Terms of service
This is the operating agreement in force between you and SharpOCR. It is written to be read rather than to be impressive, and it is not legal advice — yours or ours.
In force from 2026-08-29 · we tell you before it changes · plain-language draft
1. Who you are contracting with
The service is operated by [registered legal entity name], registered in [country of incorporation] under company number [company registration number], VAT number [VAT identification number], at [registered postal address]. In these terms that entity is “we”, “us” and “SharpOCR”, and the person or organisation holding an account is “you”.
Reach us through the contact form or at [contact email address]. A message about a contract term is answered by a person, not a queue.
2. What the service does
You send PDF documents to an HTTP API. We extract the text, report a confidence score for every page, and run a set of arithmetic and checksum checks over the result to say whether the document reconciles with itself. You get typed JSON back. The API documentation describes every endpoint and every field, and it is part of these terms in the sense that it is what we have told you the service does.
We may change how the pipeline works internally — which engine reads a page, how a threshold is set — without telling you, because that is the product improving. We will not remove an endpoint, rename a response field or narrow a documented limit without notice; see section 13.
3. Your account and your keys
You need an account to use the API. Give us an address that reaches you: it is where a service notice goes, and it is the address we will act on if you ask us to delete something.
API keys are shown once, when they are issued. We store a hash of the key and its first twelve characters, so a key you have lost cannot be recovered by us — it can only be revoked and replaced. Anything done with a live key is treated as done by you, so keep them out of source control and issue one per environment. Revocation takes effect on the next request; tell us if a key has leaked and we will help, but revoking it yourself is faster than writing to us.
4. What you may send
Only documents you are entitled to have processed. That is the whole rule, and it carries the weight: you are responsible for having the right to send us the personal data in your invoices, contracts and forms, and for telling the people in them that you use a processor, if you are required to.
You may not use the service to:
- process content that is unlawful where you or we operate;
- attempt to reach another account's documents, jobs or keys;
- work around the size, page or allowance limits, including by splitting documents solely to defeat them;
- probe, load-test or scan the service without asking us first — ask, and the answer is usually yes with a time window.
5. Plans, pages and payment
Plans are billed monthly in advance and differ only by how many pages you may send in a calendar month. Prices are on the pricing page and exclude VAT, which is added where it is due and shown before you confirm.
A page is one page of one PDF, counted when it is parsed — not per API call and not per field. A twelve-page document is twelve pages whether you send it to the synchronous endpoint or the batch queue, and your running total for the month is on your dashboard.
If you pass your allowance we get in touch about moving you up a plan. We do not cut you off mid-month and tell you afterwards, because the first thing you would learn is that your invoice pipeline stopped on a Friday afternoon. That is a commitment about how we behave, not a promise that the allowance is imaginary: sustained use well beyond a plan is a conversation, and if it does not lead to one we may limit the account on notice.
Cancel any time from the dashboard, effective at the end of the period you have paid for. We do not refund part-months, and we do not make you call anyone to leave.
6. Limits
On every plan: PDF only, up to 25 MB and 50 pages per document. Each limit fails with a status code that names it rather than a generic rejection, and the documentation lists which. These limits can move up; if one moves down, section 13 applies.
7. Availability
There is no service level agreement, and we are not going to print an uptime percentage we have not measured over a meaningful window. What we will tell you is the architecture: one server in Germany, no CDN in front of it, TLS terminated on the box, and a health endpoint you are welcome to monitor yourself. Maintenance happens; where we can foresee it, we say so in advance.
If you need a signed availability commitment, write to us and say what you need. That is a conversation, not a checkbox on this page.
8. What the output is, and what it is not
This is the clause worth reading twice. The service returns a machine's
reading of a document. It is good, it reports its own confidence, and it
checks its arithmetic — and it is still a machine's reading. The
verified field means that a set of specific
checks ran and none of the definitive ones failed. It does not mean the
document is genuine, that the supplier exists, that the goods arrived, or
that the invoice should be paid.
Do not make our output the only control on a payment, a signature or a
filing. It is designed to sit in front of a human or a second system and
make the exceptions visible, and that is the use it is fit for. A
verified: null is not a pass — it means nothing
on that document was checkable — and a client that treats it as one has
made a decision we have documented against.
9. Your documents stay yours
You keep every right in the documents you send and in the text we extract from them. We claim no licence to them beyond what is needed to run the parse you asked for and to show you the result.
We do not train models on your documents. We do not train models at all — the pipeline is a PDF text layer, local OCR, and a hosted model for the pages neither can read. What that hosted provider retains, and for how long, is stated in full on the security page, including the part that does not flatter us.
10. Data protection
For the documents you send, you are the controller and we are the processor: we process them on your instructions, which are the API calls you make. For your account — your email address, your keys, your sign-in activity — we are the controller. The privacy notice sets out both in detail.
A data processing agreement under Article 28 GDPR is available; ask and we will send it. Every provider that touches a document, and every sub-processor of theirs that we know of, is named on the security page. We will tell you before that list changes, so that you have the chance to object.
11. Suspension and termination
We may suspend an account that is being used against section 4, that is not paid after a reminder, or that is doing something which threatens the service for everyone else. Where we can tell you first, we will; where we cannot, we tell you as soon as we have.
You may close your account at any time. Closing it erases your jobs and sessions along with the account — deliberately, and it is not reversible. Export anything you want to keep first.
12. Liability
Nothing here limits liability that cannot be limited by law: death or personal injury caused by negligence, fraud, or anything else the law of [governing-law country] puts beyond contract.
Subject to that, our total liability to you for all claims in any twelve month period is limited to the fees you paid us in that period, and we are not liable for indirect or consequential loss, lost profits, lost data where you held no copy, or a decision made on the basis of an extraction without the human or system check section 8 describes.
The service is provided as it is described on this site. We do not promise it is free of errors, and we do not promise a particular accuracy rate — you can see why on any page of this site: we do not publish accuracy percentages we have not measured.
13. Changes to these terms
We may change these terms. If a change materially affects you — a price rise, a narrower limit, a removed endpoint, a new sub-processor — we tell you by email at least 30 days before it takes effect, and you may cancel before it does. Anything else, such as a clarification or a corrected typo, takes effect when it is published, and the date at the top of this page changes with it.
14. Governing law
These terms are governed by the law of [governing-law country], and the courts of [competent courts / city] have exclusive jurisdiction. If you are a consumer, this does not take away the protection of the mandatory law of the country you live in.
15. The rest
If a clause here turns out to be unenforceable, the rest stays. Not enforcing something once does not mean giving it up. You may not transfer this agreement without asking us; we may transfer it to a successor of the business, and we would tell you if we did.
The bracketed fields above are unfilled. They are the entity name, registration and VAT numbers, postal address, contact address and governing law, and they are left blank on purpose: a company registration number invented to make a page look finished is a worse problem than a visibly incomplete one. Fill them from the incorporation documents before relying on this page.
A clause you cannot live with?
Tell us which one and why. Terms that nobody negotiates are terms nobody read.