RED PIXEL

Privacy Policy

Effective 18 September 2026

This Privacy Policy explains how RED PIXEL (“RED PIXEL”, “we”, “us”, “our”), operated by Daniel Nagaets, collects, uses, stores and shares personal data when you visit redpixel.club or use the RED PIXEL application (together, the “Service”). It forms part of our Terms of Service. By creating an account or using the Service you acknowledge that you have read this Policy. If you do not agree with it, do not use the Service.

1. Who is responsible for your data

The data controller for the Service is Daniel Nagaets, reachable at nagaets.daniel@gmail.com. Where this Policy refers to “you”, it means the person using the Service; if you use it on behalf of a company, you confirm that you are authorised to accept this Policy for it.

2. Data we collect

We do not knowingly collect special categories of data (such as health, political or biometric data). Images of people that you upload may reveal such information; you decide what you upload and you are responsible for it (see section 4).

3. Why we use data and on what legal basis

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing.

4. AI processing and third-party models

The Service generates images and text with models operated by OpenAI, L.L.C. (USA). Content you submit for generation — images, prompts, dictated audio — is transmitted to OpenAI and processed under OpenAI’s API terms and usage policies. According to OpenAI’s API data-usage commitments, content sent through the API is not used to train OpenAI’s models; OpenAI may retain it for a limited period for abuse monitoring. We have no control over how OpenAI operates its models and we are not responsible for its acts or omissions.

The People Enhancement tools detect and segment people locally, inside your browser; nothing leaves your device for that step. Person crops are sent to OpenAI only when you press an enhancement button.

You must have the right, and where required the informed consent of every person depicted, to upload and process any image of a person. Do not upload images of minors, images of people who have not agreed to it, or images you have no right to use. AI outputs are produced automatically; they may be inaccurate, unexpected, inappropriate or similar to outputs produced for other users, and they are provided without any warranty (see the Terms).

5. Who we share data with

We share personal data only with providers that process it on our behalf under contracts that restrict their use of it:

We may also disclose data to professional advisers, to authorities when the law requires it or to protect the rights, property or safety of anyone, and to a successor in the event of a merger, acquisition or sale of the Service (who will be bound by this Policy). We never sell personal data and we never share it for third-party advertising.

6. International transfers

Our providers operate in the European Union and in the United States. Where personal data leaves the European Economic Area, the United Kingdom or Switzerland, the transfer is protected by an adequacy decision, by the provider’s certification under the EU-US Data Privacy Framework, or by the European Commission’s Standard Contractual Clauses, together with additional safeguards where necessary.

7. Cookies and local storage

The Service sets one strictly necessary cookie that keeps you signed in. We use no advertising cookies, no third-party analytics cookies and no cross-site tracking. Your browser’s local storage, session storage and IndexedDB hold preferences, the per-tab identifier and a backup of unsaved canvas changes; these stay on your device. Clearing them may lose unsaved work and signs you out.

8. How long we keep data

We may keep de-identified or aggregated data indefinitely.

9. Security

We protect data with TLS in transit, hashed passwords, encryption of secrets at rest, access limited to the operator and reputable infrastructure providers. No system is completely secure; you are responsible for keeping your password confidential and for the security of your own device. If we learn of a breach affecting your data we will notify you and the competent authority as the law requires.

10. Your rights

Depending on where you live (including the EU/EEA, the United Kingdom, Switzerland and California), you may have the right to access the personal data we hold about you, to correct it, to delete it, to restrict or object to its processing, to receive it in a portable format, to withdraw consent, not to be discriminated against for exercising your rights, and to lodge a complaint with your data-protection authority. To exercise a right, email nagaets.daniel@gmail.com from the address registered on your account; we may ask for additional verification and will answer within one month (extendable where the law allows). We do not sell or share personal data for cross-context behavioural advertising, so there is nothing to opt out of.

11. Age

The Service is for adults only. You must be at least 18 years old (or the age of majority where you live, if higher) to create an account. We do not knowingly collect data from minors; if we learn that an account belongs to a minor we will close it and delete its data.

12. Changes to this Policy

We may update this Policy. The current version, with its effective date, is always published at this address. For material changes we will notify you by email or inside the Service before they take effect. Continued use of the Service after the effective date means you accept the updated Policy.

13. Contact

Daniel Nagaets — nagaets.daniel@gmail.com