Privacy Policy
In short: scanning happens on your device; your history and codes stay on your devices and, if sync is on, in your private iCloud. The free version shows ads from Google, Unity and other advertising companies working through them; they receive technical data such as your IP address and, only if you allow it, your device’s advertising identifier. Statistics and crash reports go to our own servers in the European Union and are never sold. If you use editable links or publish a code as a web page, we store what is needed to run them — and a published page can be seen by anyone who has its link.
1. Who we are
Scan QR is developed by Ivan Kuvshinov, an individual developer based in Portugal (“we”, “us”). Ivan Kuvshinov is the data controller for the processing described in this policy, except where a third party — such as an advertising company, Apple, Google or an app store — acts as an independent controller. For any privacy question write to support@qrcodeapp.org.
This policy covers all versions of the app. A particular version may not use everything described here — for example, it may have no ads, purchases or notifications.
2. Data on your device and in your iCloud
Scanning happens on your device: the camera image and the pictures you choose are analysed there and are never sent to us. Your scan history, the codes you create and your settings are stored on your device. On Apple devices they may also be synced through your private iCloud, which Apple operates and we cannot access; you can turn the sync off in the app’s settings.
The app asks only for the permissions it needs and uses the system screens to choose photos and contacts, so it receives only what you choose. Deleting the app removes its data from the device; data in iCloud can be deleted in your iCloud settings. Keys that the operating system keeps in its secure storage — the keychain on Apple devices, which may sync them through your iCloud Keychain — remain after the app is deleted, until you delete them in the app or remove them from your keychain; other apps cannot read them.
3. Editable links
An editable code points to a short link on our server that forwards to an address you choose. To run it we store the link, its destination and earlier destinations, the title you give it, dates, its status and the public part of a key that proves the link is yours; the private part stays on your devices.
When someone scans the code, our server forwards them to the destination and counts scans by day and country. The country is derived from the IP address, which is not stored with the counts, and we do not identify or track the people who scan. We check destinations against public lists of dangerous websites — without sending the addresses to anyone — and show a warning instead of forwarding to a dangerous one.
4. Sharing a code as a web page
A simple shared link carries the content of the code in the part of the address that stays in the browser and is not sent to our server; anyone who has the link can read it. When you publish a page, the app uploads the image of the code and the details shown on the page to our server; anyone who has the link can open the page and see them. When the page expires or you unpublish it, we delete its content and keep only a short record that the page existed.
5. Notifications
If you allow notifications, the app sends them to tell you about events in the app. To deliver them we store your device’s push token and your notification settings. Notifications are delivered through the push services of Apple and Google or of your browser, so the token and the text of a notification pass through them. You can switch notifications off at any time in the app or in your device settings.
6. Purchases
Paid features — one-time purchases or subscriptions — are sold and billed by Apple (App Store) or Google (Google Play). We never receive your payment details. To give you what you bought, the app or our server checks the purchase with the store, and we store its status, the product, the dates and the store’s transaction identifier. The stores also notify our server when a subscription is renewed, cancelled or refunded.
7. Advertising
The free version of the app shows ads. If you have paid to remove them, you see none.
- Who provides the ads. Ads are provided through the advertising platforms of Google and Unity and by other advertising companies working through them — advertising networks, exchanges and bidders and the advertisers they represent. The current lists are published by Google (mediation partners, ad technology providers) and Unity (advertising networks).
- What they receive. Depending on your choices: your device’s advertising identifier (on Apple devices — only if you allow tracking) and other identifiers of your device or installation; your IP address and the approximate location derived from it; technical information about your device and the app; the ads you are shown and how you interact with them; and your consent choices. In a browser they may also use cookies and similar technologies. With your consent, they may combine this with information collected in other apps and on websites.
- What they use it for. To select, show and measure ads, to prevent fraud, to report to advertisers and improve their products and — with your consent — to personalise ads. These companies are independent controllers of the data they receive and process it under their own privacy policies.
- Your choices. Where the law requires it, the app asks for your choices before personalised ads are shown: through the tracking permission request on Apple devices and through a consent form that lists the advertising companies and their purposes. Where the law allows, some of these companies rely on their legitimate interests; you can object in the same form. If you do not consent, you still see ads, but they are not personalised. The app works the same whatever you answer, and you can change your choices in the app’s settings or in your device settings.
- United States. Under the laws of some US states, making data available to advertising companies for personalised advertising may count as “selling” or “sharing” personal data. You can opt out by declining tracking, by deleting or resetting your device’s advertising identifier and, where available, in the app’s settings.
Privacy policies: Google (and how Google uses data from apps that use its services); Unity. Each of the other advertising companies has its own privacy policy.
8. Usage statistics, crash reports and settings from our servers
To understand how the app is used and to fix problems, the app sends to our own servers:
- Usage statistics — events that describe what happens in the app, for example that a feature was used. They never contain what you scan or create. If you allow statistics, each event carries a random identifier of your installation or account and technical information such as the app version, the type and model of the device, the operating system and the language. If you do not, then in the European Economic Area, the United Kingdom and Switzerland — and wherever the app cannot tell the region — the app sends no events at all; elsewhere it sends only counters without an identifier, which cannot be linked to one device for longer than a day. Our server derives an approximate location from the IP address of the request and does not store the IP address with the statistics. Statistics are not used for advertising, not shared with advertisers and not sold.
