Privacy Policy
App and website: OnDevice OCR Pro · Developer: Christian Schröder
Controller
The party responsible for processing personal data in connection with this website is:
Christian Schröder
Marktstraße 242
47798 Krefeld
Germany
Email: support@ondeviceocr.com
1. General
The protection of your personal data is our top priority. “OnDevice OCR Pro” was developed according to the “privacy first” principle. This privacy policy explains the nature, scope, and purposes of the collection and use of personal data when using our application and visiting this website.
2. App: No data collection (“Zero Data Collection”)
Our app “OnDevice OCR Pro” does not collect, store, process, or transfer any personal data to us.
No servers: The app does not communicate with any external servers, neither ours nor those of third parties.
No tracking: We do not use any analysis tools (such as Google Analytics, Firebase, or similar).
Local processing: All documents (PDFs, images) are processed exclusively locally on your device
(on-device). Text recognition (OCR) is performed by Apple Vision Frameworks directly on your Mac.
3. Website hosting via Cloudflare
This website is hosted and delivered using services provided by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (“Cloudflare”). Cloudflare provides DNS, content delivery, security, and performance services for this website.
When you visit this website, technically necessary connection data may be processed by Cloudflare. This may include your IP address, the requested URL, date and time of the request, browser and device information, referrer information, and other technical metadata required to deliver and secure the website.
The purpose of this processing is to make the website available, improve loading speed, and protect the website against abuse and attacks. The legal basis is our legitimate interest in operating a secure and reliable website, Art. 6(1)(f) GDPR. This connection data is processed only for as long as necessary for these purposes and is deleted thereafter.
Cloudflare may process data in countries outside the European Union, including the United States. Such international transfers are safeguarded by the European Commission’s Standard Contractual Clauses and, where applicable, Cloudflare’s certification under the EU–U.S. Data Privacy Framework, as set out in Cloudflare’s data processing terms. Further information is available in Cloudflare’s privacy policy and data processing terms: Cloudflare Privacy Policy and Cloudflare Data Processing Addendum.
4. Website Analytics with Cloudflare Web Analytics
We use Cloudflare Web Analytics / Real User Measurements (RUM) to understand, in aggregated form, how this website is used and how quickly it loads. This does not set cookies, create persistent user identifiers, or use localStorage, sessionStorage, or IndexedDB in the browser. For this purpose, Cloudflare may process technical usage and performance data, including the visited page, date and time of the visit, referrer information if provided by the browser, approximate country, browser and device type, and technical performance metrics such as load times and Core Web Vitals. The IP address is transmitted to Cloudflare as part of the technical connection to the website. According to Cloudflare, Web Analytics does not use IP addresses to identify individual visitors and does not store them in the analytics data. This processing helps us understand and improve the reach, stability, and loading speed of this website. The legal basis is our legitimate interest in providing a secure, fast, and user-friendly website pursuant to Art. 6(1)(f) GDPR. You have the right to object to this processing on grounds relating to your particular situation, Art. 21 GDPR. We do not use advertising trackers, profiling tools, or cookie-based analytics such as Google Analytics. We do not offer user accounts or contact forms on this website. We do not send a newsletter; for the one-off notification about OnDevice OCR Business see section 6. Cloudflare may process technically necessary connection data as described above. To protect email addresses shown on this website from spam bots, Cloudflare automatically applies email address obfuscation, which inserts a small Cloudflare script whose sole purpose is to obscure those addresses; it does not track you or collect analytics. If you contact us by email, your message and email address will be processed only for the purpose of handling your request.
We also keep anonymous counts of App Store clicks and direct downloads. For a temporary test on the English and German homepages, we additionally record which of four hero/header variants was shown and whether the first product action on that page load was an App Store click, direct download, or purchase-button click. All visitors within the same 15-minute period see the same variant; the variants rotate by time period. Stored fields are the time, approximate country, language, variant, referring page, coarse browser family, event type, and bot/self-test markers. The IP address is not stored. The test uses no cookies, localStorage, sessionStorage, persistent identifier, or cross-page tracking. A reload within the same period normally keeps the variant; a reload after the period changes may show another one. This processing helps us assess and improve the usability of the website on the basis of our legitimate interest under Art. 6(1)(f) GDPR. You may object on grounds relating to your particular situation under Art. 21 GDPR.
