Privacy & Data Security

Last updated: August 22, 2026

What We Keep, and For How Long

Documents you upload are kept in your workspace — the file itself, the text extracted from it, and the embeddings used for search and chat. The product reads all three back every time you open, export or question a document, so they remain available until you delete the document or your account.

Nothing is retained on the GPU workers that perform recognition: the file is written to a temporary path for the duration of the job and removed when it completes. We do not maintain a training corpus, and your documents are never used to train models, ours or a provider’s.

Data Processing

When you submit a document, the file is transmitted over encrypted transport (TLS) to our application layer. The document is then dispatched to isolated GPU workers running on Modal infrastructure for optical character recognition, optional AI-assisted structuring or refinement, and—where enabled—embedding generation for search and chat features within your workspace.

Recognition itself occurs in ephemeral compute environments: on those workers the input bytes exist only for the duration of the job. The resulting text and its embeddings are then stored against your account, because search, export and document chat read them back. System logs may record non-content metadata (such as job identifiers, timestamps, and status codes) strictly for reliability, abuse prevention, and support. We do not use document contents for profiling, advertising, or unrelated analytics.

Uploaded files are held in private storage: they have no public URL, and each request to view or download one is authorised against your session and served through a link that expires. Account-related data (such as email address, subscription status, and usage quotas) is stored separately from document payloads in our authentication and billing systems (e.g., Supabase) under access controls appropriate to production SaaS operations.

Third-Party Sharing

We do not sell, rent, or license your documents or extracted text to third parties. Your content is not contributed to public or proprietary large-language-model training datasets, and we contractually and technically restrict subprocessors to processing on our instructions only.

Infrastructure providers (including cloud GPU hosts and email delivery services) may process data solely as processors to deliver the service you request. They do not acquire ownership of your materials and may not use them for their own product development or model training purposes.

We may disclose information only where required by applicable law, valid legal process, or to protect the rights, safety, and integrity of OCR Context, our users, and the public—always to the minimum extent necessary.

Cookies, Analytics & Advertising

We run advertising campaigns, and we measure whether they work. That measurement is about how people arrive at and move through this site — pages viewed, whether a visit became a sign-up, whether a sign-up became a subscription. It is never about the contents of documents you upload. Those two things are kept apart by design: nothing in a document, and no text extracted from one, is sent to any analytics or advertising provider.

Where measurement is switched on, we use Google Analytics and Google Ads conversion tracking, and we may use the Meta (Facebook and Instagram) pixel. These providers set cookies and similar identifiers in your browser in order to recognise a return visit and attribute it to the campaign that produced it.

In the European Economic Area, the United Kingdom and Switzerland, none of that storage is used until you allow it. Advertising and analytics storage is withheld by default in those regions, and a banner asks before anything changes. If you decline, the tags stay switched off and measurement continues only in an aggregated, cookieless form that cannot identify you. Elsewhere the tags run by default and the same banner is not shown, but declining is available to everyone: the Cookie preferences link in the site footer reopens the choice at any time, and changing it takes effect immediately.

Alongside provider cookies, we store a small number of values in your browser’s local storage rather than on our servers: your cookie choice, the campaign details of your first visit, a record of which conversion events have already been counted so they are not counted twice, and — for logged-out trial use — a browser identifier described under Abuse Prevention. Clearing your browser storage removes all of them.

Campaign Attribution

When you arrive from an advertisement, the link carries parameters identifying the campaign (such as utm_source, utm_campaign, and the click identifiers gclid or fbclid). If you later create an account, those parameters, the page you first landed on and the site you came from are stored once against your account.

We keep this because advertising platforms report only their own conversions and only for a limited window; without it we cannot tell, some weeks later, whether the people a campaign brought in are still using the service. It is recorded on first visit and never overwritten, it is not shared with the advertising platforms, and it contains no information about you beyond how you found us. The lawful basis is our legitimate interest in understanding which of our own marketing works (GDPR Art. 6(1)(f)); it is deleted with your account.

Error Monitoring

We use Sentry to be told when something breaks — a page that fails to render, a request that errors, a document whose processing gives up after retrying. Without it a failure that does not crash the site is invisible to us and the person affected simply sees nothing happen.

Reports carry what is needed to find the fault: an error message, a stack trace, a document or job identifier, the page in question. They deliberately do not carry personal details, request bodies or IP addresses, and we do not use session recording, which would capture the contents of the page you were looking at — on this service, your documents.

Payments

Subscriptions are sold and processed by Polar as merchant of record. Card details are entered on their systems and never reach ours: we receive only the resulting subscription state — plan, status, renewal date — which we store against your account to decide what the service should make available to you.

GDPR & KVKK Compliance

OCR Context is designed to align with the principles of the EU General Data Protection Regulation (GDPR) and the Turkish Law on Protection of Personal Data (KVKK). Where we act as a data controller for account and billing information, we process personal data on lawful bases such as contract performance, legitimate interests, and—where applicable—consent.

Where we process documents on your behalf, you remain responsible for ensuring that you have an appropriate legal basis to submit those materials (for example, employee notices, customer agreements, or data-processing agreements with your own clients). We implement technical and organizational measures including encryption in transit, role-based access, row-level security in the database, private object storage that has no publicly reachable address and is opened only through short-lived links issued to your own account, least-privilege administration, and the deletion behaviour described below.

Abuse Prevention & Account Deletion

When you request account deletion, your uploaded files, their extracted text, the embeddings generated from them, your preferences and your account record are all deleted. However, to maintain the integrity of our platform and prevent free-tier abuse, we retain a cryptographically hashed (one-way, mathematically irreversible) footprint of your email address. This hash cannot be used to identify you, contact you, or reverse-engineer your email. It is stored strictly under our legitimate business interest (GDPR Art. 6(1)(f)) solely to prevent unauthorized creation of duplicate trial accounts.

The same purpose is served before you have an account at all. The small trial available without signing up is metered against an identifier derived from your browser, stored locally and sent with those requests, and protected by Cloudflare Turnstile, which distinguishes a person from an automated script. Both exist so that a free allowance offered once cannot be taken repeatedly, and neither is used to build a profile of you, to advertise to you, or for any purpose beyond that metering.

Data subjects in applicable jurisdictions may have rights to access, rectify, erase, restrict, or object to certain processing of personal data, and to lodge complaints with supervisory authorities. To exercise rights or request information about our processing activities, contact support@ocrcon.com.

International transfers, if any, are conducted with appropriate safeguards consistent with applicable law. We review our subprocessors and security practices periodically to maintain compliance as the product and regulatory landscape evolve.