Privacy Policy
QR & Barcode Studio ("the Service", "we") is built so that your codes, scans and photos stay on your device. This policy explains the little data we do process, why, and the choices you have.
Effective date: October 8, 2026
1. Summary
- QR codes and barcodes are generated and decoded on your device. Camera frames, images, contacts and Wi-Fi passwords are never uploaded.
- Your history, templates and settings are stored locally in your browser or app and can be deleted at any time.
- We do not use advertising trackers, analytics cookies or third-party profiling.
- We only receive data you choose to send us (feedback) and minimal technical data needed to run and secure the Service.
2. Data processed on your device only
The following never leaves your device unless you explicitly share or export it yourself: the content of codes you create or scan, camera video, images and screenshots you scan, logos you upload, CSV files used for batch printing, history, notes, tags, templates and settings.
This data is stored with your browser's IndexedDB/localStorage or the Android app's private storage. Uninstalling the app or clearing site data removes it. You can also use Settings → Delete all data, or set an automatic retention period.
3. Data we receive
- Feedback (optional): the category, message, app version, language and platform you submit, and an email address only if you enter one. A keyed hash of your IP address is stored to prevent abuse; we never store the raw IP. Retained for up to 12 months.
- Security reports: when your browser blocks a disallowed script on our site it may send a Content-Security-Policy report containing page and blocked addresses (without query strings). Retained for 30 days.
- Service logs: our hosting providers process standard request data (IP address, time, requested URL, user agent) to deliver pages and protect against attacks. We do not combine these logs with other data.
- Usage statistics: to show total visits, people online and downloads in the footer, the app sends a random per-tab session ID, the platform (web, PWA or Android) and the type of file saved. No cookies or IP addresses are stored; session IDs are deleted within 24 hours and only totals are kept.
- Language cookie: only if you choose a language yourself, its code (e.g. "en") is stored in a qrb_lang cookie so the home page opens in that language next time. It is not used for tracking or advertising and is removed when you reset settings.
4. Purposes and legal bases
- Providing the Service and keeping it secure (legitimate interests / performance of a contract).
- Answering and improving the Service based on your feedback (consent, which you can withdraw at any time).
- Complying with legal obligations where applicable.
5. Camera and other permissions
Camera access is requested only when you start the scanner and is used solely to decode codes in real time. Video is not recorded or transmitted. If you deny access, you can still scan images or enter codes manually.
The Android app requests the Camera permission for scanning, Internet access for optional lookups and feedback, and Wi-Fi state access so it can offer to save a scanned Wi-Fi network through the system's confirmation dialog. It does not request contacts or location permissions; files you save are written through the system's download and share features.
6. Service providers and international transfers
We use Cloudflare (website hosting and content delivery) and Railway (API hosting and database for feedback). They process data on our behalf under their data-processing terms and may operate servers outside your country, protected by appropriate safeguards such as standard contractual clauses. We do not sell or rent personal data.
7. Links opened from codes
When you choose to open a link, call a number or send a message from a scanned code, you leave the Service. The destination's own privacy practices apply. We show the destination and safety warnings before you continue, but we cannot guarantee that third-party sites are safe.
8. Optional third-party lookups
Product lookups are user-initiated. Lookup buttons (for example Google or Open Library) simply open the website you choose in your browser, where that site's own policy applies; the app sends nothing itself.
The in-app Open Food Facts summary sends only the barcode number to Open Food Facts (openfoodfacts.org) and only after you agree, either once or always. You can withdraw this permission in Settings at any time. Encrypted backup files you create stay wherever you save them; we never receive them or your password.
9. Your rights
Depending on where you live (for example under the EU/UK GDPR, Korea's Personal Information Protection Act, Japan's APPI, Brazil's LGPD or California's CCPA/CPRA), you may have the right to access, correct, delete or port your data, to restrict or object to processing, and to withdraw consent. Because most data stays on your device, you can exercise many of these rights directly in the app. For feedback data, email us at [email protected]. You may also lodge a complaint with your local data protection authority.
10. Children
The Service is a general-audience utility and is not directed at children under 14 (or the minimum age in your country). We do not knowingly collect personal data from children. If you believe a child has sent us personal data, contact us and we will delete it.
11. Security
We use HTTPS everywhere, strict Content-Security-Policy and other security headers, input validation, rate limiting and minimal data retention. No method of transmission or storage is completely secure, but we work to protect the data we hold.
12. Changes to this policy
We may update this policy as the Service evolves. We will change the effective date above and, for material changes, notify you in the app. The current version is always available at this address in every supported language.
13. Contact
Privacy officer / data controller contact: [email protected]