LogoNoteOCR
Data & Privacy

Privacy Policy

Your privacy is foundational to how NoteOCR is built. This policy explains exactly what data we collect, why we collect it, and how we protect it — in plain language.

GDPR Compliant
Swiss nFADP
No Data Selling
No AI Training
Last Updated: January 2026
Who We Are & Controller

Your data, your control

NoteOCR Inc. ('NoteOCR', 'we', 'us', 'our') is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website at noteocr.com or use our platform, API, and related services (collectively, the 'Services'). This policy is compliant with the General Data Protection Regulation (GDPR), the Swiss Federal Act on Data Protection (nFADP), and other applicable privacy laws. By using NoteOCR, you agree to the practices described in this Privacy Policy.

§01

Who We Are & Controller

NoteOCR Inc. is the data controller responsible for your personal data. We are a technology company incorporated under Swiss law and headquartered in Zug, Switzerland. Our Services include an AI-powered handwriting OCR platform, a cloud-based document editor, and a developer API. If you have questions about how we handle your personal data, you may contact our data protection point of contact at support@noteocr.com. We are committed to handling your data transparently, lawfully, and with the level of care it deserves.

§02

What Data We Collect

We collect the minimum data necessary to provide and improve our Services. The categories of data we collect include: (a) Account Information, your name, email address, and hashed password when you register, or basic profile information provided by OAuth providers such as Google; (b) Usage Data, pages processed, credit balance, conversion history, session activity, and feature interactions to support your account and improve accuracy; (c) Device & Technical Data, IP address, browser type and version, operating system, referrer URL, and general geographic region (country or city-level) collected automatically via server logs and cookies; (d) Payment Data, billing details and transaction records, processed exclusively by our third-party payment processors (Stripe). NoteOCR never stores full card numbers or CVV codes; (e) Communications, messages you send us via email or support forms, retained to resolve your inquiries; (f) Uploaded Content, documents, images, and files you upload for OCR processing, subject to the strict handling rules described in Section 4.

Account info

Authentication & account management

ContractDuration of account + 90 days

Usage data

Platform functionality & analytics

Legitimate interestUp to 24 months

Uploaded files

OCR conversion only

ContractDeleted after conversion

Payment records

Billing & compliance

Legal obligation7 years

Communications

Support resolution

Legitimate interest3 years

§03

How We Use Your Data

We use your personal data only for the purposes for which it was collected, on the following legal bases: (a) Performance of Contract, to create and manage your account, process your page credits, execute document conversions, and deliver the Services you have purchased; (b) Legitimate Interests, to prevent fraud, maintain platform security, resolve technical issues, and generate aggregated analytics that help us improve the product; (c) Legal Obligation, to comply with applicable tax, accounting, and regulatory requirements in Switzerland and the EU; (d) Consent, to send optional product updates and feature announcements by email, which you may withdraw at any time. We never sell your personal data or use it for advertising purposes. We do not share your data with data brokers, ad networks, or any third party for commercial profiling.

§04

Your Uploaded Documents

Documents you upload are treated with the highest level of confidentiality and are subject to strict technical controls. All uploaded files are encrypted in transit using TLS 1.3 and at rest using AES-256. Files are processed in isolated compute environments, no document is co-mingled with another user's data during processing. Once a conversion job is complete, the source file is automatically deleted from our processing servers. If you store converted documents in your NoteOCR library, they are retained until you manually delete them or close your account. We do not access, read, annotate, or analyse the content of your documents for any purpose other than executing the conversion you requested. Critically, NoteOCR never uses the content of your uploaded documents to train, fine-tune, evaluate, or improve any AI or machine learning model.

TLS 1.3 + AES-256

Encrypted end-to-end

Isolated Processing

No cross-user exposure

Auto-Deleted After Job

Source file gone immediately

§05

Cookies & Tracking

We use a minimal set of cookies and similar technologies to operate and improve our Services. Strictly Necessary Cookies are essential to authenticate your session and keep you logged in, these cannot be disabled. Functional Cookies remember your preferences such as language and theme. Analytics Cookies (optional) help us understand how pages are used at an aggregate level so we can improve the product. We use privacy-respecting analytics and do not deploy third-party advertising cookies or cross-site tracking pixels of any kind. You can manage your cookie preferences at any time through your browser settings or our in-platform cookie banner. Disabling optional cookies will not affect your ability to use the core Services.

