Security & Data Privacy
We built this tool to handle sensitive documents. This page explains in plain language exactly what happens to your files, how long they are kept, who can access them, and how to request deletion.
Last updated: June 25, 2026
TL;DR: Your uploaded files are sent over HTTPS (TLS 1.2+), processed by our OCR engine on Vercel + Google Cloud infrastructure, and then permanently deleted immediately after conversion completes. We do not train AI models on your content. No account is required. No file history is stored.
Encryption in Transit
All data (including uploaded images, PDFs, and any text you enter) is transmitted over HTTPS using TLS 1.2 or higher (TLS 1.3 preferred). This means your file is encrypted in transit between your browser and our servers and cannot be intercepted in a readable form.
Our application is hosted on Vercel (edge network and serverless functions) with OCR processing performed via the Google Cloud Vision API. Both providers maintain industry-standard encryption and security certifications.
Vercel
Hosting & Edge Network
Google Cloud
OCR Processing & Vision API
Data at rest (where any temporary storage applies) is protected with AES-256 encryption at the infrastructure level.
File Deletion Window
| File Type | Processing Time | Maximum Retention | How Deleted |
|---|---|---|---|
| Uploaded images (JPG, PNG, BMP, WebP, TIFF) | Seconds | Immediately after OCR | Deleted automatically on processing completion |
| Uploaded PDFs | Seconds β minutes | Immediately after OCR | Deleted automatically on processing completion |
| Extracted text output | Returned to browser | Never stored server-side | Exists only in your browser session |
Images are deleted immediately after OCR processing completes β typically within seconds. Files are never written to a persistent database. They are passed to the OCR engine in memory or via short-lived cloud storage, and the deletion is triggered as part of the same request lifecycle.
Storage Policy
We operate a no-persistent-storage policy for uploaded files and extracted text. Specifically:
- βUploaded files are never written to a permanent database.
- βExtracted text output is returned directly to your browser and is not logged or stored on our servers.
- βNo copies of your documents are made for training AI models.
- βNo copies are made for quality review, research, or any other internal purpose.
- βWe do not create thumbnails, previews, or cached versions of uploaded files beyond what is needed for immediate processing.
- βPaid subscriber account data (email, billing info) is stored separately from file processing infrastructure.
What Happens to Extracted Text
Key point
The extracted text is returned directly to your browser and displayed on screen. It is never stored, logged, or transmitted to any third party from our side.
When you click "Extract Text", the following happens:
- 1Your browser sends the image file to our server over HTTPS.
- 2Our OCR engine (Google Cloud Vision API) processes the image and returns raw text.
- 3Our server forwards that text back to your browser over HTTPS.
- 4The image file is deleted from temporary storage.
- 5The extracted text lives only in your browser tab. It is never written to our database.
Third-Party Processors
We use a small number of trusted sub-processors to operate the service. Each is listed below with its role and data handling relevance.
What data: Receives the uploaded image for text recognition
Retention: Not retained by Google beyond the API call. Google's API data usage policies apply.
Privacy policy: https://cloud.google.com/vision/docs/data-usage
What data: Hosts the application; processes requests at the edge
Retention: Vercel does not store uploaded file content beyond request completion.
Privacy policy: https://vercel.com/legal/privacy-policy
What data: Stores account emails and subscription status for paying users only. Uploaded files are never stored here.
Retention: Retained until account deletion is requested.
Privacy policy: https://firebase.google.com/support/privacy
What data: Handles billing for paid plans. We do not store payment card data.
Retention: Governed by Paddle's privacy policy.
Privacy policy: https://www.paddle.com/legal/privacy
What data: Collects anonymized page views and performance metrics. No file content or extracted text is included.
Retention: Aggregated; no personal identifiers.
Privacy policy: https://vercel.com/docs/analytics/privacy-policy
We do not sell your data to any third party. We do not use your files or extracted text for advertising targeting. No sub-processor receives your extracted text.
We Do Not Train AI on Your Content
Explicit No-Training Commitment
We do not use your uploaded images, documents, or extracted text to train, fine-tune, or evaluate any AI or machine learning models β including our own or any third party's. Your content is used solely to perform the OCR conversion you requested and is then discarded.
The OCR engine we use (Google Cloud Vision API) is a production inference API. Google's terms for this API prohibit the use of submitted data for model training without explicit consent. Your images are not used for that purpose.
No Human Review of Your Files
No member of our team views, reviews, or accesses the content of your uploaded images or documents. Processing is fully automated.
The only exception is if you voluntarily submit a file to our support team as part of a bug report. In that case we will only use it to diagnose the reported issue and will delete it afterwards.
