The short version
What you put into a QR code is never sent anywhere. Text, links, Wi-Fi passwords, UPI IDs, contact details, message bodies, coordinates — all of it is encoded on your own device and never transmitted to us or to anyone else. There is no upload path for it in either the website or the app.
We do collect anonymous usage statistics and crash reports, and the Android app shows advertising. Those are described in full below.
Who we are
QR Generator (this website, qrlite.app) and QR Generator Lite (the Android
app, package com.abln.qrgenerator) are made by ABLN Technologies, the data
controller for the purposes of this policy. Contact:
abln.technologies@gmail.com.
What we never collect
The content of any code you generate. That includes the network name and passphrase on the Wi-Fi page, the UPI ID, payee name, amount and note on the payments page, every field on the contact page, the recipient and body of an SMS or email, event details, and map coordinates.
We also have no accounts, so we hold no names, email addresses, passwords or profiles. We do not sell data, and we do not share it with anyone beyond the service providers listed below.
You can verify the first claim yourself: open your browser's developer tools, switch to the Network tab, and generate a code. No request carries what you typed.
What we do collect
Anonymous usage statistics
Both the website and the app use Google Analytics for Firebase to count how the tool is
used. We record that a code was generated, copied, downloaded or shared, and
which kind it was — url, wifi, upi,
vcard, and so on. The content is deliberately never attached to these
events.
Google Analytics additionally collects, by default: an approximate location derived from your IP address (typically city level — your full IP address is not retained by us), device or browser type, operating system, language, screen size, and referring page. It stores a randomly generated identifier on your device to tell repeat visits apart. This identifier is not linked to your name or to any account.
Crash reports (Android app only)
The app uses Firebase Crashlytics. When it crashes, we receive the stack trace, the
device model, the operating system version, and a short trail of the last actions taken
— recorded as event names such as qr_generated(url), never as the content
of a code.
Feature flags
Both use Firebase Remote Config to turn features on and off without shipping an update. This assigns a Firebase installation identifier to your copy of the app or browser so it can fetch its configuration. No personal data is sent to retrieve it.
Advertising (Android app only)
The Android app displays banner advertising through Google Ad Manager. Google may use your device's advertising identifier, coarse device and network information, and your interactions with an ad to select and measure advertising. Google's handling of that data is governed by its own policies, linked below.
The website shows no advertising and contains no advertising code.
Stored on your device only
The website remembers your light or dark theme choice in your browser's local storage. The app stores the same choice locally. Neither ever leaves the device and neither is readable by us.
The map on the location page
One page needs calling out. The map picker on the location page is the only part of the website that contacts a server on your behalf.
Opening the map requests map tiles from the OpenStreetMap Foundation, and searching for a place sends your search text to their Nominatim service. Those requests reveal roughly which part of the world you are looking at, and are handled under OpenStreetMap's privacy policy. Pressing “use my location” asks your browser for your position; it is used to place the pin and is not transmitted to us.
None of this happens unless you open the map. Paste coordinates instead and the page makes no external map requests at all. Either way, the coordinates you settle on are encoded locally like everything else.
Who processes data for us
- Google — Firebase Analytics, Crashlytics, Remote Config, Hosting, and Ad Manager for the Android app. See the Google Privacy Policy and Firebase privacy documentation.
- OpenStreetMap Foundation — map tiles and place search, only when you open the map picker.
These providers operate internationally, so the data described above may be processed outside your country, including in the United States.
How long it is kept
Analytics data is retained according to our Google Analytics configuration, which is set to the standard retention period; aggregate reports may be kept longer. Crash reports are retained by Crashlytics for its standard period, currently 90 days. We hold no database of our own, because there is nothing in it to hold.
Your choices
On the web: a tracker-blocking extension or browser setting will stop the analytics script loading, and the generator will continue to work normally — that behaviour is deliberate. Clearing site data removes the analytics identifier and your theme preference.
On Android: Settings › Privacy › Ads lets you reset or delete your advertising ID and opt out of ad personalisation. Uninstalling the app removes its local data.
Depending on where you live — under India's Digital Personal Data Protection Act, the UK and EU GDPR, or similar laws — you may have the right to access, correct, or erase personal data we hold about you, and to object to its processing. Because we hold no accounts and no directly identifying data, in practice such a request usually concerns the analytics identifier on your device, which you can clear yourself as described above. Write to abln.technologies@gmail.com and we will help.
Children
Neither the website nor the app is directed at children under 13, and we do not knowingly collect personal data from them.
Changes
If this policy changes materially, we will update the date at the top and, for changes affecting the Android app, note it in the release notes. This version is dated 6 September 2026.