OCR Usage Policy
What text extraction from your identity document is for, where it runs, what it is never allowed to decide, and what is kept afterwards.
العربية1. Current state
As at this version, no text extraction is performed. Identity fields are entered by hand and confirmed by you.
The approved provider is Google Cloud Vision. It is recorded in the Subprocessor Register as approved and not yet in use. This policy governs it from the version that turns it on, and turning it on requires a new version of this policy, the Privacy Policy and the Worker Verification Policy, together with renewed acceptance.
The rest of this policy describes how extraction will operate. It is published now so that the rules are settled before the capability exists, rather than written to fit whatever gets built.
2. What it is for
One purpose: reading the text printed on your National ID so it can be pre-filled into the form you are about to complete.
It saves you typing an identity number from a photograph. That is the entire benefit, and it is the entire justification for processing the document this way.
3. Where it runs
Server-side only. Your document is sent from Warsha's server to the provider, never from your phone.
Provider credentials exist only on the server and are never present in the application, so a copy of the Warsha app cannot be taken apart to obtain them.
Only the extracted fields come back to your device. The provider's raw response never reaches it.
In mock mode — used for development and demonstration — no external call is made at all.
4. You confirm everything
Extracted values are candidates. They are shown to you, you check them against the document in your hand, and you correct anything wrong.
Nothing is treated as a fact about you until you confirm it. An unconfirmed extraction has no effect on your account.
Confidence scores are internal. You will never be shown one, a customer will never be shown one, and no decision is ever made on one.
5. What extraction may never decide
Extraction never determines whether a document is genuine, whether it is yours, whether it has been altered, or whether you are eligible to work. Those are human decisions and the Worker Verification Policy sets out how they are made.
A poor-quality scan produces a request to retake the photograph, never a rejection of you.
Warsha does not extract, infer or store a gender or sex marker from an identity document. There is no product purpose for it that has been documented and approved, and processing a special category of data because it happens to be printed on a card is not a reason.
The Egyptian National ID encodes a governorate of issue. Warsha does not treat that as your current address, your residence, or your service area. Where you live and where you work are things you tell Warsha, not things it deduces from a number.
6. What is kept
After extraction, Warsha keeps:
- The extracted field values, as candidates, until you confirm your fields.
- A confidence value per field, internal only.
- A hash of the document, so it can be shown later that the document reviewed is the document submitted.
- The provider name and version.
- The timestamp.
7. What is not kept
The provider's raw response is not retained. It is a second copy of your identity document in another form, and keeping it would double the exposure for no benefit that the extracted fields do not already give.
Your document is not retained by the provider beyond the call, and a provider that requires otherwise is not eligible.
Your document is never used to train a model. See the AI Usage Policy.
8. Changes
Introducing extraction, changing provider, changing what is extracted, or changing what is retained is a material change: a new version, a change summary, an updated Subprocessor Register, and renewed acceptance before your documents are processed under it.