This Privacy Policy explains how StartOCR Inc. ("StartOCR", "we", "us", or "our") collects, uses, stores, and protects your personal information when you use our website, API, dashboard, and related services (collectively, the "Services").
1. Information we collect
1.1 Account and billing information
When you register for an account, we collect your email address, name, and payment details processed by Stripe. We do not store full credit card numbers on our servers.
1.2 Documents and input data
We temporarily process images, PDFs, and other files you submit through the API or dashboard solely to provide OCR results. Files are stored in Cloudflare R2 with configurable retention tiers and automatically deleted according to your plan settings.
1.3 Usage and diagnostic data
We collect request metadata (timestamps, page counts, error codes), browser or client information, and aggregated analytics to operate, secure, and improve the Services.
2. How we use your information
- To provide, maintain, and improve OCR processing and API delivery.
- To bill and administer your account, including subscription status and usage limits.
- To detect abuse, fraud, and security incidents.
- To communicate product updates, security notices, and support responses.
3. Data retention
Uploaded files are retained only as long as necessary to generate results and are deleted automatically after the configured retention period (default 1 hour for free sandbox, 24 hours for paid plans, or custom enterprise tier). Result JSON and logs follow the same retention schedule.
4. Sharing and third parties
We do not sell your personal data. We share limited data with trusted infrastructure providers (Cloudflare for compute and storage, Stripe for billing) under strict confidentiality and security obligations.
8. Data Processing Agreement (DPA)
For business customers, StartOCR acts as a processor of personal data contained in documents submitted for OCR. We process such data only on documented instructions, implement appropriate technical and organizational security measures, and assist customers in responding to data subject requests. A standardized DPA is available upon request.
9. Sub-processors
We use the following sub-processors to provide the Services:
| Sub-processor | Service | Location | Data processed |
|---|---|---|---|
| Cloudflare, Inc. | Compute, storage, CDN, and security | United States | Uploaded files, request metadata, and account data |
| Stripe, Inc. | Payment processing | United States | Billing information and payment method data |
5. Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or export your personal data. Contact privacy@startocr.com to submit a request. privacy@startocr.com.
6. Security
We encrypt data in transit with TLS 1.3 and at rest using provider-managed encryption. API requests require authenticated tokens and are rate-limited per account.
7. Changes to this policy
We may update this Privacy Policy as our Services evolve. We will notify account holders of material changes via email or dashboard notice at least 30 days before they take effect.