Privacy policy
Last updated: 4 September 2026. Applies to QRCraft Studio at qr.bitwiz.in, operated by bitwiz ("we", "us").
- Summary
- Data we collect
- Scan analytics and people who scan your codes
- Cookies, Google Analytics and Google AdSense
- How we use data
- Sharing and processors
- Data retention
- Your rights and deleting your data
- Security
- Children
- Changes to this policy
- Contact
1. Summary
QRCraft Studio is a free, ad-supported QR code generator. You can create static codes without telling us anything. If you create an account, we store your email address, the content of the codes and pages you create, and anonymised statistics about scans of your dynamic codes. We never store raw IP addresses of people who scan a code, we do not sell personal data, and you can delete your account and everything in it at any time.
2. Data we collect
2.1 Visitors without an account
The static generator on the home page runs entirely in your browser. The text you type and the images you download are not sent to our servers. Our hosting provider records standard server logs (IP address, user agent, requested URL, timestamp) for security and capacity purposes, which are kept for a short period. Cookies and analytics are described in section 4.
2.2 Account holders
- Account data: email address, display name, a salted hash of your password (never the password itself), account role, the time of creation and last sign-in, and the status of email verification.
- Session data: a hashed session token, the browser user agent and a hashed IP address for each active sign-in, so you can review and revoke sessions.
- Content you create: QR code titles, destinations and payloads (URLs, vCard fields, Wi-Fi credentials, event details, text), design settings including any uploaded logo, custom aliases, tags, UTM parameters, and bio page content (name, headline, photo, links, social handles, contact details).
- Support correspondence: emails you send us.
Note that a Wi-Fi QR code contains the network password in plain form because that is how the Wi-Fi QR standard works. Only create dynamic Wi-Fi codes for networks you are comfortable storing with us.
3. Scan analytics and people who scan your codes
When someone scans a dynamic code, their phone requests a short link on our domain and we redirect them to the destination. For each such request we record:
- the time of the scan;
- operating system family (for example iOS, Android, Windows), device type (mobile, tablet, desktop) and browser family, derived from the user agent string;
- coarse location (country, region and city) derived from the IP address by our hosting provider or an IP geolocation service. Precise location or GPS data is never collected;
- a one-way salted hash of the IP address, used only to estimate unique visitors. The raw IP address is discarded and cannot be recovered from the hash;
- the referrer and preferred language sent by the browser, if any, and whether the request looks like an automated bot.
This data is shown to the owner of the code as aggregated statistics and as an anonymised scan list. We do not set cookies on the phones of people who scan a code and we do not build profiles of them. If you scanned a code and have questions about the destination, contact the person or business that published the code.
Public bio pages (addresses starting with /b/) record a view counter and the same anonymised request information as above. Bio pages are public web pages and may be indexed by search engines unless their owner unpublishes them.
4. Cookies, Google Analytics and Google AdSense
4.1 Strictly necessary storage
qcs_session: an HttpOnly cookie that keeps you signed in for up to 30 days.qcs_theme,qcs_consent: browser local storage entries that remember your light or dark theme and your cookie choice. They contain no personal data.
4.2 Google Analytics 4
We use Google Analytics 4 to understand how the site is used (pages viewed, features used, approximate country). Analytics cookies are only set after you accept them in the consent banner; until then Google Consent Mode keeps analytics storage disabled. IP anonymisation is enabled. Google's use of this data is described in How Google uses information from sites that use its services. You can opt out at any time by choosing "Reject" in the banner, clearing your cookie choice, or installing the Google Analytics opt-out browser add-on.
4.3 Google AdSense
Advertising keeps the service free. Ads are served by Google AdSense. Google and its partners may use cookies or device identifiers to show ads based on your visits to this and other sites, subject to your consent choice. If you reject, Google serves non-personalised ads that do not use cookies for personalisation. You can manage ad personalisation in Google Ads Settings and learn more at Google's advertising policies. Third-party vendors listed by Google may also place cookies; you can opt out of many of them at aboutads.info or youronlinechoices.com.
Ads are never shown inside dialogs or over controls, and we do not place ads on bio pages or on short-link redirects.
5. How we use data
- to provide the service: sign you in, store your codes and pages, redirect scans and show you analytics;
- to send transactional email such as verification and password reset messages;
- to keep the service secure: rate limiting, abuse detection, revoking sessions;
- to improve the product using aggregated usage statistics;
- to fund the service through advertising, as described in section 4.
Where the GDPR or similar laws apply, our legal bases are performance of a contract (providing the service you asked for), legitimate interests (security, product improvement, funding through non-personalised ads) and consent (analytics cookies and personalised ads). We do not send marketing email.
6. Sharing and processors
We do not sell personal data. We share data only with service providers that process it on our behalf: our hosting and database providers (for example Vercel and Neon), an email delivery provider for transactional messages, optionally an IP geolocation service that receives IP addresses solely to return a coarse location, and Google for analytics and advertising as described above. Providers may be located outside your country; where required we rely on standard contractual clauses or equivalent safeguards. We may disclose data when the law requires it or to protect the rights and safety of users and the public.
7. Data retention
| Data | Kept for |
|---|---|
| Account and content | Until you delete the item or your account |
| Scan records (hashed IP, device, coarse location) | Until the related link or account is deleted |
| Sessions | 30 days of inactivity, or until revoked |
| Verification and password reset tokens | Until used or expired (hours) |
| Server logs | Up to 30 days |
| Google Analytics data | Per the retention setting in our Analytics property (default 14 months) |
8. Your rights and deleting your data
Depending on where you live you may have the right to access, correct, export, restrict or delete your personal data, to object to processing, and to complain to a supervisory authority. You can exercise most of these yourself:
- Export: download your scan data as CSV from Analytics.
- Correct: edit your name in Settings and your content anywhere in the app.
- Delete a code or page: deleting it also deletes all of its scan records.
- Delete your account: Settings, then "Delete account". This removes your account, codes, pages and scan data immediately and permanently. Printed dynamic codes will stop working.
For anything else, email us (section 12). We respond within 30 days.
9. Security
All traffic is encrypted with HTTPS. Passwords are hashed with scrypt, session tokens are stored only as hashes, and IP addresses in scan records are hashed with a secret salt. Access to production systems is limited to the operator. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as required by law. Security researchers can find our contact details in security.txt.
10. Children
The service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
11. Changes to this policy
We may update this policy as the service or the law changes. The date at the top shows the latest revision. Significant changes will be announced in the app.
12. Contact
bitwiz, operator of QRCraft Studio. Email: hello@bitwiz.in. Website: bitwiz.in.