Privacy and security
Understand result retention, access controls and your backend's responsibilities.
INE images and extracted values can contain sensitive personal data. Submit documents only when your organization is authorized to process them, and limit access in your own application to the people and workflows that need it.
Processing and storage
The current extraction service processes images using Cloudflare Workers, Images and Workers AI. The application does not persist uploaded photographs or generated crops. That describes application storage; it is not a claim that data never leaves your server or that all infrastructure processing occurs in Mexico.
Results are encrypted before storage using AES-256-GCM and are bound to the owning company and request. The API key is authenticated using its stored hash. These controls do not replace secure handling of credentials and results in your own system.
Retention
| Data | Current handling |
|---|---|
| Photographs and crops | Processed for the request; not persisted by the application. |
| Extracted result | Encrypted storage, accessible for 23 hours from reservation. |
| Expired result ciphertext | Cleared from the active table by the next successful hourly cleanup. |
| Job metadata | Retained for quota and idempotency. |
| Operational metrics | Durations, outcome and usage; removed from the active metrics table after seven days by scheduled cleanup. |
Expiry is an access deadline, not a claim of immediate physical erasure. Database recovery history and backups can retain earlier encrypted versions. Cleanup depends on its scheduled execution. Save needed results in your own system before expires_at, with retention rules appropriate to your application.
The application's metrics exclude photographs, extracted text, API keys and client/job identifiers. Public API errors omit raw provider diagnostics. API responses use Cache-Control: no-store. These safeguards do not prevent your reverse proxy, browser, terminal or application from logging data if you configure it to do so.
Integration practices
- Keep the API key on your server. The private dashboard code is a separate credential.
- Use HTTPS and keep certificate verification enabled.
- Do not follow redirects with credentials or send a key to an unvalidated polling URL.
- Avoid logging image uploads or full OCR responses. Use request identifiers, status codes and error codes for support.
- Apply access controls and retention limits to any result you save.
- Review missing, conflicting and unusual values before using them for consequential decisions.
Scope of the service
OCR does not establish authenticity, liveness, identity ownership or status in an INE registry. The service is not a substitute for identity verification. A successful HTTP response, a plausible CURP or a readable MRZ is not independent proof that the credential is valid.
The usage dashboard shows company usage metadata. It does not display photographs, extracted identity fields or the OCR API key.