QR Scanner & Barcode Reader

Privacy Policy

This policy explains how the Android app handles camera input, scanned content, local history, generated QR codes, product analytics, crash diagnostics, advertising and regional privacy choices.

Effective and last updated: September 5, 2026

1. Scope and developer contact

This Privacy Policy applies to QR Scanner & Barcode Reader, Android package com.kodashield.qr.barcode.scanner (the “App”). “We”, “our” and “developer” refer to the App's development team.

Privacy questions can be sent to easygamedevs@gmail.com. The App does not require an account, and we do not operate a proprietary server or cloud service that receives your scanned barcode contents, history, favorites, notes or generated QR contents.

Summary: Camera images and barcode values are analyzed on your device. Scan history and preferences are stored in the App's private local storage. The App does not send raw scanned or generated content to analytics or crash reporting. Data handled separately by Google ML Kit, Firebase, Google Mobile Ads and the User Messaging Platform is described below.

2. Information handled by the App

The App handles information only when needed to scan, organize, generate or act on a code.

InformationPurposeHandling and storage
Live camera framesDetect and decode supported QR and barcode formats.Processed in memory on the device. The App does not save camera frames or upload them to our server.
Images you select or share into the AppDecode a code from an existing image.The App reads only the item you selected or shared. It is processed locally and is not copied into a proprietary cloud.
Text you paste from the clipboardInterpret content without using the camera.Read only after you choose Paste. The App can also write a result to the clipboard when you choose Copy or enable its optional auto-copy behavior.
Decoded value, format, content type, date, scan count, favorite status, title and noteBuild the searchable history and provide content-aware actions.Stored in the App's private local storage. You can change the retention period, export records or delete them.
QR creator entries such as a URL, Wi-Fi details, contact details, message, event, coordinates or textCreate the QR code you request.Processed locally. A PNG is stored outside private app storage only when you explicitly save it; temporary copies may be created in app cache when you share.
Language, theme, palette, haptics, scan mode, history retention and other preferencesRemember how you configured the App.Stored locally in the App's private preferences.
History import and export filesLet you move or back up your records in supported formats.Imported only from a file you select. Exported files go to the destination or receiving app you choose.

Android backup is disabled for the App. The App does not request permission to read your contacts or precise location. Contact and location QR values are based on information you enter or scan.

3. On-device scanning and link-safety signals

The production App uses the bundled Google ML Kit barcode model and a ZXing fallback. Barcode image input and decoded results are processed on the device and are not sent to our servers. Scanning remains available without an internet connection.

For web links, the App performs a local heuristic inspection. It can highlight indicators such as unencrypted HTTP, a direct IP address, a local address, an unusual port, a misleading or shortened destination, and a link to an executable file. The App does not submit the scanned URL to a remote reputation service.

Important: These signals are informational. They cannot prove that a link is safe, malicious or trustworthy. Review the exact destination and use your own judgment before opening it.

4. Actions and third-party apps you choose

The App does not automatically open a website, send a message, place a call, connect to Wi-Fi, save a contact, add an event, start a payment or activate an eSIM. It first shows the decoded content and waits for your action.

If you choose an action, Android can pass the relevant value to the browser, phone, email, messaging, maps, calendar, contacts, Wi-Fi settings, payment, eSIM or another compatible app. That receiving app or service processes the information under its own privacy policy. Product searches similarly open only when you request them.

If you share a result, safety report, QR image or history export, the selected receiving app obtains the content you chose to share. We do not control how that third party retains or uses it.

5. Google ML Kit diagnostics

Google states that ML Kit processes feature input such as images and resulting outputs on the device and does not send that input or output to Google servers. ML Kit may nevertheless contact Google for updates, compatibility information and operational metrics.

According to Google's ML Kit Android disclosure, the SDK can collect device and app information, per-installation identifiers not intended to identify a person or physical device, performance metrics, API configuration, input/output sizes, feature version, event types and error codes for diagnostics and usage analytics. Google states that this data is encrypted in transit and is not transferred to third parties.

Learn more in Google's ML Kit Terms & Privacy and ML Kit Android data disclosure.

6. Firebase Analytics and Crashlytics

When enabled in a distributed build, the App uses Google Analytics for Firebase to understand aggregate feature use and Firebase Crashlytics to diagnose crashes, non-fatal errors and application-not-responding events. These services can process app interactions, app and device information, installation identifiers, diagnostics, crash stack traces and related application state under Google's terms.

Privacy-limited custom events

Our custom analytics events are deliberately limited to categorical or numeric product metadata, such as the screen viewed; scan source, mode, decoder, barcode format and broad content category; local safety classification and signal count; batch state; whether history was saved; result actions; generated QR category, quality and customization state; history actions and item counts; and enabled or disabled settings.

Never included in our custom telemetry: the decoded barcode or QR value; a URL, hostname or search query; a product number; Wi-Fi network name or password; contact, email, phone, payment, event or location details; generated QR payloads; notes; file names or file locations; clipboard text; or camera and selected images.

