Your artwork stays private.
Effective September 20, 2026. CrispyFlyer is built to process customer files, not turn them into a public gallery.
CrispyFlyer is operated by Halloween Parts Plus LLC. Halloween Parts Plus LLC is responsible for the CrispyFlyer service and the information described in this policy.
What we collect
When you use CrispyFlyer, we may process the artwork you upload, generated cleanup versions, selected output settings, transaction references, basic technical and security logs, and information you send when contacting support.
Payment-card details are handled by Stripe. CrispyFlyer does not receive or store your full card number.
How we use it
We use this information to provide the cleanup service, verify purchases, create and deliver results, support retries and re-downloads, troubleshoot failures, prevent abuse, secure the service, and respond to customer-support requests.
AI and service providers
Your uploaded artwork may be sent to service providers required to operate CrispyFlyer, including OpenAI for image processing, Cloudflare for hosting, image transformation, and private file storage, and Stripe for payment processing. These providers process information under their own applicable terms and privacy practices.
File retention
Guest re-download and paid-session access is normally available for 7 days from purchase. Uploaded and generated artwork is temporary. Guest job files are queued for automatic deletion after that access window, with a one-day safety grace and daily cleanup. Copies may be retained longer only when reasonably needed for support, payment troubleshooting, security, abuse prevention, or legal obligations.
Sharing and selling
We do not sell customer artwork or use customer uploads as public gallery content. We may disclose information when required by law, to protect the service or its users, or to service providers that need it to perform the functions described above.
Browser storage
CrispyFlyer may briefly use browser session storage while a paid checkout returns to the site. After payment is verified, the browser keeps a site-scoped recovery token instead of the raw Stripe Checkout session ID. Local browser storage may keep up to five recent-flyer recovery tokens so you can reopen paid flyers on this browser without an account. These entries expire with the configured guest access window (currently 7 days). Clearing browser data removes the local list. Recovery tokens do not contain your payment-card number. Account features are disabled for the initial launch.
Security
We use reasonable technical measures designed to limit access to customer files and payment-linked results. No internet service can guarantee absolute security.
Your questions or requests
For privacy questions, file-removal requests, or support related to a purchase, contact aicreatureverse@gmail.com.