Privacy Policy.
EFFECTIVE AUGUST 21, 2026 · PENNYOCR IS OPERATED BY TATSMANY LLC
01 / THE HEADLINE: ZERO RETENTION BY DEFAULT
Documents you send to the API are processed in memory and discarded once the response is returned. By default we do not store your documents or their extracted text, and we never use them to train models. Two exceptions, both under your control: (a) runs you submit through the dashboard playground are stored so you can view them — delete them anytime; (b) if you switch "API result storage" ON, API documents and results are stored to your account until you delete them or turn it off.
02 / WHAT WE DO STORE
Account data: your email address, hashed API keys (we cannot see the originals), session tokens, and settings. Billing data: your prepaid balance and a ledger of purchases and usage (page counts, timestamps, request IDs — not document contents). Payments are processed by Stripe; we never see or store card numbers. Login codes are stored hashed and expire in 15 minutes.
03 / WEBSITE ANALYTICS
The website uses Google Analytics to understand traffic (pages visited, referrer, approximate location, device type), which sets cookies. The API itself sets no cookies and is not analytics-tracked beyond the usage ledger above.
04 / SUBPROCESSORS
Infrastructure that touches data, and what it touches:
· Cloudflare (site hosting, DNS, API routing) — traffic transits it.
· RunPod (GPU + gateway compute) — documents transit during processing.
· Supabase/PostgreSQL (database) — account, billing and opted-in stored runs.
· Stripe (payments) — email and payment details you enter at checkout.
· Resend (email delivery) — your email address, for login codes.
· Google Analytics (website only) — see section 03.
05 / YOUR RIGHTS
Access, export, correct or delete your data anytime: stored runs are deletable in the dashboard; for account deletion or a data export, email hello@pennyocr.com and we'll complete it within 30 days. We don't sell personal data, full stop. If you're in a jurisdiction with statutory rights (GDPR, CCPA and friends), those rights apply and the same email exercises them.
06 / SECURITY
TLS everywhere, API keys and codes stored only as SHA-256 hashes, prepaid balances that cap financial exposure, and a deliberately small stack. No system is perfect; if we learn of a breach affecting your data we will notify you promptly.
07 / RETENTION & CHILDREN
Billing/usage ledgers are kept as long as your account exists (and as required for tax/accounting). Stored runs live until you delete them. The Service is not directed at children under 13 and we don't knowingly collect their data.
08 / CHANGES & CONTACT
Material changes will be announced on this page with a new effective date. Questions or requests: hello@pennyocr.com. See also the Terms of Service.