Política de Privacidade
Última atualização: July 23, 2026
This Privacy Policy describes how CrazyOCR operated by Mathew Wu ("we", "us", or "our") collects, uses, processes, and shares your information when you use the website crazyocr.com(the "Service"). This policy applies to all visitors, registered users, and customers of the Service. By using the Service, you agree to the terms of this Privacy Policy.
1. Controlador de dados
The entity responsible for your personal data is:
CrazyOCR
CEO, Mathew Wu
Email: privacy@crazyocr.com
Website: https://crazyocr.com
Jurisdiction: United States of America
2. Categorias de dados que tratamos
2.1 Information you provide to us
- Account information. When you sign in with Google, we receive your name, email address, Google account identifier, and profile picture from Google's OAuth service.
- Uploaded documents. Files (images, PDFs, DOCX, XLSX, PPTX and other supported formats) that you upload for OCR processing. These may contain text, tables, images, and any other content contained in the document.
- Communications. Feedback, support requests, bug reports, and any email correspondence you send us.
- Billing information. When you subscribe to a paid plan, payments are processed by Stripe. We receive a Stripe customer identifier, subscription status, and the last four digits of your card. We never receive or store your full card number or CVC.
- API keys. If you use our REST API (available on paid plans), we generate and store API key credentials that authenticate your requests. Keys automatically expire 30 days after creation and can be revoked at any time from the API Management dashboard. They grant access to your account's OCR quota and should be kept secret.
2.2 Information collected automatically
- Usage data. Pages visited, features used, number of OCR requests performed, timestamps of requests, error events.
- Device and connection data. IP address (truncated in logs after 30 days), browser type and version, operating system, referring URLs, and rough geographic region derived from IP.
- Cookies and similar technologies. We use an essential session cookie to keep you logged in. We do not use advertising cookies.
3. Como usamos seus dados (finalidades e base legal)
We process your personal data only when we have a valid legal basis under applicable law (GDPR, CCPA, etc.):
- Contract performance (Art. 6(1)(b) GDPR): to operate the OCR service, create your account, process your documents, deliver OCR results, handle billing and subscriptions.
- Legitimate interests (Art. 6(1)(f) GDPR): to detect abuse, enforce our Terms of Service, improve accuracy and reliability, monitor infrastructure performance, analyze anonymized usage patterns, prevent fraud.
- Legal obligation (Art. 6(1)(c) GDPR): to maintain records for tax and compliance purposes, respond to lawful requests from authorities.
- Consent (Art. 6(1)(a) GDPR): where you have expressly given consent, e.g. for optional marketing communications.
4. Processamento e retenção de documentos
Documents you upload are transmitted to our OCR processing providers for the sole purpose of producing the OCR output. We are committed to a strict no-training policy:
- Your uploaded documents and extracted text are never used to train, fine-tune, or improve any machine learning model, ours or a third party's.
- On the free tier, uploaded files are automatically deleted within 24 hours of processing. OCR results are retained for up to 24 hours to allow you to copy/export them.
- On paid tiers, uploaded files and OCR results are retained for 90 days after which they are automatically deleted, unless you delete them earlier via the History view.
- You can permanently delete any of your documents and results at any time from your dashboard.
- CrazyOCR Small (on-device engine) runs entirely in your browser. Your images are never uploaded and never stored by us — only the extracted text (or a failure record) is sent to us when you keep the result.
- Tasks submitted via the API are counted toward your usage but are not stored in your OCR history or file storage.
5. Compartilhamento de dados e operadores
We share personal data only with the following categories of service providers, each acting under data processing agreements. All processing occurs on infrastructure located within the United States.
- Cloud infrastructure provider (USA) — hosting, CDN, object storage, and database. All data is stored and processed on Cloudflare infrastructure in the US East region (Virginia / DC metro area). Data is encrypted at rest and in transit.
