Last updated: September 27, 2026

Privacy Policy

OCRs.ai is the trade name of Guni Innovations Pte. Ltd. (collectively, “OCRs.ai,” “we,” “us,” or “our”). We provide layout-preserving OCR and text extraction for documents, images, and video. Because customers upload sensitive files and authenticate with API keys, we are designed around minimal collection, strong security, and clear boundaries. This policy explains what we process, why, and your choices.

1. Introduction

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you interact with our websites, APIs, dashboard, and related services (collectively, the “Services”).

This Privacy Policy is intended to comply with applicable privacy and data protection laws, including the Personal Data Protection Act 2012 of Singapore (“PDPA”), the General Data Protection Regulation (“GDPR”) and UK GDPR (where applicable to individuals in the EEA or United Kingdom), the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), and other applicable data protection legislation.

By accessing our websites or using the Services, you are informed of the practices described in this Privacy Policy. This Privacy Policy does not constitute consent to the processing of your personal data; where consent is required, it will be obtained separately in accordance with applicable law.

2. Who we are

Guni Innovations Pte. Ltd. is a technology company providing OCR, text extraction, layout reconstruction, and related embedding services under the trade name OCRs.ai. Our full contact details are in Section 18 below.

3. Our role in processing personal data

Depending on the context, OCRs.ai may act as either a Data Controller or a Data Processor.

  • Controller. We act as a controller for account, billing, website analytics, marketing, and support data that we collect and determine the purposes of processing.
  • Processor. When you submit documents, images, or video via the API or dashboard for OCR or text extraction, we act as a processor on your behalf. You (or your organization) remain the controller/data fiduciary for that content and must have a lawful basis to submit it for processing. OCRs.ai processes such content solely for the purpose of performing the requested extraction and delivering results, in accordance with your instructions.

If you require a Data Processing Agreement for your compliance needs, please contact us.

4. Categories of personal data we process

CategoryExamples
Account & identityName, email address, profile details received via sign-in provider
OrganizationOrganization name, domain, industry, team membership
API keysKey identifiers, secure hashes/prefixes, creation and revocation timestamps
Usage & billingRequest timestamps, job IDs, page/minute usage summaries, wallet balance changes, error codes
PaymentProcessed by our payment processor (e.g. Stripe); we do not store full card numbers on our systems
Support & communicationsEmails, contact form submissions, feedback
File content & OCR artifactsUploaded file bytes, extracted text, layout data, QC outputs — retained only for the minimum period necessary to process and deliver results (see Section 7)
Website & technicalIP address, browser/device information, cookies, log files, analytics identifiers

5. How we collect personal data

We may collect personal data:

  • Directly from you, when you create an account, submit files, or contact us;
  • From identity and sign-in providers (e.g. Google OAuth), when you choose to authenticate through them;
  • From our payment processor, to facilitate billing and transactions;
  • Automatically through our websites and APIs, including via cookies and similar technologies; and
  • From OCR, AI inference, and related subprocessors, solely as part of producing extraction results on your behalf.

6. How we use personal data

We process personal data to:

  • Provide, operate, secure, and improve the Services;
  • Process files you submit and deliver OCR / extraction results;
  • Authenticate API requests and prevent abuse;
  • Process payments and maintain billing records;
  • Respond to enquiries and support requests;
  • Comply with legal and regulatory obligations;
  • Communicate with you about the Services, incidents, or policy updates; and
  • Improve and develop our products (without using your submitted files to train AI models).

7. File processing and retention

Purpose-limited processing. File content you submit is processed solely to produce and deliver the requested OCR / extraction result (and optional embeddings or vector export you request). We do not use your files to train AI models, for marketing, for resale, or for any purpose unrelated to providing the Services.

No customer file archive. We do not operate a long-term customer file archive for secondary analytics. File content is retained only for the minimum period necessary to process the job and deliver results, after which it is discarded from operational processing paths, subject to any retention settings you configure in the product.

Operational reality. Like any file-processing service, transient infrastructure storage, logs, backups, or diagnostics may retain fragments for a short period beyond delivery. We apply technical and organizational measures to keep this window as short as practicable and to restrict access.

Job metadata. Metadata associated with jobs (e.g. status, page/minute counts, timestamps, job identifiers, error codes) may be retained for audit, billing, reliability, and abuse-prevention purposes. This is distinct from the file content itself.

If you require specific contractual commitments regarding data handling for your regulatory environment, please contact us to discuss a Data Processing Agreement.

8. Legal bases for processing

We rely on the following legal bases, depending on the nature of the processing and applicable law:

Processing activityPDPA / GDPR basis
Operating your account and providing the ServicesContract performance; legitimate purposes
Processing file content on your instructionsCustomer's instructions (processor role); contract
Security, fraud prevention, abuse detectionLegitimate interests / legitimate purposes
Non-essential cookies and analyticsConsent (where required)
Tax, accounting, and regulatory record-keepingLegal obligation
Marketing communicationsConsent; legitimate interests (where permitted)

9. Who we share personal data with

We may share personal data with the following categories of recipients, each engaged under appropriate contractual safeguards:

  • Payment processors — to handle billing and transactions;
  • Identity and authentication providers — to facilitate sign-in;
  • Cloud hosting, storage, and CDN providers — to operate and deliver the Services;
  • OCR, AI inference, and related providers — solely to process extraction requests on your behalf;
  • Email and messaging providers — for transactional and support communications;
  • Bot and fraud protection providers — to prevent abuse (including Turnstile on auth flows);
  • Analytics providers — to understand website usage and improve the Services;
  • Professional advisors — including legal counsel and auditors, under confidentiality obligations; and
  • Regulators and law enforcement — where required by applicable law or valid legal process.

