Summary
- We store the email address and password you sign up with, and the QR codes you save.
- Signed-out visitors are counted with a salted hash of their IP address, not the address itself.
- We set one essential cookie, to keep you signed in.
- Advertising cookies are set by Google AdSense, and only after you agree to them.
- We do not sell your personal data.
Who we are
QR Studio ("we", "us") operates this website, a free QR code generator. For the purposes of the UK GDPR and the EU GDPR, we are the data controller for the personal data described below. You can reach us using any of the methods on our contact page.
What we collect
Account data
When you create an account we collect your email address, an optional
display name, and a password. Passwords are never stored in readable form:
we derive a scrypt hash with a per-account random salt and
store only that.
Content you create
We store the QR codes you choose to save — the type, the values you typed into the form (a URL, a Wi-Fi password, contact details, and so on), the design options, and when it was created. This is what makes your history work. You can delete any entry at any time, and deleting it removes the stored payload.
The live preview on the generator page is deliberately not stored. Codes only persist when you press Generate.
Anonymous usage
Signed-out visitors receive three free QR codes. To enforce that limit we keep a counter keyed to a salted, one-way hash of your IP address. The raw address is not written to the database, and the hash cannot be reversed to recover it. The counter only ever increases; it is not used for tracking you across other websites.
Server logs
Our hosting provider records standard request logs (IP address, timestamp, requested URL, user agent) for security and abuse prevention. These are retained on the provider's normal schedule.
Cookies
We use a small number of cookies and similar technologies:
| Name | Type | Purpose |
|---|---|---|
| Session cookie | Essential | Keeps you signed in. Set only after you log in or sign up. It is httpOnly, SameSite=Lax, and expires after 30 days or when you sign out. |
| Consent choice | Essential |
A localStorage entry recording whether you accepted or
rejected advertising cookies, so we do not ask on every page.
|
| Google advertising cookies | Advertising | Set by Google AdSense to serve and measure ads. These are only set after you accept advertising cookies. |
Essential cookies cannot be switched off without breaking sign-in, so they are set on the basis of our legitimate interest in operating the service. Advertising cookies are set only with your consent, which you can give or refuse in the banner shown on your first visit. To change your mind later, clear this site's data in your browser settings; the banner will appear again on your next visit.
Advertising and Google AdSense
QR Studio is free, and advertising pays for the servers. We use Google AdSense to display ads, and we want to be specific about what that involves, because it is a common source of confusion.
- Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this website and other websites.
- Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to our site and/or other sites on the internet.
- You can opt out of personalized advertising by visiting Google Ads Settings.
- You can opt out of some third-party vendors' use of cookies for personalized advertising by visiting www.aboutads.info, or in the EU at Your Online Choices.
- We do not serve ads on the account, sign-in, verification or error screens. Ads appear only alongside editorial content, and every ad unit is labelled as an advertisement.
If you decline advertising cookies, we do not request an ad at all, and no advertising cookie is set. You can still use every feature of the site.
For visitors in the European Economic Area, the United Kingdom and Switzerland, we rely on Google's certified consent management platform to collect and record your advertising consent, because Google requires a certified CMP for those regions.
Who else processes your data
We share personal data only with the providers needed to run the service:
- Hosting provider — serves the site and stores the database and request logs.
- Email delivery provider — sends account verification and password reset messages, and therefore processes your email address.
- Google — serves advertising and, where applicable, consent messages, as described above.
We do not sell, rent or trade your personal data. We may disclose data where we are legally required to, or where it is necessary to investigate abuse of the service.
How long we keep it
- Account data and saved QR codes: until you delete them or close your account.
- Anonymous usage counters: retained while the trial limit is enforced.
- Verification and reset tokens: 24 hours and 1 hour respectively, then discarded.
- Server logs: per our hosting provider's retention schedule.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing of your personal data, to receive it in a portable format, and to withdraw consent you previously gave. To exercise any of these, contact us using the details on the contact page. We will respond within the period required by applicable law, normally 30 days.
If you are in the EU or UK and believe we have handled your data unlawfully, you have the right to complain to your national data protection authority.
California residents: we do not sell or share your personal information as those terms are defined by the CCPA/CPRA. You may still request access to, or deletion of, the information we hold about you.
Security
Passwords are hashed with scrypt and compared in constant time.
Sessions use random 32-byte tokens stored in httpOnly cookies. Verification
and reset tokens are stored only as SHA-256 hashes, are single-use, and
expire. The site is served over HTTPS. No system is perfect, so we cannot
guarantee absolute security — but we do not store anything we do not need.
Children
QR Studio is not directed at children, and we do not knowingly collect personal data from anyone under 13 (or under 16 in the EEA). If you believe a child has created an account, contact us and we will remove it.
International transfers
Our providers may process data outside your country, including in the United States. Where that happens, we rely on the transfer safeguards those providers have put in place, such as the European Commission's Standard Contractual Clauses.
Changes to this policy
If we change this policy we will update the date at the top of the page. If the change is material, we will make that clear on the site.
Contact
Questions about this policy, or a request to exercise your rights, can be sent to the addresses listed on our contact page. See also our Terms of Service.