release you can put a flag and a small badge beside your name, and both are public. They are new things an account can hold and new things other collectors can see, so they are written down here before the release rather than after it: a country you pick from a list, and one small mark — a platform badge, or a moderator's mark if you are one. Nothing new is worked out about you and nobody new can read anything. The point worth stating on its own is that the flag is chosen and never inferred: it comes from a list you tap, not from your internet address, your phone's settings or your phone's location, and it is a different thing from the country in section 2, which is recorded from your address, is shown to no other collector, and neither feeds this nor changes because of it. Both are optional, both can be taken off, and both go when the account does. Sections 3 and 12 describe them.

6 September 2026 — the picture on a community and the photo on a group are now checked for explicit content before they go up, which sends two more kinds of picture to Google. Since 2 September 2026 a photo attached to a post has been sent to Google's Cloud Vision to be answered one question — how likely it is to be explicit or graphic — and this page said, in as many words, that it happened to post photos and to nothing else. That is no longer true, and this is the notice. What changed and why. The line those two are on is not public against private; it is that a picture like that is shown to people rather than sent to them. It sits next to a name in a list for everybody in that place, whether or not they opened anything — a community's picture is public to every signed-in collector browsing for one, and a group's photo is in the list of everybody in that group. Nobody there chose to look at it, which is exactly what a post photo and these two have in common and a message photo does not. A photo you send to somebody is still never sent to Google, and neither is a support photo, a voice message or anything you write; that boundary has not moved and is not going to. Nothing new is stored. The picture itself is not kept by Google or by me — what is written down is the answers that came back and a fingerprint of the file, the same as for a post photo, and a picture that is turned away is not stored at all. Unlike the post half, this one does refuse: a confident yes means the picture does not become the community's or the group's, you are told so, and you can pick another. It is about the one picture and nothing else — never a strike, never a mark on your Account Standing, never a restriction on your account. Sections 4 and 6 have the wording.

6 September 2026 — whoever started a community will be able to close it, and that ends it for everyone in it. Until now nothing anybody did in the app ended a community: the only way one closed was its owner deleting their whole account with nobody they had made a moderator to inherit it. From a future release its owner — and only its owner, never a moderator — can close it outright. Everyone in it loses it and every one of its rooms, at once, and nobody is told, because there is nothing anybody else could do about it. Nothing is deleted by this and nothing new is collected. What was said in its rooms is kept the way every other message is kept and stops being reachable, which is what lets a report about something that happened there still be looked at afterwards; your own messages in it go when you delete your account, exactly as they did before. Section 4 has the wording.

6 September 2026 — your conversations now follow you onto a new phone, and this page used to promise the opposite. Until today the apps kept a conversation only on the device it arrived on: signing in somewhere new showed who you had been talking to and the last thing said in each conversation, and nothing above it. This page described that as a deliberate limit, and it was one — but it was a limit in the app, never in what is stored. The server has kept every message the whole time, which section 4 has always said, and it is what the operator tools read when a scam report needs the context. So what the limit actually did was leave collectors looking at their own conversations with the words missing, and it did it to exactly the people least able to work around it — somebody whose phone was lost, broken or replaced. From today, opening a conversation on a device that does not hold it downloads it, and a button at the top of the conversation loads the rest of it, back to the beginning. Nothing new is collected and nobody new can read anything: the same messages, in the same place, kept for the same time, shown to the same account that wrote and received them. The web version has worked this way since it gained accounts on 4 September 2026. Section 4 has the wording, and the note about backups still stands — the copy on the device is still left out of them, because the server is what your history survives on.

5 September 2026 — I can now set aside the tickets of somebody who writes in about the same thing indefinitely. Support is one person answering everybody, in the order the tickets arrived, and a collector who will not accept an answer can sit at the front of that queue for weeks while everyone else waits. So from today I can stop reading one person's tickets for a set time — three months usually, a year at the most, never permanently. It takes nothing away from them. They can still write in on the same daily limit, the automatic reply still answers what it can, the conversation still stays open at their end, their tickets and photos are stored exactly as everybody else's are, and nothing about their account, their profile, their posting or their messaging changes in any way. Nobody reads it, that is all, and only until it runs out. A report about somebody's safety is never set aside — that reaches me in the ordinary order whoever sends it. The only thing stored is a note to myself: the account, the reason, the date and the date it ends, kept in the operator tools and shown to nobody. Section 4 has the wording.

5 September 2026 — helping run the community server is now recorded against your linked account. Until today, linking a Discord account only ever sent information the other way: your collection and trading standing became roles in the server, and nothing about the server came back. From today one thing does. Once a day the app looks at who is wearing one of the roles given to the people who moderate and answer questions there, and records the name of it against the account they have linked. It does three things and no others: it stops another collector putting a public scam warning on that profile, it stops the automatic safety checks acting on it without a person, and it gives that account the verified badge if it carries no mark already. Reporting one of them still works normally — a report still reaches me and still counts, which is the point. Losing the role, disconnecting, or deleting the account takes all of it away. Section 2 has the detail.

5 September 2026 — every photo sent in a conversation is now looked at as it is sent. Until today the only automatic look at a message photo was the safety program in section 4, and that one only ever looked at pictures from a small number of accounts something else had already singled out — this page said so, and said it was not a check on every upload. That is no longer true of the app. A separate check now runs on every photo sent in a direct message or a group, as it is sent, and asks one question: whether the picture is sexual and whether the person in it appears to be a child. It exists because of the one thing I am obliged to report, in section 6. It runs on Cloudflare's own service — no photo of yours goes to another company, and a message photo is still never sent to Google. It cannot recognise a face and is not allowed to learn how. It never looks at a support photo and never touches a voice message. Today it turns nothing away, and this page will say so plainly on the day that changes. What is written down is two words and a fingerprint of the file — never the picture, and never a description of it. Sections 4, 9 and 11 have the detail.

5 September 2026 — network addresses are now stored, for 90 days. Until today this app kept no record of the address you connect from: it was scrambled into something nobody can read back, and the address itself was discarded. From today it is written down when you create an account, sign in, upload a photo or voice message, post, or send a message, and erased after 90 days — after which only the scrambled form remains. This is new information collected about you and it is the first of its kind on this page, so it is described in full in section 2, its retention is in section 9, and it is named in section 6 as something a report to the authorities can carry. Nothing about it is used for advertising, analytics, or working out where you are; nothing is shared with anybody in the ordinary course; and no law required it. The reason is the one in section 2: a report about child sexual abuse material is close to useless without an address, and this app had none to give. If you would rather it did not apply to you, deleting your account erases them, and sections 9 and 10 say how.

5 September 2026 — a preservation that overrides the deletion promises, and one new recipient. United States law requires a service like this one to report apparent child sexual abuse material to the National Center for Missing & Exploited Children, and — once a report is made — to preserve the material and the account records around it for at least one year, longer if asked. An earlier version of this page, published this morning, said 90 days. That was the figure the law used until 2024 and it was wrong to publish; the period is longer, not shorter, so nothing was kept for less time than it should have been. Until today that duty was written down as a procedure I follow; it is now built into the app, so the automatic clean-ups that erase things on a schedule cannot run against an account it covers. Three things changed on this page rather than in what is collected: NCMEC and, through it, law enforcement are named in section 6 as a recipient in that one situation; section 8 records that the law can require information to be kept and not only disclosed; and section 9 says plainly that a preservation stops every clock on that list, including the 30 days after a deletion request and the 30 days a voice message otherwise gets, and that it reaches the other person in an affected conversation as well. Nothing new is collected about anybody, and nothing is shared with anybody in the ordinary course — this is a change to how long some things last and to who sees them in one specific, legally compelled case. As section 6 says, a report is not announced to the account it concerns, because the same law expects that.

If this policy changes materially I will update the date at the top of this page and note the change in the app's release notes.

This version is about the web version, which became a real version of Sprite Catch on 4 September 2026 and moved house doing it. It is at spritecatch.com now; app.spritecatch.com, which is where it used to be, is now only the page that tells people about the app, and the old addresses send you to the new one. You can sign in there with the same account as the phone, and once you do, the web version does what the app does: your collection syncs, and you can post, reply, react, trade, message, follow, block, report, mark a scammer, change your settings and delete your account. A reader who never signs in can now read the live feeds and public profiles there, and there is a new public leaderboard of collectors who have chosen to be public. Nothing new is collected about anybody by any of it — it is the same account, the same records and the same rules, reached from a second place — and no new company is involved: the web version still loads no third-party script, font or content delivery network, and every request it makes for your data goes to my own server.

Five things this page used to say about the web version are no longer true, and I am not going to quietly delete them. It said the web version has no account and no sign-in; it now has both. It said it stores nothing in your browser and that nothing there is tied to a browser; once you sign in it keeps the token that keeps you signed in, your own profile and your own collection, listed in full in section 3. It said the web version stores nothing on the server, so that clearing your browser was permanent deletion; that is still exactly true until you sign in, and after you sign in your collection is on the server like the app's. It said the web version had no social features to restrict, in the section for parents; it has them now, and section 11 says which protections follow the account there and which — Safe Mode and the parental passcode — stay on the phone they were set on. And it said the community feed shown on the web was not live, a fixed sample of about twenty posts with invented author names; that page is gone and the feeds shown now are the real ones under real names. What has not changed is the part people ask about most: still no cookie — with the one long-standing exception of the Discord linking page, which runs Apple's and Google's sign-in code and always has; still no advertising and no third-party analytics; still no third-party script, font or CDN anywhere else. The visit count in section 2 works exactly as it did and still stores nothing in your browser. There is a new Cookies page that says all of this on one screen, which is why you have never been shown a cookie banner here and will not be.

This version says that the web version now keeps the conversations you have already read in your own browser. It did not before: every time you opened a conversation there, the whole recent history was fetched again, and closing the tab threw it away. Now the messages stay on the computer that read them, so opening a conversation is instant and the list is still there when the connection is not. Nothing new is collected about anybody and nothing new is sent to me — it is a copy of messages you can already read, held on your side rather than asked for again — and the server's copy, what it keeps and for how long, is unchanged. Two limits are part of it rather than added to it, and they are why this has a paragraph. It belongs to the account that is signed in: signing out deletes it, and so does signing in with a different account on the same computer, so nothing one person read is left behind for the next person to open that browser. And clearing your browser data removes it like everything else on the list in section 3 — which loses nothing, because your conversations are on the server and come back when you sign in. The Cookies page lists it with the rest.