- OCR processing partners (USA / US-operated) — documents are transmitted via encrypted API (TLS 1.3) for OCR inference only. Processing is executed on infrastructure based in the United States. No document data is stored, logged, or retained by these partners beyond the duration of a single processing request.
- Payment processor (USA) — subscription billing. We receive only a customer identifier and subscription status; we never receive or store your full payment card details.
- Authentication provider (USA) — OAuth login. Receives only the OAuth login flow data initiated by you.
We do not sell, rent, or lease your personal data or your uploaded documents to any third party for advertising, data brokerage, or any purpose beyond delivering the service.
6. Localização dos dados e jurisdição
CrazyOCR is a United States-based service. All data processing — including document upload, OCR inference, storage, and result delivery — occurs entirely on infrastructure located within the United States of America. Our application is deployed on Cloudflare's US East region (Northern Virginia / Washington DC metro area), one of the world's largest and most secure cloud infrastructure zones.
We do not transfer your personal data or uploaded documents outside the United States. All sub-processors listed in Section 5 are either US-domiciled entities or operate exclusively on US-based infrastructure bound by data processing agreements that require data to remain within US territory during processing. For users accessing the Service from outside the US, data is transmitted to and processed exclusively within the United States under the protections described in this policy.
7. Segurança dos dados
We implement industry-standard security measures including:
- Encryption in transit (TLS 1.3) for all data transfer between your browser and our servers, all of which are located in Cloudflare's US East region.
- Encryption at rest for stored documents, results, and database records using AES-256 encryption.
- Session tokens stored in HttpOnly, Secure, SameSite=Lax cookies.
- Regular dependency and infrastructure security reviews.
- Access to production systems is restricted to authorized personnel based in the United States only.
- API keys are transmitted only over TLS 1.3 and should be stored securely by you; treat them like passwords. We never display a key again after it is first created.
No security measure is 100% effective. In the event of a data breach affecting your personal information, we will notify you and applicable regulators within the timeframes required by law.
8. Seus direitos
As a US-based service, we respect the privacy rights available under applicable laws, including the California Consumer Privacy Act (CCPA) for California residents and the General Data Protection Regulation (GDPR) for residents of the European Economic Area and United Kingdom. Depending on your jurisdiction, you may have the following rights:
- Right of access: request a copy of personal data we hold about you.
- Right to rectification: request correction of inaccurate data.
- Right to erasure ("right to be forgotten"): request deletion of your personal data, including uploaded documents.
- Right to restriction: request limitation on how we process your data.
- Right to data portability: request your data in a machine-readable format.
- Right to object: object to processing based on legitimate interests.
- Right to withdraw consent: withdraw previously given consent at any time.
- Right to non-discrimination (CCPA): you will not receive discriminatory treatment for exercising your privacy rights.
To exercise any of these rights, email privacy@crazyocr.com. We respond to valid requests within 30 days.
9. Privacidade de crianças
The Service is not directed to children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us at privacy@crazyocr.com and we will promptly delete it.
10. Cookies
We use strictly necessary cookies to maintain your authenticated session and remember your language preference. We do not use analytics or advertising cookies. You can control cookies through your browser settings, but disabling session cookies will prevent you from using authenticated features.
11. Períodos de retenção
| Data category | Free tier | Paid tier |
|---|---|---|
| Uploaded files | 24 hours | 90 days |
| OCR results | 24 hours | 90 days |
| Account data | While account active + 12 mo | While account active + 12 mo |
| Billing records | — | 7 years (tax) |
| Server/access logs | 30 days | 30 days |
12. Alterações nesta política
We may update this Privacy Policy from time to time. Material changes will be announced via email (to registered users) or a prominent notice on the website at least 14 days before taking effect. The date at the top indicates the latest revision.
13. Contato
For privacy questions, data subject requests, or to report an incident, contact our Data Protection Officer at:
privacy@crazyocr.com
You also have the right to lodge a complaint with your local data protection authority (e.g., your national DPA in the EU/EEA) if you are unsatisfied with our handling of your request.