5. Purchase and license delivery (Paddle, Resend)
If you buy a license directly through this website, the purchase is processed by our merchant of record, Paddle.com Market Ltd (“Paddle”). Paddle acts as the seller of record and processes the data required to complete the transaction, such as your name, email address, billing address, VAT number if provided, and payment details, and issues the invoice. We receive from Paddle the information needed to deliver and manage your license (such as your name, email address, and order details), but no full payment data. The legal basis is the performance of a contract, Art. 6(1)(b) GDPR. For details, see Paddle’s privacy policy.
After a successful purchase, your license file is sent to you by email. For this we use the email delivery service Resend, operated by Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA (“Resend”), acting as a processor on our behalf. The data processed for this purpose is limited to your name, your email address, and the license file itself. The legal basis is the performance of a contract, Art. 6(1)(b) GDPR. This involves a transfer of data to the United States. The transfer is safeguarded by Resend’s certification under the EU–U.S. Data Privacy Framework and by the European Commission’s Standard Contractual Clauses contained in Resend’s data processing addendum. Resend stores the message data for a maximum of 30 days and deletes it thereafter. Further information is available in Resend’s privacy policy and Resend’s Data Processing Addendum.
6. Notification about OnDevice OCR Business
On the home page, you can enter your email address to receive a one-time notification as soon as OnDevice OCR Business becomes available. Providing this information is optional; you can use the website without restriction even if you do not provide it.
We use the "double opt-in" verification process for this: After entering your information, you will first receive an email with a confirmation link. Your email address will only be added to the notification list once you click on this link. If you do not click the link within 48 hours, your registration will expire. Deletion occurs automatically once a day, so there may be up to one day between the expiration of the 48-hour period and the actual deletion. This process protects you from third parties adding your email address without your knowledge.
We process your email address, the language you selected, as well as the date, time, and IP address associated with your registration and confirmation. The latter two pieces of information are used exclusively to verify your consent; without this verification, we would be unable to prove the lawfulness of the mailing in the event of a dispute. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 7 Abs. 2 UWG (German Unfair Competition Act).
Technically, this also includes the random keys for the confirmation and unsubscribe links as well as, if delivery fails, the number of delivery attempts and the reason for the error. The reason for the error does not contain an email address.
You will receive exactly one notification. Immediately after it is sent, we will delete your address and the associated verification data. If the notification cannot be delivered—for example, because the mailbox no longer exists—we will retain the entry so that we can trace and correct the error. It will be deleted no later than 30 days after the last delivery attempt; this deletion also occurs once a day. You may revoke your consent at any time with future effect, without providing a reason and at no cost to you: via the unsubscribe link in the notification or by sending an informal email to [support@ondeviceocr.com]. After revocation, your entry will be completely deleted. As long as you have not yet confirmed, simply ignoring the confirmation email is sufficient; your registration will then expire automatically. The lawfulness of the processing carried out up to that point remains unaffected.
These emails are sent via Resend under the conditions described in Section 5. The address data is stored on a Cloudflare, Inc. service within its global network; the standard contractual clauses mentioned in Section 3 apply here. To protect against automated submissions, we limit the number of requests per address and per IP address. The counters used for this purpose do not contain addresses in plain text, but only irreversible checksums. They are no longer taken into account after one hour and are deleted no later than the next daily cleanup run.
7. Access to files in the app
The app only accesses files that you explicitly load into the app via drag & drop or via the file selection dialog (“Open File”). These files never leave your device.
8. Use with AI agents and automation tools
OnDevice OCR Pro itself does not upload documents, OCR text, filenames, or usage data. If you choose to use external AI agents or automation tools with access to the app or to folders containing your documents, you are responsible for deciding which files and data those tools may access. Any processing performed by such external tools is outside the control of OnDevice OCR Pro and is governed by the respective tool provider and your configuration of that tool.
9. Disclosure to third parties
The app does not disclose your documents, OCR text, filenames, or usage data to third parties. For the website, Cloudflare processes technically necessary connection data as described above in order to deliver and protect the website.
10. Your rights
Subject to the applicable legal requirements, you have the right to request access to, rectification, erasure, restriction of processing, and portability of your personal data. You may also have the right to object to processing based on Art. 6(1)(f) GDPR. You also have the right to lodge a complaint with a competent data protection supervisory authority.
11. Contact
If you have any questions about data protection, please contact: Christian Schröder [support@ondeviceocr.com]
As of: August 5, 2026