This version adds communities, and with them the first thing in Sprite Catch one collector can do to another. From a future release you can start a community, find one and join it, and whoever runs a community can hand out the ability to run it and can remove somebody from it. That is new in two ways worth stating plainly. It is a new public surface: a community's name, what it is for, how many people are in it and who they are can be seen by any signed-in collector who opens it. And it is a new kind of decision about you made by somebody who is not me — so being removed is something you are told, with a reason from a fixed list, and it takes nothing else away and closes no door to reporting. It also adds records: who is in each community and what they may do there, which of its rooms they have joined, and a log of every time one of those powers was used. The section Communities under Direct messages and groups is the whole of it, and section 10 covers what happens to all of it when you delete your account.

This version makes a public profile's follower and following lists readable by anybody, where before they were readable only by the collector they belonged to. Nothing new is collected and nothing new is stored: the two numbers were already on every public profile, and this publishes the names behind them. It is still a new public surface, which is why it has a paragraph here rather than a line. Two limits are part of it rather than added to it. Only public profiles appear on either list, so going private takes you off every copy of both, and an account belonging to somebody under 13 — which starts private — is never on one unless that has deliberately been changed. And neither list says anything about whoever is reading it. The section Your public profile is the whole of it.

This version also moves your trading record onto your posts, and tightens what happens behind a moderator's decision. Nothing new is collected by any of it, and no new group of people can read anything about you. From a future release the star rating from your completed trades, and the warning an account carries once enough scam marks have been left on it, appear beside your name on your posts and replies as well as on your profile — the same record, already public, shown where somebody is deciding whether to trade with you rather than one tap away; it is deliberately not drawn on your own posts, and it changes nothing about what your posts do. Separately, a moderator's decision can now name several reasons instead of one, and you are shown all of them on your Account Standing screen; and every decision they make — including an attempt the server refused — is now sent to me as it happens, so that the record of a power I handed out reaches me the same hour instead of waiting for me to open a tool. The moderator's private note is not in what reaches me that way, and still never reaches anybody's phone. Report reasons gained one entry, for selling Sprites for real money. Sections Your public profile and Moderation and safety carry the detail.

This version records something new about achievements: the few badges that are handed out rather than earned. Achievements have always been worked out on your device from numbers your profile already carries, and that is still how almost all of them work. From a future release a small number of badges exist that no rule could describe — for helping test the app, for being here early, for reporting a problem — and those are given out one account at a time, so which of them your account holds is stored with it and shown on your profile. Section 2 describes it under Questionnaire answers and rewards. Nothing else about achievements changed, and nothing new is collected from you: this is a note about something I record, not something you tell me.

This version opens the Discord bot to every server, and it collects something new from people who do not have a Sprite Catch account at all. Until now the bot connected an account and drew pictures. It can now be added to any server, and inside one it does three more things, all described in full in section 2 under Tracking your collection with the Discord bot. It keeps a list of which Sprites you have marked, saved against your Discord account rather than a Sprite Catch one — so somebody who has never installed the app now has information stored about them here, which is new, and is why this paragraph exists. It keeps which servers you have used it in and roughly when, which is what lets other members of those servers find you when they are looking for a Sprite you have; that is a new way to be found, it is limited to servers you have used the bot in, and /spritecatch privacy switches it off and deletes everything the bot holds, from inside Discord, without asking me. And it opens private trade threads between two collectors — those live on Discord, under Discord's rules and that server's moderators, and this app neither stores nor reads a word of them, which the bot says in the first message of every room. Linking an account moves the bot's marks into your collection and deletes its copy. That list also marks who on it has linked an account, which is the same single fact the Verified Collector role already publishes, and it now covers only people who are still in the server — leaving one deletes what the bot remembered about your being a member of it. From this version the bot can also learn who is in a server from its member list, rather than only from who has typed a command — which affects you only if you have linked an account, never applies to a private profile, and is switched off for you by /spritecatch privacy; and a server may give you one role for completing a season, chosen by that server's admins. Nothing about the app's own data changed, no new company receives anything, and a trade agreed in Discord still changes nothing about your trading record here.

This version gives the moderators a way to see and undo their own decisions, and stops them being publicly accused for making them. Nothing new is collected about you by any of it. Three things change and each is described in full in section 3 under Moderation and safety. The handful of accounts allowed to moderate the feed can now read, one collector at a time, whether that account is currently paused and the list of decisions already made about it — the categories, the dates and who acted, never the private notes, and nothing at all about your messages, your photos, your collection or your own Account Standing screen. That is a new group of people able to read a record about you, which is why it is written here. Those same accounts can now undo: lift a pause, or take back a scam mark they filed, and where they say the decision was wrong the entry on your standing screen is marked as removed and stops counting — the first time anything on that screen could come off other than by waiting or appealing. They can also remove a single reply rather than the whole post it sits under. And a public scam mark aimed at one of those accounts is now discarded rather than published, because marking whoever paused you is the obvious retaliation; an ordinary report against a moderator still reaches me exactly as before, and it should, because a moderator abusing what I gave them is a thing I need to be told. One more visible change comes with it: a mark left by a moderator now shows a short line on the profile, and above a conversation with that account, saying what they say they saw — from a fixed list the app translates, plus the public review they chose to write. A mark from an ordinary collector is still only counted, never quoted.

This version works out one more thing about your age, and it never leaves your phone. From 2 September 2026 the app decides whether you are 18 or over as well as whether you are over 13. On an iPhone that is one extra boundary in a question Apple's service was already being asked, so there is no second prompt and Apple still reports no age; everywhere else it comes from the number you already gave. It changes exactly one thing you can see: the short safety note above a conversation with somebody new is no longer shown to collectors of 18 and over. The result is kept on the device, is not sent to my server, and is not attached to your account — over or under 13 remains the only age result I hold. The same release lets anybody switch that note off for good, which is also remembered on the phone alone, and puts it back under Settings → Privacy & Safety. Nothing about reporting, blocking or closing a conversation moves with any of it. Sections 3 and 4 carry the detail.

This version starts sending one kind of picture to another company, and it is the first time anything in this app has done that. From 2 September 2026, a photo you attach to a post is sent to Google's Cloud Vision before the post is published, and Google answers how likely it is to be explicit or graphic. If the answer is a confident yes the upload is refused and the photo is not stored. Nothing else about you goes with it and no new kind of information is collected: the picture was already being uploaded and already being published to everyone. What has changed is who sees it on the way, which is why this is a paragraph here rather than a release note. It covers photos on posts and nothing else. A photo you send in a direct message and a photo you attach to a support ticket are not sent to Google, are not part of this, and the promises made about them elsewhere on this page are unchanged — the whole reason a post photo is treated differently is that you are publishing it to everyone, including people who never signed in. Google is asked one question, is never asked to detect or recognise a face, handles the photo as a service provider, does not keep it and does not train on it; on my side the picture is not kept either, only the scores and a fingerprint of the file. If Google cannot be reached the photo is published rather than held back. Right now it refuses nothing — it is set to record its answers rather than act on them while I learn how it behaves on real photos — and this page will say so plainly on the day that changes. It is not a check for illegal images of children and is never treated as one. Sections 4, 6, 9 and 11 carry the detail, and section 6 now lists Google in two places for this reason: for this one job it works on my behalf, and for sign-in and Android notifications it does not.

This version adds a screen that tells you how your own account is doing. Nothing new is collected about you and nothing new is shared with anybody. What changes is that decisions a moderator makes about your account — a post removed, a pause applied, a scam mark filed with evidence — and the two things that count without a person (several separate serious reports, and asking different collectors for gift-card codes) are now written down as a short, dated record and shown to you, in Settings → Account Standing, instead of happening where you cannot see them. Each entry stops counting after a set time and then falls away on its own; none of it is permanent, and none of it is visible to any other collector. As that record grows the app pauses posting, then replying, then starting new chats and posting trades, and it says on the screen when each comes back. The full description is in section 3 under Moderation and safety, and the retention line is in section 9.

This version adds codes you can redeem, and one small thing they store about you. From a future release, a short code given out on a stream, in a Discord post or on a card can be typed into the Rewards screen to be handed a profile decoration, some Gems, or both. The app records which of its codes you used, when, and how many Gems that code paid — that record is what your Gems are counted from and what stops one code being used twice by the same account. Nobody else can see it, and it is deleted with your account. Two things are worth saying plainly, and both are in section 2. These are the app's own codes and not Fortnite's: the app still cannot grant, transfer or change anything in the game, and the checklist of Fortnite's codes described in section 2 is a separate thing that redeems nothing. And a code is always free — there is no way to buy one, they are never sold or bundled with anything, so nothing here changes the fact that nothing in this app can be bought with money.

This version adds a way to close a conversation. It sits between deleting one and blocking somebody, and it exists because neither of those fits the commonest reason a chat ends: the trade is done. Closing stops new messages in that conversation for both of you, keeps everything that was said, and leaves everything else about the two of you exactly as it was — no hiding, no verdict, nothing removed. Two things are worth reading in full in section 4, because both reach the other person. They are told, in a line inside the conversation naming who closed it. And only whoever closed it can reopen it, which is the point rather than a side effect: someone who ends a conversation because the person on the other end makes them uncomfortable should not be able to have it reopened by that person. I now store, for each conversation, whether it is closed and which of you closed it. Reporting, scam marks and everything else in section 10 work in a closed conversation exactly as they did before.

This version adds a second item-shop notification, and it is off until you ask for it. The first one has always been about your wishlist — it is sent only because you hearted something, and only about the thing you hearted. The new one is the shop itself: once a day, what has gone on sale, the same message for everybody who wants it. It is not built from anything about you and needs nothing from you; the only thing stored is that you turned it on. Section 4 describes both, and they are separate switches.

This version removes the ability to buy anything, and opens the shop that spends the earned currency. Two changes on the same day, and they are two halves of one thing. The ability to sell profile decorations through the App Store — built, never opened, never used by anybody — has been taken out of the app and off the server entirely. It is not switched off any more; there is no code left that could charge you, and the sections describing what a purchase would have involved have gone with it. Nothing is lost by anybody: nothing was ever sold, no payment information ever reached me, and every decoration that had a money price now has a Gem price instead — eighteen of them, which is what put stock in the shop the previous version introduced. Gems are earned by using the app and cannot be bought at any price, so the practical effect is that things which were once going to cost money are now things you can earn. This collects nothing new. It collects less: there are no purchase records, no transaction references and no refund messages, because there are no purchases. Sections 2, 6 and 9 are shorter for it, and the App Store is no longer a recipient of anything.