Account & Personal Data (Paid Users)
For users on a paid plan, we store the following account data in Firebase:
- Email address (used for login and billing communications)
- Subscription status and plan type
- Usage count (number of OCR conversions, for quota enforcement)
- Payment records managed by Paddle (we do not store card details)
Free (unauthenticated) users do not have accounts and we store no personal data linked to them beyond anonymized analytics.
Request Data Deletion
Because uploaded files are automatically deleted within 1 hour, there is typically nothing left to delete by the time you finish using the tool. However, if you are a registered user and wish to delete your account and all associated personal data, you can request deletion using any of the methods below.
π§ Email Request
Send a deletion request to:
support@extractimagetotext.orgSubject: "Data Deletion Request"
Include your registered email address.
π Contact Form
Use our contact page and select "Data & Privacy" as the topic.
Go to Contact Page βWe will confirm deletion within 7 business days.
GDPR β EU Users
General Data Protection Regulation (GDPR)
If you are located in the European Economic Area (EEA), UK, or Switzerland, you have rights under the GDPR and equivalent legislation. This section explains how those rights apply to our service.
- βLegal basis for processing: Our lawful basis for processing your uploaded image is the performance of the service you requested (Article 6(1)(b) GDPR β contract). No consent is required because you are requesting the OCR conversion yourself.
- βData minimization: We collect only the image file necessary to perform OCR. No metadata beyond what is technically required is collected.
- βStorage limitation: Images are deleted immediately after processing. No retention period applies because we do not store them.
- βData subject rights: You have the right to access, rectify, erase, restrict, and port your personal data. For file data, nothing is retained; for account data (paid users), submit a request to support@extractimagetotext.org.
- βData Protection Officer (DPO): We are a small business and currently do not have a designated DPO. Privacy inquiries can be directed to support@extractimagetotext.org.
- βData Processing Agreement (DPA): Enterprise or institutional customers requiring a signed DPA may contact us at support@extractimagetotext.org to arrange one.
- βCross-border transfers: Processing occurs via Vercel (US-based) and Google Cloud Vision API (US-based). Both providers maintain EU-US Data Privacy Framework compliance or Standard Contractual Clauses (SCCs) to cover data transfers from the EEA.
CCPA β California Users
California Consumer Privacy Act (CCPA) / CPRA
If you are a California resident, you have rights under the CCPA and California Privacy Rights Act (CPRA).
- βWe do not sell your personal information. This includes uploaded file content and any extracted text.
- βWe do not share your personal information with third parties for cross-context behavioral advertising.
- βRight to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you (paid account users only; free users have no account data stored).
- βRight to Delete: You may request deletion of personal information we have collected about you. File content is already deleted immediately after processing.
- βRight to Correct: You may request correction of inaccurate personal information in your account.
- βRight to Opt-Out of Sale / Sharing: We do not sell or share personal information, so no opt-out mechanism is required. If this changes, we will update this page and provide a "Do Not Sell or Share My Personal Information" link.
- βTo exercise your CCPA rights, contact us at support@extractimagetotext.org with the subject "CCPA Privacy Request".
Compliance Roadmap
We are a growing service and take compliance seriously. Below is our current status and planned roadmap:
GDPR-aligned data handling
No persistent storage of file data; immediate deletion
CCPA-aligned data handling
No sale or sharing of personal information
TLS 1.2+ encryption in transit
Enforced via Vercel edge network
AES-256 encryption at rest
Provided by Google Cloud and Vercel infrastructure
SOC 2 Type II audit
Planned β we are currently evaluating audit partners
GDPR Data Processing Agreement (DPA)
Available upon request for enterprise customers
ISO 27001 certification
Long-term roadmap item
Enterprise customers requiring compliance documentation should contact support@extractimagetotext.org.
Your Rights
Regardless of where you are located, we respect the following rights in relation to your personal data:
Right to Access
Request a copy of any personal data we hold about you.
Right to Erasure
Request deletion of your account and personal data.
Right to Correction
Update inaccurate personal data held in your account.
Right to Portability
Receive your data in a machine-readable format.
Right to Object
Object to processing of your data for certain purposes.
Right to Withdraw Consent
Opt out of any non-essential data processing at any time.
To exercise any of these rights, email support@extractimagetotext.org.
Changes to This Policy
If we make material changes to how we handle your data (for example, introducing a new sub-processor or changing retention windows), we will update this page and revise the "Last updated" date at the top. For significant changes affecting paid users, we will send a notification to your registered email address.