Privacy Policy
Last updated: August 28, 2026
This Privacy Policy explains how Passport OCR collects, uses, processes, stores, and protects information when authorized users access or use the service.
Passport OCR is a restricted-access document-processing application operated under liuhailin.net.
For privacy-related questions, requests, or concerns, contact:
1. Information We Process
Passport OCR may process the following categories of information.
1.1 Account and Authentication Information
Authentication is performed using Google sign-in through Cloudflare Access.
For authentication and access-control purposes, the service may process information associated with your Google account, including:
- your email address;
- authentication status;
- session information;
- access-control decisions;
- related authentication metadata.
Passport OCR does not request access to your Gmail messages, Google Drive files, contacts, calendars, or other unrelated Google services.
1.2 Uploaded Passport Documents
When using Passport OCR, you may upload passport scans, images, or PDF documents.
These documents may contain personal information including, but not limited to:
- full name;
- date and place of birth;
- nationality;
- sex;
- passport number;
- passport book number;
- issuing authority;
- date of issue;
- date of expiry;
- machine-readable zone (MRZ) information;
- photograph;
- signature information;
- other information visible on the passport.
Users should only upload documents that they are authorized to process.
1.3 Extracted Information
Passport OCR extracts structured information from uploaded passport documents.
This may include:
- identity information;
- passport metadata;
- MRZ data;
- validation results;
- normalized document fields.
Extracted structured fields and OCR results are used during processing but are not persistently stored as separate application records.
1.4 Generated Documents
Passport OCR may generate documents such as DOCX or PDF files as part of document-processing or translation workflows.
These generated files are stored temporarily so that users can access or download them.
2. How We Use Information
Information processed by Passport OCR is used only for purposes related to providing, securing, and maintaining the service, including:
- authenticating users;
- enforcing the authorized-user allowlist;
- processing uploaded passport documents;
- extracting structured information;
- validating passport and MRZ information;
- supporting translation workflows;
- generating requested output documents;
- maintaining service security;
- preventing abuse;
- diagnosing technical failures.
Passport OCR does not sell personal information.
Passport OCR does not use passport information for advertising or marketing.
Passport OCR does not use uploaded passport documents to train its own machine-learning models.
3. Third-Party Processing
Passport OCR relies on third-party service providers for authentication, network security, traffic routing, and AI inference.
Information transmitted to these providers may be subject to their own:
- privacy policies;
- terms of service;
- data-processing terms;
- retention policies;
- product settings;
- security practices;
- legal obligations.
Passport OCR does not control the internal retention or secondary-processing practices of these third-party providers.
3.1 Alibaba Cloud Model Studio
Uploaded passport images are transmitted to Alibaba Cloud Model Studio (DashScope) for multimodal AI inference using Qwen models.
The transmitted data may include the complete uploaded passport image and other information necessary to perform the requested recognition and extraction.
Alibaba Cloud may retain, log, analyze, or otherwise process request data according to its applicable:
- privacy policies;
- service terms;
- data-processing terms;
- product configuration;
- security practices;
- legal obligations.
Depending on the applicable Alibaba Cloud terms, configuration, and service policies, transmitted data may also potentially be used for purposes such as:
- operating the service;
- security and abuse prevention;
- diagnostics;
- service improvement;
- model development;
- model training or related machine-learning improvement activities.
Passport OCR does not independently control these practices.
Users should therefore only upload documents when they are authorized to have the information processed by an external cloud AI provider.
3.2 Google
Google is used as an identity provider for user authentication.
Passport OCR uses Google sign-in only to establish user identity for access-control purposes.
Passport OCR does not request access to unrelated Google services such as Gmail, Google Drive, Contacts, or Calendar.
Information processed by Google during authentication may be retained, logged, analyzed, or otherwise processed by Google according to Google’s own privacy policies, service terms, and legal obligations.
3.3 Cloudflare
Passport OCR uses Cloudflare services, including Cloudflare Access and related network and security infrastructure, for:
- authentication;
- authorization;
- secure routing;
- application protection;
- access-control enforcement;
- security monitoring.
Cloudflare may process information including:
- email addresses;
- authentication identifiers;
- IP addresses;
- timestamps;
- request metadata;
- connection metadata;
- access-control decisions;
- session information;
- security and authentication events.
Cloudflare may retain or process this information according to its applicable service configuration, privacy policies, contractual terms, security practices, and legal obligations.
Such processing may include purposes such as:
- service operation;
- security;
- abuse detection;
- diagnostics;
- analytics;
- service improvement.
