Skip to main content
OpenQRS
Tools
Current language: English
100% Private

Privacy statement

Last updated

What happens to what you type

Whatever you type into a generator on this site — a Wi-Fi password, a phone number, a wallet address, the contents of a contact card — stays in the page. JavaScript running in this tab turns those values into the payload string and encodes that string into a QR symbol. The preview you see and the file you export are both produced on your own device.

OpenQRS does not transmit that input, because there is nowhere for it to be transmitted to. The deployment is a set of static files. There is no upload endpoint, no API, no database and no server-side function anywhere in it, and the site is served without any server code at all.

The methodology page gives you the exact steps to check this in your own browser rather than take the paragraph above on trust.

The logo image

A tool that offers a centre logo reads the image you choose with the browser'sFileReader, inside this tab, into a data: URL held in memory. That URL is drawn into the preview and embedded into the exported file on your device. The image is never sent anywhere, and a logo hosted at a web address is not accepted — a remote image would mean a request at generation time and is blocked by the site's Content Security Policy in any case.

What is stored in your browser

Two things, both of which belong to the site rather than to you:

  • One preference, in localStorage: the colour theme, under the keyoq-theme, holding light or dark. That is the only key the site writes. It is not an identifier, nothing else reads it, and it never travels anywhere. Style choices you make in a workspace — colours, shapes, sizes — are held in the page while the tab is open and are not stored at all.
  • The site's own files, in the cache a service worker manages: the pages this device has fetched, and the stylesheets, scripts and other files those pages load. It holds nothing but files served from this domain, and it is what lets you open a page again after your connection has dropped. A page that has never been fetched here is not in it and is not available offline. A tab you already have open needs nothing from the cache at all, because a code is built by JavaScript that is already running in it.

Nothing you type is written to either. Form values, the logo image and the generated symbol live in the tab's memory and are gone when you close it. There is no history, no saved list of codes and no recovery, and nothing to log in to, because there is no account.

Analytics and advertising

At launch the site loads no analytics and no advertising: no tracking script, no tag manager, no pixel, no session recording and no consent platform, because there is nothing to consent to. The flags that would enable them are fixed to off in the source and no such markup or script is included in what is published.

If advertising is ever enabled, two limits hold: it will never appear on these legal and transparency pages, and it will never appear inside the generator workspace itself. This statement will be updated and re-dated in the same release that changes anything here.

Error reports

No crash report, error report or diagnostic is sent, because no code path exists that could send one. When the engine refuses a payload or the browser cannot encode a format, the message is shown to you in the page and goes no further. It never contains what you typed.

Hosting

The static files are served by Cloudflare Pages. Like any web host, Cloudflare processes the network requests needed to deliver a page — which includes your IP address and the fact that a request was made — and its handling of those requests is governed by Cloudflare's own terms and is outside this operator's control. That is true of every website you visit, and it is stated here rather than glossed over. What Cloudflare never receives is the content of a form on this site, because that content is never part of a request.

What this statement cannot claim

This describes OpenQRS's own behaviour. It is not, and cannot be, a claim about anything in the list below, none of which any website controls:

  • browser extensions you have installed, which can read the contents of any page;
  • your operating system, which can see anything you type and any file you open;
  • your network operator, DNS resolver or workplace proxy, which can see that you visited this domain;
  • security software on your device that inspects pages or downloads;
  • where your browser saved an exported file, and who can read it there.

A QR code is a plain encoding

This is the part people are most often surprised by. A QR code is not a link to a secret; it is the data itself, written as a picture. Anyone who scans or photographs the symbol gets everything encoded in it, and no permission is asked and no record is made.

A Wi-Fi code taped to a wall hands the network name, the security type and the password to everyone who photographs the wall, including anyone in a photograph taken by someone else. The same applies to a phone number, a home address in a contact card, a discount code and a payment address. Print accordingly: privacy in the generator says nothing about privacy on paper.

Minimum age

The site is intended for people aged 16 and over. There is no account, no profile and no behavioural data about anyone, of any age, so there is no children's data to hold — the age applies to the responsibility for what you choose to encode and publish, not to a record kept about you.

Your data rights and how to exercise them

Colombia's data protection law gives you rights over personal data an organisation holds about you: access to it, correction of it, deletion of it, and knowing what it is used for. Those rights apply to ZENIT GROUP S.A.S. as they do to any operator. What makes them unusual here is that using this site creates nothing for them to apply to. No account, no profile, no identifier, no server-side record, so there is no file to request, correct, export or delete.

The two things that do exist are entirely under your own hand: clear the site's data in your browser settings to remove the preferences and the cached files described above, and delete any exported file yourself from wherever you saved it.

If you write to the operator, the address you write from and whatever you put in the message become personal data, processed for the single purpose of answering you. Ask for that correspondence to be deleted and it will be.

Operator and contact

OpenQRS is operated by ZENIT GROUP S.A.S., Cali,Colombia. Legal representative: Emilssen Rodríguez Ballesteros. Privacy questions go to info@zenitgroup.com.co, or by telephone on+57 314 729 1775. The full company block is on the about page.