Privacy Policy
Last updated:
1. Introduction & Scope
RGBKit ("we," "our," "us") is committed to protecting your privacy and maintaining the trust you place in us. This comprehensive Privacy Policy explains in detail how we collect, use, store, and share your data when you use our free online tools and services.
This policy covers all aspects of our services:
- RGBKit website: rgbkit.com and all its subdomains, including informational pages, tool interfaces, and user dashboards
- Free online tools: All our image editors (background remover, silhouette maker, passport photo creator), PDF tools (editor, merger, compressor, organizer), and AI tools (content detector, grammar fixer, text humanizer)
- User accounts: Registration, authentication, profile management, saved projects, and personalized settings
- Community features: User feedback systems, support requests, forums, and collaborative features
- Mobile applications: Our iOS and Android apps, progressive web apps, and mobile-optimized web interfaces
- Communication channels: Email newsletters, support tickets, in-app notifications, and marketing communications
2. Types of Data We Collect
(A) Data Provided Directly by You
- Account Registration Information: When creating an account, we collect your full name, email address, and a secure password. Optional information may include profile picture, bio, company name, and professional details to enhance your experience.
- Tool Usage Files: Images, PDFs, text documents, and other files you upload for processing. This includes photos for background removal, documents for PDF editing, text for AI enhancement, and any other content you input into our tools.
- User-Generated Content: Feedback submitted through our feedback forms, customer reviews, ratings, comments on tools, suggestions for improvements, bug reports, and any content you contribute to our community features.
- Communication Data: Messages sent to our support team, email correspondence, chat transcripts, support ticket details, and any information you provide when seeking assistance or reporting issues.
- Preferences and Settings: Tool customization settings, language preferences, notification preferences, saved templates, and any personalized configurations you set within your account.
(B) Data from Third-Party Sources
- Social Login Authentication: If you choose to sign in using Google, Facebook, or other social platforms, we receive basic profile information including your name, email address, and profile picture from those services after your explicit authorization.
- Service Integration Data: When you connect RGBKit with third-party services (cloud storage, design platforms, or productivity tools), we receive authentication tokens, user IDs, and basic account information necessary for the integration to function.
- Payment Processing Information: For any premium features or services, our payment processors (Stripe, PayPal, etc.) provide us with transaction confirmation, payment method type (but not full card details), and billing address information.
- Analytics and Advertising Partners: Our analytics providers (Google Analytics, etc.) and advertising partners provide aggregated demographic and behavioral data to help us understand our audience and improve our services.
- Professional Networks: If you import professional profiles or connect with business services, we may receive relevant professional information to enhance your experience.
(C) Automatically Collected Technical Data
- Device and Browser Information: Browser type and version (Chrome, Firefox, Safari, etc.), operating system (Windows, macOS, iOS, Android), device type (desktop, tablet, mobile), screen resolution, and browser language settings.
- Usage Analytics and Behavior: Pages visited, tools used, time spent on each tool, feature interactions, click patterns, session duration, frequency of visits, paths taken through our site, and tool usage statistics.
- Location and Geographic Data: Country, region, and city derived from IP address geolocation, timezone information, and general location data used for content localization and analytics.
- Technical Connection Data: IP address, Internet Service Provider (ISP), connection type, browser fingerprint (unique browser characteristics), referrer URLs, and timestamps of your visits.
- Performance and Error Data: Page load times, tool processing speeds, error messages, crash reports, and technical diagnostics that help us maintain and improve our services.
3. How We Use Your Data
Service Delivery
Process your uploaded files, provide core tool functionality (image editing, PDF manipulation, AI text processing), maintain service performance, ensure tool reliability, and deliver the features you request in real-time.
Personalization
Customize tool recommendations based on your usage patterns, save your preferences and settings, remember frequently used tools, suggest relevant features, and create a tailored experience that matches your workflow.
Communication
Send important service updates, respond to your support requests and inquiries, provide notifications about tool status, deliver account-related information, and communicate about service maintenance or improvements.
Analytics
Understand usage patterns and behaviors, identify popular tools and features, analyze performance metrics, discover areas for improvement, optimize tool efficiency, and make data-driven decisions to enhance our services.
Marketing
Inform you about new tools and features, send relevant updates about service enhancements, share educational content about tool usage, announce special offers (if applicable), and provide information that may interest you based on your preferences.
Legal Compliance
Meet legal and regulatory obligations, protect our rights and property, prevent fraud and abuse, ensure service security, respond to legal requests, and maintain compliance with data protection laws.
