Privacy & Data
What we collect, what we don't, and how your scans help build Canada's public QR safety record.
Last updated: July 2026
The short version
- No account required to scan. Use QRbolt without signing in.
- Pseudonymous device ID: we use a random device identifier for sync and rate limits, not your name (unless you sign in with Apple).
- URLs checked for safety: scanned links are verified against threat databases (including Google Safe Browsing when needed).
- Aggregated Shelf Index: synced scans contribute to public brand and category statistics; individuals are never published.
- Canadian infrastructure: mobile data stored and processed in Canada, PIPEDA-aligned minimisation.
- We do not sell your data.
What we collect
Scan and URL data
When you scan a QR code, the full destination URL is sent to our servers so we can check it against threat databases. After the check, scan records are synced in the background: the URL is stored encrypted at rest (AES-256-GCM), along with a URL hash, domain, safety verdict, whether HTTPS was used, and when the scan occurred. QR-type classification (GS1, dynamic, or legacy) may be added later by a background process.
Device identifier (pseudonymous)
The app generates a random device identifier stored on your phone. It is used for API rate limits, scan sync, and linking optional features (push notifications, telemetry). On the server we store a one-way hash of this identifier, not your name. If you do not sign in, we do not know who you are; we only know that a particular device scanned particular links.
Sign in with Apple (optional)
If you choose to sign in, we store Apple's subject identifier so you can restore scan history across devices. Apple may also share your name and email if you allow it. Sign-in is never required to scan or receive a safety check.
Aggregate statistics
We compute totals and percentages per brand and product category from synced scans. These aggregates are what appear in the public Shelf Index. No individual scan or user is ever published.
App updates
When the app checks for over-the-air updates, it sends your platform (iOS or Android), runtime version, and current update bundle ID to our update server. This helps us deliver the correct JavaScript bundle to your device.
What we do not collect
- Your GPS location: we do not request or store location data
- Data from other apps on your device
- The content of websites you visit after you leave QRbolt and open a link in your browser
- Advertising profiles or data sold to third parties
Threat checking
When you scan a URL, QRbolt checks it against our local threat database (sourced from PhishTank and OpenPhish) and, when configured, Google Safe Browsing. On a cache miss, the full URL may be sent to Google for that lookup.
A result of "No warnings found" means the URL was not on any list we checked at that moment. It does not mean the site is certified safe. Always use your judgment before opening unfamiliar links.
Community link reports
If you choose to report a link as safe or malicious, we store the URL, domain, report type, the prior automated verdict, and when you reported it. Aggregated report counts may be shown to other users for context only. They do not change the automated safety verdict.
In-app usage data
To improve educational content and measure how features are used, QRbolt collects anonymous interaction data tied to the same pseudonymous device identifier used for scan sync:
- Learn articles: which articles are opened, dismissed, or read through; optional 1–5 star ratings
- Business CTAs: when promotional cards are viewed, tapped, or dismissed
- Wi‑Fi and vCard QR codes: when static codes are detected and whether you joined, saved, or dismissed
This data is not sold or shared with third parties for advertising. There is no per-feature toggle to disable it. It is part of how we operate and improve the product, similar to anonymous scan-verdict data.
Sharing your impact
When you tap Share on your scan stats or a scanned link — including "Share to Instagram Story" and "Copy Caption" — QRbolt generates an image and/or text caption on your device and hands it to your phone's normal share sheet, or opens Instagram directly. None of this touches QRbolt's servers. What happens after you choose where to share is governed by that destination app's own privacy policy.
Push notifications (iOS)
On iOS, you may grant permission to receive push notifications. If you do, we store an Apple push notification device token so we can send security alerts or important app updates. You can revoke permission at any time in iOS Settings; there is no separate in-app push toggle.
Shelf Index and brand classification
Synced scans feed Canada's public Shelf Index: aggregated statistics on how brands use QR codes (GS1, dynamic, or legacy). Only totals and percentages are published; no individual scan or user appears in the Index. Brands with too few scans are suppressed until they meet a minimum sample threshold.
To label brands and categories, new scan domains may be sent to Anthropic (Claude Haiku) for lookup. Only the domain name is sent, never full URLs. Results are cached so each domain is classified once.
A per-user opt-out from Shelf Index contribution is not available yet. Your scans still receive a full safety check regardless of how they are used in aggregates.
Canadian data residency
Mobile app data is stored and processed in Canada on Canadian infrastructure. Scan data is not transferred outside Canadian jurisdiction for storage. This is how the system was built from day one, not a future roadmap item.
QRbolt's data practices are designed to be consistent with the Personal Information Protection and Electronic Documents Act (PIPEDA) and its provincial equivalents. We take a minimisation posture: we collect only what we need to operate the safety service and build the Shelf Index.
Website visitors (qrbolt.app)
This marketing website uses Google Analytics (Google Tag Manager) to understand page traffic. Standard cookies and page-view data may be collected by Google. The native QRbolt app does not include Google Analytics. See Google's Privacy Policy for how Google handles that data.
Contact
Questions about data or privacy? Email us at privacy@qrbolt.com. For enterprise and business-customer data practices on qrbolt.com, visit qrbolt.com/privacy.