Privacy Policy

QRMaker privacy policy — every code is generated and decoded on your device; nothing you type or upload reaches our servers.

Last updated: October 2026.

QRMaker handles sensitive inputs — Wi-Fi passwords, names, phone numbers — so it is built around one rule: the data stays in the tab. This page lists what is processed, what is transmitted, and what we never see.

Data that never leaves your device

Everything you type into the generator — URLs, SSIDs and passwords, contact details, message text, coordinates — is assembled into a payload and encoded by JavaScript running locally. The rendered image, the PNG/SVG downloads, and any logo you add never touch a network. The same holds for the scanner: an image you drop in is decoded by jsQR in the browser and forgotten when you close the page. There is no upload endpoint for any of it; you can verify that by loading the site, going offline, and continuing to use every feature.

Automatic data

  • Hosting (Cloudflare): serving the pages involves ordinary request metadata — IP address, user agent, requested URL, time — for delivery, abuse protection and aggregate traffic measurement. There are no accounts and no forms storing data for those logs to attach to.
  • Usage counts: the site emits one small cookieless beacon per view (page address, referring site, country reported by the CDN, time on page) so we can tell which tools get used. It carries no cookies, no identifiers and none of your inputs.
  • Advertising (Google AdSense): where ads run, the network may set or read cookies to count impressions and, where permitted, personalise them. Opt out via Google’s Ads Settings or your browser’s cookie controls — the generator is unaffected either way.

Storage

The tool writes nothing to cookies or localStorage. Your inputs live in the page’s memory only and are discarded on reload.

Contact

Privacy questions: hello@photopassport.online.