How We Handle Your Data
Last updated: August 16, 2026 This page states exactly how space-ocr handles your images and the values extracted from them, separated by whether you use the web app or the API. Our Privacy Policy follows the handling described here. ━━━━━━━━━━━━━━━━━━━━ 1. Domains this service talks to ━━━━━━━━━━━━━━━━━━━━ These are the only domains involved. [Via the API] api.space-ocr.com — that is all. [Via the web app] space-ocr.com — this site api.space-ocr.com — API server *.firebasedatabase.app — where extracted values and metadata are stored *.firebasestorage.app — where uploaded images are stored *.googleapis.com — authentication and function execution (Google Cloud / Firebase) ━━━━━━━━━━━━━━━━━━━━ 2. Retention, period, and region ━━━━━━━━━━━━━━━━━━━━ ■ Via the API (POST /ocr/fields, /ocr/markdown, /ocr/text, etc.) Images     not retained Extracted values not retained These endpoints are stateless. The image is processed in the memory of the processing server and discarded once the response is returned. If you pass the image as a URL, that URL is not retained either. ■ Via the web app / upload Images     retained Extracted values retained Retained until you delete them, or until this service is discontinued. You may delete them at any time, and deletion takes effect immediately. ■ Regions (where processing and storage happen) * If you use the API only, nothing is stored at all and processing happens in Tokyo only. Processing (by us)    Tokyo, asia-northeast1 (Google Cloud Run) Extracted values, metadata Singapore, asia-southeast1 (Firebase Realtime Database) Uploaded images     United States, us-east1 (Firebase Storage) Rows 2 and 3 above apply only to items saved into MySpace in the web app. ━━━━━━━━━━━━━━━━━━━━ 3. Use for training ━━━━━━━━━━━━━━━━━━━━ We never use your images or extracted values for machine learning or model development. The same applies to the recognition engine provider: we use the paid tier (Gemini API Tier 1 or above), and under its terms content sent on a paid tier is not used to improve their models. ━━━━━━━━━━━━━━━━━━━━ 4. Subprocessors and their countries ━━━━━━━━━━━━━━━━━━━━ Google LLC (United States) - Cloud Vision API — character recognition - Gemini API — structuring (paid tier, Tier 1 or above) - Cloud Run — processing server (Tokyo) - Firebase Realtime Database — storage of extracted values (Singapore) - Firebase Storage — storage of images (United States) Note that Cloud Vision API and Gemini API are called on their global endpoints, without a region pin. Where that processing physically happens follows Google's infrastructure. Stripe, Inc. (United States) / GMO Payment Gateway, Inc. (Japan) - Payment processing only. No images or extracted values are passed to them. ━━━━━━━━━━━━━━━━━━━━ 5. What the logs contain ━━━━━━━━━━━━━━━━━━━━ ■ Via the API Recorded  timestamp / which endpoint was called / success or failure / the reason on failure / what billing requires (API key ID, credits consumed) Not recorded the image itself, the image URL, any extracted value ■ Via the web app The above, plus the images and extracted values that are retained by design (see section 2). ━━━━━━━━━━━━━━━━━━━━ 6. How to delete, and how long it takes ━━━━━━━━━━━━━━━━━━━━ Select the item in the web app and delete it. Deletion takes effect immediately and the data is removed from storage. For API traffic there is nothing to delete, because nothing was retained. ━━━━━━━━━━━━━━━━━━━━ 7. What happens when you delete your account ━━━━━━━━━━━━━━━━━━━━ When you delete your account, the images, extracted values, and account information tied to it are deleted within 7 days. ━━━━━━━━━━━━━━━━━━━━ 8. Contact ━━━━━━━━━━━━━━━━━━━━ Byeolbit LLC (ビョルビ合同会社) DeLCCS Kagurazaka 1F, 2-16 Higashi-Gokencho, Shinjuku-ku, Tokyo 162-0813, Japan Phone: 03-4400-9771 Email: oisidonut@gmail.com