Sphera AI Games
Privacy Policy
1. Introduction
Sphera AI Games Ltd. (“Sphera”, “we”, “us” or “our”), a company incorporated in the State of Israel with registered office at 10 Zarchin St., Ra’anana 4366238, Israel, operates a browser-based, AI-prompt-powered gaming platform available at https://sphera.games (the “Site”, and together with all related features, the “Services”). Users can generate and play games simply by describing them in natural language.
This Privacy Policy (this “Policy”) explains what personal information we collect from users of the Services, how we use, share, protect, and retain it, and the rights available to you. It applies to all users of the Services worldwide, with jurisdiction-specific provisions in Section 12. For the purposes of the EU and UK General Data Protection Regulation (“GDPR” / “UK GDPR”), Sphera AI Games Ltd. is the controller of the personal information described in this Policy. Israel benefits from adequacy decisions issued by the European Commission and the United Kingdom, meaning personal information may lawfully flow from the EEA and the UK to Sphera in Israel.
This Policy should be read together with our Terms of Service. If you do not agree with this Policy, please do not use the Services.
2. Information We Collect
2.1 Information You Provide
- Account data: name, email address, username, and country, provided when you register directly or sign in with Google. If you sign in with Google, we receive the profile information you authorize Google to share (such as your name and email address); Google’s own privacy policy governs its processing.
- Phone number (optional, when introduced): if we enable phone-based account recovery or two-step verification, we will collect your phone number solely for those security purposes.
- Prompts and projects: the text prompts (and, once available, voice prompts) you submit to create or modify games, together with your Generated Game project data. Prompts are stored and associated with your account so you can continue to develop your games.
- Profile avatar (future versions): if avatar features are introduced, any image you choose to upload.
- Communications: information you provide when you contact support, report a security issue, or exercise privacy rights.
2.2 Information Collected Automatically
- Technical data: IP address, browser type and version, operating system, approximate (city-level) location derived from IP, timestamps, pages and features accessed, session identifiers, and error and diagnostic logs. On future mobile versions, device identifiers may also be collected.
- Usage and analytics data: we use Mixpanel to understand how features are used (for example, prompts submitted, games generated and played). Analytics data is configured so that it is not linked to your account identity and cannot reasonably be used to identify you.
- Cookies: as described in Section 8.
2.3 Payment Information
Purchases are processed by our payment provider, Paddle, acting as merchant of record. Paddle collects and processes your payment card details, billing address, and related purchase data under its own privacy policy (paddle.com/legal/privacy). Sphera does not receive or store full payment card details; we retain only transaction identifiers and amounts for accounting, reconciliation, and support.
2.4 Information We Do Not Want
The Services are a gaming and creation platform. Please do not submit — in prompts, projects, or otherwise — any health information, financial account numbers, government identifiers, biometric data, precise geolocation, or other special categories of sensitive personal information. We do not intentionally collect such data, our systems are not designed for it, and we may delete it if detected.
3. How We Use Personal Information
We use personal information to:
- provide, operate, and maintain the Services, including generating games from your prompts, saving your projects, and enabling you to publish and play Generated Games;
- create and administer your account and authenticate you (including, when introduced, phone-based recovery and two-step verification);
- process transactions through Paddle and maintain accounting records;
- secure the Services: detect, prevent, and investigate fraud, abuse, security incidents, and attempts to manipulate the Platform or its AI systems;
- moderate content, including automated screening of text prompts for offensive content and automated validation and filtering of AI outputs (see Section 10);
- analyze usage in de-identified form to improve performance, reliability, and features;
- communicate with you about the Services, including transactional and administrative messages, and — only with your consent where required and always with an unsubscribe option — marketing communications, if and when we introduce them;
- comply with legal, regulatory, tax, export-control, and sanctions obligations, and establish, exercise, or defend legal claims.
No AI training. We do not use your prompts, your Generated Games, or other personal information to train or improve artificial intelligence models — ours or anyone else’s. Because we do not train on your data, no training opt-out is necessary.
4. Legal Bases (EEA / UK Users)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Performance of a contract: to provide the Services you request, including processing your prompts to generate games, maintaining your account, and processing purchases.
- Legitimate interests: to secure the Services, prevent fraud and abuse, moderate content, produce de-identified analytics, and improve the Services, where these interests are not overridden by your rights and freedoms.
- Consent: for non-essential cookies, marketing communications (when introduced), and any other processing that requires consent. You may withdraw consent at any time without affecting prior processing.
- Legal obligation: to retain records and make disclosures required by applicable law.
5. AI Processing and Third-Party AI Providers
The core function of the Services is the transformation of your prompts into playable games. To do this, prompts are transmitted to and processed by third-party AI providers — currently Anthropic (anthropic.com/privacy) and OpenAI (openai.com/policies/privacy-policy) — via their API services, which generate scene and level data returned to our Platform. We cache AI responses to improve speed and reduce duplicative processing. Our use of these providers’ API services is subject to commercial terms under which API inputs are not used to train their models.
