Last updated: July 30, 2026
Privacy Policy
This policy explains how SquareAvatarAI handles the browser-based avatar generator, Creator Pack accounts and payment records, commercial licenses, and the noindex photo conversion stub.
Information We Do Not Require
The Free homepage Square Face Generator does not require signup, payment information or a photo upload. Google sign-in is requested only when you choose to buy or manage a Creator Pack.
Browser-Local Avatar Data
The generator saves avatar settings, locks and export size in browser local storage under the existing square-face-generator-v1 store. This keeps your editable avatar available on the same device. You can remove it by clearing site data.
Avatar Exports
Free PNG and SVG exports, and licensed Platform ZIP image variants, are rendered in your browser from editable local SVG or Pixel parts. When you finalize a Creator Pack, the exact AvatarConfig and an SVG snapshot are sent to the SquareAvatarAI service so the license can be bound and re-downloaded.
Google Sign-In
Google Identity Services provides the sign-in button. The Google ID token is verified on the Cloudflare server for signature, audience, issuer and expiration. We use the stable Google subject identifier to identify the account and may store the display name, email address and profile image returned in that token. We do not store Google passwords or access tokens and do not use automatic One Tap.
PayPal Payments
PayPal processes the one-time Creator Pack payment. SquareAvatarAI stores order and capture identifiers, product, amount, currency, payment status, timestamps, refunds and reversals. We do not receive or store card numbers, PayPal passwords or bank credentials.
Cloudflare D1 Account Records
Cloudflare D1 stores the user record, a hash of the session token, PayPal order records, Creator Pack credits, selected Style Mixer seed and styles, generated batch configs, commercial license records, avatar snapshots, License IDs, webhook event IDs and status history. These records provide cross-device recovery, payment integrity and re-downloads.
Necessary Session Cookie
Signed-in Creator Pack workflows use a necessary HttpOnly, Secure, SameSite=Lax session cookie. D1 stores only a SHA-256 hash of the session token. This cookie is not used for advertising.
Photo to Square Avatar Tool
The /photo-to-square-avatar page is a noindex implementation stub until a real photo conversion API is connected. In the current code, selected photos remain in the browser for validation and preview only; no AI service provider receives them from this static site.
Analytics and Ads
Creator Pack checkout loads Google Identity Services and the PayPal JavaScript SDK only where needed for authentication and payment. The current codebase does not include advertising scripts. Any later analytics or advertising changes require an update to this policy.
Photo Retention and Deletion
Because the photo conversion backend is not live, the current site does not store uploaded photos on a server. Use the remove-photo control or refresh the tab to clear the local preview. Creator Pack order and license records may be retained as needed for delivery, refunds, fraud prevention, accounting and legal obligations; contact us for an applicable data request.
Policy Updates
This policy may be updated when the product changes. The latest version will remain available on this page.
Contact
For privacy questions, visit the Contact page.