Privacy Policy - How We Protect Your Data | rsz.app

    We value your privacy

    We use cookies to improve your experience, measure performance, and deliver relevant content. Manage your preferences below. See our Cookie Policy.

    Privacy Policy - How We Protect Your Data and Privacy at rsz.app

    Privacy Policy

    Last updated: 5 August 2025

    rsz.app is owned and operated by Spectracular

    Thank you for choosing rsz.app, which is owned and operated by Spectracular (“Spectracular”, “we”, “our”, or “us”). Spectracular provides a Software-as-a-Service platform and API for AI image resizing (the “Service”). This Privacy Policy explains how we collect, use, and protect information when you visit our website, create an account, or interact with our API.

    1. Scope

    This Policy applies to all users of the Service worldwide. It forms part of our Terms of Service. By accessing or using the Service, you agree to the practices described below.

    Controller: For GDPR and similar laws, Spectracular is the data controller for personal data processed via rsz.app and its API.

    2. Information We Collect

    CategoryExamplesPurpose
    Account InformationName, email address, password (hashed), company name, billing informationAccount creation, authentication, invoicing
    Content DataImages and related metadata submitted for processingTo perform the resizing operation and return results
    Usage DataAPI keys, request logs, IP address, browser type, device identifiers, timestampsSecurity monitoring, rate limiting, analytics, service improvement
    Cookies and Similar TechnologiesSession cookies, CSRF tokens, analytics cookiesMaintain login state, measure site performance

    We do not intentionally collect sensitive personal data (e.g., health or biometric data). If you choose to include such data in images, you are responsible for ensuring you have the legal right to do so.

    3. How We Use Your Information

    We process information to:

    • Provide, maintain, and improve the Service
    • Authenticate users and secure accounts
    • Monitor, detect, and prevent fraud or abuse
    • Respond to inquiries and support requests
    • Generate aggregated statistics that do not identify individuals
    • Comply with legal obligations and enforce our Terms

    4. Legal Bases for Processing (GDPR & UK GDPR)

    We rely on one or more of the following bases:

    • Contractual necessity - to deliver the Service you request
    • Legitimate interests - to secure and improve the Service
    • Consent - for optional cookies or marketing communications
    • Legal obligation - to comply with applicable law or lawful requests

    5. Data Retention

    • Content Data: deleted automatically within 90 days of processing unless you request earlier deletion or retain copies in your account.
    • Account & Billing Records: retained for as long as your account is active and as required for tax, accounting, and legal compliance (typically up to 7 years).
    • Logs: retained up to 90 days for security and troubleshooting, then aggregated or deleted.

    6. Disclosure to Third Parties

    We do not sell, rent, or share personal data with third parties for their own marketing. We may disclose information only:

    • Service Providers - vetted subcontractors that perform hosting, payment, or support functions under contractual confidentiality obligations
    • Legal Compliance - when required by law, court order, or governmental request
    • Business Transfers - in connection with a merger, acquisition, or sale of assets, provided the acquirer assumes equivalent privacy commitments

    7. International Transfers

    We operate globally using servers located in the United States and the European Economic Area. When we transfer personal data across borders we rely on:

    • Adequacy decisions of the European Commission
    • Standard Contractual Clauses or UK Addendum
    • Other legally recognized transfer mechanisms

    8. Security

    We implement industry-standard administrative, technical, and physical safeguards, including:

    • HTTPS/TLS encryption in transit
    • Encryption at rest for stored Content Data
    • Least-privilege access controls and API key management
    • Regular penetration testing and vulnerability scanning

    No method of transmission or storage is entirely secure; therefore, we cannot guarantee absolute security.

    9. Your Rights

    Depending on your jurisdiction, you may have rights to:

    • Access, correct, or delete personal data
    • Object to or restrict processing
    • Data portability
    • Withdraw consent at any time
    • Lodge a complaint with a supervisory authority

    To exercise these rights, contact us at [email protected]. We will respond within 30 days or as required by law.

    10. Cookies and Analytics

    We use first-party cookies for authentication and Google Analytics (IP anonymization enabled) to understand site usage. You can disable non-essential cookies in your browser or via our cookie banner.

    11. Children's Privacy

    The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us and we will delete it promptly.

    12. API Users

    You must keep your API keys confidential, comply with rate limits, and ensure that any end-user data you submit has been lawfully obtained and is adequately anonymized or encrypted if required.

    13. Changes to This Policy

    We may update this Policy periodically. Material changes will be posted on this page with a new “Last updated” date and, where required, notified to you by email.

    14. Contact Us

    If you have questions or concerns about this Privacy Policy or our privacy practices, please contact:

    Spectracular
    Attn: Privacy Officer
    Email: [email protected]

    By continuing to use rsz.app you acknowledge that you have read and understood this Privacy Policy.