This version adds a currency, and it is earned rather than bought. From a future release the app has Gems, given for using it — trading, posting, keeping a daily streak, filling in your collection, being around a while, taking part in a creator-code campaign — and spent on profile decorations in a small shop. No amount of money will ever produce one: there is nothing to top up, no pack, no bundle and no subscription, and the App Store still sells nothing for this app. Earlier versions of this page said flatly that there was no currency in the app, and that is no longer true. Three things are now kept against your account that were not before: what you have spent Gems on and when, anything I have handed you by hand, and a one-off adjustment made when Gems were introduced so that a long-standing collector's history did not pay out all at once. How many Gems you have is not stored at all — it is worked out from things the app already knew about your account. Nothing the app draws at random can be bought with them, and nothing that can be drawn is ever put in the shop. Section 2 has the detail.

This version changes one thing about blocking, and only for the handful of accounts allowed to moderate the feed. A block used to hide both people from each other everywhere, without exception. From 1 September 2026 a block you place on a moderator stops hiding you from them — your profile, your public posts, the replies under them and your name in search stay visible to that account, because a block that hid them was a way of putting your posts beyond the reach of the only people who can act on them while everyone else went on reading them. Nothing else about blocking moves: your own side is untouched, a moderator you block is still gone from your app, the block still stops them following you, messaging you or replying to you, and it changes nothing at all between you and any other collector. No new information is collected, kept or shared for this, and there is no new recipient — it is the same public content, seen by the same handful of accounts, which section 4 already described. Section 4 sets it out in full.

This version also describes signing in with Epic, which section 2 covers. It is worth being plain about what it is and is not: it confirms who you are, it stores an account identifier and a name, and it can never tell this app what you own in Fortnite, because no level of access to Epic offers that to anybody. It has since shipped — see the entry at the top of this section.

This version adds a way to fill in your locker by pasting a link instead of ticking every item. Section 2 describes it in full. The short version is that the reading happens on your phone, the app does not visit the site the link points at, and what is saved is a list of cosmetics and nothing about where the list came from — not the address you pasted, and not the account creation date those links carry, which is discarded. It is not a connection to your Fortnite account. Importing reads nothing from Epic, and the sentences elsewhere on this page saying so are still true: it cannot see what you own, cannot change anything in the game, and never asks for an Epic password.

This version lets you react to a Fortnite cosmetic, and publishes the counts. From a future release each item in the shop carries five faces you can tap, and how many people picked each one is shown to everybody. Two things about that are new and section 2 describes both: a small amount is stored about you that was not stored before — which item, which face, when — and a number derived from it is public, which nothing about your locker or your wishlist has ever been. Which face you picked is not published and is not on your profile. Deleting your account deletes your reactions; it does not walk back a public count, because a count of opinions is not information about a person — and taking a reaction back before you delete removes it from both.

This version is about the community feed, which has gained a second half. The feed used to ask only what you had caught and what you were hunting; from a future release it has a general Fortnite and Sprite Catch section beside the trading one, and four things about it are worth stating plainly rather than leaving to be discovered.

A post can carry a photo, and that photo is public. Until now the only pictures in this app went to one person in a message or to me in a support ticket. A photo on a post can be seen by anyone using the app, including people who never signed in, because reading the feed needs no account. It is stored on the server like a message photo, it is stripped of the details a camera records with it before it leaves your phone, it is not put on the public web profile page and it is not indexed by search engines — but it is published, and section 4 says so in those words.

The measure that stops keeping an account's photos now covers posts too. It covered messages only, which would have left the public half of the app out of the one measure aimed squarely at pictures. A support photo is still always kept, and is still the one exception.

You can now tag any collector with a public profile, where a tag used to work only if that person followed you and silently did nothing otherwise. Tagging someone notifies them unless they have turned mentions off in Settings, and it still cannot reach a private profile or somebody either of you has blocked.

Posts can be liked and reposted, and both are stored the way a reaction already was: who did it and to which post, kept while the post is, and gone when it goes. A photo goes with the post that carried it, including out of storage, on the same 90-day clock section 9 describes for the post itself.

This version gives every collector a username, and moves what is in the address of your public profile page. Until now people found each other by a randomly generated friend code that the app printed on your profile. From a future release that code is your account ID — still yours, still what a support conversation quotes, but shown only to you in Settings — and the thing other collectors see and search for is a short username you pick.

Three things about that are worth stating plainly rather than leaving to be discovered. You choose it, so it can be recognisable in a way a random code was not; if you reuse a handle you use elsewhere, somebody may connect the two, and that is now your call rather than the app's. It is in your profile's web address, at spritecatch.com/u/<your username>, which no account is needed to open — so a guessable handle makes a page that was effectively unfindable somewhat findable. The page itself shows exactly what it showed before, and the old code-based address still works, so nothing already shared has broken. And accounts that existed before this release are given one automatically, worked out from the display name already on the account, so that nobody becomes unfindable on the day the change ships; the app then puts a one-time notice on your own profile showing what you were given and offering to change it. Nothing else is collected: a username and the date you last changed it (which is how the app tells you when you may change it again — once every fourteen days) are the whole of it, there is no new recipient, and going private still hides you from search entirely.

This version adds three Discord commands that post a picture, and a new recipient for information that was already public. A collector who has linked their Discord account can now type /missing, /collection or /rating in a channel and have the app reply there with an image of their collection or their trading record — or of another collector's, if that collector's profile is public. Nothing new is collected or stored to draw one, and everything on the picture is what a public profile already shows to anybody; what is new is that it now leaves for Discord, which keeps its own copy under its own rules. A private profile cannot be looked up this way, and nothing is ever posted unless somebody types the command. The commands arrive with the release that carries them.

This version adds a place to read one collector's posts, and collects nothing for it. A profile now has a Posts tab listing everything that collector has written. Every one of those posts was already public and already listed in section 4 as something anyone can see; no new information is collected, kept or shared to draw it, and nothing that was private has become public. What is new is that one person's posts can now be read together rather than found one at a time, which is worth saying plainly even though the posts themselves have not changed. The same limits apply to the list as to the profile it sits on: a private profile withholds it, a block hides it, and a deleted post is gone from it.

It also adds a check that runs on your phone and collects nothing. The app now reads a post or reply while you are typing it, on your own device, to tell you if it will be refused or if it breaks the feed's rules, and to offer you a report instead when it reads as an accusation against another collector. Nothing about that reading — the words, the warning, or the fact that there was one — is sent to me or stored anywhere, and it is listed here because it reads what you write, not because it collects it.

This version adds one small record: a note that mail to an address bounced. Sign-in codes had been going to addresses that could never receive them — misspelled domains, mailboxes that do not exist — and enough of them bounced that the email provider warned it would stop letting this service send at all, which would have left everybody without a way to sign in. So two things changed. An address is now checked before a code is sent, by looking up whether the domain after the @ can receive email; and when a message does bounce, the address, the reason and the date are written down so the same message is not sent again. That note holds nothing else, is not linked to an account, and is not shared with anyone. A temporary failure is forgotten within a day; a permanent one is kept while it remains true, and unlike everything else here it is not removed when an account is deleted — section 2 says why, and section 9 gives the whole rule. You can ask to have one cleared. Nothing else about what is collected, who sees it, or what it is used for has changed.

This version removes the ability for questionnaire answers to be sold, and every part of this page that described it. Since 1 August 2026 the app has carried machinery for offering a questionnaire whose answers were sold to game companies as market research, and this policy set it out in detail: a purpose, a category of buyer, a separate consent screen, and a switch in Settings. None of it was ever used — no such questionnaire was ever offered to anybody, no answer of yours was ever sold to anyone, and no money ever came of it. From today it is gone rather than switched off: the server refuses to serve or accept a questionnaire of that kind, and the app carries no consent screen and no sharing switch. Answers to a questionnaire are read by me, to work out what to build next, and go nowhere else. Nothing about you is sold, and nothing ever was. One thing is deliberately kept: the iOS tracking permission. The app still asks it, and nothing in the app reads the answer or tracks you — it is held so the choice is already made if anything ever needs it, and this page would change before anything did. Section 2 describes it, and the App Store listing declares no tracked data. Sections 2, 5, 6, 10 and 11 lost the paragraphs that described the old arrangement, and section 10's Do Not Sell heading is kept — pointing at an answer rather than a control — because a page that has carried it since 1 August should not simply drop the anchor. The entries below from 1 and 30 August 2026 are left standing as the record of what was disclosed at the time.

This version says the arcade has stopped paying out decorations. The games were built with a way of handing one over for a high score, or for being first on a board, and from today that is switched off. Nothing has been taken away from anybody: no decoration was ever given out for a score, so there is nothing on any profile that this removes. Nothing else about the games changed — your best scores are still kept and still ranked, exactly as Playing the arcade describes — and nothing new is collected or kept as a result. It is written here rather than left to a release note because this page has been describing, in the present tense, something the app no longer does. If it is ever switched back on, this page will change with it before it does. Sections 2 and 4 describe it.

This version describes one new thing the app keeps, and it is small and short-lived. From a future release, opening a reward box shows you a few decorations and lets you keep the one you want, instead of handing you a single one. While you are deciding, the app keeps a note of which decorations it has offered you, so that closing it and coming back brings you to the same ones. It is deleted the moment you keep one, and it goes with everything else if you delete your account. Nothing about a box has become buyable and nothing costs money: the extra looks are free, fixed in number and came with the box, and none of the promises this policy already made about free draws has changed. Section 4 describes it.

This version describes the typing indicator, and puts it behind the switch it should always have been behind. A conversation shows the other person while you are typing. That has been true on iPhone since 27 August 2026 and this page did not say so; from today it is written down, and it arrives on Android in the same release. Nothing is stored — it is passed between the two of you as it happens and there is no record of it afterwards — so this adds nothing to what is kept about you. What has changed is that it now obeys Show When I'm Active, in both directions, exactly as the "last active" time already does: until today it was sent whatever that switch said, which was not what this page promised the switch would do. Section 4 describes it.

This version adds one recipient, and it is a person rather than a company. The terms now carry a copyright-complaint procedure, because the app has always let you post pictures and never said what happens when one of them belongs to somebody else. Running that procedure means a complaint reaches the collector it names, and a reply disputing it reaches the complainant — each carrying the sender's own name and contact details, because the law that governs it gives neither side a way to stay anonymous. Nothing new is stored about you and nothing new is collected; what is new is that a stranger can end up holding your name and address if you dispute a complaint about something you posted, and you should know that before you decide to. Section 6 describes it, and the procedure itself is in section 9 of the terms.

