Privacy Policy - How We Protect Your Data and Privacy at rsz.app
Privacy Policy
Last updated: 5 August 2025
rsz.app is owned and operated by Spectracular
Thank you for choosing rsz.app, which is owned and operated by Spectracular (“Spectracular”, “we”, “our”, or “us”). Spectracular provides a Software-as-a-Service platform and API for AI image resizing (the “Service”). This Privacy Policy explains how we collect, use, and protect information when you visit our website, create an account, or interact with our API.
1. Scope
This Policy applies to all users of the Service worldwide. It forms part of our Terms of Service. By accessing or using the Service, you agree to the practices described below.
Controller: For GDPR and similar laws, Spectracular is the data controller for personal data processed via rsz.app and its API.
2. Information We Collect
Category | Examples | Purpose |
---|---|---|
Account Information | Name, email address, password (hashed), company name, billing information | Account creation, authentication, invoicing |
Content Data | Images and related metadata submitted for processing | To perform the resizing operation and return results |
Usage Data | API keys, request logs, IP address, browser type, device identifiers, timestamps | Security monitoring, rate limiting, analytics, service improvement |
Cookies and Similar Technologies | Session cookies, CSRF tokens, analytics cookies | Maintain login state, measure site performance |
We do not intentionally collect sensitive personal data (e.g., health or biometric data). If you choose to include such data in images, you are responsible for ensuring you have the legal right to do so.
3. How We Use Your Information
We process information to:
- Provide, maintain, and improve the Service
- Authenticate users and secure accounts
- Monitor, detect, and prevent fraud or abuse
- Respond to inquiries and support requests
- Generate aggregated statistics that do not identify individuals
- Comply with legal obligations and enforce our Terms
4. Legal Bases for Processing (GDPR & UK GDPR)
We rely on one or more of the following bases:
- Contractual necessity - to deliver the Service you request
- Legitimate interests - to secure and improve the Service
- Consent - for optional cookies or marketing communications
- Legal obligation - to comply with applicable law or lawful requests
5. Data Retention
- Content Data: deleted automatically within 90 days of processing unless you request earlier deletion or retain copies in your account.
- Account & Billing Records: retained for as long as your account is active and as required for tax, accounting, and legal compliance (typically up to 7 years).
- Logs: retained up to 90 days for security and troubleshooting, then aggregated or deleted.
6. Disclosure to Third Parties
We do not sell, rent, or share personal data with third parties for their own marketing. We may disclose information only:
- Service Providers - vetted subcontractors that perform hosting, payment, or support functions under contractual confidentiality obligations
- Legal Compliance - when required by law, court order, or governmental request
- Business Transfers - in connection with a merger, acquisition, or sale of assets, provided the acquirer assumes equivalent privacy commitments
7. International Transfers
We operate globally using servers located in the United States and the European Economic Area. When we transfer personal data across borders we rely on:
- Adequacy decisions of the European Commission
- Standard Contractual Clauses or UK Addendum
- Other legally recognized transfer mechanisms
8. Security
We implement industry-standard administrative, technical, and physical safeguards, including:
- HTTPS/TLS encryption in transit
- Encryption at rest for stored Content Data
- Least-privilege access controls and API key management
- Regular penetration testing and vulnerability scanning
No method of transmission or storage is entirely secure; therefore, we cannot guarantee absolute security.
9. Your Rights
Depending on your jurisdiction, you may have rights to:
- Access, correct, or delete personal data
- Object to or restrict processing
- Data portability
- Withdraw consent at any time
- Lodge a complaint with a supervisory authority
To exercise these rights, contact us at [email protected]. We will respond within 30 days or as required by law.
10. Cookies and Analytics
We use first-party cookies for authentication and Google Analytics (IP anonymization enabled) to understand site usage. You can disable non-essential cookies in your browser or via our cookie banner.
11. Children's Privacy
The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us and we will delete it promptly.
12. API Users
You must keep your API keys confidential, comply with rate limits, and ensure that any end-user data you submit has been lawfully obtained and is adequately anonymized or encrypted if required.
13. Changes to This Policy
We may update this Policy periodically. Material changes will be posted on this page with a new “Last updated” date and, where required, notified to you by email.
14. Contact Us
If you have questions or concerns about this Privacy Policy or our privacy practices, please contact:
By continuing to use rsz.app you acknowledge that you have read and understood this Privacy Policy.