Privacy Policy
Last updated: July 20, 2026
This policy explains what data is and is not processed when you use GenerateQRCodes.net (generateqrcodes.net). The short version: the generators run entirely in your browser and we never see what you
type; the only personal data we hold is for people who choose to create an account, and it is
limited to their email, credentials, and the codes they explicitly saved.
1. Generating codes: 100% in your browser
Everything you type into a generator — WiFi passwords, links, contact details, coordinates, messages — is encoded into a QR code by JavaScript running on your own device. Your inputs are never transmitted to us to make a code: the page performs no network request containing them, they are not logged, and closing the tab discards them. This applies equally to the live preview, the PNG/SVG downloads, copying, sharing, and printing.
2. The device library stays on your device
"Save to this device" stores the code in your browser's own IndexedDB storage. That data never leaves your device: we cannot see, access, or recover it. You control it entirely — delete individual codes on the My codes page, export or import it as a JSON file, or wipe it by clearing the site's data in your browser. Note that browsers may evict site storage themselves (Safari deletes it after seven days without visiting); the export button exists so you can keep your own backup.
3. Optional accounts and the account library
Creating an account is optional and never required to generate or download codes. If you create one, we process:
- Your email address and password credentials for sign-in;
- The QR codes you explicitly save to your account — their content, title, and styling. Nothing is saved automatically, and the generator shows an explicit warning before the first account save of sensitive content (WiFi passwords, contact cards).
This data is stored with our database provider, Supabase, acting as a processor, protected so that only your authenticated account can read your rows. Passwords are handled by Supabase's authentication service and are never visible to us in plain text. When you sign in, authentication session tokens are kept in your browser's local storage strictly to keep you signed in — they are not used for tracking.
Deletion is under your control, and works like this today:
- Individual saved codes — delete them any time on the My codes page; deletion removes the row from the database.
- All saved codes at once — the self-serve "Delete all my saved codes" button on the account page.
- The account itself (your email and sign-in) — request deletion via the contact page from your account's email address. This last step is a manual request because the site runs without its own server, and deleting authentication records safely requires verifying the request outside the browser. We action such requests promptly.
4. Technical hosting data
GenerateQRCodes.net is hosted on Vercel. Like virtually all web hosting, serving pages involves processing technical request data such as your IP address, browser user-agent, and requested URLs, which may appear in short-lived infrastructure logs used for security, abuse prevention, and operations. This processing is performed by the hosting provider as part of delivering the site; the payloads of your QR codes are never part of it, because they never leave your browser. See Vercel's privacy policy for their practices.
5. Cookies, local storage, and today's third-party scripts: none beyond the above
The generators work without cookies. The site currently loads no third-party analytics scripts, no advertising scripts, and no tracking pixels. Browser storage is used for exactly two things, both first-party and functional: the device library described in section 2, and — only if you sign in — the Supabase authentication tokens described in section 3.
6. Advertising (not active today; disclosed in advance)
To keep the tools free, GenerateQRCodes.net may in the future display advertising provided by Google AdSense. No advertising is served today and no advertising code loads. If ads are enabled, this policy will be updated first, and where consent rules apply, a consent dialog will govern which optional technologies may run before any personalized advertising is shown. When active, Google and its partners would process technical data (such as IP address and page context) as described in Google's advertising policies and Google's privacy policy.
7. Analytics (not active today)
No analytics service currently runs on this site. If aggregate usage measurement is added later, it will be limited to coarse interaction events (for example, "a code was generated"), will never include the text you typed or the contents of any code, and will be disclosed here with the consent treatment it requires.
8. Third parties, summarized
- Vercel — hosting and content delivery (always).
- Supabase — authentication and account-library storage, as processor (only if you create an account).
- Google AdSense — advertising (not active today; see section 6).
GenerateQRCodes.net does not sell personal information, and does not share it with anyone beyond the processors listed above.
9. Data retention
Anonymous use leaves nothing with us to retain: generator inputs never reach our servers, and the device library is on your device. Account data — your email, credentials, and saved codes — is retained while the account exists and deleted as described in section 3. Technical hosting logs are retained according to Vercel's published retention practices.
10. Your rights and contact
Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict the processing of personal data. For account data we can act directly: the deletion routes in section 3 are available to everyone without a formal request, and access or correction requests can be made via the contact page. For hosting-level technical data we will point you to the correct controller and assist where we can.
11. Changes to this policy
This policy is updated whenever the site's actual behavior changes — for example, if advertising or analytics are enabled. The date at the top reflects the latest revision.