Crashlytics receives standard crash reports. The App adds only limited context such as its current screen, scanner mode, batch state, app language, build type and version. Non-fatal reports created by the App replace exception messages and causes with a generic operation and error-class label before submission, because original messages can unexpectedly contain user content.

Google states that Firebase data is encrypted in transit. Details, service-specific data disclosures and user controls are available in Firebase's Google Play data disclosure guide and Firebase Privacy and Security.

7. Advertising, consent and Google data

The App uses Google Mobile Ads (AdMob) for banner, interstitial and app-open advertisements. Google reports that the Mobile Ads SDK automatically collects and shares these data types for advertising, analytics and fraud prevention:

  • IP address, which may be used to estimate a device's general location;
  • user product interactions, including app launches, taps and ad interactions;
  • diagnostic information about App and SDK performance; and
  • device and account identifiers, including the Android advertising ID, app set ID and other applicable device identifiers.

Google states that Mobile Ads SDK data is encrypted in transit. Details and available controls are described in Google's Mobile Ads SDK data disclosure and Privacy Policy.

Consent and privacy options

The App integrates Google's User Messaging Platform (UMP). It updates consent information at launch, displays a configured consent form when required, and requests ads only after UMP reports that ads may be requested. Where Google reports that a privacy-options entry point is required, Settings includes an Advertising privacy choices action so you can revisit the available choices.

Depending on your region, selections and Google's serving rules, ads may be personalized, non-personalized, limited or restricted to technical delivery. Non-personalized ads may still use limited identifiers or local storage for functions such as frequency capping, security and aggregated reporting.

8. Android permissions and capabilities

  • Camera: used only to display the live preview and scan codes after you grant permission.
  • Internet and network state: used by Google SDKs for consent, advertising, operational services and diagnostics. Core scanning and local link inspection do not require a network connection.
  • Vibration: provides optional haptic feedback after a successful scan and for supported interface actions.
  • Legacy external storage write access (Android 9 and earlier only): used when you ask to save a generated QR image or export data on older Android versions.

The system photo picker lets you choose a specific image without granting broad photo-library access on supported Android versions. The Quick Settings tile is only a shortcut that opens the scanner. The App does not read notifications.

9. Retention and deletion

The local history is limited to 1,000 records. You can retain non-favorite records forever or automatically remove them after 1, 7 or 30 days. Favorite records are protected from age-based cleanup. You can delete individual records or all history inside the App.

Preferences remain until changed, App storage is cleared or the App is uninstalled. Temporary shared files are held in app cache and can be removed by Android or when App storage is cleared. Saved QR images and files exported to a user-selected or public location remain there until you delete them from that location.

You can remove all private local data through the App's delete controls, Android Settings → Apps → QR Scanner & Barcode Reader → Storage → Clear storage, or by uninstalling the App. Because we do not maintain a scanner account or proprietary scan database, there is no separate server-side scan profile for us to delete.

Firebase Analytics event retention is governed by the configured Analytics-property retention setting and Google's terms; aggregated reporting may follow different retention rules. Google determines retention for information processed by ML Kit, Mobile Ads and UMP. Firebase states that Crashlytics crash reports and associated identifiers are retained for 90 days before the deletion process begins. Use the available Google and Android privacy controls or contact Google for information controlled by Google.

10. Security

Scan records and preferences use Android app-private storage, Android backup is disabled, and exported content is created only in response to your action. No storage or transmission method can be guaranteed completely secure. Protect access to your device and review sensitive information before copying, exporting or sharing it.

11. Your choices and rights

  • Deny camera permission and use selected images, shared images or pasted text instead.
  • Choose whether haptics, automatic clipboard copying, history retention and other optional behaviors are enabled.
  • Review every result and decline any external action.
  • Delete, export or import local history using the App's controls.
  • Open Advertising privacy choices when that option is required and available through UMP.
  • Reset or delete the Android advertising ID and manage ad privacy in Android settings where supported.
  • Contact us to ask a privacy question or exercise rights available under applicable law.

Because we do not keep an account database for scan content, we may have no server-side personal record that can be identified from an email request. Third-party providers handle requests for data they control under their own procedures.

12. Children's privacy

The App is a general-audience utility and is not directed to children under 13 or the minimum digital-consent age in their country. We do not knowingly create child profiles or collect children's scan history through an account or proprietary server. Parents and guardians should supervise device use and configure Google Play, Android and advertising controls appropriate for their family.

13. This website

This is a static product and support website. It contains no proprietary analytics, advertising scripts, tracking pixels, account registration or contact forms. The home-page language selector can save only the chosen language code in your browser's local storage. External links and email actions are handled by the service you select.

14. Changes to this policy

We may update this policy when App functions, SDKs, legal requirements or data practices change. The revised version will be published on this page with a new effective date. Material changes may also be communicated in the App or store listing when appropriate.

15. Contact

For privacy or support questions:

Email: easygamedevs@gmail.com
App: QR Scanner & Barcode Reader
Android package: com.kodashield.qr.barcode.scanner