This version narrows the measure that stops an account's photos being kept, and says plainly what an earlier version of this page got wrong. Since 9 August 2026 that measure has thrown away what the account uploads instead of storing it, and this policy said it applied in messages and on support tickets alike. From today it applies to messages only: a photo attached to a support ticket is always kept, whoever sends it. A support photo has two readers — the person who sent it and me — so discarding one protected nobody; it only meant that somebody who had been asked for a screenshot, to settle a reward claim or show me a bug, sent one that arrived empty, with neither of us told. This keeps more of your information than the earlier wording promised, which is why it is written here rather than left to a release note: for an account under such a decision, a support attachment is now kept on the same terms as anybody else's, described in sections 4 and 9. Nothing changes for messages, and nothing changes for an account this has never been applied to. Photos already thrown away were never written down anywhere and cannot be recovered — if you were asked for one and it did not arrive, send it again.

This version also corrects a sentence about how far back those measures reach. It said that messages and photos sent before such a decision are untouched. That stopped being true of the photo measure on 21 August 2026, and this page should have said so then: stopping an account's photos being kept can also take the pictures it has already sent, in messages and on tickets both, and unless I choose otherwise that is what it does. The messages themselves stay, and still read as conversations somebody sent a picture in; the pictures are deleted and there is nothing to restore. Nothing about the other measures changed — a withdrawn report, post or message is still stored and still shown back to the person who wrote it.

This version says that an arcade score can now be shown to one conversation. From a release shipping shortly, you can send a challenge into a chat you already have: it arrives as a card that stays in the conversation and keeps a small scoreboard on it, and either of you can play the game straight from it. New information is kept — who opened a challenge, which game, which conversation, when, and one best attempt per person who plays it — and it is described in full under Playing the arcade. Two limits are the reason this is a small change rather than a large one. A challenge can only go into a conversation you already have, so nobody can be challenged by somebody they have never agreed to hear from. And the number on a card is always one you chose to put there — your own record at that game, or a run you played on the card — so a score can never appear anywhere you did not send it. The one genuinely new thing it makes possible is that a private profile, which is on no leaderboard at all, can now show a score to the people in one conversation, and only to them. The same release adds a short Friends list to each game's screen, which publishes nothing a leaderboard does not: it lists only accounts a leaderboard would already list, so a friend whose profile is private is simply not on it. Nothing about either is sold, shown on the web, or used for anything but the screen it is on.

This version says that the language shown beside a post is now worked out from the post itself, on your phone. Until now it was taken from the language setting on your account, which is seeded from the language the app is displaying itself in — so somebody who reads the app in Spanish and writes to the feed in English had their English posts labelled Spanish, and both filters gave the wrong answer. From a release shipping shortly, the app asks the language recogniser built into iOS what language you have actually typed, before the post is sent. Nothing is uploaded to do it and nothing new is stored: the analysis happens entirely on your phone, what leaves it is a single language code, and that code goes in the place the setting's code used to go — the same label, on the same post, visible to the same people. Where there is too little text to tell, nothing is guessed and the setting is used instead, exactly as before. Your setting is unchanged and still yours to set or clear; what it no longer does is decide what language other people are told your words are in. Sections 2, 4 and 5 describe it.

This version says that the safety program which reads conversations on my server is switched off. It ran for one day, from 29 August 2026, and I turned it off on 30 August 2026 because of what it costs to run. Since that date no program on my server reads a whole conversation, or looks at a photo. This is a change that collects less and reads less, not more. Everything else in Moderation and safety is unchanged and still running, including the parts that do read written words: the word list that screens each message as it sends, the check that holds back a public post putting its author at risk, the check your own phone makes on messages you receive, reports, blocks, and the measures I apply by hand. I have not removed the program — it is still built into the service and I can switch it back on — which is why sections 4, 6 and 11 still describe it in full rather than deleting it, and why this page does not go back to saying that nothing you write is read by a machine or that photos are never looked at on my server. Those are things I can no longer promise. If it runs again, this page will say so on the day, in the same plain words.

This version says that I am no longer the only person who can moderate the feed. From a release shipping shortly, a few collectors I choose by hand can remove a public post and pause its author from posting for a while. It is the first time anybody but me can act on your content, so it is written out in full under Moderation and safety: what they can see (only what you have already made public), what they cannot do (any of the measures on this page that work by not telling you), and what is written down about it. The pause itself is the one measure here that is deliberately announced to the person it applies to — you are told that it happened, why, and when it ends.

This version says plainly that nothing about you has ever been sold, because nothing has. Earlier versions said that some questionnaire answers "are sold" to game companies, and described that as how the app pays for itself. The ability to run such a questionnaire was built and disclosed — and it was never used. No questionnaire whose answers are sold has ever been offered to anybody, no answer of yours has ever been sold to anyone, and the app has no income. What those sections describe is kept, in the conditional, because the ability still exists and because a switch you can set in advance is only worth having if you know what it is for. If one is ever offered, this page will say so before it happens. (Superseded the following day: on 31 August 2026 the ability itself was removed, and the sections describing it went with it — see the entry at the top of this section.)

This version says plainly that nothing in the app can be bought, because nothing can be. Earlier versions said the app had optional in-app purchases and described buying a profile decoration in the present tense. That was written when the ability shipped, and it was never switched on: the shop was closed on both the app and the server before a single decoration was offered, none was ever put on sale, and nobody has ever bought anything. No payment information has ever reached me, and there are no purchase records to keep, share or delete. What the sections below say about purchases is kept as a description of what would happen if the shop were ever opened — nothing there has taken place. If it is ever opened, this page will say so on the day, and not before. (Superseded on 1 September 2026: the ability itself was removed from the app and the server, and the sections describing it went with it — see the entry at the top of this section.)

This version adds two things around age, and neither collects anything new about how old you are. Accounts holding an age that an older version of the age screen recorded by default, rather than by anybody choosing it, are asked the question again — and when anybody confirms the age on their account is right, the app now keeps a record that they confirmed it and when, which is what stops it asking. That record says only that the question was answered; it is not proof of the answer. Separately, accounts that stated an age under 13 now see a notice naming 1 October 2026, the date from which the community, direct messages and news will be switched off for them; the collection, the scanner, Rewards and their own profile are unaffected. Section 8 describes both.

You can also now report an account for appearing to be under 13. It is a new reason on the reporting form described in section 10, it puts the account in front of me rather than restricting anything by itself, and it is deliberately weighted below a report of harassment or of a scam.

This version changes what being blocked does to your side of a conversation, and section 10 now describes it. Until 29 August 2026 a block hid the conversation from both people, which meant the one who had not blocked lost the transcript as well — and that is the person most likely to need it, because blocking the collector you have just taken a sprite from is a scammer's second move. From that date a conversation somebody blocks you out of stays in your list and stays readable, with no way to reply and Report in place of the message box. Nothing new is collected and nothing new is shared: those messages were sent to you in the first place. Your own blocks work exactly as before — block someone and their conversation goes.

This version also lets that safety program look at photos, which is a change from what this page promised before. Until 29 August 2026 photos attached to messages were never scanned on my server — they were stored as sent and looked at only when somebody reported one. That is no longer true and this page no longer says it. What it does is narrow, and the shape is the point: it looks at pictures only for the small number of accounts something else has already singled out, never at every upload, and never at a photo attached to a support ticket. What it is looking for is one account showing different people to different children — the way an adult most often gets a child's trust in an app like this, and something that has happened here. It cannot recognise a face and is not permitted to learn how: it answers simple questions about each picture (is there a real person in it or is it a game screenshot, roughly how old they look, is it sexual) and compares those answers between conversations. No faceprint is made, nothing measures anybody's features, and no picture is matched against a named person. It keeps a line about what it saw and a fingerprint of the file, never a copy of the picture, and where a picture may be child sexual abuse material it keeps not even that — only a note that a person must look. A voice message is still never touched. Sections 4, 9 and 11 moved with it.

This version adds a safety program that reads written messages and posts on my server, and that can hold an account's messages back on its own. Until now the only automatic reading of a message on the server was a word list checking one message at a time as it was sent, and the only thing that could hold an account back automatically was a count of how often it had done a small number of specific things. Both are still there. What is new is a program that reads whole conversations — both sides, plus public posts, replies and the note on a message request — a few times an hour, on a small number of accounts chosen because something about them stands out, looking for strangers approaching children. It reads writing only: not a photo, which is still never scanned on my server, and not a voice message, which nothing turns into words. It can hold an account's messages back for seven days, silently, and only when something independent — a report somebody filed, or your own phone's check — points the same way; everything else it finds is written down for me to read. Its reasoning is stored so a decision can be reviewed and undone, and it names the messages it was looking at rather than copying them, so deleting a message removes it from that record too. It runs on Cloudflare's own service, which is not a new company on this page (section 6), does not keep what it reads and does not use it to train anything. You are entitled to have a person look at any decision made about you this way, and section 4 says how. Sections 4, 6, 9 and 11 all moved with it.

This version narrows the age question to 13 and up, and adds Safe Mode for everybody below it. The list of ages on the setup screen used to start at 4; it now starts at 13, because the social side of the app is a 13+ product, and the button under it saying My age isn't listed leads to an explanation and to Safe Mode — a limited version of the app with the community, direct messages and news switched off, leaving the collection, the scanner, Rewards and your own profile. This collects less, not more: an account that takes that door is recorded as under 13 with no age number at all, where before it would have stored one, and every under-13 protection in section 4 applies to it. Nothing about an age switches a feature off by itself — Safe Mode is chosen, and a parent can undo it, or lock the same restrictions with a passcode, on the Parental Controls screen.

This version lets collectors send each other web addresses inside a conversation, and puts a warning in front of every one. Until now the app refused a link in every piece of text anybody could write. That has changed in one place only — a conversation both people already agreed to have — and nowhere else: a public post, a display name, a profile description, a trade listing, a group's name and the note attached to a message request all still refuse one. Tapping a link never opens it straight away: the app shows you the website's address on its own, says that a collector sent it and that nobody has checked where it goes, reminds you never to type a password into it and that no site gives away free V-Bucks, and offers to keep you here before it offers to take you there. Only an ordinary web address can be tapped at all — a link that would open another app, or one written to look like one website while going to another, stays plain text. Sprite Catch has no browser of its own, so following a link opens your phone's browser and leaves the app. None of this collects, stores or shares anything new about you: nothing about the visit comes back here, and the app tells nobody which links you followed.

This version adds a wishlist to the locker, and one notification that comes with it. Tapping a heart on a cosmetic stores which item you hearted and when, and once a day the app compares your hearted items with what is in Fortnite's item shop and sends you a single notification if any of them are there. Nothing is sent until you heart something, it is never more than one notification a day, and a switch in Settings turns it off without changing your wishlist. A wishlist is private on exactly the terms the locker already is: not on your profile, not on the shareable web page, and not visible to any other collector. The list of what is in the shop comes from the same public Fortnite community database the cosmetics catalogue does; it describes the game rather than any player, and nothing about you or what you hearted is sent to it, to Epic Games, or to anyone else.