4. Your Files & Privacy
How Files Are Processed Locally:
- Browser-Based Processing: Image editing (background removal, filters, adjustments), PDF manipulation (merging, splitting, compressing), and AI text processing all happen directly in your browser using powerful client-side algorithms.
- Temporary Browser Storage: Files may be temporarily stored in your browser's memory or cache during processing to ensure smooth performance. This data is automatically cleared when you close the browser tab or after a short timeout period.
- No Server Upload Required: For standard tool usage, your files are never transmitted to our servers. The entire processing happens locally, maintaining complete privacy and control over your data.
- Real-Time Processing: Advanced web technologies enable complex operations like AI-powered background removal and PDF editing to happen instantly in your browser without server dependencies.
When You Choose Cloud Storage:
- Explicit User Choice: Files are only stored on our servers when you create an account and explicitly choose to save your work, create projects, or enable cloud synchronization features.
- Enterprise-Grade Encryption: All stored files are protected using AES-256 encryption at rest and TLS 1.3 encryption during transmission, ensuring your data remains secure and private.
- Strict Access Control: Only you can access your saved files through your authenticated account. Our employees cannot access your personal files without your explicit permission and a valid legal reason.
- Secure Cloud Infrastructure: Files are stored on reputable cloud providers (AWS, Google Cloud) with redundant backups, disaster recovery, and comprehensive security monitoring.
- Retention and Deletion: You can delete your saved files at any time. Files are also automatically deleted when you close your account, ensuring no data remains on our servers longer than necessary.
5. Data Sharing & Disclosure
We maintain strict control over your data and only share it in specific, limited circumstances as detailed below:
Service Providers and Partners
- Cloud Infrastructure Providers: We use AWS and Google Cloud for hosting our services. These providers handle data storage, computing resources, and network infrastructure under strict privacy agreements and data protection obligations.
- Analytics and Monitoring Services: Google Analytics and similar tools help us understand service usage, performance, and user behavior. These services receive anonymized, aggregated data that cannot be used to identify individual users.
- Communication and Support Platforms: Email delivery services (SendGrid, Mailgun), customer support platforms (Zendesk, Intercom), and helpdesk systems that enable us to communicate with you and provide support.
- Security and Authentication Services: Authentication providers, security monitoring tools, and fraud detection services that help protect our platform and your account.
- Development and Testing Tools: Third-party services used for software development, bug tracking, and performance monitoring that may have access to limited, non-personal system data.
Legal and Safety Requirements
- Legal Compliance: When required by applicable laws, regulations, court orders, subpoenas, or government requests. We only disclose data that is legally required and will challenge overly broad requests when possible.
- Safety and Protection: To protect the rights, property, and personal safety of RGBKit, our users, or the public. This includes preventing fraud, abuse, security threats, or illegal activities.
- Business Transfers: In connection with any merger, acquisition, sale of assets, or business restructuring, where your data may be transferred as part of the business assets, subject to the same privacy protections.
- Enforcement of Rights: To enforce our terms of service, protect our intellectual property, or defend against legal claims brought by or against us.
6. Data Security Measures
Advanced Encryption
TLS 1.3 encryption for all data in transit, AES-256 encryption for data at rest, end-to-end encryption for sensitive communications, and regular encryption key rotation.
Strict Access Controls
Multi-factor authentication, role-based access permissions, principle of least privilege, regular access reviews, and automated access logging for all systems.
Employee Security
Comprehensive background checks, mandatory security training, strict confidentiality agreements, need-to-know access policies, and regular security awareness programs.
Secure Infrastructure
SOC 2 compliant hosting, regular security updates, 24/7 threat monitoring, automated vulnerability scanning, and disaster recovery procedures.
7. GDPR Compliance & Data Protection
Legal Basis for Processing
RGBKit processes your personal data on the following legal bases under the GDPR:
- Consent: When you create an account or explicitly agree to specific data processing activities. You can withdraw consent at any time.
- Legitimate Interest: For providing and improving our services, analyzing usage patterns, and ensuring security. Our legitimate interests include:
- Delivering and maintaining our free online tools
- Analyzing service usage to improve functionality
- Preventing fraud and ensuring platform security
- Communicating with users about service updates
- Contractual Necessity: When processing is necessary to provide services you've requested, such as processing files you upload to our tools.
- Legal Obligation: When required by applicable laws, regulations, or legal proceedings.
Your GDPR Rights
Under the GDPR, you have the following rights regarding your personal data:
Right of Access
Request a complete copy of all personal data we hold about you, including the purposes of processing, categories of data, and recipients of your data.
Right of Rectification
Request correction of inaccurate or incomplete personal data. We will correct errors promptly and notify you of changes made.
