Last updated · July 30, 2026

Privacy

Static tools keep content in your browser. Dynamic QR persistently stores the campaign configuration and coarse aggregate scan reporting described below.

Local static processing

Static QR content, Wi-Fi passwords, vCard details and CSV files are not uploaded. QR rendering and export happen in your browser.

Local history

When you save an item, the latest 20 entries are kept in localStorage on this device. You can clear them from the tool.

Dynamic QR account data

Management requires Sign in with ChatGPT and a server-side Pro check. Your email is used transiently for that check, then converted to an opaque HMAC subject; raw email is not stored in the QR database. For each dynamic code, we persist the campaign title, short slug, enabled state, full HTTPS target including its path and query string, UTM values, timestamps and destination version history.

Aggregate scan data

Dynamic scans store UTC day and hour buckets, Cloudflare country code, a coarse device family and totals. We do not persist IP addresses, full user agents, referrer queries, fingerprints or raw visitor data.

Retention and deletion requests

Dynamic campaign records, including target and version history, currently remain stored without an automatic expiry schedule so printed redirects and account history can keep working. Automatic deletion is not implemented. To request deletion, use the Contact page; we will need to verify control of the account or campaign before acting.

Request deletion through Contact

Billing

This app contains no Lemon Squeezy secrets or webhook. Checkout is hidden unless the central billing hub is ready and can verify entitlement server-side.