§06

Data Sharing & Third Parties

We share personal data with a limited set of trusted service providers who assist us in operating our platform, and only to the extent necessary. These include: (a) Stripe, payment processing, subject to PCI-DSS compliance; (b) Google OAuth, optional sign-in authentication; (c) Cloud Infrastructure Providers, encrypted server storage and compute, available in US-East (N. Virginia), EU (Frankfurt), and APAC (Singapore) regions; (d) Email Delivery, transactional and notification email services. All third-party processors are bound by data processing agreements (DPAs) that prohibit them from using your data for any purpose other than the service they provide to us. We do not transfer personal data to third parties for marketing, profiling, or any commercial purpose beyond operating the Services.

§07

International Data Transfers

NoteOCR is headquartered in Switzerland, which the European Commission recognises as providing an adequate level of data protection. Where we transfer personal data to service providers operating outside the EEA or Switzerland (for example, cloud infrastructure in the US or APAC), we rely on the European Commission's Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms to ensure that your data receives the same level of protection as it would within the EEA. You may select your preferred data processing region (EU, US, or APAC) within your account settings. By default, new accounts are assigned to the EU (Frankfurt) region.

§08

Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes described in this policy. Account Information is retained for the duration of your account and for up to 90 days after account closure to allow for recovery or dispute resolution, after which it is permanently deleted. Processed source files are deleted automatically upon conversion completion. Documents stored in your NoteOCR library are retained until you delete them or close your account. Payment and transaction records are retained for 7 years in compliance with Swiss and EU tax regulations. Support communications are retained for up to 3 years. Anonymised and aggregated analytics data may be retained indefinitely as it does not identify any individual.

§09

Your Privacy Rights

Access your data

Correct inaccuracies

Request deletion

Restrict processing

Export your data

Object to profiling

Withdraw consent

Depending on your location, you may have the following rights regarding your personal data: Right of Access, request a copy of all personal data we hold about you; Right to Rectification, request correction of inaccurate or incomplete data; Right to Erasure, request deletion of your personal data where there is no overriding legal basis for its retention; Right to Restriction, request that we limit how we process your data while a dispute is resolved; Right to Portability, receive your data in a structured, machine-readable format; Right to Object, object to processing based on legitimate interests, including profiling; Right to Withdraw Consent, withdraw consent for email communications at any time without affecting prior processing. To exercise any of these rights, email support@noteocr.com with the subject line 'Privacy Request'. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

§10

Security Measures

We implement technical and organisational security measures designed to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include: AES-256 encryption at rest for all stored files and account data; TLS 1.3 encryption for all data in transit; isolated compute environments for each document processing job; role-based access controls limiting internal access to personal data on a strict need-to-know basis; regular security audits and penetration testing; and automatic deletion of source files upon processing completion. Despite these measures, no method of transmission over the internet or electronic storage is 100% secure. If we become aware of a personal data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR.

AES-256 at RestTLS 1.3 in TransitIsolated ProcessingRole-Based Access72hr Breach NotificationRegular Pen TestingZero Model TrainingGDPR Compliant

§11

Children's Privacy

NoteOCR is not directed at children under the age of 13, and we do not knowingly collect personal data from children under 13. Users between 13 and 18 must have parental or guardian consent before using our Services, as stated in our Terms of Service. If you are a parent or guardian and believe your child has provided personal data to NoteOCR without your consent, please contact us at support@noteocr.com. We will promptly investigate and delete any such data. We do not knowingly serve personalised content or advertising to minors.

§12

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will notify registered users by email and update the 'Last Updated' date at the top of this page. We may also display a banner within the platform to draw attention to significant changes. Your continued use of the Services after the effective date of any revised Privacy Policy constitutes your acceptance of those changes. We encourage you to review this policy periodically. Previous versions of this policy are available upon request.

§13

Contact & DPO

If you have questions, concerns, or requests regarding this Privacy Policy or the way we handle your personal data, please contact us. We are committed to resolving all privacy-related enquiries promptly and in good faith. You also have the right to escalate unresolved concerns to a supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC). In the EU, you may contact the data protection authority in your member state.

Privacy Support

Privacy questions or data requests?

Our team handles all privacy enquiries personally. Whether you want to access, correct, or delete your data, or simply have a question — we respond within 30 days as required by GDPR.

Email our privacy team

support@noteocr.com

Response within 30 days (GDPR requirement)

© 2026 NoteOCR Inc. · All Rights Reserved · Governed by Swiss Law & GDPR