01
This app is not released yet
QR Protector is still in development and is not on any app store. This policy describes how the app handles data as it is currently built, and it will be reviewed and dated again before the app is published.


Privacy
QR Protector checks whether a QR code's link is safe before you open it. Checking a link means sending it to services that can judge it — so the address you scan does leave your phone. This policy names every service that sees it and says what is kept.
01
QR Protector is still in development and is not on any app store. This policy describes how the app handles data as it is currently built, and it will be reviewed and dated again before the app is published.
02
The camera image is decoded on your phone using Google ML Kit. The picture itself is never uploaded — no image of what your camera saw leaves the device.
The address inside the code is a different matter, and it has to leave. Checking whether a link is dangerous means following it and looking at where it lands, which cannot be done on your phone without the phone itself visiting a potentially malicious site. So the URL is sent to our backend, which does the visiting on your behalf and in your place.
Our backend then follows the redirect chain to its destination, checks the address against Google Web Risk, inspects the TLS certificate, looks up the domain's age through the public registry service at rdap.org, and reads the final page. Each of those services sees the address being checked.
03
A premium scan adds services that look at the destination page rather than just its address. It is captured as a screenshot by Screenshot Machine, read by Google Cloud Vision to find text and logos in the image, and assessed by Google's Gemini model, which may run a Google Search to corroborate what it has found.
Those services receive the address being checked and the contents of the page at it. They do not receive your account details, and they are not told who scanned it.
04
Sign-in is handled by Firebase Authentication. We hold the account identifier and the email address attached to it.
Each account keeps a small registry of the devices it is used from, holding when a device first signed in and when it was last active. It exists to stop one subscription being shared across an unlimited number of phones, and you can review and remove devices in settings.
05
Your history of scans is kept on your own device, not in your account, and you can clear it from inside the app. Uninstalling the app removes it.
06
The backend runs on Google Cloud Run in the United States and writes ordinary operational logs — which requests arrived, whether they succeeded, and how long they took — held in Google Cloud Logging. They exist to find faults and to spot abuse of the service.
07
QR Protector is a general-purpose safety tool rather than an app aimed at children, and we do not knowingly collect data from them. If you believe a child has created an account, email us and we will delete it.
08
Scan history is on your device and clearing it in the app removes it immediately. To delete your account and the records attached to it, email us and we will do it within one month, usually much sooner.
09
You have the right to ask what we hold about you, to have it corrected or deleted, to object to how it is used, and to have it in a portable form. Email us and we will respond within one month. If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk.
10
The date at the top changes whenever the substance does, and this page is always the current version. Because the app is still in development, expect this to be revised before release.
Support & privacy
Back to
QR Protector
Check the code before you trust it