Privacy policy

Updated on 2026-07-09

Who we are

OCR Nerd is the data controller for the processing described here. For any privacy request, contact [email protected].

What we process

The PDF you upload and the text extracted from it; an optional email address; payment metadata (we never store card data); and minimal technical logs needed for security and to run the service.

Legal basis (GDPR)

We process your files to perform the service you request (Article 6(1)(b), contract). Any email you provide is processed on the same basis to deliver your result. Security logs rely on our legitimate interest (Article 6(1)(f)).

Where your data is stored

Your data stays in the European Union. Files are stored on Cloudflare R2 with EU jurisdiction (data residency) under Cloudflare’s Data Processing Addendum; our database runs on Neon (AWS, Europe — Frankfurt, eu-central-1); transactional email is sent via Resend (Ireland, eu-west-1).

AI processing

Text recognition is performed by an AI OCR model provided by Mistral AI (an EU company, France) under a data-processing agreement. Your files are used only to produce your result and are not used to train AI models.

Retention

The uploaded PDF is deleted right after OCR is completed. The result and its download link are automatically deleted after 7 days — or sooner on request. Unpaid uploads are removed within a couple of hours.

Processors we use

Cloudflare (hosting and EU storage), Neon/AWS (database, EU), Mistral AI (OCR), Stripe and Mercado Pago (payments — they process payment data as controllers/processors under their own terms), Resend (email, EU), and a privacy-friendly analytics provider (Himetrica) that measures usage without cross-site tracking or advertising profiles.

Your rights

You have the right to access, rectify, erase, restrict, port and object to the processing of your personal data, and to lodge a complaint with your local supervisory authority. To exercise any right, email [email protected].

International transfers

We aim to keep processing within the EU. Where a processor operates outside the EEA, transfers are covered by Standard Contractual Clauses or an adequacy decision.

Feito por FlamTI LGPD/GDPR: Ribeiro Cavalcante — Brazilian Lawyers VoxScriber