Prompts sent to AI providers are processed on infrastructure that may be located in the United States. Section 9 describes the safeguards applicable to these transfers.
6. How We Share Personal Information
We do not sell personal information, and we do not share it with third parties for cross-context behavioral advertising. We share personal information only with:
- Infrastructure providers: Amazon Web Services (hosting and storage, with customer data stored in Western Europe) and Cloudflare (content delivery, caching, and security).
- AI providers: Anthropic and OpenAI, as described in Section 5.
- Payment provider: Paddle, as merchant of record, which collects payment data directly from you.
- Analytics provider: Mixpanel, which receives usage data in a form not linked to your account identity.
- Authentication provider: Google, if you choose to sign in with Google.
- Professional advisers and authorities: legal, accounting, and other advisers where necessary, and public authorities where we believe in good faith that disclosure is required by law, legal process, or to protect the rights, safety, or property of Sphera, our users, or the public. Unless legally prohibited, we will endeavor to notify you before disclosing your data in response to a governmental request.
- Corporate transactions: a successor or acquirer in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
If you publish a Generated Game, the game (and any username associated with it) will be visible to other users of the Platform, including in any public game gallery we may introduce.
7. Log Data
Our servers automatically record log information when you use the Services, including IP address, request details, browser and device characteristics, timestamps, feature and API usage, session identifiers, and error codes. We use log data to operate and secure the Services, troubleshoot issues, maintain audit trails, and detect abuse, and we retain it as set out in Section 11.
8. Cookies
We use the following categories of cookies and similar technologies:
- Strictly necessary cookies — sign-in, session management, security, and consent storage. These do not require consent.
- Functional cookies — remembering your preferences and settings.
- Analytics cookies — measuring feature usage and performance via Mixpanel. Where required (including in the EEA and UK), these are set only with your prior consent, and we honor opt-out preference signals such as Global Privacy Control where applicable U.S. law requires.
We do not use advertising cookies or AI-personalization cookies. You can manage cookies through our cookie settings and your browser controls; disabling non-essential cookies does not affect core functionality.
9. International Data Transfers
Customer data is hosted on AWS infrastructure in Western Europe. Personal information is accessed by Sphera in Israel, a jurisdiction covered by EU and UK adequacy decisions. Prompts are transmitted for processing to AI providers (Anthropic and OpenAI) whose processing may occur in the United States; these transfers are safeguarded by the EU Standard Contractual Clauses and/or the providers’ certification under the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions), as applicable. Where we transfer personal information to any other jurisdiction not deemed adequate, we will implement a lawful transfer mechanism such as the Standard Contractual Clauses, supplemented where necessary.
10. Automated Content Moderation
We use automated systems to screen text prompts for offensive content, to validate and filter AI outputs for quality and safety, and to monitor for attempts to manipulate or abuse the Platform. Automated flags may result in content being blocked or removed and, in serious or repeated cases, in restrictions on your account. We do not currently use automated decision-making that produces legal or similarly significant effects on individuals without human involvement: where an automated action significantly affects your access to the Services, you may contact support@sphera.games to have the decision reviewed by a human, express your point of view, and contest the outcome.
11. Data Retention
We retain personal information only as long as necessary for the purposes described in this Policy, to comply with legal obligations, to resolve disputes, and to enforce agreements. Our standard retention periods are:
| Data category | Retention period |
|---|---|
| Account and profile data | For the life of your account, and deleted or anonymized within [30] days of verified account deletion, subject to the exceptions below. |
| Prompts and Generated Game project data | For as long as your account remains active and the related project exists, so that you can continue to play, edit, and enhance your Generated Games. You may delete your projects at any time through your dashboard; deleted projects are removed from production systems within [30] days. |
| Cached AI responses | Retained for [•] to improve performance and reduce duplicative processing, then deleted or anonymized. |
| Server, security, and audit logs | Up to [12] months, unless a longer period is required for security investigations or legal compliance. |
| Analytics data (Mixpanel) | Held in pseudonymized/de-identified form that is not linked back to your account; retained per our analytics configuration and no longer than [•]. |
| Billing and transaction records | Transaction identifiers and amounts retained for the period required by applicable tax and accounting law (in Israel, generally 7 years). |
| Support correspondence | Up to [24] months after the matter is closed. |
| Backups | Deleted data may persist in encrypted backups for up to [90] days before being permanently overwritten. |
When retention periods expire, we delete or irreversibly anonymize the data. You may request deletion of your account and personal information at any time at privacy@sphera.games, subject to the legal-retention exceptions above.