Passport OCR does not independently control Cloudflare’s retention periods or internal processing practices.
4. Storage and Retention
4.1 Uploaded Passport Documents
Uploaded passport images and PDF documents are stored temporarily in the application’s cache while they are required for processing and user access.
The application performs an automated cache cleanup once per hour.
During each cleanup cycle, cached files that are more than one hour old are deleted.
As a result, uploaded passport documents are normally retained for approximately one to two hours before automatic deletion.
Uploaded passport documents are not intended to be retained as a long-term document archive.
4.2 Extracted Structured Data
Structured OCR results and extracted passport fields are not persistently stored as independent application records.
They may exist temporarily:
- in application memory;
- during an active session;
- during document generation or validation.
They are not intentionally written to persistent application storage as a separate long-term dataset.
4.3 Generated DOCX and PDF Files
Generated DOCX, PDF, or similar output files are stored temporarily in the application cache so that users can access or download them.
The same automated cleanup mechanism applies to generated files:
- cleanup runs once per hour;
- files older than one hour are removed.
Generated files are therefore normally retained for approximately one to two hours before automatic deletion.
4.4 Technical and Security Logs
Application components and infrastructure providers may maintain limited technical or security logs for purposes such as:
- authentication;
- security;
- abuse prevention;
- troubleshooting;
- service operation.
These logs are not intended to contain complete passport-document contents.
However, third-party infrastructure providers may retain metadata or other information according to their own policies and configurations.
4.5 Third-Party Retention
The retention periods described above apply only to data stored directly by Passport OCR.
Copies of information transmitted to third-party providers, including:
- Alibaba Cloud;
- Google;
- Cloudflare;
may be retained for different periods according to those providers’ own policies, service terms, configuration, and legal obligations.
Deletion from Passport OCR’s own temporary storage does not necessarily result in simultaneous deletion of copies or records held by third-party providers.
5. Data Security
Passport OCR uses technical and organizational measures intended to reduce the risk of unauthorized access to personal information.
These measures include:
- HTTPS encryption for network communications;
- Google-based authentication;
- Cloudflare Access authorization;
- an explicit authorized-user allowlist;
- restricted access to the application backend;
- temporary rather than long-term storage of uploaded documents;
- automatic cache cleanup;
- separation of authentication from document processing.
However, no internet-connected service, cloud platform, or method of data transmission can guarantee absolute security.
Users should consider the sensitivity of passport information before uploading documents.
6. User Responsibilities
Passport documents contain sensitive personal information.
By using Passport OCR, you confirm that you have an appropriate legal basis, authorization, or legitimate reason to process the documents you upload.
You should not upload passport documents belonging to another person unless you are authorized to process that person’s information.
You are responsible for ensuring that your use of Passport OCR complies with applicable laws, regulations, contractual obligations, and institutional policies.
7. Automated Processing and Accuracy
Passport OCR uses automated recognition, validation, and machine-learning systems.
Extracted information may contain errors due to factors including:
- image quality;
- scan quality;
- document condition;
- unusual layouts;
- model limitations;
- OCR errors;
- incomplete or ambiguous document content.
Users must verify extracted and generated information against the original passport before relying on it.
Passport OCR should not be treated as an authoritative source of identity information.
8. Access, Deletion, and Privacy Requests
Uploaded passport documents and generated files are designed to be deleted automatically according to the temporary retention process described above.
If you have questions about information associated with your use of Passport OCR, or wish to request access to or deletion of information that may still be retained, contact:
When contacting us, provide only the information necessary to identify the relevant request.
Do not send additional passport scans, passport numbers, or other sensitive identity information by email unless specifically requested and necessary.
9. Children’s Privacy
Passport OCR is not intended for independent use by children.
Users processing documents relating to minors are responsible for ensuring that they have appropriate authority and a lawful basis to process those documents.
10. International Processing
Passport OCR relies on cloud infrastructure and external service providers.
As a result, information may be transmitted to or processed in jurisdictions different from the user’s location.
This may include processing by third-party providers such as Alibaba Cloud, Google, and Cloudflare.
The privacy, data-protection, and legal requirements applicable to such processing may differ between jurisdictions.
11. Changes to This Privacy Policy
This Privacy Policy may be updated when:
- the service changes;
- processing practices change;
- infrastructure providers change;
- retention practices change;
- legal or regulatory requirements change.
The Last updated date at the top of this page indicates the most recent revision.
The current published version of this Privacy Policy applies to use of the service.
12. Contact
For privacy questions, data-access requests, deletion requests, or other concerns relating to Passport OCR, contact: