Privacy Policy - How We Protect Your Data and Privacy at rsz.app

Privacy Policy

Last updated: 2 January 2026

rsz.app is owned and operated by Spectracular

Thank you for choosing rsz.app, which is owned and operated by Spectracular (“Spectracular”, “we”, “our”, or “us”). Spectracular provides a Software-as-a-Service platform and API for AI image resizing (the “Service”). This Privacy Policy explains how we collect, use, and protect information when you visit our website, create an account, or interact with our API.

Important Notice About Advertising: Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this website or other websites. You may opt out of personalized advertising by visiting Google Ads Settings or aboutads.info.

1. Scope

This Policy applies to all users of the Service worldwide. It forms part of our Terms of Service. By accessing or using the Service, you agree to the practices described below.

Controller: For GDPR and similar laws, Spectracular is the data controller for personal data processed via rsz.app and its API.

2. Information We Collect

CategoryExamplesPurpose
Account InformationName, email address, password (hashed), company name, billing informationAccount creation, authentication, invoicing
Content DataImages and related metadata submitted for processingTo perform the resizing operation and return results
Usage DataAPI keys, request logs, IP address, browser type, device identifiers, timestampsSecurity monitoring, rate limiting, analytics, service improvement
Cookies and Similar TechnologiesSession cookies, CSRF tokens, analytics cookies, advertising cookiesMaintain login state, measure site performance, serve personalized ads

We do not intentionally collect sensitive personal data (e.g., health or biometric data). If you choose to include such data in images, you are responsible for ensuring you have the legal right to do so.

3. How We Use Your Information

We process information to:

  • Provide, maintain, and improve the Service
  • Authenticate users and secure accounts
  • Monitor, detect, and prevent fraud or abuse
  • Respond to inquiries and support requests
  • Generate aggregated statistics that do not identify individuals
  • Comply with legal obligations and enforce our Terms

4. Legal Bases for Processing (GDPR & UK GDPR)

We rely on one or more of the following bases:

  • Contractual necessity - to deliver the Service you request
  • Legitimate interests - to secure and improve the Service
  • Consent - for optional cookies or marketing communications
  • Legal obligation - to comply with applicable law or lawful requests

5. Data Retention

  • Content Data: deleted automatically within 90 days of processing unless you request earlier deletion or retain copies in your account.
  • Account & Billing Records: retained for as long as your account is active and as required for tax, accounting, and legal compliance (typically up to 7 years).
  • Logs: retained up to 90 days for security and troubleshooting, then aggregated or deleted.

6. Disclosure to Third Parties

We do not sell, rent, or share personal data with third parties for their own marketing. We may disclose information only:

  • Service Providers - vetted subcontractors that perform hosting, payment, or support functions under contractual confidentiality obligations
  • Legal Compliance - when required by law, court order, or governmental request
  • Business Transfers - in connection with a merger, acquisition, or sale of assets, provided the acquirer assumes equivalent privacy commitments

7. International Transfers

We operate globally using servers located in the United States and the European Economic Area. When we transfer personal data across borders we rely on:

  • Adequacy decisions of the European Commission
  • Standard Contractual Clauses or UK Addendum
  • Other legally recognized transfer mechanisms

8. Security

We implement industry-standard administrative, technical, and physical safeguards, including:

  • HTTPS/TLS encryption in transit
  • Encryption at rest for stored Content Data
  • Least-privilege access controls and API key management
  • Regular penetration testing and vulnerability scanning

No method of transmission or storage is entirely secure; therefore, we cannot guarantee absolute security.

9. Your Rights

Depending on your jurisdiction, you may have rights to:

  • Access, correct, or delete personal data
  • Object to or restrict processing
  • Data portability
  • Withdraw consent at any time
  • Lodge a complaint with a supervisory authority

To exercise these rights, contact us at [email protected]. We will respond within 30 days or as required by law.

10. Cookies, Analytics, and Advertising

We use cookies and similar technologies to operate and improve our Service. Below is an overview of the types of cookies we use:

Essential Cookies

These cookies are necessary for the Service to function properly, including authentication, security (CSRF tokens), and maintaining login state.

Analytics Cookies

We use Google Analytics (with IP anonymization enabled) to understand how visitors interact with our site. This helps us improve the Service.

Advertising Cookies

Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this website or other websites. Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to rsz.app and/or other sites on the Internet.

These advertising cookies may be set on pages that include ad tags, even if ads are not visibly displayed.

Your Choices and Opt-Out Options

You can control cookies in several ways:

  • Cookie Banner: Use our cookie consent banner to accept or reject non-essential cookies when you first visit the site.
  • Browser Settings: Most browsers allow you to block or delete cookies through their settings.
  • Google Ads Settings: You can opt out of personalized advertising by visiting Google Ads Settings.
  • Network Advertising Initiative: You can opt out of some third-party vendors' use of cookies for personalized advertising by visiting aboutads.info.
  • European Users: Visit Your Online Choices for additional opt-out options.

Please note that opting out of personalized advertising does not mean you will stop seeing ads—it means the ads you see may be less relevant to your interests.

11. Children's Privacy

The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us and we will delete it promptly.

12. API Users

You must keep your API keys confidential, comply with rate limits, and ensure that any end-user data you submit has been lawfully obtained and is adequately anonymized or encrypted if required.

13. Changes to This Policy

We may update this Policy periodically. Material changes will be posted on this page with a new “Last updated” date and, where required, notified to you by email.

14. Contact Us

If you have questions or concerns about this Privacy Policy or our privacy practices, please contact:

Spectracular
Attn: Privacy Officer
Email: [email protected]

By continuing to use rsz.app you acknowledge that you have read and understood this Privacy Policy.