Privacy Policy

How we handle your information

What 404tools.dev collects, how it is used, who it is shared with, and specifically what happens to the documents you send to the OCR API.

Last updated August 6, 2026

1. The free tools collect nothing

The cron, regex, confusion matrix and other browser utilities on this site run entirely in your browser. Whatever you paste into them stays on your device and is never transmitted to us.

This section is first because it covers most visitors. Everything below applies only if you create an account and use the paid OCR API.

2. Information we collect

For OCR API accounts we collect information you provide directly, information created while you use the API, and limited technical information needed to run the service securely.

  • Account details: your name, email address and a securely hashed password. Authentication is handled by Supabase on our behalf.
  • API key metadata: a name you choose, a one-way hash of the key, its display prefix, when it was last used and how many requests it has served. We do not store the key itself in a form we can read.
  • Usage records: per request, the timestamp, the file name you supplied, the file size, the page count, whether it succeeded, how long it took, and any error. This is what your usage dashboard is built from.
  • Purchase records: which page pack you bought, the number of pages, the amount, and the Paddle transaction reference.
  • Standard server logs including IP address, used for security, abuse prevention and diagnostics.

3. What happens to documents you send to the OCR API

This is the part most people want to know about, so it is stated plainly. Your document is received by our API, forwarded to Microsoft Azure AI Document Intelligence for text extraction, and the extracted text is returned to you in the HTTP response.

We do not write the document, or the text extracted from it, to our database or to any persistent storage of ours. Once the response has been returned, our copy exists only in memory and is released.

What we do keep is the metadata listed above: the file name you supplied, its size in bytes, and the page count. We keep those because they are what your usage log and your bill are made of. We do not keep the contents.

We do not use your documents or extracted text to train any model, and we do not permit our processor to do so.

4. How we use information

We use personal information to run the service, meter usage accurately, communicate with you, prevent abuse, and meet legal or operational obligations.

  • Create and manage your account and API keys.
  • Authenticate API requests and deduct pages from the correct balance.
  • Show you your own usage history and remaining balance.
  • Process purchases and handle billing support.
  • Monitor performance, troubleshoot failures and protect the service from abuse.
  • Comply with legal obligations and enforce our terms.

5. Sub-processors and sharing

We do not sell your personal information. We share data only with the providers needed to operate the product, and only to the extent needed.

  • Microsoft Azure AI Document Intelligence: receives the documents you submit, in order to perform the text extraction you asked for.
  • Supabase: hosts our database and handles authentication, so it stores your account record, API key hashes, usage metadata and purchase records.
  • Paddle: acts as merchant of record and processes all payments. Paddle collects your payment details directly. We never receive or store your card number.
  • Vercel: hosts the application and processes request traffic.
  • We may also disclose information if required by law, regulation, legal process or a valid government request, or as part of a merger, acquisition or sale of business assets, subject to appropriate safeguards.

6. Data retention

Document contents are not retained at all, as described in section 3.

Usage and purchase records are kept for as long as your account exists, and afterwards for as long as needed for accounting, tax and dispute-resolution purposes.

Deleting your account removes your profile, API keys and usage history. Purchase records may be retained where we are legally required to keep them.

7. Security

API keys are stored only as SHA-256 hashes, so a copy of our database cannot be replayed against the API. Row-level security is enforced in the database so one account cannot read another's keys, usage or purchases.

All traffic is served over HTTPS. No system can be guaranteed perfectly secure, so please also use a strong, unique password and rotate any API key you suspect has been exposed.

8. Your choices and rights

Depending on where you live, you may have rights to access, correct, export, delete or object to certain uses of your personal information.

  • You can review and update your name and password from your account settings.
  • You can revoke any API key at any time from your dashboard.
  • You can request access to, correction of, or deletion of your data by contacting us.
  • Because nothing auto-renews, you can simply stop using the service at any time without cancelling anything.

9. International transfers

Our providers operate infrastructure in multiple countries, so your information may be processed outside the country where you live. Where required, transfers rely on the safeguards those providers have in place, such as standard contractual clauses.

10. Children's privacy

404tools.dev is not directed to children, and we do not knowingly collect personal information from anyone below the age required by applicable law to use the service independently.

11. Policy updates

We may update this policy to reflect changes to the service, our sub-processors or legal requirements. Material updates will be reflected in the effective date on this page and, where appropriate, notified by email.

12. Contact

Questions about this page can be sent to support@404tools.dev. For anything relating to a specific charge, include the order or transaction reference from your Paddle receipt so we can find it quickly.