Last updated: June 2026
This policy explains what information ieatQR collects when you use our QR code generator, scanner, dynamic QR service, and related features, and how that information is used and protected.
Account information. If you create an account, we collect your email address and, optionally, your name. Passwords are stored securely (hashed) by our authentication provider and are never visible to us in plain text.
QR code data. When you create a static QR code, the data you enter (a URL, text, WiFi credentials, contact details, etc.) is encoded directly into the QR image and is not stored on our servers unless you create a dynamic QR code, in which case the destination URL is stored so it can be edited later and so scans can be redirected correctly.
Scan analytics. When someone scans one of your dynamic QR codes, we record the approximate country and city (derived from IP address, which is not stored), device type, browser, and operating system. We do not store the scanning visitor's IP address directly — it is cryptographically hashed for abuse-prevention purposes only and cannot be reversed to identify the visitor.
Uploaded files. If you upload a file (such as a PDF or image) to link to a dynamic QR code, that file is stored on our infrastructure (Cloudflare R2) and is publicly accessible via its unique link. Do not upload files containing sensitive personal information you would not want to be publicly accessible.
We use the information above to operate the service: to authenticate your account, to redirect dynamic QR scans to the correct destination, to show you analytics about your own QR codes, and to enforce reasonable usage limits (such as free-plan storage caps) so the service can remain free for everyone.
We rely on a small number of infrastructure providers to operate ieatQR: Cloudflare (hosting, edge compute, file storage, DNS), Supabase (database and authentication), and Runware (AI image generation, used only for the optional AI Art QR feature). These providers process data on our behalf under their own privacy and security commitments.
Account data and dynamic QR codes are retained for as long as your account remains active. If you delete a dynamic QR code, its associated uploaded file (if any) is deleted from our storage at the same time. If you delete your account, your QR codes, files, and account data are removed.
You can edit or delete any dynamic QR code, uploaded file, or your account at any time from your dashboard. Static QR codes are generated entirely in your browser and are never transmitted to or stored on our servers.
We use industry-standard practices to protect your data, including encrypted connections (HTTPS) for all traffic, database-level access controls (Row Level Security) so users can only access their own data, and secret management for any third-party API credentials.
ieatQR is not directed at children under 13, and we do not knowingly collect personal information from children under 13.
We may update this policy from time to time as the product evolves. We'll update the "Last updated" date above when we do.
If you have questions about this policy or how your data is handled, you can reach out via the contact options listed on our site.