Your account. Your collection.
This page describes the data used by Spriteswapper and the controls available today.
Account and collection data
Spriteswapper stores your email, handle, display name, avatar, collection, wanted sprites, group memberships, and activity needed to show your squad’s progress. Password accounts use salted password hashes. Google sign-in stores the Google account identifier and profile information used to establish your account.
What other people can see
If you link Epic, your Fortnite display name is shown instead of your chosen name, so other players can find you in-game to trade. Your handle, display name, avatar, collection, mastered status, and wanted sprites are available on your public profile, including to people who are not signed in. Trade matching also shares collection and wanted-sprite information with other members. Group members can see group activity, presence, when you were last seen, when you joined the group, and your linked Epic display name and last sync time. Your email is not part of your public profile; site administrators can access account information to operate the service.
Profile and account pages ask search engines not to index them. This is not a privacy barrier: anyone with a public profile link can still open it, and search engines may take time to remove previously indexed pages.
Optional Epic connection
Epic connection and collection requests pass through api-fortnite.com. Spriteswapper stores the returned access, refresh, or device credentials encrypted, together with your Epic account identifier, display name, and sync status. Those credentials are sent to the service when needed to refresh your collection. Spriteswapper does not collect your Epic password.
Pause automatic syncing or unlink in your profile. Unlinking deletes Spriteswapper’s saved Epic credentials; it does not revoke access at Epic or at the third-party service. Your existing collection marks remain.
Cookies and browser storage
A secure, HTTP-only cookie keeps you signed in. Google sign-in uses a temporary state cookie. Browser storage remembers display preferences and the lobby codes you have marked as used.
Services involved
Cloudflare hosts the site, database, and live group connections. Google provides optional sign-in and hosted fonts. Resend sends verification and password-reset emails. api-fortnite.com provides Epic connection and collection services; fortnite-api.com supplies cosmetic search and avatar images. Sprite images load from cdn.api-fortnite.com and sprites.ahaz.net. These services receive the information required for their respective requests.
Age
You must be at least 13 years old to create an account. See the terms of use.
Contact requests
The contact form stores your email, request type, message, and submission time in an inbox visible only to the site administrator. Requests are retained for review; submitting one does not automatically change your account.
Retention and controls
Account and collection records remain stored while the account is in use; there is no automatic account-deletion schedule or self-service account deletion currently implemented. Sessions last 60 days, and password reset signs out existing sessions. Operational logs and service-provider backups may have separate retention periods. Use the contact form for an account or data request.