Security

Your ID document does not stay with us

We process official identity documents, so the question that matters is not what we promise but what we keep. The short answer: when an extraction succeeds, nothing. Not the image, not the data.

Last updated: July 29, 2026

Zero retention

This is not a policy we promise to honor: it is implemented in the service code. These statements describe what the system does, not what we would like it to do.

Your image is not stored

When an extraction succeeds, the image is processed in memory for that single request and is never saved. No copy remains on our servers or in our database.

Neither is the extracted data

The result travels in the response to your request, and that is where it ends. Not the name, not passport number and MRZ code, not any other field is written to our database.

There is no content history

Your history holds the timestamp, status, and tokens used — nothing else. Nobody can retrieve the content of a successful extraction: not you, not our team, not a third party with database access. It simply is not there.

Never sold, never used for training

We do not sell, rent, or trade your data or your images under any circumstances. The vision providers we use process the image for inference and do not use it to train their models.

What we do keep

Saying "we keep nothing" would be false, and we would rather be exact. This is everything that is recorded, and for how long.

Usage and billing record

Permanent

Internal identifier, account, timestamp, status, and tokens consumed. This is what lets us bill you correctly and show you your usage. It contains no data from the document.

Image from a failed extraction

7 days

When a read fails we keep the image to diagnose the error and fix the service; it is deleted automatically and permanently once the 7 days elapse. API clients can switch this capture off, and the iOS app always does.

Your account data

While the account exists

Name, email, and a password stored solely as an irreversible hash. You can request deletion of your account at any time.

Payment records

As required by tax law

Amount, currency, status, and transaction identifiers. Your card is captured directly by Stripe: we never receive or store its details.

If something is not in this table, we do not keep it.

Accuracy verified, not assumed

A misread value costs more than a missing one: it enters your system without warning. That is why the service does not simply read the document once and trust the result.

We cross-check fields against each other

A value can be correctly formatted and still be wrong. We check passport number and MRZ code against the rest of the printed information and repair inconsistencies before returning your result.

Automatic re-read when something does not add up

If passport number and MRZ code does not match its expected format, or a required field comes back empty, the system re-reads the image in a second corrective pass. No extra cost, and nothing for you to do.

The document is read twice

When you send both sides, we read the passport as a pair and also read the front on its own, then compare. That stops information from the back contaminating the identity fields on the front — a silent error that is hard to catch.

An honest error beats an invented value

If the photo does not allow passport number and MRZ code to be read, our API responds with an explicit error naming the unreadable field, instead of handing you a record with blank fields that look valid.

If it fails, you are not charged

Every failed extraction automatically returns the token to your balance. We also run two computer-vision providers: if the primary degrades, the request switches to the secondary without you noticing.

Questions worth asking any provider

Before uploading identity documents to any service — ours included — these questions are worth asking, and worth a concrete answer. Here are ours.

Do you store the image after processing it? For how long?

No. On a successful extraction the image is not stored. We keep only the images of extractions that fail, for 7 days, for the sole purpose of diagnosing the error.

Do you store the extracted data in your database?

No. The result is returned in the response and never written. Our own admin panel cannot show the content of your extractions, because it does not exist.

Can I browse my extraction history with its content?

No, by design. If a provider can show you the content of what you extracted a month ago, it means they stored it — and that someone else could read it too.

Do you use my images to train AI models?

No. They are sent to the vision providers solely for that request’s inference, under terms that exclude training use.

What happens if the read fails? Am I charged anyway?

No. The token is automatically returned to your balance on every failed extraction.

If the photo is unreadable, do I get empty fields or an error?

An explicit error naming the field that could not be read. A blank field that looks valid is the worst possible answer: it poisons your database without you noticing.

Still need a detail?

The privacy policy covers the full legal detail, including your ARCO rights and the list of processors. If you need something that is not there, write to us.

Or email us at [email protected]