Right of Erasure (Right to be Forgotten)
Request deletion of your personal data when it's no longer necessary for the purposes collected, or when you withdraw consent.
Right of Data Portability
Receive your personal data in a structured, machine-readable format (JSON, CSV) and transfer it to another service provider.
Right to Object
Object to processing based on legitimate interests, direct marketing, or processing for scientific/historical research purposes.
Right to Restrict Processing
Request restriction of processing in certain circumstances, such as when data accuracy is contested or processing is unlawful.
Data Controller Details
RGBKit acts as the Data Controller for your personal data:
- Company Name: RGBKit Digital Tools Platform
- Registered Address: [Your registered business address]
- Contact for Data Protection: privacy@rgbkit.com
- Regulatory Compliance: We comply with GDPR and other applicable data protection laws
- Data Protection Officer: For data protection matters, contact our DPO at dpo@rgbkit.com
International Data Transfers
Your data may be transferred outside your country of residence. We ensure appropriate safeguards:
- EU Standard Contractual Clauses: We use EU-approved standard contractual clauses for international transfers
- Adequacy Decisions: We only transfer to countries recognized by the EU as providing adequate data protection
- Technical Safeguards: End-to-end encryption and secure data transfer protocols
- Cloud Provider Compliance: Our cloud providers (AWS, Google Cloud) maintain GDPR compliance certifications
Exercising Your Rights
To exercise your GDPR rights:
- Response Time: We will respond to your request within 30 days of receipt
- Verification: We may request identity verification to protect your privacy
- No Fees: Exercising your rights is free of charge, except for excessive or unfounded requests
- Complaint Rights: If unsatisfied with our response, you can complain to your local data protection authority
8. Your Rights & Controls
Access Your Data
Request complete copies of all personal data we hold about you, including account information, usage data, and any other personal information stored in our systems.
Correct Your Data
Update or correct any inaccurate, incomplete, or outdated personal information in your account profile or other records we maintain about you.
Delete Your Data
Request permanent deletion of your account and all associated personal data, subject to legal retention requirements and legitimate business interests.
Export Your Data
Download all your personal data in a structured, machine-readable format (JSON, CSV) for use with other services or personal record-keeping.
Opt Out
Unsubscribe from marketing communications, limit data collection for analytics, or opt out of specific data processing activities where technically feasible.
Privacy Settings
Manage privacy preferences, control cookie settings, adjust notification preferences, and configure account privacy settings through your dashboard.
To exercise these rights:
Email us at: privacy@rgbkit.com
We respond to all requests within 30 days.
9. Cookies & Tracking
RGBKit uses cookies and similar technologies to:
- Essential Cookies: Required for basic site functionality
- Analytics Cookies: Help us understand how you use our tools. We use Google Analytics for this purpose.
- Preference Cookies: Remember your settings and preferences
- Advertising Cookies: Used by Google AdSense and other advertising partners to serve ads
You can also control cookies through your browser settings. Disabling cookies may affect some features of our services.
10. Data Retention
We retain your data as follows:
- Account Data: Until you delete your account
- Temporary Files: Browser cache cleared when you close the browser
- Saved Files: Until you delete them or your account is closed
- Analytics Data: Aggregated and anonymized after 24 months
- Legal Requirements: As required by applicable laws
11. Children's Privacy
RGBKit does not knowingly collect personal information from children under 13 years of age. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
Parental Rights
Parents and guardians have the right to:
- Review and delete their child's personal information
- Refuse to permit further collection of their child's information
- Request information about our data practices regarding children
If we become aware that we have collected personal information from children without parental consent, we will take steps to delete that information promptly.
12. International Data Transfers
RGBKit operates globally and may transfer data across borders. We ensure appropriate safeguards including:
- Standard contractual clauses
- Compliance with international data protection laws
- Adequate security measures for cross-border transfers
13. Role as Data Controller/Processor
RGBKit acts primarily as a Data Controller for the personal information we collect from users of our free online tools.
Our Role
As Data Controller: We determine the purposes and means of processing your personal data when you use our services.
As Data Processor: When you use our tools to process your own files (images, PDFs, documents), you remain the data controller for that content, and we act as a processor on your behalf.
Third-Party Processors
We use carefully selected third-party processors to provide our services:
- Cloud Infrastructure: AWS, Google Cloud for hosting and storage
- Analytics: Google Analytics for usage insights
- Communication: Email delivery services for notifications
- Security: Security monitoring and threat detection services
All third-party processors are subject to data processing agreements that ensure GDPR compliance and adequate data protection.
