QR codes come in two very different data models, and the privacy answer depends on which one you scan. A **static** code is a self-contained image — the payload is decoded on the device and is not sent to QRPress for generation; site telemetry may still be collected as described in the Privacy Policy. A **dynamic** code is a pointer to our redirect service, which stores your destination and records aggregated scan events. Everything we collect, for either type, is described below in plain language.
Static QR codes: the payload stays in the pattern
A static QR code encodes its payload directly into the pixel pattern. When it is scanned, the phone decodes the image locally — there is no request to our servers, no account, no log entry, and no way for us (or anyone) to count scans. The pattern is the data, so privacy is structural, not a policy.
Make one and inspect the traffic yourself: the static generator never uploads your input. That is why static codes also work fully offline — see do QR codes need wifi?.
Dynamic QR codes: what we store
| Field | Stored for dynamic codes | Why |
|---|---|---|
| Destination URL | Yes | Required to redirect scans |
| Label | Yes | Your dashboard naming |
| Your account email/name | Yes | Login and ownership |
| Scan timestamp | Yes | Dashboard analytics |
| Device type / browser | Yes (derived from User-Agent) | Device split in analytics |
| Country / city | Yes (Cloudflare headers) | Geography split in analytics |
| Referrer | Yes | Campaign source |
| Scanner identity | No | Never collected |
We do not collect or store any personal identifying information about the people who scan your dynamic codes.
The scan lifecycle
- A scanner points its camera at a dynamic code — the pattern decodes to a short ID like `api.qrpress.in/r/xyz`.
- The redirect service looks up the code’s current destination.
- The scan count is incremented and a scan event (time, device, country, referrer) is logged asynchronously.
- The scan is redirected (HTTP 302) to the destination — your app scheme, if the code is app-configured.
Total — scanners are redirected, never tracked across pages, and never fingerprinted.
Redirect safety & abuse reporting
Dynamic destinations are validated at creation: only `http(s)` URLs or registered app schemes (like `myapp://`) are accepted — there is no open-redirect vector that could forward scans to arbitrary handlers. If you run across a code in the wild that redirects somewhere abusive, report it via contact with the code you scanned and we remove it.
How we compare on privacy
For context, QRCode Monkey states on its homepage that entered data is \"not saved or reused\" and that its QR-image files are cached for 24 hours — a snapshot we took in September 2026, re-verify before you rely on it. This site takes a different stance for dynamic codes: the destination and scan analytics are intentionally stored for the dashboard, which is why dynamic codes here require an account while static codes never touch a server.
| Tool | Static codes | Dynamic codes |
|---|---|---|
| QRPress | Nothing leaves your device | Destination + aggregated scan analytics stored |
| QRCode Monkey | Not saved or reused; images cached 24h | No dynamic codes offered |
| qr-code-generator.com | Saved on account (dynamic enabled) | Paid tiers store redirect + analytics |
Retention, deletion, and export
Delete a dynamic code from the dashboard and its redirect plus analytics are removed. Your account data is covered by the privacy policy; you can delete the account and its codes at any time. Scan events are retained for the campaign window the analytics view needs; there is no third-party data sharing or sale — the print-shop product at qrpress.in is a separate service with its own terms.
