Legal
Privacy policy
This is a courtesy translation – only the German version is legally binding. View German version
1. Privacy at a glance
General information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally. You can find detailed information in the sections below.
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find their contact details in the section “Controller” of this privacy policy.
How do we collect your data?
On the one hand, your data is collected when you provide it to us – here specifically: the image you upload for checking. Other data is collected automatically by our IT systems when you visit the website. This is mainly technical data (e.g. web browser, operating system or time of the page request).
What do we use your data for?
Uploaded images are used exclusively to check them for problematic content and to show you the result. Technical data is collected to ensure that the website is provided without errors. To improve our service, we use Fathom Analytics – privacy-friendly visitor statistics without cookies and without collecting personal data. We use no cookies.
What rights do you have regarding your data?
You have the right at any time to receive information free of charge about the origin, recipients and purpose of your stored personal data. You also have the right to request that this data be corrected or deleted. If you have given consent to data processing, you can withdraw it at any time with effect for the future. You also have the right, under certain circumstances, to request the restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority. You can contact us at any time about this and any other questions regarding data protection.
2. Hosting
Hetzner
We host the content of our website with Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (hereinafter “Hetzner”). When you visit our website, Hetzner collects various log files, including your IP address. For details, please refer to Hetzner's privacy policy: https://www.hetzner.com/de/legal/privacy-policy/.
Hetzner is used on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in presenting our website as reliably as possible.
Data processing agreement
We have concluded a data processing agreement (DPA) with the above-mentioned provider. This is a contract required by data protection law which ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
3. General information and mandatory disclosures
Data protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy. Please note that data transmission over the internet (e.g. when communicating by email) may have security gaps. Complete protection of data against access by third parties is not possible.
Controller
The controller responsible for data processing on this website is:
Michael LefrancoisLerchenstr. 16
63150 Heusenstamm, Germany
Email: pixisma@lefrancois.de
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data (e.g. names, email addresses, etc.).
Storage period
Unless a more specific storage period is stated in this privacy policy, your personal data will remain with us until the purpose for the data processing no longer applies. If you assert a legitimate request for deletion or withdraw your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing it (e.g. retention periods under tax or commercial law); in the latter case, deletion takes place once these reasons no longer apply.
Legal bases for data processing
If you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR. If your data is required for the performance of a contract or for taking pre-contractual steps, we process it on the basis of Art. 6(1)(b) GDPR. Furthermore, we process your data where this is necessary for compliance with a legal obligation, on the basis of Art. 6(1)(c) GDPR. Data processing may also be carried out on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR.
Withdrawal of your consent to data processing
Many data processing operations are only possible with your express consent. You can withdraw consent you have already given at any time. The lawfulness of the data processing carried out until the withdrawal remains unaffected by the withdrawal.
Right to object to data collection in special cases (Art. 21 GDPR)
IF DATA PROCESSING IS BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21(1) GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the member state of their habitual residence, their place of work or the place of the alleged violation. The right to lodge a complaint is without prejudice to any other administrative or judicial remedies.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in fulfilment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done insofar as it is technically feasible.
Information, correction and deletion
Within the scope of the applicable statutory provisions, you have the right at any time to receive information free of charge about your stored personal data, its origin and recipients and the purpose of the data processing and, where applicable, a right to have this data corrected or deleted. You can contact us at any time about this and any other questions regarding personal data.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. The right to restriction of processing applies in the following cases:
- If you dispute the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of the verification, you have the right to request the restriction of processing.
- If the processing of your personal data was or is unlawful, you can request the restriction of data processing instead of deletion.
- If we no longer need your personal data but you need it to exercise, defend or assert legal claims, you have the right to request the restriction of processing instead of deletion.
- If you have lodged an objection pursuant to Art. 21(1) GDPR, your interests and ours must be weighed against each other. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of processing.
SSL/TLS encryption
For security reasons and to protect the transmission of confidential content – such as the images you upload – this site uses SSL/TLS encryption. You can recognize an encrypted connection by the browser's address bar changing from “http://” to “https://” and by the lock icon in your browser bar.
Objection to promotional emails
We hereby object to the use of contact data published as part of our legal notice obligation for sending unsolicited advertising and information material. The operators of these pages expressly reserve the right to take legal action in the event of unsolicited advertising, such as spam emails.
4. Data collection on this website
Image checking with OpenAI Omni-Moderation
The core function of this website is the automated checking of images for problematic content (e.g. violence, sexual content or self-harm). When you select an image, drop it via drag & drop or paste it from the clipboard, it is transmitted in encrypted form to our server and from there forwarded for analysis to OpenAI's moderation API (model “omni-moderation”). For users in the European Economic Area, the provider is OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland (hereinafter “OpenAI”).
