Compliance & Trust

Privacy & Data Telemetry Policy

Last revised: August 2026 ยท Global Compliance

1. Privacy by Architecture

At QR Studio, privacy is an engineering invariant. We never inject third-party ad pixels or sell scan telemetry data. All incoming scans are routed cleanly through our privacy-preserving edge proxies.

2. Anonymized Scan Telemetry

When a physical camera decodes a dynamic QR code, our edge node aggregates non-identifiable environmental metadata: city-level geographic region, device operating system, browser engine, and precise timestamp. No individual biometric or cellular fingerprint is recorded.

3. Account & Security Credentials

User emails and passwords are encrypted using salted Argon2/bcrypt hashing. Bearer API tokens are generated cryptographically and cannot be reversed or read in plaintext by our team.

4. GDPR & CCPA Rights

You maintain the absolute right to export your complete scan database via CSV or trigger a full cryptographic account deletion from your workspace settings at any time.