Where Your QR Data Goes — Data-Flow, Privacy & Redirect Safety

By QRPress Editorial Team|

QR codes come in two very different data models, and the privacy answer depends on which one you scan. A **static** code is a self-contained image — the payload is decoded on the device and is not sent to QRPress for generation; site telemetry may still be collected as described in the Privacy Policy. A **dynamic** code is a pointer to our redirect service, which stores your destination and records aggregated scan events. Everything we collect, for either type, is described below in plain language.

Static QR codes: the payload stays in the pattern

A static QR code encodes its payload directly into the pixel pattern. When it is scanned, the phone decodes the image locally — there is no request to our servers, no account, no log entry, and no way for us (or anyone) to count scans. The pattern is the data, so privacy is structural, not a policy.

Make one and inspect the traffic yourself: the static generator never uploads your input. That is why static codes also work fully offline — see do QR codes need wifi?.

Dynamic QR codes: what we store

FieldStored for dynamic codesWhy
Destination URLYesRequired to redirect scans
LabelYesYour dashboard naming
Your account email/nameYesLogin and ownership
Scan timestampYesDashboard analytics
Device type / browserYes (derived from User-Agent)Device split in analytics
Country / cityYes (Cloudflare headers)Geography split in analytics
ReferrerYesCampaign source
Scanner identityNoNever collected

We do not collect or store any personal identifying information about the people who scan your dynamic codes.

The scan lifecycle

  1. A scanner points its camera at a dynamic code — the pattern decodes to a short ID like `api.qrpress.in/r/xyz`.
  2. The redirect service looks up the code’s current destination.
  3. The scan count is incremented and a scan event (time, device, country, referrer) is logged asynchronously.
  4. The scan is redirected (HTTP 302) to the destination — your app scheme, if the code is app-configured.

Total — scanners are redirected, never tracked across pages, and never fingerprinted.

Redirect safety & abuse reporting

Dynamic destinations are validated at creation: only `http(s)` URLs or registered app schemes (like `myapp://`) are accepted — there is no open-redirect vector that could forward scans to arbitrary handlers. If you run across a code in the wild that redirects somewhere abusive, report it via contact with the code you scanned and we remove it.

How we compare on privacy

For context, QRCode Monkey states on its homepage that entered data is \"not saved or reused\" and that its QR-image files are cached for 24 hours — a snapshot we took in September 2026, re-verify before you rely on it. This site takes a different stance for dynamic codes: the destination and scan analytics are intentionally stored for the dashboard, which is why dynamic codes here require an account while static codes never touch a server.

ToolStatic codesDynamic codes
QRPressNothing leaves your deviceDestination + aggregated scan analytics stored
QRCode MonkeyNot saved or reused; images cached 24hNo dynamic codes offered
qr-code-generator.comSaved on account (dynamic enabled)Paid tiers store redirect + analytics

Retention, deletion, and export

Delete a dynamic code from the dashboard and its redirect plus analytics are removed. Your account data is covered by the privacy policy; you can delete the account and its codes at any time. Scan events are retained for the campaign window the analytics view needs; there is no third-party data sharing or sale — the print-shop product at qrpress.in is a separate service with its own terms.

Frequently Asked Questions

Can you track me when I scan a static QR code?

No — and it is not a policy, it is physics. A static code contains its payload in the image; scanning decodes it on the device with no request to our servers, so no scan can be counted or logged for static codes.

What data do you store about dynamic code scans?

For dynamic codes we store the destination, your label, and aggregated scan events: timestamp, device type/browser, country/city from Cloudflare headers, and referrer. We never collect personal identifying information about scanners.

How do I delete my dynamic codes and their data?

Delete a code from the dashboard and its redirect and analytics are removed. Account deletion removes the account and its codes; the privacy policy covers the retained data. No third-party sale or sharing of scanner data occurs.

Do you sell or share scanner data?

No. Static codes generate no server data at all, and dynamic scan analytics are aggregated for your dashboard only. qrpress.in’s print-shop service is a separate product with separate terms.

Build on software that documents its data flow

Static codes that never phone home, dynamic codes with honest analytics. Generate your first print-ready code now.

Generate a QR Code