This version adds a locker: a place to track which Fortnite cosmetics you own. It works exactly like the code checklist already did — you tick what you have, the app remembers it against your account so it survives a new phone, and it checks nothing, because it is not connected to your Fortnite account and cannot see it. A locker is private. It does not appear on your profile, it is not on the shareable web page, and no other collector can see it. From a future release there may be a setting that lets you choose to publish it; nothing is published unless you turn that on yourself. The list of cosmetics the app shows you comes from a public Fortnite community database that describes the game rather than any player, and nothing about you is sent to it, to Epic Games, or to anyone else.

This version grows the game on the Rewards screen into five games, and with them sixteen more leaderboards. Alongside the original — flying your character through a run of pipes — there are now four more, all drawn by the app out of its own artwork and the sprites you already collect. Nothing new is collected. What is kept for each of them is exactly what was already kept for the first: your best score and the date you set it, plus your best inside the current day, week and month, each rewritten only when you beat it, so the games you lose still record nothing. What is genuinely new is where a name can appear: each game keeps its own four leaderboards, twenty in all, on the same terms as before — inside the app only, fifty names each, and only for profiles that are public. A game's boards are its own and the games are never added up. One game a day is spotlit on the arcade screen, which is worked out from the date and nothing about you. Playing can still earn a profile decoration and still cannot be paid into. Sections 2, 4, 9 and 11 have been reworded throughout to say "the arcade" and "each game" where they used to name one game and four boards.

This version adds one small thing that is stored about you: a checklist of Fortnite's own codes. Fortnite gives out codes you type into its Admin Panel, and it does not tell you which ones you have already used — so the app now lists them and lets you tick them off, and the ticks are kept against your account so a new phone still has them. Only the ticks are stored, and only for codes the app has published: not the time you ticked one, not whether it worked, and nothing at all read from Fortnite or from your Epic account, which this app cannot read. Nobody else can see the list, it is deleted with your account, and ticking is optional — the codes are readable without ticking anything.

This version widens invites, removes a deadline, and adds one thing that is drawn at random. Nothing new is stored about you: it is still only who invited you, if anybody did, and still worked out from that how many people you have brought in. Three things change. There are more decorations to unlock, at more points along the way. The one-week deadline for entering somebody's code is gone — an account of any age can now credit the person who invited it, still only once and still never changeable afterwards — and there is a decoration for doing so, so the person who was invited gets something too. And one of the rewards is a box: it opens into a single decoration out of a published set, on the same terms as every other box in the app, which section 2 sets out — nothing about it costs money, nothing can be bought to change the chances, something you already hold is never drawn again, and the set and your real odds are shown before you open it. Everything the last version promised about invites otherwise still holds: your count is shown to you and to nobody else, nobody is told who invited them, an invite page names nobody, and nothing won this way can be traded or sold.

This version gives you a switch over something that has always been shown and never had one: when you were last using the app. Nothing new is collected. That time has been on public profiles and behind the trade board's "active this week" filter since trading launched; what changes is that a conversation now draws it as "Online" or as how long ago it was, accurate to the minute rather than to the hour, and that Show When I'm Active in Settings → Privacy & Safety turns the whole thing off. The switch is deliberately reciprocal — off means nobody is told about you and you are told about nobody — and it also removes you from that trade board filter, so it cannot be worked around. Accounts under 13 start with it off. Section 4 describes it in full, including the one thing switching it off does not do, which is stop the service noting when it last saw you.

This version changes what linking your Discord account does, and it narrows something the last version said absolutely. Finishing a link now gives your Sprite Catch account a profile decoration, sends you a direct message from the app's bot confirming it — carrying your display name and friend code, in your Discord inbox, under Discord's own retention — and gives your Discord account a Verified Collector role in the community server. The last version said the link was visible to me and to nobody else. That is still true of the link itself, and it is no longer true of the fact that you have one: a role is visible to everyone in the server, so anybody there can see that your Discord account has linked a Sprite Catch account — though not which one, and not your name, friend code or collection. Disconnecting removes the role; the decoration is yours to keep. Nothing else changes: no new data is collected on this side, the link is still one account each way, still only happens if you type the command, and the Disconnect button is still on the same page and the same screen that made it. Section 2 describes it in full and section 6 says what Discord receives.

This version also publishes one thing about you to the community server that used to stay inside the app: how your trading has gone. A linked Discord account is now also given a trader role — Bronze, Silver, Gold or Diamond — matching the standing the app already shows under your name, and that role is visible to everyone in the server. It is worked out from trades, ratings and reports that are already described in section 2, so nothing new is collected about you; what is new is who can see it, and the honest way to put that is that linking now carries your trading reputation from one place to the other. It is checked once a day, so it goes up and down with your record and comes off when you disconnect. Two limits are deliberate and worth having in writing: a warning on your record is never published to Discord — an account carrying one simply has no role — and nobody with no trades yet gets one either. The only thing stored on this side is which roles the server was last told to give you. If you would rather none of this were on Discord, disconnecting removes them and takes seconds; section 2 says where the button is.

The same version adds a season role, and one limit that applies to both. A linked account is also given a role for any past season whose Sprites it has mastered — the same achievement the app already shows you, and, unlike the trader role, kept once earned rather than re-checked against your collection. And neither role is given to a private profile. That limit is the point: section 4 promises a private profile keeps its collection and its record to yourself, and a Discord role is that information shown to a whole server, so linking Discord must not become a way to publish a collection you chose to keep private. A profile that goes private after the fact has both roles removed the next day.

This version adds group conversations, and the change worth reading is who your messages reach. A conversation can now have up to thirty-two people in it, so a message, a photo or a voice message you send to a group goes to everybody in it rather than to one collector. Alongside it I store the group's name and picture, who is in it, when each person joined, whether they have muted it and how far each has read. Anyone in a group can add other collectors to it; nobody can remove anybody else. Being added is still your choice — people you follow or already talk to can add you straight away and you can turn that off, while somebody you do not know always has to ask, and a group you join shows you nothing that was said before you arrived. Section 4 covers what is stored and section 9 what happens to it when you leave or delete your account.

This version adds the first thing the website has ever asked you for: an email address, so that you can be told when the Android app is released. A box on spritecatch.com and on app.spritecatch.com now takes an address, and what is kept beside it is which of the two pages you typed it on and the language that page was in — no account, no network address, and nothing linking it to a collection. It is used for one email, on release day, and your address is deleted as that email is sent. There is no newsletter and nothing to unsubscribe from afterwards; if the release slips or the email is never sent, the whole list is erased 30 days after the announced date regardless. It is not sold, it is not shared, and the only company that ever handles it is the one that already sends every other email this service sends. The box asks you to be 13 or older and, unlike everything else here, has no account behind it to check that — section 11 is blunt about what that does and does not mean. Section 2 describes it in full, section 9 gives the deadline, and you can have an address removed at any time by emailing me.

This version adds a game, and with it a few new things stored about you and a new place your name can appear. The Rewards screen now has a small arcade game in which the character you designed flies through a run of pipes. What is kept is your best score and the date you set it, plus your best inside the current day, week and month — each rewritten only when you beat it, so the games you lose record nothing, and the three shorter ones simply replaced when a new day, week or month starts. The new public surface is a set of four leaderboards of the fifty highest scores, shown inside the app, carrying the same name, character and decorations any collector row already shows, and only for profiles that are public. Playing can now earn a profile decoration — for reaching a published score, or for being first on one of the boards. There is no draw and no currency, nothing about the game costs money, and nothing that can be bought changes a score or what it earns; an earlier draft of this policy said nothing was won by playing, and that is no longer true. Section 2 describes what is stored, section 4 describes the leaderboards and who is on them, section 9 says how long it all lasts, and section 11 says how it applies to an account under 13.

This version adds one new thing that can be stored about you, and it only happens if you ask for it: a link between your Sprite Catch account and your Discord account. The community server now has a /link command that connects the two, so that the person asking a question there and the collector it is about are recognisably the same person. What is stored is the identifier Discord uses for your account, the username it had at the time, and when the link was made — nothing else about Discord, and nothing at all unless you type the command and finish the page or screen it opens. No other collector can see it, it is one account each way, and there is a Disconnect button on the same page that made it. Section 2 describes it in full, section 6 says what Discord and the two sign-in providers receive, and section 9 says how long it lasts. This also narrows something this page used to say absolutely: every page on spritecatch.com loaded nothing from any other company, and the linking page is the one exception — it loads Apple's and Google's sign-in code, because that is the only way either sign-in works in a browser. Doing the link inside the app loads neither.

This version says that deleting one of your own posts no longer reduces the number of reactions your profile has collected. That total is shown on your profile and is what one of the achievement badges counts, and it used to be worked out from the posts still on the feed — so tidying up an old post that people had reacted to quietly took the badge back, which is not what anybody deleting a post is asking for. It is now a running total that a deletion leaves alone. Nothing new is collected and nothing extra is kept: the post, its replies and the reactions themselves are still erased on exactly the terms in section 3, and what survives is a number you can already see on your own profile, holding nothing about the post and nothing about who reacted. It goes when your account does. A post I take down myself is not counted this way.

This version takes something back that this page used to promise: a photo you unsend is no longer deleted. Until today, taking a message back deleted any photo attached to it outright, while the words were kept on the server for moderation — and the page said so plainly. The photo is now kept on the same terms as the words: out of both apps, unreachable by either collector, readable only by me and only for the reasons in section 4. The reason for the change is the reason the words were always kept, applied honestly: when what somebody sends is a picture — a fake receipt, a photograph they should not have sent a child — deleting it on request destroyed the evidence for the very report that follows, and unsend became the thing to do immediately after doing something worth reporting. Nothing new is collected: the photo was already on the server, sent by you and seen by the person you sent it to, and this changes only whether it survives your taking the message back. Two things are worth being clear about. Photos unsent before today are gone and cannot be brought back. And a voice message is still deleted outright when you unsend it, with nothing kept, because recordings have a thirty-day life of their own (sections 4 and 9). If you do not want a photo you sent to exist on the server, deleting your account still removes it, as section 10 describes.

This version corrects what this page said about the Android app, which had fallen behind what the app actually does. Two places still described it as collection-only — no feed, no trades, no direct messages, no reputation, no reports — and one of them also said it had no Parental Controls screen. None of that has been true since the August 2026 parity work: the Android app has all of those, and it also sends usage analytics, stores an email address if you sign in with one, and can record a voice message. Nothing about what is collected changed with this edit — the collection had already been described in section 2, and the apps were already doing it. What changed is that section 4 and section 11 no longer tell an Android user that features they can see do not exist. The Google Play data disclosure was corrected on the same day to match.