12. Your Privacy Rights
12.1 All Users
You can access and update your profile information and billing history through your account dashboard, and you can delete your projects at any time. For any request that cannot be completed through the dashboard, contact privacy@sphera.games. We will verify your identity and respond within thirty (30) days (or the shorter/longer period your local law requires); if we need more time, we will tell you why.
12.2 EEA, UK, and Swiss Users
Subject to the conditions and exemptions of applicable law, you have the right to: access your personal information and receive a copy in a portable format; rectify inaccurate data; erase your data; restrict or object to processing (including processing based on legitimate interests); withdraw consent at any time; and lodge a complaint with your supervisory authority — including the data protection authority of your habitual residence, the UK Information Commissioner’s Office, or the Swiss FDPIC. You may also complain to the Israeli Privacy Protection Authority regarding Sphera’s processing in Israel.
12.3 U.S. State Residents
If you reside in California or another U.S. state with a consumer privacy statute, you have, subject to legal limits, the rights to: know/access the personal information we collect; delete it; correct it; obtain it in a portable format; and opt out of “sale”, “sharing”, or targeted advertising — noting that Sphera does not sell or share personal information as those terms are defined under U.S. privacy laws and does not use personal information for targeted advertising. We do not use or disclose sensitive personal information for purposes requiring a right to limit. We will not discriminate against you for exercising your rights. You may authorize an agent to submit requests on your behalf. If we deny your request, you may appeal by replying to our decision within sixty (60) days; if your appeal is denied, you may contact your state attorney general.
12.4 Categories Disclosure (U.S. Law)
In the preceding 12 months we have collected the following categories of personal information: identifiers (name, email, username, IP address); customer records information (country; transaction identifiers and amounts); internet or network activity (log data, feature usage, prompts submitted); and, in future versions, audio data (voice prompts) and mobile device identifiers. We collect them from you directly, from your devices, and from Google if you use Google sign-in, for the business purposes in Section 3, and we disclose them to the service providers in Section 6.
13. Children’s Privacy
The Services are intended for users aged thirteen (13) and older. We do not knowingly collect personal information from children under 13. Registration includes an age confirmation, and users aged 13–17 may use the Services only with parental or guardian consent as described in our Terms of Service. Consistent with the U.S. Children’s Online Privacy Protection Act (COPPA), if we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete it promptly. Parents and guardians may contact privacy@sphera.games to review, correct, or delete their child’s information or to withdraw consent for their teen’s use of the Services.
14. Information Security
We implement technical and organizational measures appropriate to the risk, including: encryption of data in transit and at rest; role-based access controls limiting access to personnel who need it; audit logging; and continuous security monitoring. Our practices are aligned with SOC 2 and ISO 27001 standards, and our infrastructure providers operate certified data centers. We maintain an incident-response process; if a personal data breach occurs that is likely to result in a risk to your rights, we will notify you and the competent authorities within the timeframes required by applicable law (including, where the GDPR applies, notification to the supervisory authority within 72 hours of becoming aware of a notifiable breach). No system is perfectly secure, and we cannot guarantee absolute security, particularly with respect to third-party providers we do not control. Please use a strong, unique password, enable available account-security features, and report suspected incidents to security@sphera.games.
15. Third-Party Links and Services
The Services may contain links to, or integrations with, third-party services (currently limited to Google sign-in). Those services are governed by their own privacy policies, which we encourage you to review. We are not responsible for the privacy practices of third parties.
16. Communications
By using the Services you consent to receive transactional and administrative communications (such as account, security, and billing messages), which are necessary to the Services and cannot be opted out of while your account is active. If we introduce marketing communications (newsletters, product updates, promotions, or event invitations), we will send them through a reputable third-party service, only where permitted by applicable law — on an opt-in basis where required, including for EEA/UK users — and every marketing message will include a functioning unsubscribe mechanism. Marketing preferences will also be manageable in your account settings.
17. Changes to This Policy
We may update this Policy to reflect changes in our practices, the Services, or applicable law. We will post the revised Policy on the Site with an updated “Last Updated” date, and for material changes that expand our processing or reduce your rights, we will give at least thirty (30) days’ advance notice by email or in-product notice. Continued use of the Services after the effective date constitutes acceptance.
18. Governing Law
This Policy is governed by the laws of the State of Israel, without prejudice to mandatory data protection and consumer rights available to you under the law of your place of residence (including the GDPR, UK GDPR, and applicable U.S. state privacy statutes), which prevail to the extent of any conflict.
19. Contact Us
Privacy requests: privacy@sphera.games
Security incidents: security@sphera.games
General support: support@sphera.games
Postal address: Sphera AI Games Ltd., 10 Zarchin St., Ra’anana 4366238, Israel
Website: https://sphera.games
We have not appointed a Data Protection Officer at this time; privacy matters are handled by our privacy team at the address above. If our processing activities change such that a DPO or an EU/UK representative under Article 27 GDPR / UK GDPR is required, we will appoint one and update this Policy with their contact details.