14. User Content Privacy
Your privacy is central to our service design. We've implemented several privacy-first features:
Client-Side Processing
Content Sharing and Public Features
RGBKit does not make your uploaded content public unless you explicitly choose to:
- Share a project link (if available)
- Participate in community features
- Submit content for support or feedback
Content Ownership
You retain full ownership and rights to all content you create or process using our tools. RGBKit does not claim ownership of your files, images, or documents.
15. Marketing and Communications
We may send you various types of communications. You have control over what you receive:
Types of Communications
- Service Communications: Essential updates about your account and our tools
- Marketing Emails: Information about new tools, features, and updates
- Newsletters: Tips, tutorials, and best practices for using our tools
- Support Communications: Responses to your inquiries and support requests
Your Choices
You can control marketing communications by:
- Unsubscribing via the link in any marketing email
- Adjusting email preferences in your account settings
- Contacting us at privacy@rgbkit.com
Service communications (account updates, security alerts) cannot be opted out of as they are necessary for providing our services.
16. AI Tools and GDPR Compliance
AI-Powered Tools Overview
RGBKit offers several AI-powered tools that process your content to provide intelligent services:
- AI Content Detector: Analyzes text to identify AI-generated content
- AI Grammar Fixer: Automatically corrects grammar and style issues
- AI Text Humanizer: Converts AI-generated text to more natural human-like writing
- AI Writing Assistant: Provides suggestions for improving written content
GDPR Compliance for AI Processing
Our AI tools comply with GDPR through the following measures:
Data Minimization
We only collect and process the minimum data necessary for AI functionality. No personal data is stored longer than required.
Anonymization
Personal identifiers are removed from AI training data. Processing is anonymized where possible.
Legal Basis
AI processing is based on legitimate interest for service improvement and explicit consent when required.
Privacy by Design
Privacy protections are built into our AI systems from the ground up, not added as an afterthought.
AI Data Processing Details
When you use our AI tools:
- Input Data: Your text is processed to provide the requested AI service
- Processing Location: Most AI processing happens in your browser for privacy
- Temporary Storage: Input may be temporarily stored during processing, then deleted
- Model Training: We do not use your personal content to train our AI models without explicit consent
- Third-party AI Services: Some AI features may use third-party APIs with GDPR-compliant agreements
AI Content Responsibility
Important disclaimer about AI-generated content:
- No Control Over Output: RGBKit does not control, endorse, or take responsibility for the specific content generated by AI models
- Inappropriate Content: We are not responsible for any offensive, harmful, NSFW (Not Safe For Work), or otherwise inappropriate content that AI models may generate
- User Responsibility: Users are solely responsible for the content they input into AI tools and the output they choose to use or share
- Content Filtering: While we implement reasonable safeguards, we cannot guarantee that AI models will never generate inappropriate content
- Third-Party Models: AI content is generated by third-party machine learning models over which we have limited control
- Usage Guidelines: Users must comply with applicable laws and our Terms of Service when using AI-generated content
Your Rights Regarding AI Processing
You have the following specific rights for AI-processed data:
- Right to Explanation: Request information about how AI decisions are made
- Right to Human Review: Request human intervention for significant AI decisions
- Right to Object: Object to automated decision-making when it produces legal effects
- Right to Correction: Request correction of biases in AI processing affecting you
AI Model Transparency
We are committed to transparency about our AI systems:
- Model Information: We provide information about the types of AI models used
- Purpose Disclosure: Clear explanation of what each AI tool does and its limitations
- Accuracy Information: We disclose known accuracy rates and limitations where applicable
- Bias Mitigation: We actively work to identify and mitigate biases in our AI systems
International AI Data Transfers
Some AI processing may occur outside your country. We ensure:
- GDPR-Compliant Transfers: All international AI data transfers use standard contractual clauses
- Secure Processing: AI services are provided by GDPR-compliant providers
- Data Localization: Where possible, AI processing occurs within your region
17. Legal Compliance and Policy Updates
We are committed to complying with all applicable data protection laws and regulations.
Applicable Laws
We comply with:
- GDPR: General Data Protection Regulation (EU)
- CCPA: California Consumer Privacy Act (California, USA)
- LGPD: Lei Geral de Proteção de Dados (Brazil)
- PIPEDA: Personal Information Protection and Electronic Documents Act (Canada)
- Other applicable regional data protection laws
Policy Updates
We may update this Privacy Policy from time to time to reflect:
- Changes in our services or business practices
- Updates to applicable laws and regulations
- Feedback from users and regulators
- Technical improvements to our services
Significant changes will be communicated via email notifications for registered users and prominent website notices.
18. Contact Information
If you have questions about this Privacy Policy or want to exercise your GDPR rights, please contact us:
We respond to all privacy inquiries within 30 days as required by GDPR.