Only the image file itself is transmitted. No file name, IP address or other information about you is passed on to OpenAI. If the image itself contains personal data (e.g. identifiable people), this data is transmitted as part of the image. Please therefore only upload images that you are authorized to have processed.
We do not store uploaded images. The image is processed only for the duration of the request in our server's memory and then discarded. The image preview is generated locally in your browser. The check result is displayed only in your browser and is not stored. According to OpenAI, data submitted via the API is not used to train its models, but may be retained for up to 30 days for abuse detection.
A transfer of data to the USA cannot be ruled out. Any such transfer takes place on the basis of the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR), which form part of the data processing agreement with OpenAI.
Processing is carried out to provide the function you have expressly requested, on the basis of Art. 6(1)(b) GDPR. You can find further information in OpenAI's privacy policy: https://openai.com/policies/privacy-policy/.
Extended analysis (Pro analysis)
In addition to the image check, you can request an extended analysis. It is only started if you expressly trigger it with a click. In this case, the image is again transmitted in encrypted form to our server and from there forwarded to a multimodal AI language model from OpenAI (provider as above: OpenAI Ireland Limited). The model describes the image and provides an assessment of any text, brand logos, critical symbols, the number of people depicted and sensitive objects (e.g. weapons, alcohol) it contains.
Apart from the image, only the language you have selected is transmitted, so that the result is generated in that language. Beforehand, the image is checked by the moderation API as described above; images with sexual content are not passed on to the extended analysis. Text recognized in the image is additionally transmitted as text to OpenAI's moderation API in order to check it for problematic content (e.g. hate or threats).
No identification of people takes place. People depicted are merely counted. The model is instructed neither to recognize people by name – including public figures – nor to draw conclusions about origin, religion or health. No processing of biometric data for the purpose of uniquely identifying a person (Art. 9 GDPR) takes place.
We store neither the image nor the result of the extended analysis; the result is displayed only in your browser. The request to OpenAI is made with storage of the response in the OpenAI account disabled. Otherwise, the information in the previous section on retention by OpenAI and on the transfer of data to the USA applies accordingly.
The result is an automated assessment without legal effect for you; no automated decision within the meaning of Art. 22 GDPR takes place. Processing is carried out to provide the function you have expressly requested, on the basis of Art. 6(1)(b) GDPR.
Server log files
The provider of these pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are browser type and version, operating system used, referrer URL, host name of the accessing computer, time of the server request and IP address. This data is not merged with other data sources. The data is collected on the basis of Art. 6(1)(f) GDPR; we have a legitimate interest in the technically error-free presentation and optimization of our website.
Request limiting (rate limit)
To prevent abuse and ensure availability for everyone, the number of image checks per IP address is limited. For this purpose, your IP address is held together with a counter exclusively in our server's memory and is automatically discarded after 24 hours at the latest. It is not stored permanently or passed on. The legal basis is our legitimate interest in the secure and stable operation of the website (Art. 6(1)(f) GDPR). A separate counter is kept in the same way for the extended analysis.
Fathom Analytics
This website uses Fathom Analytics, a privacy-friendly analytics service provided by Conva Ventures Inc., 4694 Muir Rd, Victoria, BC V8Y 2H9, Canada.
Fathom Analytics does not collect any personal data, sets no cookies and does not create individual user profiles. Only aggregated, anonymous statistics about website visits are collected (e.g. pages viewed, country of origin, device type and referring websites). In addition, we anonymously count how often certain actions are performed – a completed image check, the start of a Pro analysis and a click on the support link. No images, check results or other content are transmitted to Fathom in the process. It is not possible to identify individual persons.
To load the analytics script, your browser establishes a connection to Fathom's servers, which for technical reasons involves transmitting your IP address. According to Fathom, it is neither stored nor used for identification.
Canada is covered by an adequacy decision of the EU Commission pursuant to Art. 45 GDPR, so the data transfer is permissible without additional safeguards.
Fathom Analytics is used on the basis of our legitimate interest in a privacy-compliant analysis of user behaviour in order to improve our service (Art. 6(1)(f) GDPR). Since Fathom does not collect any personal data and sets no cookies, consent is not required. You can find further information in Fathom's privacy policy: https://usefathom.com/legal/privacy.
Cookies and local storage
This website sets no cookies and does not use any comparable technologies to store information on your device. Consent pursuant to § 25 TDDDG (German Telecommunications Digital Services Data Protection Act) is therefore not required.
Fonts
The fonts used on this website (Geist, Geist Mono, Instrument Serif) are hosted locally on our server. No connection to third-party servers such as Google is established when the page is loaded.