- Crash reports — technical details of an error, information about the device and the app, the app’s recent actions before the error and the IP address the report was sent from; if you allowed statistics, also the identifier of your installation. We use them only to find and fix errors and to protect our servers from abuse. You can switch crash reports off in the app’s settings.
- Requests for settings — the app asks our server which features and settings apply to it. The request includes technical information and an identifier: that of your account if you have one, that of your installation if you allowed statistics, and otherwise a one-time identifier made for that request. With a lasting identifier you consistently see the same variant of a feature.
You can change your choice about statistics at any time in the app’s settings.
9. Earlier versions of the app
Devices that cannot run the current version keep version 1.x, which works differently from what is described in section 8: instead of our own servers it uses Google Firebase — statistics, crash reports and settings operated by Google, which may receive usage and diagnostic data, identifiers of the device and the installation and your IP address; see Google’s privacy information for Firebase. Its free version shows ads as described in section 7.
10. This website, support and email
The website uses no cookies or advertising and loads nothing from third-party domains. Like any web server, our servers process the IP address, the time and the requested address of every request — from the website, from the app and from links to our services — and keep technical access logs for security and troubleshooting.
Website statistics. To learn which pages of the website are read and which links are used, and to improve the website, we count visits on our own statistics server in the European Union. For each page view, click on a link to another website (for example, to an app store) and sent form — not its content — the statistics record the page and the website you came from, technical information about your browser and device and an approximate location (country and city) derived from your IP address. The statistics use no cookies, store nothing on your device and do not contain your IP address: to tell visits apart, our server combines your IP address and browser details with a secret value that changes every day, so the resulting identifier cannot link your visits for longer than about a day or across our websites. The statistics are not used for advertising, not combined with other data and not shared with anyone. If your browser sends a “Do Not Track” or Global Privacy Control signal, your visits are not counted; you can also object by writing to us.
If you write to us — by email or through the form on this website — we receive what you send: your name, email address and message and any details you add, such as your device and the app version. We use the IP address a form message is sent from only to protect the form from abuse; it is not included in the message. We use all this only to reply to you and to fix the problem. We also send email that the service needs, for example to reset a password.
11. Where your data is stored and who receives it
- Our servers. The data we collect is processed on servers we operate ourselves in the European Union, rented from a hosting provider that acts only as our processor. The software we use for statistics, crash reports, settings and our services runs on these servers, so the companies that develop it receive none of your data.
- Third parties that act as independent controllers: the advertising companies described in section 7; Apple and Google when you use their services with the app — for example sign-in, purchases, notifications or sync; and the app stores, which may process data about downloads, purchases and diagnostics under their own privacy policies.
- Protection. Companies that process data on our behalf do so under a contract and only on our instructions. We share data only with third parties that provide the same or equal protection of your data as described in this policy and required by law.
- We do not sell personal data for money; how advertising works is described in section 7.
- Legal bases. We process data to provide the app and its services to you under the Terms of Use (performance of a contract) — for example your account, the content you create or share with the app, and your purchases. Notifications, statistics with an identifier and personalised advertising rely on your consent, which you can withdraw at any time. Counters without an identifier, website statistics, crash reports, settings from our servers, server logs, protection from abuse and replies to your requests rely on our legitimate interests in keeping the app and our servers working, fair and secure; you can object by writing to us. Where the law requires it, we process data to comply with a legal obligation. You are not required by law or by contract to give us personal data; but a feature that needs certain data — for example an account, shared content or a purchase — does not work without it.
12. How long we keep data
- Editable links — until you delete them; scan counts — up to 13 months.
- Published pages — for the period you choose or until you unpublish them.
- Statistics — up to 13 months; crash reports — up to 90 days; server logs and data used to prevent abuse — up to 30 days.
- Messages you send to support — for as long as needed to handle your request, and no longer than two years.
- Backups — up to five weeks. Data you delete disappears from backups when they expire.
13. Children
The app is intended for people aged 16 and over and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to us and we will delete it.
14. International transfers
Our own servers and backups are in the European Union. Advertising companies, Apple, Google, the app stores and the other companies named in this policy may process data outside the European Economic Area — including in the United States, the United Kingdom, Israel, China, Singapore, Japan, Taiwan and Russia, not all of which the European Commission considers to provide an adequate level of data protection — relying on safeguards such as the European Commission’s Standard Contractual Clauses or the EU–US Data Privacy Framework; see their privacy policies. You can ask us which safeguards apply to your data.
15. Your rights
If you are in the European Economic Area, the United Kingdom or another jurisdiction with similar laws, you have the right to access, correct or delete your personal data, to object to or restrict its processing, to data portability, and to withdraw consent at any time. To exercise these rights, use the app’s settings or write to support@qrcodeapp.org; we reply within one month. You can also lodge a complaint with your data protection authority (in Portugal — the Comissão Nacional de Proteção de Dados, CNPD).
Where you have no account with us, statistics and crash reports are linked only to a random identifier of your installation, so we cannot find yours unless you give us that identifier. For data held by advertising companies, use their controls and the consent settings in the app.
We do not make decisions about you by automated means that have legal or similarly significant effects.
16. Security
Connections to our servers are encrypted. Access to the servers is restricted to the developer.
17. Changes
If this policy changes, the new version will be published on this page with a new effective date. Material changes will also be announced in the app or in its release notes.
18. Contact
The controller responsible for your data is:
Ivan Kuvshinov
Rua do Casalinho 186
Avelar, Leiria 3240-352
Portugal
support@qrcodeapp.org