I Read the Privacy Policies of Four Free Online OCR Sites. One Keeps Your File for a Week
Search for whether free online OCR sites are safe and you get an interesting result: Google largely answers with the OCR sites themselves. The accused party gets to write the verdict.
So I read four of their privacy policies instead. All quotes below were taken on 9 August 2026, and policies change, so check the current wording before relying on any of them. If you’d rather not upload at all, on-device apps such as Textora read the text on your phone; more on that at the end.
What they actually say
ocr.space is the most direct of the four:
All uploaded documents are deleted after processing. We do not keep any of your data.
It also names its jurisdiction, which most don’t: “The OCR.space team headquarter is in Europe (Germany). The strict European data protection laws apply.” The policy carries no last-updated date, and says nothing about whether uploads are used to improve the service.
img2txt.com is the one that surprised me:
The file that you sent for recognition is physically stored for up to one week. It is automatically deleted following the end of the term.
A week, not an instant. And separately, recognition results are retained for up to two years. Google Analytics and Google AdSense are disclosed as third parties. No jurisdiction is specified and training use isn’t addressed.
Think about what that means for a document you converted once and forgot about. The image sits on their infrastructure for seven days; the extracted text, which is the part that actually contains your name and account number, stays for two years.
onlineocr.net states two things on the same page. First:
Your privacy is our priority. We don’t store any of your documents.
Two sentences later, on the same page:
All documents uploaded under the free “Guest” account will be deleted automatically after conversion. Output files for registered users are stored one month.
Read together, those two sentences point in different directions. I’d take the specific one over the general one, but the site is the authority on its own practice, so check the current wording before relying on either.
newocr.com has no privacy policy document to read. The site states that “all of your files will be removed from the server after use for added privacy” and that “Your data is kept safe and secure with us.” That’s a claim on a marketing page, not a commitment you could point to later.
The comparison
| Site | Uploaded file | Extracted text | Jurisdiction stated | Formal policy |
|---|---|---|---|---|
| ocr.space | Deleted after processing | Not stated | Germany, EU law | Yes |
| onlineocr.net | Guests: after conversion. Registered: output kept 1 month | Not stated | Not stated | Yes |
| img2txt.com | Up to one week | Up to two years | Not stated | Yes |
| newocr.com | ”Removed after use” | Not stated | Not stated | None found |
Two things this table can’t tell you.
None of the four say whether your uploads train anything. Not one addressed it in either direction. An absence isn’t a denial, and it isn’t an admission either.
A policy is a promise, not a mechanism. ocr.space’s commitment reads well, and I have no reason to doubt it. But the breaches I wrote about recently all happened at companies whose policies also read well. Storage that exists can leak. Storage that doesn’t exist can’t.
When an online tool is genuinely the right choice
I’d rather be useful than alarming, so: for a restaurant menu, a public notice, a page of a library book, a conference flyer, upload away. Nothing on it is yours. Free web OCR is fast, needs no install, works on any device, and the retention question is academic when the content is public.
The calculus changes when the image contains something that identifies you or someone else. A payslip, an ID, a medical letter, a contract, a bank statement, a document belonging to a client. For those, the question isn’t which site has the best policy. It’s whether a copy needs to exist on someone else’s server at all.
The on-device alternative
On iPhone, the built-in options don’t upload: Live Text and the Files app scanner both work with the network off. The ten-second test for any tool is airplane mode. If the text still appears, the image wasn’t uploaded to read it. Where they stop is everything after that: Live Text copies text from the image in front of you, but keeps no searchable history of your scans and won’t turn a stack of pages into one searchable PDF.
Textora passes the same airplane-mode test, because text recognition runs on the iPhone, and it needs no account to start. It is free to download and adds what the built-ins don’t: multi-page scanning, a searchable library of everything you’ve scanned, searchable PDF export, and a one-tap save of the scanned PDF to Files. Its cloud AI features are off unless you turn them on, and even then only masked text is sent, never the photo.
It runs on iPhone and iPad only, so if you’re on a Windows desktop with a scanned PDF, the table above is what to go on. The retention windows differ by orders of magnitude, and only you know how sensitive the document in front of you is.
I build Textora. Every quote above is from the site’s own page, read on 9 August 2026 and linked below; email support@textora.app if something has changed.
Sources: ocr.space privacy policy · onlineocr.net · img2txt.com privacy · newocr.com
Frequently asked questions
Is it safe to use free online OCR websites?
How long do online OCR sites keep my uploaded file?
Do online OCR sites use my documents to train their models?
What is the safest way to extract text from an image?
Which free online OCR site has the clearest privacy policy?
Ready to extract text from photos in seconds?
Textora uses AI to scan and organize text from any image — receipts, menus, handwritten notes, and more. Works offline, recognises 12 languages on-device.
Download on the App Store