Privacy Policy
Last updated 22 September 2026
This policy explains what personal information QRGEN collects when you use QRGEN — the website, the Android app and the API — what we do with it, and the choices you have. It sits alongside our Terms and Conditions.
1. The short version
- We keep what is needed to run your account and the codes you make: your name, email address and the content you put into codes.
- When someone scans one of your dynamic codes, we record the scan, including their IP address, for 90 days so you can see statistics.
- We do not sell personal information, show advertising, or use tracking or advertising cookies.
- The app's scanner reads codes on your phone. Camera images are never uploaded.
- You can delete your account at any time from https://qrgen.hyperaisolutions.space/account/delete or in the app.
2. What we collect
Account details. Your name, email address and password (stored only as a one-way hash). If you turn on two-factor sign-in, we store its secret and recovery codes in encrypted form. We record when you verified your email address.
What you create. The content of your QR codes — which can include contact details, links, Wi-Fi names and passwords, phone numbers, messages and event details — together with names, colours, destinations and settings. Codes you generate as a guest without signing in are not saved.
Files you upload. Logos and images you add to a workspace brand kit or a digital business card.
Workspace and team information. The workspaces you belong to, your role in each, and invitations you send or receive, including the invited email address.
Activity and security records. An activity history of actions in a workspace (for example "code created" or "member invited"), with the time and the IP address they came from. API tokens you create are stored as hashes.
Limit requests. If you ask for a higher generation limit, the details of that request and its review.
3. People who scan your codes
A static code holds its content directly; scanning it does not contact us, and we learn nothing about the scan. A dynamic code or digital business card opens through our servers, and each scan is recorded with: the time, the IP address, an approximate country and city worked out from that address, the type of device, the operating system and browser, the browser's user-agent text, and the referring page if the browser sends one.
These records are shown only to members of the workspace that owns the code. If you are the owner of a code, you decide who scans it and why; where the law makes you responsible for those people's data, you should tell them in your own privacy notice.
4. The Android app
- Camera. Used only to read QR codes while the Scan tab is open. The picture is processed on the phone and never stored or uploaded.
- Photos. Only when you choose "Scan from photo" or add your own logo. A photo you scan is read on the phone; a logo you choose is uploaded to your workspace.
- Contacts, calendar and Wi-Fi. The app has no permission to read these. When a scanned code holds a contact, an event or a network, the app opens your phone's own screen with the details filled in; nothing is saved unless you confirm it there.
- Sign-in. The app keeps an access token in the phone's secure storage so you stay signed in. Signing out removes it and revokes it on our side.
- The app contains no advertising or third-party analytics.
5. How we use it
- To provide the service: saving and drawing codes, redirecting dynamic codes, showing statistics, and letting teams work together.
- To keep accounts and the service secure: sign-in, two-factor checks, rate limits, and investigating abuse such as phishing codes.
- To send the emails the service needs: email verification, password resets and workspace invitations. We do not send marketing email.
- To apply free-use limits and handle requests for a higher limit.
- To understand overall use of the service from aggregated figures that do not identify anyone.
Where a legal basis is required, we rely on performing our agreement with you (running your account), our legitimate interests in keeping the service secure and working, and our legal obligations.
8. How long we keep it
- Scan records: 90 days, then deleted automatically.
- Account details: while your account is open. When you delete it, they are removed at once, as described below.
- Codes, logos and workspace content: until a workspace member deletes them. A deleted code stays restorable in the workspace library until it is removed for good.
- Server backups and logs may hold copies for a short time before they are overwritten.
9. Deleting your account
You can delete your account at any time on the website at https://qrgen.hyperaisolutions.space/account/delete, or in the app under Account. You will be asked for your password, and for a two-factor code if you use one.
Removed straight away: your name, email address, password, two-factor secrets and recovery codes, API tokens and app sign-ins, pending invitations sent to you, and the IP addresses in your activity history. You are removed from every workspace you share with others.
Kept: the codes, scan records and uploaded logos in your workspaces, so that codes already printed keep working. They are no longer linked to your name or email. The activity history keeps entries such as "code created" against an anonymous "Deleted user". If you owned a workspace that other people use, ownership passes to its longest-standing admin. If you would like the content of your own workspace removed as well, delete those codes and logos before you delete your account, or email us and we will remove it.
10. Your choices and rights
You can see and change most of your information yourself: your profile, your codes and your logos. Depending on where you live, you may also have the right to ask for a copy of your personal information, to have it corrected or deleted, to object to or restrict how we use it, and to complain to your local data protection authority. Email support@example.com and we will answer within 30 days.
11. Security
Traffic to the service is encrypted with HTTPS. Passwords and API tokens are stored as hashes, two-factor secrets are encrypted, uploaded files are kept in private storage and shown only to workspace members, and access within a workspace follows each member's role. No system is perfectly secure; if we learn of a breach that affects you, we will tell you.
12. Children
You must be at least 13 to hold an account. We do not knowingly collect personal information from younger children; if you believe a child has given us their details, email us and we will delete them.
13. Changes to this policy
We will update this page when our practices change and show the date at the top. If a change is significant, we will tell account holders by email or in the service before it applies.
14. How to contact us
QRGEN
Email: support@example.com