This version also makes the age question compulsory, and asks it on Android for the first time. It was previously an iPhone-only question that could be left unanswered, which meant most accounts had no age on file — and the age is what sets an account's privacy defaults and decides which safety reminders it sees. It is now asked on both apps, it has to be answered before the app continues, and it is asked once of existing accounts that were never asked. Still a number and never a date of birth, still never shown to another collector, and answering it still takes no feature away (section 4).

This version adds three child-safety measures, and one of them stores something new. A public post whose writer says how old they are and asks strangers for a relationship is now kept out of the feed automatically — the writer still sees it in their own feed, nobody else does, and the fact that it was held is stored with the post so I can review it and put it back (section 3). The check the app already ran on your own phone as you send a message now recognises two more kinds of request — moving the conversation to another app, and meeting or calling — which are recorded for me to read but, unlike the first three, can never on their own hold an account's messages back (section 3). And the app now shows the safety rules before your first conversation and records on your account that you have read them, so that reinstalling does not ask you again (section 3). Separately, your phone now puts a short caution under a message you receive that asks for a picture of you, asks you to move to another app, or asks to meet; that reading happens entirely on your device and nothing about it is sent to me or stored anywhere.

Correction: the support arrangement with Discord described below never actually happened. In August 2026 this page said that volunteer moderators would help answer the support queue from a private staff channel on Discord, and that Discord would therefore handle some of what you wrote to support. It was disclosed in advance, as it should have been — and then it was never switched on. No ticket ever reached that channel, no moderator ever received anything about one, and no support content of any kind has ever reached Discord. The connection was removed from the app on 20 August 2026 without ever having carried anything. Earlier versions of this page said a residue of those tickets remained on Discord's systems; there is no such residue, because nothing was ever sent. Support has always been answered by me alone. The community Discord server is unrelated and unchanged: it was never part of the support queue, joining it has always been your own relationship with Discord, and section 6 still describes it under community links.

This version also corrects something about the website, and the correction is an admission. Until 20 August 2026 the pages at spritecatch.com loaded their two typefaces from Google's font service, which meant that opening one of those pages sent your IP address and your browser's description of itself to Google — a request this policy did not describe, on pages whose section 10 says there is nothing to opt out of. That was wrong of the pages, not of the policy, and it is fixed the right way round: the typefaces are now stored on and served from the website itself, so no page on spritecatch.com or app.spritecatch.com loads anything from a third party — no font, no script, no CDN beyond Cloudflare, which serves the site. Nothing about the apps changed, and what reaches Google from the app remains exactly what sections 2 and 6 describe: a sign-in you chose to start, and notifications on Android.

This version changes how signing in with Google works on Android, and adds a second piece of Google software to the app there. It adds no company, no new information about you and no new permission: Google was already listed in section 6 for this exact feature, and what it receives is unchanged. What changed is where you pick your account. Until now that happened on Google's own page in your browser on both phones, which meant no Google software ran in the app for sign-in. Google no longer supports that arrangement on Android, so from a future release the Android app shows you Google's own account chooser, drawn inside the app by Google software, the way most Android apps do. The reason this is written down rather than left as a detail is that the previous version of this policy said sign-in put no Google software in the app, and on Android that stops being true. It stays true on iPhone, where nothing about signing in changes. Still no Google analytics, no advertising SDK, no crash reporter and no advertising identifier, on either phone. Sections 4 and 6 describe it.

This version adds a new company to the list in section 6, for Android only: Google's notification service. Until now no Google software ran inside either app, and this policy said so. From a future release, an Android device that turns notifications on registers with Google's messaging service so that notifications can be delivered to it — the same arrangement iPhone has always had with Apple's, and for the same reason: there is no way to deliver a notification on either platform except through the company that makes it. What that costs is stated plainly rather than buried: Google's service creates an identifier for that installation of the app and holds it while notifications are on, and it receives the notifications themselves, which for a direct message includes the message. It does not receive your collection, and it is the messaging component only — no analytics, no advertising SDK, no crash reporter, no advertising identifier. Notifications stay off until you turn them on, turning them off ends it, and deleting your account asks Google to delete the installation identifier as well. Nothing changes on iPhone, and nothing changes for anyone who leaves Android notifications off. Sections 2 and 6 describe it.

This version adds two new things to what an account records: the country your requests come from, and the language you read and write the community in. The country is worked out from your internet address by the service that hosts the app — never anything finer than the country, with no location permission asked for and nothing read from your phone — and it exists so I can see which countries the app is used in and which languages are worth translating it into. It is written down the first time your account is seen and not updated afterwards, so it is where you started rather than where you are, and no other collector can see it. The language is a setting you choose, and from a future release it does two things with one choice: it labels the posts and trade listings you write, which other collectors can see, and it lets you narrow the feed, the trade board and the list of collectors who own a Sprite to one language — which also means your language decides whether you appear on somebody else's narrowed list. If you never choose one, the app uses the language it is already showing you and your feed keeps showing every language, which is what it does today. Sections 2, 4, 5, 8 and 9 describe both, and section 11 has been reworded so that what it tells parents stays exact.

This version says that deleting a post no longer erases it immediately. It disappears from the app for everyone the moment you delete it, exactly as before, but I keep a copy I alone can read for 90 days and it is then erased automatically. Before this change a deleted post was gone at once, which also destroyed the evidence behind any report about it — the posts that get taken down fastest are usually the ones a report is about. This is a change to how long something is kept, not to what is collected: nothing new is gathered, nothing new is shown to anyone, and no one but me can reach a deleted post. Sections 3 and 9 describe it. Deleting your account still erases your posts outright, without waiting out the 90 days.

This version corrects one sentence about what a second phone shows you. It used to say that signing in on a new phone showed who you had been talking to but nothing that was said. The last message in each conversation was always an exception — the list of conversations has always shown a preview of it — and from a future release the app draws that message in the conversation too, instead of an empty screen. Nothing new is stored or sent to do it: it is the same message, already on the phone, drawn where you would look for it. Everything older is unchanged and stays on the device that received it. Section 4 has the full description.

This version says the app now asks for the microphone, and that it keeps recordings of your voice for a while. From a future release you can send a voice message in a conversation instead of typing one — which is why the app asks for the microphone for the first time. It is described in sections 2, 3 and 4. Two things about it are new rather than restatements of what already happens to a photo. Your voice is a new kind of thing to be holding, so it is held differently: a sent recording is deleted from my server after 30 days, which is the only clock of its kind on this page and is much shorter than the life of a written message. And nothing transcribes it — no machine of mine turns a voice message into words and none of anyone else's does either, which is also why a recording is not screened for banned content the way a written message is; it is reviewed only if somebody reports it. Recording only ever runs while you are holding the record button, nothing is sent until you let go and choose to send it, and refusing the microphone leaves everything else working exactly as before.

This version also adds an official mark beside a few names. From a future release a small number of accounts — mine, the moderators', the app's own, and collectors the team vouches for — show a mark next to the name so you can tell them from somebody imitating them. It is described in section 4. Nothing new is collected for it: it is something I set by hand on an account, not anything gathered about the person holding it, and it is the one thing beside a name that an account cannot give itself. It is shown inside the app only, not on the shareable web page.

This version says the camera has a second use, and that this one sends the picture. From a future release, claiming a reward that a person checks lets you photograph your proof inside the app rather than switching to your camera's own app first — which is what you need when the thing you are proving is on a television. It is described in sections 2 and 4. It is here because this page said, accurately until now, that scanning was the app's only use of the camera and that camera photos are never sent anywhere. The scanner has not changed and still never uploads or saves a frame. What is new is one picture, taken only when you ask for it, attached only to a message you send, going to the same people and kept under the same rules as a photo you pick from your library. No new information is kept about you. (The same release also asks for the photo library for the first time, for a different reason — the entry below.)

This version says the app now asks to see your recent photos. From a future release, attaching a picture to a message shows the most recent ones on your phone in a strip, so you can pick a screenshot without hunting through your library — which is why the app asks for photo access for the first time. It is described in section 4. It is here because this page and the information for parents both said the app never asks for your photo library, and that is no longer true. Nothing is collected by it. The strip is drawn on your phone from your own pictures; the app reads only the one you tap, sends nothing until you send it, and never adds anything to your library or removes anything from it. You can refuse and still attach photos — the picker that was always there is one tap away — and iOS also lets you share selected photos only, which the app handles normally.

This version describes a reward that arrives as a box, and it collects nothing new. From a future release, a reward a person has checked and given you can arrive as a box you open, which reveals one decoration out of a published set rather than the same one for everybody. It is described in section 2. It is here because the page said, accurately until now, that exactly one thing in the app was drawn at random — that sentence would otherwise have become untrue. No new information is kept about you: which decorations you own was already recorded and already private, and this adds only which box gave you one. Nothing about it costs money, nothing can be bought to change the odds, the whole set and your real chances are shown before you open it, and nothing won can be traded or sold.

This version says that a notification about a direct message now carries the message. From a future release, the notification the other person's phone receives contains what you wrote, instead of a shortened preview of it. The reason is speed: their app can put your message straight into the conversation, so tapping the notification opens onto your words rather than onto a wait while it goes and asks what they were. What changes for you is who handles the text on the way: it passes through Apple's push service, which already carried the preview and the sender's name, and now carries the message itself. It is described in sections 4 and 6. Nothing new is kept about you — the message was already stored, already private from other users, and is not kept by anyone new; a notification is delivered and not filed. Turning notifications off stops it entirely, and a message too long to fit a notification is fetched the old way.

This version also says that an account's photos can stop being kept at all. The moderation measures described above all worked the same way: the thing was stored and then withheld from everyone else. From today there is one that goes the other way — for an account whose pictures are the problem, what it uploads is discarded rather than stored, in messages and on support tickets alike. (The part about support tickets changed on 30 August 2026 — see the entry at the top of this section.) It is strictly less of your data kept, it changes nothing for anybody it has not been applied to, and like the others it is not announced to the account it applies to. Ask support if you think it has been applied to you.

This version says that a refunded decoration is taken back, because from today it is. Until now, if you bought a decoration and Apple refunded you, the decoration stayed on your profile — not as a kindness, but because nothing here was listening for the refund. Apple offers a way to be told, it is now switched on, and the earlier wording — that a refund was between you and Apple and that I was not part of that conversation — was about to stop being the whole truth. So: Apple still decides refunds and I still cannot grant or refuse one, and when it grants one, the decoration is removed from your account and the purchase record is marked refunded. The same applies when a decoration reached you through Family Sharing and that sharing ends. Nothing else about your account is affected, nobody is told, and you can buy it again if you want it back. (Superseded on 1 September 2026: buying was removed altogether, so there is nothing left to refund and nothing listening for one. No refund was ever processed, because nothing was ever sold.) What this adds to what is held is one thing, described in section 2: Apple's message about the refund, which carries a reference for the transaction and nothing about your name, your card or how you paid, kept with the purchase record and deleted with it (section 9). If you have never bought a decoration, none of this paragraph applies to you.

