Política de privacidad

Última actualización: July 23, 2026

This Privacy Policy describes how CrazyOCR operated by Mathew Wu ("we", "us", or "our") collects, uses, processes, and shares your information when you use the website crazyocr.com(the "Service"). This policy applies to all visitors, registered users, and customers of the Service. By using the Service, you agree to the terms of this Privacy Policy.

1. Responsable del tratamiento

The entity responsible for your personal data is:

CrazyOCR
CEO, Mathew Wu
Email: privacy@crazyocr.com
Website: https://crazyocr.com
Jurisdiction: United States of America

2. Categorías de datos que tratamos

2.1 Information you provide to us

  • Account information. When you sign in with Google, we receive your name, email address, Google account identifier, and profile picture from Google's OAuth service.
  • Uploaded documents. Files (images, PDFs, DOCX, XLSX, PPTX and other supported formats) that you upload for OCR processing. These may contain text, tables, images, and any other content contained in the document.
  • Communications. Feedback, support requests, bug reports, and any email correspondence you send us.
  • Billing information. When you subscribe to a paid plan, payments are processed by Stripe. We receive a Stripe customer identifier, subscription status, and the last four digits of your card. We never receive or store your full card number or CVC.
  • API keys. If you use our REST API (available on paid plans), we generate and store API key credentials that authenticate your requests. Keys automatically expire 30 days after creation and can be revoked at any time from the API Management dashboard. They grant access to your account's OCR quota and should be kept secret.

2.2 Information collected automatically

  • Usage data. Pages visited, features used, number of OCR requests performed, timestamps of requests, error events.
  • Device and connection data. IP address (truncated in logs after 30 days), browser type and version, operating system, referring URLs, and rough geographic region derived from IP.
  • Cookies and similar technologies. We use an essential session cookie to keep you logged in. We do not use advertising cookies.

3. Cómo usamos tus datos (fines y base legal)

We process your personal data only when we have a valid legal basis under applicable law (GDPR, CCPA, etc.):

  • Contract performance (Art. 6(1)(b) GDPR): to operate the OCR service, create your account, process your documents, deliver OCR results, handle billing and subscriptions.
  • Legitimate interests (Art. 6(1)(f) GDPR): to detect abuse, enforce our Terms of Service, improve accuracy and reliability, monitor infrastructure performance, analyze anonymized usage patterns, prevent fraud.
  • Legal obligation (Art. 6(1)(c) GDPR): to maintain records for tax and compliance purposes, respond to lawful requests from authorities.
  • Consent (Art. 6(1)(a) GDPR): where you have expressly given consent, e.g. for optional marketing communications.

4. Procesamiento y conservación de documentos

Documents you upload are transmitted to our OCR processing providers for the sole purpose of producing the OCR output. We are committed to a strict no-training policy:

  • Your uploaded documents and extracted text are never used to train, fine-tune, or improve any machine learning model, ours or a third party's.
  • On the free tier, uploaded files are automatically deleted within 24 hours of processing. OCR results are retained for up to 24 hours to allow you to copy/export them.
  • On paid tiers, uploaded files and OCR results are retained for 90 days after which they are automatically deleted, unless you delete them earlier via the History view.
  • You can permanently delete any of your documents and results at any time from your dashboard.
  • CrazyOCR Small (on-device engine) runs entirely in your browser. Your images are never uploaded and never stored by us — only the extracted text (or a failure record) is sent to us when you keep the result.
  • Tasks submitted via the API are counted toward your usage but are not stored in your OCR history or file storage.

5. Comunicación de datos y encargados

We share personal data only with the following categories of service providers, each acting under data processing agreements. All processing occurs on infrastructure located within the United States.

