This page states exactly how space-ocr handles your images and the values extracted from them, separated by whether you use the web app or the API. Our Privacy Policy follows the handling described here.
━━━━━━━━━━━━━━━━━━━━
1. Domains this service talks to
━━━━━━━━━━━━━━━━━━━━
These are the only domains involved.
[Via the API]
api.space-ocr.com — that is all.
[Via the web app]
space-ocr.com — this site
api.space-ocr.com — API server
*.firebasedatabase.app — where extracted values and metadata are stored
*.firebasestorage.app — where uploaded images are stored
*.googleapis.com — authentication and function execution (Google Cloud / Firebase)
━━━━━━━━━━━━━━━━━━━━
2. Retention, period, and region
━━━━━━━━━━━━━━━━━━━━
■ Via the API (POST /ocr/fields, /ocr/markdown, /ocr/text, etc.)
Images not retained
Extracted values not retained
These endpoints are stateless. The image is processed in the memory of the processing server and discarded once the response is returned. If you pass the image as a URL, that URL is not retained either.
* The one exception is Idempotency-Key. Only when you send that header, we hold the response for up to 24 hours so a repeated request returns the same result; it expires automatically after that (held in Firebase Realtime Database, Singapore). Without the header no such retention occurs. The image itself is not retained in this case either. We will delete it before expiry on request.
■ Via the web app / upload
Images retained
Extracted values retained
Retained until you delete them, or until this service is discontinued. You may delete them at any time, and deletion takes effect immediately.
■ Regions (where processing and storage happen)
* If you use the API only, neither the image nor the extracted values are stored. The only host your application talks to is api.space-ocr.com, and our processing servers run in Tokyo (only when you use Idempotency-Key, the response is held in Singapore for up to 24 hours as described above).
Processing (our servers) Tokyo, asia-northeast1 (Google Cloud Run)
* Character recognition and structuring themselves run on global endpoints with no region pinning (see section 4)
Extracted values, metadata Singapore, asia-southeast1 (Firebase Realtime Database)
Uploaded images United States, us-east1 (Firebase Storage)
Rows 2 and 3 above apply only to items saved into MySpace in the web app.
━━━━━━━━━━━━━━━━━━━━
3. Use for training
━━━━━━━━━━━━━━━━━━━━
We never use your images or extracted values for machine learning or model development.
The same applies to the recognition engine provider: we use the paid tier (Gemini API Tier 1 or above), and under its terms content sent on a paid tier is not used to improve their models.
━━━━━━━━━━━━━━━━━━━━
4. Subprocessors and their countries
━━━━━━━━━━━━━━━━━━━━
Google LLC (United States)
- Cloud Vision API — character recognition
- Gemini API — structuring (paid tier, Tier 1 or above)
- Cloud Run — processing server (Tokyo)
- Firebase Realtime Database — storage of extracted values (Singapore)
- Firebase Storage — storage of images (United States)
Note that Cloud Vision API and Gemini API are called on their global endpoints, without a region pin. Where that processing physically happens follows Google's infrastructure.
Stripe, Inc. (United States) / GMO Payment Gateway, Inc. (Japan)
- Payment processing only. No images or extracted values are passed to them.
━━━━━━━━━━━━━━━━━━━━
5. What the logs contain
━━━━━━━━━━━━━━━━━━━━
■ Via the API
Recorded timestamp / which endpoint was called / success or failure / the reason on failure / what billing requires (API key ID, credits consumed)
Not recorded the image itself, the image URL, any extracted value
■ Via the web app
The above, plus the images and extracted values that are retained by design (see section 2).
━━━━━━━━━━━━━━━━━━━━
6. How to delete, and how long it takes
━━━━━━━━━━━━━━━━━━━━
Select the item in the web app and delete it. Deletion takes effect immediately and the data is removed from storage.
For API traffic there is nothing to delete, because nothing was retained. The only exception is the response held when you use Idempotency-Key, which expires automatically within 24 hours. If you would rather not wait for it to expire, ask us and we will delete it.
━━━━━━━━━━━━━━━━━━━━
7. What happens when you delete your account
━━━━━━━━━━━━━━━━━━━━
When you delete your account, the images, extracted values, and account information tied to it are deleted within 7 days.
━━━━━━━━━━━━━━━━━━━━
8. Contact
━━━━━━━━━━━━━━━━━━━━
BYULBIT LLC (ビョルビ合同会社)
DeLCCS Kagurazaka 1F, 2-16 Higashi-Gokencho, Shinjuku-ku, Tokyo 162-0813, Japan
Phone: 03-4400-9771
Email: support@space-ocr.com