An identifiable face turns an ordinary photo into special-category biometric data. This API finds every face in a photo, an archive or a live RTSP stream and masks it before the frame is ever stored — so what you keep is analytics, not personal data.
Try it below with your own image, your webcam, or one of the sample scenes.
Upload any photo, capture from webcam, or pick a guaranteed sample preset to test automatic face redaction.
The three modes differ in how much of the original scene survives the mask. Weak settings on any of them can leave a recoverable signal, so the radius matters as much as the mode you pick.
| Mode | Recoverability | Visual Effect | Best Suited To |
|---|---|---|---|
| Gaussian Blur | Irreversible above radius 15 | Scene stays readable | Published photography, press imagery and marketing footage where the crowd should still look like a crowd. |
| Pixelate | Irreversible at block size 12+ | Obvious visual signal | Broadcast and social media, where viewers need to see that redaction was deliberately applied. |
| Solid Blackout | Fully irreversible | Pixels discarded entirely | Evidence handling, legal disclosure and regulator submissions, where no residual signal may remain. |
A light blur is a cosmetic effect, not a redaction — low-radius blur and coarse pixelation can both be partially inverted. If the output is evidential or leaves your control, use solid blackout.
The whole path from ingest to anonymized output runs in memory. There is no queue to poll and no temporary file to clean up afterwards.
Accepts JPEG, PNG and WebP uploads, batch archives, or a live RTSP/RTMP stream. Frames are decoded straight into memory — nothing is written to disk at any stage.
A single-pass detector locates every face in the frame, including profiles, partial occlusions and faces as small as 20×20 pixels in dense crowd scenes.
Elliptical masks are fitted to each detection and filled using your chosen mode and radius. The mask follows the face contour, so background detail outside it is left untouched.
You get back the anonymized buffer plus telemetry — face count, bounding boxes and processing time — then every intermediate buffer is discarded from memory.
Call our REST endpoint with image files or RTSP video frames. Receive anonymized image buffers with zero personal data stored on disk.
curl -X POST https://api.dynsimulation.com/v1/vision/face-blur \ -H "Authorization: Bearer YOUR_API_KEY" \ -F "image=@crowd_photo.jpg" \ -F "mode=gaussian_blur" \ -F "radius=25"
The pattern is the same across industries: the footage has genuine operational value, but the faces in it carry obligations you would rather not take on.
Keep footfall and dwell-time analytics running while faces are stripped from every stored frame, so the recording itself never becomes biometric data.
Redact bystanders and other drivers before telematics footage leaves the vehicle, which is what makes road-scene datasets shareable with partners.
Anonymize ward photography, procedure recordings and patient intake media so that clinical records can be used for training without exposing identity.
Protect minors, protest participants and uninvolved bystanders in published imagery, with an audit record of exactly how many faces were masked.
Sanitize accident and site-inspection photos before they are passed to adjusters, third-party assessors or subrogation partners.
Run crowd density, queue and traffic monitoring on public feeds while satisfying the requirement that no identifiable individual is retained.
Same detection model in all three; the difference is where the frames are processed and who operates the runtime.
Fastest path to production
For live camera estates
For restricted networks
Once identifiable faces land in your storage, they carry retention limits, access controls, subject-access obligations and breach exposure for as long as you hold them. Masking before the write removes the obligation instead of managing it.
Talk to our compliance engineersA face in a stored image is special-category biometric data. Redacting at ingest means the data you retain falls outside that category entirely, rather than needing a lawful basis to hold it.
Full-face photographic images are one of the eighteen identifiers Safe Harbor requires you to remove before media can be treated as de-identified.
Media is processed strictly in memory. No original frame, intermediate buffer or detection crop is ever persisted to disk, and nothing is used for model training.
Every response carries the face count, bounding boxes and processing time, giving you a per-asset record that redaction actually ran and what it covered.
This page describes product capabilities and is not legal advice. Your own counsel should confirm how redaction fits your lawful basis and retention policy.
Connect with our technical team to receive sandbox API keys, RTSP video pipeline connectors, or on-premises container licenses.
Elliptical Gaussian blur, pixelation and solid blackout, with a configurable radius so the strength of the redaction can match your compliance requirement.
Yes. It handles crowd photos and CCTV stills in batch, and redacts live RTSP video streams through a continuous pipeline.
A stated 99.6% face detection recall at around 90ms per frame.
It is built for GDPR Article 9 obligations around biometric data and for HIPAA, by removing identifiable faces from media before it is stored, shared or published.
No. Media is processed strictly in memory with zero storage retention, so nothing is written to disk during redaction.
Yes. It is available as a managed API, with RTSP pipeline connectors and on-premises container licences for deployments that must stay inside your network.