Privacy policy
Last updated: July 30, 2026
In short: when an extraction succeeds we store neither the image nor the extracted data. We keep only the usage record needed to bill you correctly. What follows explains this, and everything else, in detail.
Looking for the plain-language version? See Security and data handling.
1. Who is responsible for your data
Roberto Carlos Frías Sobrevilla, owner and operator of Extract Passport Data (https://extractpassportdata.com), is the data controller ("responsable") for the personal data described here, under Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP).
The contact channel for anything related to this policy, including the exercise of your ARCO rights, is [email protected], or the form at https://extractpassportdata.com/contacto. We handle requests through these channels within the periods set out below.
2. Data we process
We process only the following categories:
- Account data: name, email address, and password (stored solely as an irreversible hash). If you sign in with Google, we receive your name, email, and account identifier from that provider. If you sign in with Apple, we receive your identifier and your email; when you choose "Hide My Email", that email is an anonymous relay address generated by Apple and we never learn the real one.
- Billing data: customer and payment identifiers, amount, currency, and transaction status. Payments are processed by Stripe: your card details are captured directly by Stripe and we never receive or store them.
- Identity-document images you choose to upload, and the personal data they contain (name, address, date of birth, sex, national identifiers, document number, validity dates, and the photograph, signature, and fingerprint printed on the document).
- Support data: the messages you send through chat or the contact form, the email address you write from, and your IP address.
- Usage data: technical records of service requests (timestamp, outcome, tokens consumed) and aggregate site analytics.
We do not request sensitive personal data beyond what the document itself contains, and we do not use it for any purpose other than the extraction you request.
3. How we handle images and extracted data (zero retention)
This is the core commitment of this policy, and it is implemented in the service code, not merely asserted here:
- When an extraction succeeds, the image you upload is processed in memory and is NOT stored. The extracted data is returned in the response to that same request and is NOT written to our database. We keep no history of your extraction content: not the image, nor the name, nor any identifier or other field.
- For each successful extraction we retain only a usage and billing record containing no personal content from the document: an internal identifier, the account, timestamp, status, and tokens consumed.
- When an extraction fails, we retain the uploaded image for 7 days for the sole purpose of diagnosing the error and fixing the service. After that period it is deleted automatically and permanently. Failed extractions are not charged.
- We never sell, rent, or trade your personal data or document images, under any circumstances.
4. Purposes
Primary purposes, necessary to provide the service:
- Perform the extraction you request and return the result to you.
- Create and administer your account, token balance, and API keys.
- Process payments, issue receipts, and resolve billing questions.
- Provide technical support and respond to your messages.
- Prevent fraud and abuse, and maintain the security and integrity of the service.
- Comply with legal and tax obligations and lawful requests from competent authorities.
Secondary purposes: sending you operational notices about your account (for example, a low-balance warning). You may opt out of these without affecting your use of the service by writing to [email protected].
We do not perform profiling, automated decision-making with legal effects on you, or targeted advertising using your data.
5. Transfers and processors
We do not transfer your personal data to third parties for those parties’ own purposes. We do rely on providers acting as processors, handling data only on our behalf and under our instructions:
- Google Cloud (Vertex AI — Gemini) and Landing AI: image processing for data recognition. Images are sent for inference and are not used to train their models.
- Stripe: payment processing.
- Resend: transactional email delivery.
- Compute and database infrastructure providers hosting the service.
- Google Analytics: aggregate site usage metrics.
- Telegram: internal operational notifications to the service administrator.
Some of these providers process information on servers located outside Mexico, primarily in the United States. By using the service you consent to this transfer, which is carried out under appropriate contractual safeguards.
We will disclose data without your consent only in the cases set out in article 37 of the LFPDPPP, in particular where required by a competent authority.
6. Retention periods
- Content of successful extractions: not retained (zero retention).
- Images from failed extractions: 7 days.
- Account data: while the account is active, and until you request its deletion.
- Payment and billing records: for the period required by applicable tax and commercial law.
- Support messages: for as long as needed to handle and evidence your case.
7. Your rights (ARCO), withdrawal of consent, and limiting use
You have the right to Access your personal data, Rectify it when inaccurate, Cancel it when you believe it is not required for the stated purposes, and Object to its processing for specific purposes (known in Mexico as ARCO rights). You may also withdraw the consent you granted us at any time, and limit the use or disclosure of your data.
To exercise any of these rights, send a request to [email protected] including: your name and a means of replying to you, proof of your identity (or of legal representation, where applicable), a clear description of the data concerned, and any detail that helps us locate it.
We will respond within 20 business days, and where the request is well founded we will give effect to it within the following 15 business days. These periods may be extended once, for an equal period, where the circumstances justify it.
You may request deletion of your account and associated data through the same channel. Account deletion is permanent and removes your account data, usage history, and API keys; payment records are retained as required by tax law.
If you believe your right to data protection has been infringed, you may file a complaint with the competent Mexican data protection authority.
8. Cookies and similar technologies
We use strictly necessary cookies to keep you signed in and to protect forms against request forgery; the service cannot function without them. We additionally use Google Analytics cookies to understand, in aggregate, how the site is used. You can block or delete cookies in your browser settings, noting that the strictly necessary ones are required in order to sign in.
9. Security
We apply reasonable administrative, technical, and physical safeguards: encryption in transit (TLS) for all communications, irreversible hashing for stored passwords, role-based access control for the administrative panel, and data minimization as a central design choice — the strongest protection for your document content is that we do not keep it.
No system is infallible. Should a breach occur that significantly affects your rights, we will notify you without delay so you can take appropriate measures.
10. Lawful use of the service
The service is intended for processing your own documents, or third-party documents for which you hold legal authority and the data subject’s consent. You are responsible for having that lawful basis. In Mexico, misuse of voter credentials and electoral roll data is sanctioned under electoral law, independently of this policy.
Do not use the service to process unlawfully obtained documents or for any purpose contrary to law.
11. Minors
The service is not directed at minors and we do not knowingly collect their data. If we identify an account created by a minor without the consent of a parent or guardian, we will delete it.
12. Changes to this policy
We may update this privacy policy to reflect changes to the service or to applicable law. The current version is always available at https://extractpassportdata.com/privacidad, showing its last-updated date. When a change is material we will notify you by email or through a prominent notice on the site before it takes effect.