Legal

Privacy Policy

This policy explains what QR Studio collects, why we collect it, who else sees it, and how you can control it.

Last updated:

Summary

Who we are

QR Studio ("we", "us") operates this website, a free QR code generator. For the purposes of the UK GDPR and the EU GDPR, we are the data controller for the personal data described below. You can reach us using any of the methods on our contact page.

What we collect

Account data

When you create an account we collect your email address, an optional display name, and a password. Passwords are never stored in readable form: we derive a scrypt hash with a per-account random salt and store only that.

Content you create

We store the QR codes you choose to save — the type, the values you typed into the form (a URL, a Wi-Fi password, contact details, and so on), the design options, and when it was created. This is what makes your history work. You can delete any entry at any time, and deleting it removes the stored payload.

The live preview on the generator page is deliberately not stored. Codes only persist when you press Generate.

Anonymous usage

Signed-out visitors receive three free QR codes. To enforce that limit we keep a counter keyed to a salted, one-way hash of your IP address. The raw address is not written to the database, and the hash cannot be reversed to recover it. The counter only ever increases; it is not used for tracking you across other websites.

Server logs

Our hosting provider records standard request logs (IP address, timestamp, requested URL, user agent) for security and abuse prevention. These are retained on the provider's normal schedule.

Cookies

We use a small number of cookies and similar technologies:

Name Type Purpose
Session cookie Essential Keeps you signed in. Set only after you log in or sign up. It is httpOnly, SameSite=Lax, and expires after 30 days or when you sign out.
Consent choice Essential A localStorage entry recording whether you accepted or rejected advertising cookies, so we do not ask on every page.
Google advertising cookies Advertising Set by Google AdSense to serve and measure ads. These are only set after you accept advertising cookies.

Essential cookies cannot be switched off without breaking sign-in, so they are set on the basis of our legitimate interest in operating the service. Advertising cookies are set only with your consent, which you can give or refuse in the banner shown on your first visit. To change your mind later, clear this site's data in your browser settings; the banner will appear again on your next visit.

Advertising and Google AdSense

QR Studio is free, and advertising pays for the servers. We use Google AdSense to display ads, and we want to be specific about what that involves, because it is a common source of confusion.

If you decline advertising cookies, we do not request an ad at all, and no advertising cookie is set. You can still use every feature of the site.

For visitors in the European Economic Area, the United Kingdom and Switzerland, we rely on Google's certified consent management platform to collect and record your advertising consent, because Google requires a certified CMP for those regions.

Who else processes your data

We share personal data only with the providers needed to run the service:

We do not sell, rent or trade your personal data. We may disclose data where we are legally required to, or where it is necessary to investigate abuse of the service.

How long we keep it

Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing of your personal data, to receive it in a portable format, and to withdraw consent you previously gave. To exercise any of these, contact us using the details on the contact page. We will respond within the period required by applicable law, normally 30 days.

If you are in the EU or UK and believe we have handled your data unlawfully, you have the right to complain to your national data protection authority.

California residents: we do not sell or share your personal information as those terms are defined by the CCPA/CPRA. You may still request access to, or deletion of, the information we hold about you.

Security

Passwords are hashed with scrypt and compared in constant time. Sessions use random 32-byte tokens stored in httpOnly cookies. Verification and reset tokens are stored only as SHA-256 hashes, are single-use, and expire. The site is served over HTTPS. No system is perfect, so we cannot guarantee absolute security — but we do not store anything we do not need.

Children

QR Studio is not directed at children, and we do not knowingly collect personal data from anyone under 13 (or under 16 in the EEA). If you believe a child has created an account, contact us and we will remove it.

International transfers

Our providers may process data outside your country, including in the United States. Where that happens, we rely on the transfer safeguards those providers have put in place, such as the European Commission's Standard Contractual Clauses.

Changes to this policy

If we change this policy we will update the date at the top of the page. If the change is material, we will make that clear on the site.

Contact

Questions about this policy, or a request to exercise your rights, can be sent to the addresses listed on our contact page. See also our Terms of Service.