QRCodeForge

Privacy policy

This page describes exactly what QRCodeForge collects, in plain language, for every part of the site. Where something is not collected, that is stated as plainly as where it is.

Making a QR code

A standard QR code is generated entirely in your browser. The text, URL, WiFi password, or other content you type into the generator is never sent to our server — it goes straight from the form into the code rendered on your screen. We have no record of what codes you have made, because we never receive that information in the first place.

Bulk generation

Uploading a CSV to generate many codes at once runs entirely on your device, in a background thread in your browser. The file is read locally, every code in it is generated locally, and the resulting zip file is built and offered for download locally. No row of your spreadsheet, and no file, is ever uploaded anywhere.

Dynamic (trackable) QR codes

If you turn on a dynamic code, its destination URL is stored on our server so it can be looked up and changed later — that is the whole point of the feature, and it is the only case where a QR code's content reaches us at all. We store the destination URL, a scan count, and — for each individual scan — the timestamp, device class (mobile, tablet, or desktop), and a two-letter country code. We donot store the IP address of anyone who scans a code, or of anyone who creates or manages one, for any code, dynamic or otherwise. That column simply does not exist in our database.

A dynamic code's management link contains a token that proves you created it. We store only a one-way hash of that token, never the token itself, so we cannot reconstruct your management link even if we wanted to — if you lose it, we cannot recover it for you, only issue a fresh one if you have optionally saved the code to an account.

Optional accounts

Creating an account is entirely optional and exists only so you can recover a new management link if you lose one. Signing in uses a one-time emailed link rather than a password; we store your email address and which dynamic codes you have chosen to save, and nothing else about you. To deliver that sign-in link, your email address is sent to our email provider, Resend, which sends the message on our behalf, and Resend never sees which codes belong to you.

Our database — the file holding account email addresses and saved codes — is backed up continuously to Cloudflare R2 so a server failure cannot destroy people's codes. A copy of that data therefore rests with Cloudflare as well as with us.

Advertising

QRCodeForge is funded by display advertising, which is what keeps every feature on this site free with no signup and no limits. If ads are enabled, the first time you visit you are asked to accept or decline them — declining is exactly as easy as accepting, and your choice is remembered on this browser so you are not asked again. Nothing related to ads loads before you make a choice.

If you accept, our advertising partner, Google AdSense, may set cookies and use device identifiers to select and measure ads shown to you, and may use data to personalise the ads you see, subject to Google's own advertising privacy policy. You can change your mind at any time with the "Manage ad consent" link in the footer of every page; declining stops any further ad request from the next page view onward.

Ads never appear, and no ad-related request is ever made, on a page whose address is itself a credential — the code-management page (/m/…) and your account dashboard (/dashboard). Both are also served with a stricter Referrer-Policy for the same reason: the address of those pages must never leak anywhere, ad-related or otherwise.

Abuse prevention

Destinations for dynamic codes are checked against Google Safe Browsing at creation and re-checked periodically, so we can stop forwarding anyone to a site later found to host malware or phishing. This check only ever sees the destination URL, never who created or scanned the code.

Creating a dynamic code may also run a bot check, Cloudflare Turnstile, which loads a script from Cloudflare and sends your IP address to Cloudflare as part of verifying the check. It is sent only at the moment you create a dynamic code, and we do not store it.

Cloudflare also carries the dynamic-code system itself.A dynamic code's short address is resolved at Cloudflare's edge, not on our server — that is what keeps a printed code working when our server is down. Two consequences worth stating plainly. The destination URL of every dynamic code is stored at Cloudflare as well as by us. And every scan of a dynamic code reaches Cloudflare first, so Cloudflare sees the scanner's IP address and browser for each scan. We receive only the two-letter country Cloudflare derives from that address, plus a coarse device class (mobile, tablet or desktop) — never the address itself, which is why there is no column for one in our database.

Questions

The services that receive any data because of this site are: Google AdSense, only if you accept ads, which by the nature of loading their script means Google sees your IP address; Cloudflare, which resolves every dynamic-code scan at its edge and therefore sees the scanner's IP address, which runs the Turnstile bot check when you create one, and which holds our database backups (including account email addresses) in its R2 storage; Google Safe Browsing, which sees destination URLs only, never who created or scanned a code; and Resend, only the email address and message for an account sign-in link. This page states what each of them sees. If a QR code you scanned took you somewhere it should not have, report it here.