Privacy Policy
Last updated: June 13, 2026
SafeScan: QR & Barcode Scanner (shown on your device as "Safe QR") is built to keep your scans on your phone. This page describes exactly what data the app touches and what leaves your device.
On-device by default
Scan history, generated codes, and your saved wallet items live in local storage on your phone. The app does not maintain a server-side account, and we cannot see what you scan. This includes payment QRs (UPI, PIX, PayNow, PromptPay and similar) — their contents are parsed on your device and are never sent to us.
Anonymous analytics
If Anonymous analytics is on (you can turn it off anytime in Settings → Data and Privacy), the app reports anonymous usage so we can understand which features people use. No scan contents, URLs, Wi-Fi passwords, payment details, or anything you type are ever sent, unless you separately opt in to Share scanned links & text (see below), which is off by default.
We use three first-party analytics tools:
- Firebase Analytics and Mixpanel receive event names (like
scan_completed,wallet_item_saved, orpaywall_shown) and bucketed counts only. (Mixpanel additionally receives the links and plain text you scan only if you opt in to Share scanned links & text, below. Firebase never receives any scanned content.) - Microsoft Clarity provides anonymous interaction analytics (aggregate heatmaps of taps and scrolls). To protect you, session recording is switched off entirely on every screen that can show scan results, payments, Wi-Fi passwords, saved codes, or your history, and on-screen text and images are masked elsewhere.
To keep your analytics consistent across your own Apple devices, the app uses an anonymous, randomly generated ID stored in your Keychain. It is a random token — never your name, email, phone number, or a hardware/advertising identifier — used only for this first-party analytics. Turning analytics off, or resetting all settings, deletes it.
All collection stops the moment you opt out.
Sharing scanned links & text (off by default)
There is a separate, opt-in setting, Share scanned links & text (Settings, Data and Privacy), which is off unless you turn it on. When it is on, the actual links (URLs) and plain text you scan are sent to our analytics provider (Mixpanel) so we can understand real usage and improve the app. This is the one case where scanned content leaves your device, and only because you chose it.
Even when it is on, we never send the contents of Wi-Fi codes (including passwords), payment codes (UPI / PIX / PayNow / PromptPay), contacts, emails, phone numbers, calendar events, SMS, or locations. Only links and plain text. You can turn it back off anytime, and resetting all settings turns it off.
Crash reports
If a crash happens, it is reported through Apple's built-in crash reporting in App Store Connect. Crash reports contain a stack trace — not your scan contents, file paths from your library, or anything you typed.
URL safety checks
When you scan a URL, the app first runs on-device pattern checks (no network) for known phishing patterns, IDN homographs, lookalike brand domains, suspicious top-level domains, and URL shorteners. These checks are entirely local.
If the URL is short or scores as suspicious, the app may then send the URL to Google Safe Browsing for a reputation lookup. Per Google's published policy, the URL is hashed by their API and not stored against any account. The URL still leaves your phone in plaintext over HTTPS.
Product and book lookups
When you scan a product barcode, the GTIN is sent to Open Food Facts. When you scan an ISBN, the ISBN is sent to Open Library and Google Books. No other information is sent.
Subscriptions
SafeScan Pro is an optional paid subscription. All purchases are processed by the Apple App Store or Google Play — we never see or store your card or payment details. We use Adapty to manage and validate subscriptions; Adapty receives a transaction identifier, your anonymous app user ID, and the product, price, and status so your Pro access stays in sync across your devices. It never receives your scan contents or anything you type. See Adapty's privacy policy for details.
Measuring our marketing (no ads in the app)
We sometimes run install ads on platforms like Meta (Facebook/Instagram) and Google so people can discover SafeScan. To measure whether those ads work, the app includes Meta's App Events SDK and uses Google / Firebase. To be clear about what this does and does not do:
- We show no ads inside the app.
- On iOS, we ask first. The app shows Apple's App Tracking Transparency prompt. Only if you tap Allow do we use your device's advertising identifier (IDFA) to measure which ad brought you to SafeScan. If you decline — or if you've turned off Allow Apps to Request to Track in Settings — no IDFA is used.
- On Android, we do not use the advertising identifier; it is disabled and stripped from the app.
- When an advertising identifier isn't available or you haven't allowed it, attribution uses aggregated, privacy-preserving measurement — Apple's SKAdNetwork, Meta's Aggregated Event Measurement, and Google Play's install referrer.
- The only signals shared for measurement are app install and, where applicable, subscription-conversion events — never your scan contents, anything you type, or your payment details.
What we never do
- We never sell your data.
- We never show ads inside the app.
- We never use an advertising identifier without your permission — on iOS the IDFA is used only if you allow tracking, and on Android it stays disabled.
- We never send your scan contents, anything you type, or your payment details to advertisers — or to anyone, for advertising.
- We never read your photo library beyond what you explicitly pick.
- We never access your contacts beyond explicit Add-to-Contacts actions you initiate.
Your rights
You can:
- Export everything as a ZIP (CSV + JSON) from Settings → Data and Privacy.
- Clear all history with one tap (irreversible).
- Clear all wallet items with one tap (irreversible).
- Reset all settings from Settings → Advanced.
- Delete the app to remove all local data.
Children
Safe QR is intended for general audiences. We do not knowingly collect personal data from children.
Changes
We will update this page when our practices change. The last updated date at the top reflects the most recent change.
Contact
Questions, deletion requests, or anything else: support@northstud.io