This version adds a safety check that runs on your own phone. From a future release, the app can recognise as you send that a message asks a stranger their age, whether they are a girl or a boy, or for a picture of themselves — and tells the service only which of those three it was and which conversation it happened in. It is described in section 3, and what it does not do is the part worth reading. The message is never sent anywhere for this and is never stored for it; there is no score, nothing is learned about how you write, and a message matching none of the three — nearly everything anybody sends — leaves no record at all. Nothing new is shared with anyone: no new company, no new service, and nothing about this leaves the app and my own server. It cannot refuse to send a message. Asking somebody their age is ordinary and counts for nothing by itself; only the same questions put to several different people can hold an account's messages back, for 24 hours, and a person reviews every one of those afterwards and can undo it. It exists because children use this app, and because the pattern it looks for is one an automatic word filter cannot see.

This version adds invites, and with them the first record of a link between two accounts. You can share your friend code, and unlock decorations as friends join — so the service now keeps who invited you, if anybody did, and works out from that how many people you have brought in. It is described in section 2, and the shape of it is the part worth reading. Your invite count is shown to you and to nobody else — not on your profile, not on the shareable web page in section 4, and not to anyone I share information with; nobody is told that you invited them, and nobody gets a list of who they invited. Only entering a code records anything: sharing your own code, and other people opening your invite link, write nothing, and a code can only be entered in the first week of a new account. The link goes when either account does — yours, or the account of whoever invited you. An invite link is a page that names nobody: it carries a friend code and an install button and says nothing about the person who sent it. Nothing here can be bought, nothing about it is random, and nothing won this way can be traded or sold.

This version starts counting visits to the web version at app.spritecatch.com. Until now that side of Sprite Catch was measured by nothing at all, so I had no way of telling whether anybody used it. It now records that a visit happened, which screen it landed on, the language and the country — described in section 2 — and the change is worth reading for what it does not do. It still sets no cookie and still stores nothing in your browser, so the promise in section 3 that nothing there identifies you is unchanged. So that repeat page loads are not counted as separate people, a visit is filed under a scrambled stand-in worked out from your IP address, your browser's description of itself and today's date; because the date is part of it, that stand-in is different tomorrow, which is what stops it being a way to follow anyone. Nothing about your collection is in it, no address is recorded — only a category of screen — and no new company receives anything: it is the same server running the same site. There is no off switch on the web version because there is nothing there tied to you to switch off, and the app's Share Usage Data setting is untouched. This changes nothing about the iPhone or Android apps, which count what they always counted, on the same terms and with the same switch.

This version adds a third moderation measure, alongside the two already in section 3. Reporting could already be withdrawn from an account that abused it, and posting from an account that kept posting abuse; messaging can now be withdrawn the same way, for an account that keeps sending harassment in private. It works exactly like the posting one: their requests and messages are still written and still shown back to them in their own copy of the conversation, they are simply delivered to nobody and notified to nobody. This changes nothing about what is collected — the messages were already stored and already readable by me for moderation, as section 3 has always said — and it gives no new information to anyone. It exists because the automatic screen catches banned words and cannot catch someone who insults people using ordinary ones, and because the alternative, telling the account it has been stopped, is how you teach somebody to start again under a new name. Like the other two it is not announced to the account it applies to, it is recorded so it can be reviewed and undone, and support will confirm it and lift it if I got it wrong.

This version also lets the oldest of those three measures be applied automatically. Withdrawing an account's ability to file reports was always something I did by hand, after noticing it; it can now also happen on its own when an account files far more in a day than anyone reporting a real problem ever does. The threshold comes from what people actually do — nearly nine in ten collectors who report anything report exactly one thing that day, and the level that triggers this is well above anything I have seen from someone with a genuine complaint. Nothing new is collected and no new company is involved; what changes is that the decision can be reached without me. It is recorded like any other, a person reviews it, and support will lift it if it caught you wrongly.

This version also lets you take back a scam mark you left on someone. Marking somebody as a scammer puts a public mark on their profile with your name on it, and until now the only way out of one you regretted was to write to support and ask me to remove it. You can now undo your own from their profile, at any time — it comes off, it stops counting against them, and the report filed with it is withdrawn. Nothing new is collected for it, and it reaches only marks you left yourself.

This version also says out loud that a public collection includes what you have mastered. Other collectors could already see every sprite you have, and a count of how many of them you had mastered; from this version they can see which ones, on your profile and in a conversation with you, as a comparison against their own collection. Nothing new is collected — mastery is something you were already recording, and the count was already public — and it goes no further than the app: it is not on the shareable web page, and going private removes it with the rest of your collection. Which sprites you marked as needing a rebuy is still shown to nobody.

This version adds a third way to sign in: Sign in with Google. It sits alongside Sign in with Apple and the email-and-password way in, and it is useful for the simple reason that many phones are already signed in to Google, which makes it one tap. Nothing is being taken away: Sign in with Apple has not changed and is still offered first, email and password still work, and collecting as a guest with no account at all still needs nothing. What it adds to this policy is one new company — Google LLC, now listed in section 6 — and one new source for something already described in section 2: your email address, which Google shows you before it shares it and which the app keeps only if Google confirms the address is yours. The identifier Google returns for your account is described under Account information in the same section. Three things are worth reading plainly. Sign-in adds no advertising identifier and no tracking prompt of its own — the app's one tracking request is the iOS permission described in section 2, which nothing reads and which signing in neither raises nor changes. (Two later changes each added a Google component, both on Android only and neither on iPhone: the notification service, described at the top of this section, and the software that draws the account chooser for Sign in with Google. On iPhone sign-in still happens on Google's own page in your browser and puts no Google software in the app. There is still no third-party analytics, advertising or crash software in either app.) Google learns that you signed in to Sprite Catch, because it is the one showing you the sign-in screen, and it keeps that under its own privacy policy rather than mine. And nothing else goes to Google — not your collection, not your posts, not your direct messages, not what you do in the app. Signing in with Google is optional and required for nothing: if you never use it, nothing in this paragraph ever applies to you. It is dated from today because it cannot reach you before you have read it — no version of the app you can install right now offers it, and it needs a future release.

This version adds a daily reward, and with it a small record of when you claim one. An upcoming release offers a reward for coming back on consecutive days, so the service now keeps how many days in a row you have claimed one, your longest run, and the date of the last claim. It is described in section 2. Three things are worth reading. Opening the app records nothing — it is claiming the reward that writes anything down, so a day you looked at the app and did not claim leaves no trace. Your streak is not shown to other collectors, is not on the shareable web page, and goes to nobody I share information with. And nothing about it costs money — the first six days unlock fixed, published decorations and every seventh draws one prize from a small pool, with the odds shown in the app, nothing purchasable to change them, and no prize ever drawn twice. The release also adds optional reminders about an unclaimed reward; those are set by your phone rather than sent from a server, collect nothing, and are described in section 3.

This version announced a company that would handle some of what you write to support — and it never came to pass. The plan was for a small number of trusted volunteer moderators to help answer the queue from a private staff channel on Discord. It is kept in this log because it was announced here and honesty about a change includes the ones that were called off: it was never switched on, and no support ticket ever reached Discord. See the correction at the top of this section. Every support ticket has always come to one person — me.

This version explains what unsending a message does and does not do. (The part about the photo changed on 24 August 2026 — see the entry at the top of this section.) An upcoming release lets you take back a message you have already sent: it leaves both apps, and a photo attached to it is deleted. The text is not deleted — it stays on the server, where neither of you can read it and I still can, because a message that vanishes completely is a message a scammer can take back the moment they are reported. No new information is collected; this is a new thing you can do, described honestly rather than sold as an erasure it is not.

This version says where your conversations are kept. (The part about a new phone changed on 6 September 2026 — see the entry at the top of this section.) Messages and the photos in them are now saved on the phone that received them and read from there, instead of being fetched from the server every time you open a chat. Nothing new is collected and nothing is kept for longer on the server — the change is about which copy the app reads, and it exists so the app asks the server for a conversation far less often. Two things follow, and both are in section 4: signing in on a new phone shows your conversations but not what was said before you got there, and there is now a Storage screen in Settings showing what is held on that phone and deleting it on request.

This version changes how the automatic support reply works, and says so because the earlier wording no longer describes it. Support is one person, and the same handful of questions arrive over and over — how to unfollow somebody, how to get a profile frame, how to move a collection to a new phone. Those get an answer straight away. Until now that answer was written by an artificial intelligence system running on the same servers as the rest of the service; that has been removed, and what replaced it is a list of phrases and a list of answers, both written by me. Nothing you write to support is now read by any such system at all. Two things follow that are worth reading. A ticket the automatic reply answers is closed, so a follow-up means opening a new ticket rather than writing again in the same thread — the reply itself says so, and section 4 explains it. And more tickets now reach me rather than being answered automatically: anything the phrases do not cover, and anything mentioning money, a refund, a ban or your own account, waits for a person. Nothing new is collected because of any of this, and the short record of what the automatic reply did with a ticket (section 9) is unchanged.

This version adds something you can buy. Profile decorations — an effect on your name, a frame around your picture, a background behind your posts, a look for your profile card — can now be bought through the App Store, so the sentence saying the app had no in-app purchases is gone. Nothing else changed about what the app does: every feature is still free, nothing has been taken away or put behind a price, and the same decorations can still be given out or earned by answering a questionnaire. What is new for this policy is one record — that this account bought that decoration — described in section 2 under Buying a decoration, kept for as long as the account exists (section 9) and relied on to give you the thing you paid for (section 8). Apple takes the payment and I never see your card, your billing address or the name on it. It is dated from today because it cannot reach you before you have read it: no version of the app you can install right now can sell you anything at all, buying needs a future release, and even then nothing is collected unless you choose to buy something — if you never do, nothing in this paragraph ever applies to you.

This version adds a second way to sign in: an email address and a password. Until now the only address the app could ever hold was one Apple offered on your behalf. Now you can type one yourself, confirm it with a short code, and choose a password — which is useful if you would rather not use your Apple ID, or if you are coming back on a phone that is not the one you started on. Sign in with Apple has not changed, is still offered first, and is still the quickest way in; collecting as a guest with no account at all works exactly as it always has.

