Last updated: September 22, 2026
This policy explains how QR Code Scanner: Scan Barcodes (the “App”) handles information when you scan, create, save or share codes, use Dynamic QR and Insights, search images, or purchase Premium. Contact: dangthixuanhuongdn@gmail.com.
The App stores your local Library, scanned codes, Static QR codes, preferences and saved history on your device. Camera scanning and text recognition run on your device. Taking or selecting an image does not by itself upload it to our cloud service. You choose when to share or export content, open a link, search the web, or send an image to Google Lens. The destination app or website then handles the information you send under its own privacy policy.
Device backups and files you export may retain copies according to your Apple or chosen storage settings. In older App versions that offer product lookup, the scanned product barcode may be sent to Open Food Facts to retrieve product information.
The App uses Firebase Anonymous Authentication to create or restore a guest session automatically, without asking you to register with an email address or password. Firebase processes a guest identifier and authentication credentials to provide access to your cloud data.
When you create a Dynamic QR, Google Firebase stores its owner identifier, label, destination link, short link, design settings, any logo you select, placement grouping, and creation/update and status information. We also maintain usage counts and request identifiers to apply service limits and prevent duplicate requests. A Dynamic QR short link is shareable: anyone with it can open the destination while the link is active. Do not use it to protect confidential content.
Session credentials are stored in iOS Keychain. Reinstalling on the same device may restore your guest session and Dynamic QR codes. Recovery is not guaranteed after a device reset, Keychain erasure or a change of device. Uninstalling the App does not delete cloud QR data or necessarily remove Keychain credentials. Guest accounts are not automatically removed after 30 days.
When someone opens a Dynamic QR link, our service records aggregate open counts, time intervals and the most recent open time. It infers broad device, operating-system, browser and browser-language categories from request headers, including whether a request appears to be an automated bot or link preview. The original user-agent and language headers are not stored in these application statistics.
Insights uses these aggregates for daily charts, weekday/hour heatmaps, QR rankings, placement comparisons and observations. Time intervals are stored in UTC and displayed using the QR owner's device time zone. Counts can include repeat visits; they do not identify unique people. Automated-request filtering is an estimate and may not detect every bot.
Our QR Insights statistics do not store raw visitor IP addresses, precise locations or individual visitor profiles. Hosting providers may process IP addresses and other connection information in infrastructure and security logs. This is separate from the app-usage analytics described below.
Choosing “Search with Google Lens” uploads a compressed copy of your selected image to temporary Firebase storage and shares a temporary image URL with Google Lens. Camera metadata is removed from that copy. Anyone with the temporary URL can access it until it expires or is revoked. The URL expires after 15 minutes.
Closing the Lens view requests deletion of our copy. If deletion is interrupted or the device is offline, the App queues a retry; the server also cleans up expired images. Physical deletion can take longer than URL expiry. Deleting our copy does not delete information already fetched by Google or copies in browser caches/history. Google's handling of the image, search and connection information is governed by Google's privacy policy.
Apple processes purchases and restores. StoreKit 2 on your device determines Premium access. Our QR backend does not receive purchase proofs or validate subscriptions. Separately, the App synchronizes purchase/transaction information with RevenueCat for subscription reporting, and sends verified transaction and purchase-flow events to Firebase Analytics. These services may process app-instance or customer identifiers, product identifiers, transaction details and subscription events. We do not receive full payment-card details.
Firebase Analytics also processes app interactions, screen views and technical information, such as app/device identifiers, app and operating-system versions, language and diagnostic information, to measure usage, improve the App and measure campaign performance. Firebase Remote Config uses installation and technical information to deliver app configuration. These providers may process connection information under their own policies.
The App may request Apple's App Tracking Transparency permission for tracking-based advertising measurement. You can decline or change this permission in iOS Settings → Privacy & Security → Tracking. Basic scanning remains available if you decline. App analytics and Apple's privacy-preserving attribution may still operate without tracking permission.
Apple Push Notification service and Firebase Cloud Messaging process device/installation registration tokens for notifications. You can control notification permission in iOS Settings.
We use information to provide scanning and cloud features, show Insights, process and report purchases, maintain service security and reliability, apply usage limits and configuration, measure usage/campaigns, and respond to support requests. If you email us, we receive your email address and the information you choose to include.
We do not sell your personal information. Information is handled by Apple, Google Firebase/Google Cloud, Google Lens and RevenueCat as described above; Open Food Facts may receive barcodes from older versions. We may also disclose information where required by law. Providers may process data outside your country under their applicable terms and privacy practices.
Provider privacy information: Apple — https://www.apple.com/legal/privacy/; Google — https://policies.google.com/privacy; Firebase — https://firebase.google.com/support/privacy; RevenueCat — https://www.revenuecat.com/privacy; Open Food Facts — https://world.openfoodfacts.org/privacy.
Cloud Dynamic QR content and its Insights are retained until you delete the QR or the associated guest data. Premium expiry hides Premium features but does not automatically delete your QR data or statistics.
To delete an individual Dynamic QR, open Library → More options → Delete Dynamic QR. This remains available after Premium expires. Deletion removes that QR's cloud destination, design and statistics, and its saved Library entry; its short link stops working. Other QR codes and the guest session remain. A minimal request-ID/code-ID marker may remain to prevent an old creation request from recreating the deleted QR; it does not retain the destination, label or design.
Clear History removes local history only. Uninstalling the App does not delete Firebase data or cancel an App Store subscription. Restoring purchases does not transfer QR data from another guest session. For remaining guest-account data deletion requests, contact us using the email below; we may need information to confirm ownership. A hashed account-deletion marker is retained for 24 hours and then removed asynchronously to prevent requests already in progress from recreating deleted data.
Temporary Lens images follow section 4. Provider analytics, transaction records, security logs, support correspondence and device/exported backups may have separate retention periods under the relevant provider's practices or legal requirements. We use access controls and encrypted transport to protect data, but no storage or transmission method is completely secure.
You can manage Camera, Photos, Contacts, Calendar, Notifications and Tracking permissions in iOS Settings. Contacts and Calendar access is used when you choose to save a contact or event. You can delete saved content, manage or cancel subscriptions through your App Store account, and contact us with privacy questions or requests. Depending on applicable law, you may have rights to access, correct or delete personal information, restrict processing, or complain to a relevant authority.
The App is not designed to knowingly collect personal information from children. If you believe a child has provided personal information, contact us so we can review and address it. We may update this policy as the App or applicable requirements change; updates will be posted here with a revised date.
For privacy questions or data requests: dangthixuanhuongdn@gmail.com.