All third parties that process personal data on our behalf do so under contract and are required to implement appropriate security measures. We do not sell personal data. A current list of subprocessors is available on request for security reviews and enterprise Data Processing Agreements.

10. International data transfers

We may process personal data in Singapore and in other countries where we or our subprocessors operate. Where cross-border transfers are required, we use appropriate safeguards consistent with applicable law, including:

  • Contractual protections consistent with the PDPA transfer obligations;
  • Standard Contractual Clauses approved by the European Commission (where GDPR applies); and
  • Other safeguards as required by applicable data protection legislation.

Regardless of where data is processed, we implement appropriate technical safeguards including encryption in transit and at rest.

11. Data retention schedule

We retain personal data only for as long as necessary for the purposes for which it was collected:

Data categoryRetention period
File content & processing artifactsMinimum period necessary to complete processing and deliver results (subject to product retention settings)
Account & organization dataWhile your account is active, plus any period required by law
Billing and tax recordsAs required by applicable law
Job metadata (status, usage, timestamps)While your account is active, for audit and service reliability
Support communicationsAs needed to resolve the request plus a reasonable follow-up period
Marketing & newsletterUntil you unsubscribe

12. Your privacy rights

Depending on where you are located and applicable law, you may have rights in relation to your personal data, including:

  • Access — to obtain a copy of your personal data;
  • Correction — to have inaccurate or incomplete data corrected;
  • Erasure / deletion — to request deletion of your personal data in certain circumstances;
  • Portability — to receive your data in a structured, machine-readable format where applicable;
  • Objection / restriction — to object to processing based on legitimate interests or to request restriction;
  • Withdrawal of consent — where processing is based on consent, you may withdraw it at any time without affecting lawfulness of prior processing; and
  • Complaint — to lodge a complaint with the relevant data protection authority (e.g. PDPC in Singapore, or your national authority under GDPR).

To exercise your rights, email hello@ocrs.ai with the subject line “Privacy request.” We will respond within 30 days (or such shorter period as required by applicable law). We may need to verify your identity before processing a request. You can also revoke API keys and close your account from the dashboard where available.

California residents (CCPA/CPRA). If you are a California resident, you may have additional rights under the CCPA, including the right to know what personal information we collect and how it is used, the right to request deletion, and the right to opt out of the sale or sharing of personal information. We do not sell or share (as defined by the CCPA) your personal information. To exercise your CCPA rights, contact us at the email above. We will not discriminate against you for exercising your rights.

File content processed as Processor. Where we process file content on behalf of an organization (as Processor), individuals should direct data rights requests to the organization that submitted the data. We will assist that organization in responding to such requests in accordance with applicable law.

13. Automated processing

OCRs.ai uses automated processes, including OCR engines and AI models, to extract text, reconstruct layout, optionally run quality control, and produce embeddings. These outputs are assistive tools — they are not legal determinations, compliance certifications, or guarantees of perfect transcription.

You (or your organization) remain responsible for validating results in your context and for any decision made on the basis of OCRs.ai outputs.

If you believe an automated result has affected you and you wish to request human review, contact us at hello@ocrs.ai with the subject line “Human Review Request” and include the job ID and the file concerned.

14. Security

We maintain appropriate technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, or destruction. These measures include:

  • Encryption of data in transit (TLS) and at rest;
  • Role-based access controls and least-privilege principles;
  • Secure handling of API keys (hashed storage; keys are not retrievable after creation);
  • Encrypted storage of vector-database connection secrets;
  • Multi-factor authentication options (TOTP and email) for accounts;
  • Monitoring, logging, and alerting for anomalous access patterns;
  • Employee confidentiality obligations and security awareness; and
  • Incident response procedures, including notification as required by applicable law.

No method of transmission or storage is 100% secure. We work continuously to reduce risk and to respond promptly if an incident occurs. See also our Security page.

15. Cookies and similar technologies

Our websites and Services may use cookies, analytics scripts, and similar technologies. We use the following types:

  • Strictly necessary — required to operate the Services (e.g. session authentication cookies). These cannot be disabled.
  • Analytics — used to understand how visitors use our website and to improve the Services. These are only set after you consent where required.
  • Preferences — used to remember settings and improve your experience.

You can manage cookies through your browser settings. Disabling non-essential cookies will not affect your ability to use the core Services.

16. Children's privacy

The Services are intended for professional and business use and are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child, we will take appropriate steps to delete it without undue delay.

17. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our Services, legal obligations, or privacy practices. We will post the revised version on this page and update the “Last updated” date. Material changes will be communicated through appropriate channels (e.g. email or in-product notice) before taking effect.

18. Contact

If you have any questions about this Privacy Policy, wish to exercise your privacy rights, or raise a concern regarding the processing of your personal data, please contact us:

  • Email: hello@ocrs.ai
  • Organization: Guni Innovations Pte. Ltd. (trading as OCRs.ai)
  • Registered address: 68 Circular Road #02-01, 049422, Singapore

See also our Terms of Service.