  • Cloud infrastructure provider (USA) — hosting, CDN, object storage, and database. All data is stored and processed on Cloudflare infrastructure in the US East region (Virginia / DC metro area). Data is encrypted at rest and in transit.
  • OCR processing partners (USA / US-operated) — documents are transmitted via encrypted API (TLS 1.3) for OCR inference only. Processing is executed on infrastructure based in the United States. No document data is stored, logged, or retained by these partners beyond the duration of a single processing request.
  • Payment processor (USA) — subscription billing. We receive only a customer identifier and subscription status; we never receive or store your full payment card details.
  • Authentication provider (USA) — OAuth login. Receives only the OAuth login flow data initiated by you.

We do not sell, rent, or lease your personal data or your uploaded documents to any third party for advertising, data brokerage, or any purpose beyond delivering the service.

6. Ubicación de los datos y jurisdicción

CrazyOCR is a United States-based service. All data processing — including document upload, OCR inference, storage, and result delivery — occurs entirely on infrastructure located within the United States of America. Our application is deployed on Cloudflare's US East region (Northern Virginia / Washington DC metro area), one of the world's largest and most secure cloud infrastructure zones.

We do not transfer your personal data or uploaded documents outside the United States. All sub-processors listed in Section 5 are either US-domiciled entities or operate exclusively on US-based infrastructure bound by data processing agreements that require data to remain within US territory during processing. For users accessing the Service from outside the US, data is transmitted to and processed exclusively within the United States under the protections described in this policy.

7. Seguridad de los datos

We implement industry-standard security measures including:

  • Encryption in transit (TLS 1.3) for all data transfer between your browser and our servers, all of which are located in Cloudflare's US East region.
  • Encryption at rest for stored documents, results, and database records using AES-256 encryption.
  • Session tokens stored in HttpOnly, Secure, SameSite=Lax cookies.
  • Regular dependency and infrastructure security reviews.
  • Access to production systems is restricted to authorized personnel based in the United States only.
  • API keys are transmitted only over TLS 1.3 and should be stored securely by you; treat them like passwords. We never display a key again after it is first created.

No security measure is 100% effective. In the event of a data breach affecting your personal information, we will notify you and applicable regulators within the timeframes required by law.

8. Tus derechos

As a US-based service, we respect the privacy rights available under applicable laws, including the California Consumer Privacy Act (CCPA) for California residents and the General Data Protection Regulation (GDPR) for residents of the European Economic Area and United Kingdom. Depending on your jurisdiction, you may have the following rights:

  • Right of access: request a copy of personal data we hold about you.
  • Right to rectification: request correction of inaccurate data.
  • Right to erasure ("right to be forgotten"): request deletion of your personal data, including uploaded documents.
  • Right to restriction: request limitation on how we process your data.
  • Right to data portability: request your data in a machine-readable format.
  • Right to object: object to processing based on legitimate interests.
  • Right to withdraw consent: withdraw previously given consent at any time.
  • Right to non-discrimination (CCPA): you will not receive discriminatory treatment for exercising your privacy rights.

To exercise any of these rights, email privacy@crazyocr.com. We respond to valid requests within 30 days.

9. Privacidad de los menores

The Service is not directed to children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us at privacy@crazyocr.com and we will promptly delete it.

10. Cookies

We use strictly necessary cookies to maintain your authenticated session and remember your language preference. We do not use analytics or advertising cookies. You can control cookies through your browser settings, but disabling session cookies will prevent you from using authenticated features.

11. Plazos de conservación

Data categoryFree tierPaid tier
Uploaded files24 hours90 days
OCR results24 hours90 days
Account dataWhile account active + 12 moWhile account active + 12 mo
Billing records7 years (tax)
Server/access logs30 days30 days

12. Cambios en esta política

We may update this Privacy Policy from time to time. Material changes will be announced via email (to registered users) or a prominent notice on the website at least 14 days before taking effect. The date at the top indicates the latest revision.

13. Contacto

For privacy questions, data subject requests, or to report an incident, contact our Data Protection Officer at:
privacy@crazyocr.com

You also have the right to lodge a complaint with your local data protection authority (e.g., your national DPA in the EU/EEA) if you are unsatisfied with our handling of your request.