[{"data":1,"prerenderedAt":214},["ShallowReactive",2],{"docs-navigation":3,"doc-\u002Fdocs\u002Fprivacy-and-security":60},[4,8,12,16,20,24,28,32,36,40,44,48,52,56],{"path":5,"title":6,"description":7},"\u002Fdocs\u002Fquickstart","Quickstart","Read both sides of an INE from your backend and receive structured JSON.",{"path":9,"title":10,"description":11},"\u002Fdocs\u002Fauthentication","Authentication","Keep company API keys on the server and separate them from dashboard access.",{"path":13,"title":14,"description":15},"\u002Fdocs\u002Fcreate-reading","Create a reading","Submit one front and back pair with a stable idempotency key.",{"path":17,"title":18,"description":19},"\u002Fdocs\u002Fretrieve-result","Retrieve a result","Read an existing job without repeating extraction or consuming another unit.",{"path":21,"title":22,"description":23},"\u002Fdocs\u002Fresponse-fields","Response fields","Choose the standard or extended response and use literal fields with review warnings.",{"path":25,"title":26,"description":27},"\u002Fdocs\u002Ferrors-and-retries","Errors and retries","Recover from errors without accidentally creating another charged reading.",{"path":29,"title":30,"description":31},"\u002Fdocs\u002Flimits-and-billing","Limits and billing","Plan allowances, shared admission limits and how reading units are counted.",{"path":33,"title":34,"description":35},"\u002Fdocs\u002Fprivacy-and-security","Privacy and security","Understand result retention, access controls and your backend's responsibilities.",{"path":37,"title":38,"description":39},"\u002Fdocs\u002Fexamples","Integration examples","Copyable server-side Node.js, Python and cURL examples with one POST per attempt.",{"path":41,"title":42,"description":43},"\u002Fdocs\u002Fdashboard","Dashboard usage","View your company's quota and request counts without exposing OCR data.",{"path":45,"title":46,"description":47},"\u002Fdocs\u002Fextended-reading","Extended extraction","Opt in to printed fields, separated address components, provenance and review checks.",{"path":49,"title":50,"description":51},"\u002Fdocs\u002Fwebhooks","Completion webhooks","Receive signed completion events without exposing OCR data in callbacks.",{"path":53,"title":54,"description":55},"\u002Fdocs\u002Fevaluation","Evaluation and limitations","Measured illustration results, remaining errors, and the limits of the extended profile.",{"path":57,"title":58,"description":59},"\u002Fdocs\u002Faddress-parts","Address parts","Use separate address inputs while retaining literal OCR and exact text sources.",{"id":61,"title":34,"body":62,"description":35,"extension":208,"meta":209,"navigation":210,"path":33,"seo":211,"stem":212,"__hash__":213},"docs\u002Fdocs\u002F08.privacy-and-security.md",{"type":63,"value":64,"toc":200},"minimark",[65,69,74,77,80,84,144,152,159,163,185,189,192],[66,67,68],"p",{},"INE images and extracted values can contain sensitive personal data. Submit documents only when your organization is authorized to process them, and limit access in your own application to the people and workflows that need it.",[70,71,73],"h2",{"id":72},"processing-and-storage","Processing and storage",[66,75,76],{},"The current extraction service processes images using Cloudflare Workers, Images and Workers AI. The application does not persist uploaded photographs or generated crops. That describes application storage; it is not a claim that data never leaves your server or that all infrastructure processing occurs in Mexico.",[66,78,79],{},"Results are encrypted before storage using AES-256-GCM and are bound to the owning company and request. The API key is authenticated using its stored hash. These controls do not replace secure handling of credentials and results in your own system.",[70,81,83],{"id":82},"retention","Retention",[85,86,87,100],"table",{},[88,89,90],"thead",{},[91,92,93,97],"tr",{},[94,95,96],"th",{},"Data",[94,98,99],{},"Current handling",[101,102,103,112,120,128,136],"tbody",{},[91,104,105,109],{},[106,107,108],"td",{},"Photographs and crops",[106,110,111],{},"Processed for the request; not persisted by the application.",[91,113,114,117],{},[106,115,116],{},"Extracted result",[106,118,119],{},"Encrypted storage, accessible for 23 hours from reservation.",[91,121,122,125],{},[106,123,124],{},"Expired result ciphertext",[106,126,127],{},"Cleared from the active table by the next successful hourly cleanup.",[91,129,130,133],{},[106,131,132],{},"Job metadata",[106,134,135],{},"Retained for quota and idempotency.",[91,137,138,141],{},[106,139,140],{},"Operational metrics",[106,142,143],{},"Durations, outcome and usage; removed from the active metrics table after seven days by scheduled cleanup.",[66,145,146,147,151],{},"Expiry is an access deadline, not a claim of immediate physical erasure. Database recovery history and backups can retain earlier encrypted versions. Cleanup depends on its scheduled execution. Save needed results in your own system before ",[148,149,150],"code",{},"expires_at",", with retention rules appropriate to your application.",[66,153,154,155,158],{},"The application's metrics exclude photographs, extracted text, API keys and client\u002Fjob identifiers. Public API errors omit raw provider diagnostics. API responses use ",[148,156,157],{},"Cache-Control: no-store",". These safeguards do not prevent your reverse proxy, browser, terminal or application from logging data if you configure it to do so.",[70,160,162],{"id":161},"integration-practices","Integration practices",[164,165,166,170,173,176,179,182],"ul",{},[167,168,169],"li",{},"Keep the API key on your server. The private dashboard code is a separate credential.",[167,171,172],{},"Use HTTPS and keep certificate verification enabled.",[167,174,175],{},"Do not follow redirects with credentials or send a key to an unvalidated polling URL.",[167,177,178],{},"Avoid logging image uploads or full OCR responses. Use request identifiers, status codes and error codes for support.",[167,180,181],{},"Apply access controls and retention limits to any result you save.",[167,183,184],{},"Review missing, conflicting and unusual values before using them for consequential decisions.",[70,186,188],{"id":187},"scope-of-the-service","Scope of the service",[66,190,191],{},"OCR does not establish authenticity, liveness, identity ownership or status in an INE registry. The service is not a substitute for identity verification. A successful HTTP response, a plausible CURP or a readable MRZ is not independent proof that the credential is valid.",[66,193,194,195,199],{},"The ",[196,197,198],"a",{"href":41},"usage dashboard"," shows company usage metadata. It does not display photographs, extracted identity fields or the OCR API key.",{"title":201,"searchDepth":202,"depth":202,"links":203},"",2,[204,205,206,207],{"id":72,"depth":202,"text":73},{"id":82,"depth":202,"text":83},{"id":161,"depth":202,"text":162},{"id":187,"depth":202,"text":188},"md",{},{"title":34},{"title":34,"description":35},"docs\u002F08.privacy-and-security","jHi2r9T9P1nxToteaQ6GIiLjGg4AnKs-UgPx-XLcRh0",1790658068795]