What that adds to this policy is described under Contact information in section 2: an address you typed, a password kept only as a one-way scrambled version that cannot be turned back into what you typed, a sign-in code that stops working within minutes, and a short-lived record of recent attempts holding a scrambled, shortened form of your network address so that nobody can use the code screen to flood a stranger's inbox. Section 9 says how long each of those lasts, section 12 covers how the password is protected, and section 6 notes that the emails go out through Cloudflare, which already runs everything else — no new company is involved. Signing in this way is refused for anyone whose age check says under 13, since it cannot work without an address, and section 11 says so.

The same version opens reading to people who are not signed in. The community feed and public profiles used to require an account to view — not because they were private, but because every request needed one. They no longer do, so somebody can read the feed and look at a public profile before deciding whether to sign up, and a person who signs out can still read. Nothing new is published by this: the same posts and the same public profiles, seen by the same kind of stranger, and a private profile is still private. What changed is that a reader no longer has to have an account, which is worth saying plainly because "other collectors" used to imply one. Everything that writes — posting, replying, reacting, following, messaging, trading — still requires signing in, and nothing about a signed-out reader is recorded beyond the ordinary request metadata in section 2.

This is a material change, and it is dated from today because it cannot reach you before you have read it: no version of the app you can install right now offers this way of signing in at all, so nothing is collected under it until the release that adds the screen arrives. Nobody is signed up to anything by this page changing. Continuing to use the app means you accept the updated policy.

Alongside it comes a control rather than any collection: from the same future release you can log out without deleting anything. Until now the only way off an account inside the app was to delete it, which is a very large answer to "not on this phone, thanks". Logging out ends the session and the notifications on that device and changes nothing else — your account, collection, profile and conversations are as you left them when you sign back in. It asks what to do with the sprites marked on that phone, and one consequence of keeping them is worth stating plainly rather than leaving to be discovered: sprites left on a phone join the collection of whichever account signs in next on it, so clearing them is the right answer if you are handing the phone on. Sections 9 and 10 describe it.

This version changes what your profile picture is. Until now it was one of the sprites you had caught. From a future release it is a small character you design — its colour, the scene behind it, and whether it has hair, glasses or facial hair — and that choice is stored with the rest of your profile and shown to other collectors wherever the sprite used to be. It is optional: leave it alone and you get the same standard character as everybody else. Nothing new is collected beyond the choice itself, there is no new recipient, and it replaces the old picture rather than adding to it.

Two things it takes away, which is the part worth stating. Your shareable web page at spritecatch.com/u/<your friend code> no longer shows your profile picture at all — it draws the app's mascot for everybody — and neither does the sample feed on app.spritecatch.com. Notifications sent to other people about something you did no longer carry a picture of you either. So this release publishes less about you outside the app than the one before it, not more.

It is dated from today for the reason the changes below are: no version of the app you can install right now can store one of these characters, so nothing is collected under it until the release that adds the screen arrives. Alongside it, some profile decorations become free for everyone rather than bought or earned — a change to what things cost, not to what is collected, and nothing anybody has already paid for is affected.

This version added the ability for some questionnaire answers to be sold. It has never been used, and nothing has ever been sold — see the correction at the top of this section. It is worth reading section 2 rather than this summary, but in short — the app can offer you a questionnaire about the games you play, and such a questionnaire would tell you before you start that its answers are sold to game companies as market research, and would not open until you agree. Nothing is sold unless you did that, and nobody ever has. It is never offered to an account the app has established is under 13, or one whose age it was never told. The answers travel either as totals with nobody identifiable in them, or — only where you separately agreed and allowed tracking — as one record under a made-up reference carrying no name, no friend code, no email address and nothing about your collection. There is a switch in Settings → Privacy & Safety that turns the whole thing off for good, and section 10 explains how to exercise the same right by email. (Superseded on 31 August 2026: the ability was removed from the app and the server without ever being used, and the switch went with it because there is no longer anything for it to turn off — see the entry at the top of this section.)

Two claims this policy used to make have gone with it, and it would be dishonest to let them fade out quietly: this app previously said it sold nothing, and that it showed no App Tracking Transparency prompt because it did not track you. Both were true when written. Neither is true now. The prompt appears before a questionnaire of the second kind above; from 10 August 2026 it can also be answered on its own, at any time, from Settings → Privacy & Safety → Tracking; and from 13 August 2026 the app puts the question to you while you are setting it up, so it is asked and answered before anything could apply it. Declining it costs you nothing either way: you can still answer, you still get the decoration, and your answers are then only ever counted in totals. Nothing else in the app has started tracking you, there is still no advertising identifier in use, no ad network, and no third-party analytics. (Partly superseded on 31 August 2026: the questionnaire this prompt existed for was removed without ever being used. The prompt itself was kept, and is still shown in the two places described above — but nothing in the app now tracks anybody or reads the answer, so of the two claims retired here the first, "it sold nothing", is true again as a plain statement of fact, while the second stands: the prompt is still there.)

This change takes effect on the date at the top of the page, and nothing is collected under it before the app release that carries the consent screen reaches the App Store — a build without that screen cannot offer one of these questionnaires at all.

This version is a material change: it adds the usage information described in section 2 and the email address described under Contact information. Both arrive with a future app release — neither is collected by any version of the app you can install before the effective date above — and both come with a switch in Settings. Continuing to use the app after the effective date means you accept the updated policy. This version also changes section 9 in three ways: it notes the anonymous record kept when an account is deleted — a date and nothing more; it explains that deleting an account now hides it immediately and erases it within 30 days rather than in the same instant; and it describes the scrambled fingerprint kept, for a year and only for an account erased while carrying a scam warning or suspension, so that a warned collector cannot start over by deleting and signing up again. Section 9 also now says that the same warning carries to a new account started on the same phone while the warned account still exists — which stores nothing further, is limited to warnings and suspensions a person decided on, and can be lifted through Support by anyone caught by it because they share a device.

This version also adds one thing you can send: from a future release a support message can carry a photo, usually a screenshot of the problem being reported. It is optional, it goes only to whoever answers your ticket, it is never published, and it is deleted with the account — sections 2, 4 and 9 describe it, and the paragraph at the top of this section says who that is now. Nothing is collected from your photo library unless you pick a picture and send it.

This version also records a change to who the community features are open to, which collects nothing new but changes when the information in section 2 starts to exist. From a future release, posting, replying, reacting, following, messaging and posting a want require you to sign in with Apple; the collection tracker is unchanged and still needs no account at all. An install already using the app keeps the community features for a week after it updates, so nobody loses access without notice. In privacy terms this means less is collected, not more: a collector who never signs in now has no posts, replies, follows, conversations or wants stored for them.

It also adds one control rather than any collection: you can now delete a conversation, which ends your copy of it and leaves the other collector's alone. Sections 4 and 9 describe what that does and does not remove.

It changes how a public profile is found rather than what is stored about it: collectors can now search for a public profile by display name, Fortnite tag or friend code, and search the text of recent posts. Nothing new is collected, and nothing becomes visible that a public profile did not already show — search only makes it reachable by typing rather than by browsing. A private profile is never returned by a search, and direct messages are not searchable at all.

This version also adds profile personalization, which is new collection and is why the effective date above has moved. Three things arrive with it, all optional and all described in section 2: a profile description you can write, which other collectors read inside the app and which is deliberately kept off the shareable web page; answers you choose to give when you complete an in-app questionnaire, which are stored as written and which I read; and a record of which reward offers you completed and which decorations your account holds and shows. None of it is collected before the effective date above, and none of it exists for you unless you write a description or complete an offer. Two things worth being explicit about: a completed offer is recorded against your account, unlike a promo-card tap, which stays an anonymous counter and is unchanged; and none of this involves uploading a picture — the decorations are artwork I made, and that release still asked for no access to your photo library.

It also records one change to section 2. An under-13 result used to switch the community feed, trades, other profiles and messaging off by itself; it no longer does, and those features are now turned off only by a person on the Parental Controls screen. What an under-13 result still does is narrower and entirely about data: no usage information is collected, no email address is kept, and the profile starts private. Nothing new is collected by that change. Section 11 has been corrected to match it — it still described the old automatic behaviour.

One further change to section 2 is new collection, and arrives with the same future release. Where the iPhone app asks how old you are — which it does only when Apple's age service declines to answer, and now during setup rather than afterwards — the age you give is kept with your account instead of being used once and discarded. An earlier version of this policy said your exact age was never stored; that is no longer true, and the sentence has been removed rather than quietly softened. What has not changed: your date of birth is still never asked for and never stored, Apple still does not reveal a birthday to the app, and your age is shown to no other collector anywhere. It is erased with your account like everything else in section 9.

This version adds a way of earning a decoration that involves a person reading a picture. From a future release, some rewards are claimed rather than completed: you do something outside the app, send a screenshot of it through Support, and I look at it and hand the decoration over. This uses the support conversation and the support photo already described in section 2 rather than adding anything new — no new upload, no access to your photo library beyond the picture you picked, and nobody new receives anything. What is new is a note of which reward a conversation is claiming, so it can be given once. Sections 2, 4 and 9 describe it, and it collects nothing for anyone who does not claim. It is worth being blunt about one thing: a screenshot of another game may carry your name in that game, so send the part that shows what you did and nothing more. Nothing you send is passed to Epic Games, and claiming a reward makes no call to them at all.

This version adds one more control and no collection at all. From a future release you can delete a request to chat that you sent, once it has been answered or has gone quiet, out of the list the app keeps of them. It is worth saying plainly what it does and does not do, because the word "delete" means different things to the two people involved: it clears your copy of that list, and where the request was never answered it takes the ask back from the other collector too, so it cannot be accepted afterwards. What it does not touch is a conversation — a request somebody accepted leaves the chat it opened where it is, for both of you — and the record that you sent the request stays on the server. That record is not kept to hold anything over you — it is the count that stops one person being asked to chat over and over, and it is what makes a "not again today" stick — so a delete that took it away would undo both. One consequence follows from taking the ask back: the same collector cannot be asked again for a day. Nothing new is collected and nothing is kept for longer. Sections 4 and 10 describe it.

This version adds a warning and no collection whatever. From a future release, a photo somebody sends you in a conversation can arrive covered, with a note that it may contain nudity, until you choose to see it — and on a phone with Communication Safety switched on in Screen Time, the app also asks before a photo like that is sent. The check behind it is your iPhone's, not mine. It runs on your device, it is switched off unless you or a parent switched it on, no photo is sent anywhere for it, and its answer never reaches me — I am not told that a photo was covered, and not told if somebody looked. Apple requires that of any app using the check, and this page now says so in section 3. Nothing new is collected, nothing extra is kept, and what is stored about a photo and who can read it are unchanged (section 4).

14. Contact

Mateo Duran — Uruguay
contact@spritecatch.com