QRone Privacy Policy
Effective 29 September 2026 · Sagar Singh (developer “Myx”)
At a glance
- Scanning and text recognition happen on your device. Camera images are not uploaded.
- Without an account, your history is stored only on your phone.
- With an account, your history and dynamic QR codes are stored in the cloud.
- QrOne shows Google AdMob ads.
1. Who is responsible
QrOne is an app for scanning and creating QR codes and barcodes. It is developed and published by Sagar Singh, an individual developer based in India, under the developer name “Myx”. QrOne is not published by a company.
In this policy, “I”, “me” and “my” mean Sagar Singh. I decide how the information described here is used and I am responsible for it. Under India’s Digital Personal Data Protection Act, 2023 I am the “data fiduciary”, and under the GDPR I am the “data controller”. I am also the grievance contact for QrOne.
2. Camera and scanning
QrOne uses the camera to scan codes and, optionally, to recognise text. Both run on your device using Google ML Kit, and camera images are not sent to me. You can also pick an image from your gallery to scan.
3. History
- Without an account: your last 100 scanned and generated items are stored in a local database on your phone.
- With an account: your history is stored in Firebase Cloud Firestore so you can see it on other devices. Only your account can read it.
History can include whatever the codes contain, such as links, text, contact cards, Wi-Fi names and passwords, and calendar events.
4. Account (optional)
You can create an account with your name, email address and password. Accounts are handled by Firebase Authentication, and passwords are never visible to me.
5. Dynamic QR codes
If you create a dynamic QR code, its destination link, your account ID, a scan count and the time of the last scan are stored in Firestore. When someone scans the code, a redirect service hosted on Firebase counts the scan and forwards them to your link. I do not record who scanned it. The hosting provider may keep standard request logs, including IP address, for security and operation.
6. Advertising
QrOne shows ads from Google AdMob. AdMob may use your device’s advertising ID, IP address and device information to show and measure ads, including personalised ads. On iOS it follows your App Tracking Transparency choice. You can limit personalised ads in your device settings or at Google Ads Settings.
7. Other permissions
- Photos: to save generated codes to your gallery and to scan images you pick.
- Wi-Fi: to connect to a network from a scanned Wi-Fi QR code, only when you choose to.
8. Service providers
- Firebase: authentication, cloud database, hosting and the dynamic QR redirect service, provided by Google.
- Google AdMob: advertising.
- Google: on-device ML Kit scanning and text recognition, and Google Play distribution.
- Apple: App Store distribution.
I do not sell, trade or rent your personal information. I may disclose it if the law requires.
9. How long data is kept and how to delete it
- Local history stays until you delete items, clear history or uninstall the app.
- Cloud history and dynamic codes are kept while your account exists. You can delete individual items and dynamic codes in the app.
- You can delete your account in Profile → Delete Account. To make sure your cloud history and dynamic codes are removed too, delete them first or contact me and I will erase them.
10. Your rights and choices
You can view and delete your history, manage dynamic codes, revoke camera and photo permissions and delete your account inside the app.
Depending on where you live, you may also have the right to:
- access the personal data I hold about you and get a copy in a portable format;
- correct information that is wrong or incomplete;
- have your data erased;
- restrict or object to certain processing;
- withdraw consent where processing is based on consent;
- nominate someone to exercise your rights if you die or become unable to (India).
To make a request, contact me. I will reply within 30 days and may need to confirm that the data is yours first. If you are not satisfied with my answer, you can complain to the Data Protection Board of India or, in the EEA or UK, to your local data protection authority.
11. Security
Cloud data is encrypted in transit, and Firestore security rules limit each user’s history and dynamic codes to that user. No system is completely secure, but if a breach affects your data I will notify you and the relevant authorities where the law requires.
12. Children
QrOne is not intended for anyone under 13. I do not knowingly collect personal information from anyone under 13. If you believe a child has provided information through QrOne, contact me and I will delete it.
13. Where your data is processed
I am based in India. The service providers named above may store or process data in other countries, including the United States and the European Union. Where data leaves the EEA or UK, the transfer relies on safeguards such as the European Commission’s Standard Contractual Clauses in the provider’s terms.
14. Changes to this policy
If I change this policy, I will update the date at the top of this page. For significant changes I will also let you know in QrOne before they take effect.
15. Contact
For questions about this policy, data requests or complaints, contact me by email. I built the app, so I will answer your message myself.
Sagar Singh (developer “Myx”), India