Privacy
Privacy Policy
What this app collects, why it collects it, and what you can ask us to delete.
AI QR Code is published by Mutludev L.L.C-FZ. This policy explains how its local QR tools, optional online features and public support page handle information.
Your codes and images
QR content, saved scans, folders, favorites, designs and selected artwork are stored on your device. Creating a standard QR, decoding an image and exporting a file do not require uploading that content to our server. Camera access is used for scanning. Photo and file access is used when you select artwork, scan an image, import a CSV or save an export. Clipboard content is read when you choose the paste action. We do not read your address book to create a contact QR.
Sharing, opening a destination, printing or saving to another application sends the selected content to that destination under your control. A QR can contain personal information or Wi-Fi credentials; anyone who obtains the code may be able to read it. Device and operating-system backup settings may also affect locally stored files.
Optional online features
Using editable links or AI drafting creates a Firebase anonymous account and an installation identifier. The app uses Firebase Authentication and App Check, together with an installation verification key, to authenticate requests, reduce abuse and protect service allowances. The private signing key stays in the device's protected key storage.
For an editable link, we store its name, destination, enabled state and optional expiry. Opening that link reaches our service before redirecting to the destination. Statistics count daily page views; they do not identify individual visitors or claim to count unique people.
The service processes network and request information needed to deliver and protect these features. Usage accounting records include identifiers, operation times, outcomes and reserved service cost. Request diagnostics use bounded error categories rather than QR content or AI prompts.
AI drafting and reports
Before the first AI request, the app asks for your consent. When you submit a brief, its text and chosen language are sent through our backend to OpenRouter and a supported model provider, currently OpenAI or Google. The result is a proposal for you to review and edit; it is not an automatic publication or a verification that a destination is safe.
Do not include passwords, private Wi-Fi credentials, payment details or sensitive personal information in a brief. Our provider requests require routes that disallow data collection and support zero data retention. Our application does not store ordinary prompt or response text on the server. Provider security and operational processing is governed by the relevant provider's policies. If you deliberately report a proposal, we store the submitted proposal and your reason so the developer can review the problem. Reporting is optional and independent of AI allowance.
Purchases and diagnostics
Apple or Google processes purchases and payment details. The app reads product and ownership information to provide paid access and restore purchases. We do not receive your full payment-card details. Store billing and transaction records are also subject to the store's policies.
Usage analytics and crash reporting are separate, optional Settings choices. Both begin disabled. If enabled, Firebase Analytics receives a limited vocabulary of app actions, automatic session and purchase events, an app-instance identifier, and approximate location derived from a masked IP address. Firebase Crashlytics receives technical crash information such as stack traces, app/device versions and diagnostic identifiers. QR payloads, prompts, names and destinations are excluded from the app's analytics events and error messages. Disabling a choice stops future collection for that choice; crash withdrawal also deletes unsent reports. The app does not use advertising personalization.
On Android, the on-device scanner uses Google ML Kit. Its SDK processes technical information such as device and app versions, a per-installation identifier, feature events, error codes and performance metrics for diagnostics and usage analysis. This SDK processing is separate from the optional Firebase choices. Camera images and decoded QR content are processed on your device and are not uploaded by the scanner. ML Kit encrypts its technical data in transit.
Retention and deletion
Local library content remains until you delete it or remove the app's local data. Copies already exported or shared remain in their chosen destinations. Online links, their daily counts and reported content remain until you delete the relevant data or cloud account.
In the app, open Settings, then Cloud data, then Delete cloud account. This removes the installation's editable links, page-view counts and submitted reports from our active database, deletes its Firebase anonymous account and removes its local cloud identity. The app shows completion only after those steps succeed, and an interrupted deletion can be retried. Your local QR library is retained. Limited identifier, public verification-key, anti-replay and usage-accounting records are retained to prevent deleted identities from being recreated by replay and to enforce service security and cost limits; they do not retain the deleted link destinations or report text.
Deleting cloud data does not cancel a subscription. Manage or cancel billing through the store's subscription settings. Store-maintained purchase records are controlled by Apple or Google.
You can also request deletion without reinstalling the app through the AI QR Code support form. Use the subject “Delete my AI QR Code data” and describe the data you want removed. Include a relevant editable-link address or other information that helps identify your records, but do not send passwords, payment details or private QR contents. We may need additional information to verify ownership before accessing or deleting records. A form confirmation means the request was accepted, not that deletion has already completed.
Service providers and your choices
Our hosting and delivery providers, including Cloudflare, process information needed to operate the public pages and API. Google Firebase provides authentication, app attestation and the optional diagnostic services described above. AI processors receive only the brief you choose to submit and the request context needed for that operation. Information may be processed outside your country. We do not sell your personal information.
The support form collects the contact information and message you enter so we can handle your request. Support messages are stored by our service and sent to the private support mailbox. Do not include secrets or unnecessary sensitive information in a message.
You may use the offline tools without using AI or editable links, decline optional diagnostics, change device permissions, and request access, correction or deletion through the support form. Contact us there about privacy questions or to exercise applicable data rights. The app is not directed to children, and it does not require a child profile or knowingly solicit children's data.
Material changes to these practices will be reflected on this page and, where needed, in the app's consent or Settings controls.