Privacy & Data Protection
Privacy by design: your files stay on your machine.
pixtotext is designed from its inception to protect your digital privacy. We do not harvest your text, store your screenshots, or transmit your images to cloud servers.
1. Core Principles
Local-first data processing.
The primary purpose of pixtotext is to convert images into text locally. Unlike web-based OCR services that upload your files to remote cloud endpoints, pixtotext runs all standard recognition models (Native Windows Media OCR, Apple Vision OCR, PaddleOCR, lightweight ocrs, and Tesseract) directly on your device CPU or GPU.
- Zero telemetry: The desktop app does not collect user behavior analytics, feature usage logs, or diagnostic dumps without explicit user consent.
- No mandatory account: You do not need to register an account, log in, or provide an email address to use the desktop software.
- Local storage: Saved OCR history and converted files remain on your local filesystem in your user profile directory. You can clear or delete your history records at any time.
2. Optional Cloud OCR
User-configured third-party providers.
pixtotext provides an optional setting for cloud OCR providers. This feature is disabled by default. It only activates if you explicitly choose to configure your own API credentials for a third-party vision provider.
When enabled:
- Direct transmission: Image payloads are transmitted directly between your local machine and your chosen provider using encrypted HTTPS.
- Secure credential vault: Your API keys are stored locally in your operating system's secure credential vault or app configuration.
- Zero proxying: MerginIT e.U. never receives, proxies, or inspects your API traffic or the processed images.
3. Website Data Collection
How pixtotext.merginit.com operates.
Our marketing website (pixtotext.merginit.com) is a static website hosted on high-performance edge infrastructure provided by Cloudflare:
- No tracking cookies: We do not use marketing trackers, analytics cookies, or cross-site tracking beacons.
- Server log files: Standard HTTP request data (such as IP address, user agent, requested resource, timestamp, and HTTP status code) are processed by Cloudflare at the network edge solely for security, DDoS mitigation, and server performance. These logs are not combined with personal profiles.
4. Legal Information & GDPR
Your rights under European data protection law.
Under the EU General Data Protection Regulation (GDPR), you have fundamental rights concerning any personal data that may be processed:
- Right of access (Article 15 GDPR): You may request confirmation as to whether personal data concerning you is processed.
- Right to rectification (Article 16 GDPR): You have the right to request the rectification of incorrect personal data.
- Right to erasure (Article 17 GDPR): You have the right to request deletion of your personal data.
- Right to lodge a complaint: If you believe your data has been handled in violation of applicable laws, you may lodge a complaint with the competent supervisory authority: Österreichische Datenschutzbehörde (Austrian Data Protection Authority), Barichgasse 40-42, 1030 Vienna, Austria (www.dsb.gv.at).
5. Data Controller
Responsible entity contact.
For inquiries regarding privacy and data protection, please contact the responsible data controller:
| Entity | MerginIT e.U. |
|---|---|
| Proprietor | Jonas Fröller |
| Address | Nußböckstraße 92, 4060 Leonding, Austria |
| jonas@merginit.com | |
| Phone | +43 664 3279885 |