Privacy
Last updated 10 October 2026.
Static QR generation happens in your browser. The payload, logo, and colors are not sent to create the image or the download.
If you create an account, QRNest stores your email, a scrypt password hash, your role, your plan, and whether the email is verified. Session cookies are httpOnly. A separate cookie holds the CSRF token the page must send back. Passwords are not stored in a recoverable form.
Templates store style settings. Content is stored only when you check the consent box. If you do not, a later export will not contain those field values.
Dynamic links store a title, a slug, and the destination URL. Each redirect stores the time and a daily HMAC of the visitor IP. The raw IP address and the user agent are not stored. Counts are shown to the link owner.
The server does not request the destination URL. It only redirects the visitor’s browser after checking that the destination is an http or https address and not a private or local host.
Contact messages store the name, email, and message you submit.
If Stripe is enabled, QRNest stores a customer id and subscription id returned by Stripe. Card numbers are entered on Stripe’s site, not here.
You can export or delete your account from the dashboard. Deletion removes the user, sessions, templates, dynamic links, scan events, and contact messages for that email. Audit records may keep the email so the operator can see that the deletion occurred.
Support staff can search accounts and open a legal request. Only an admin can fulfill it, and only after a justification is stored. The export contains stored records. It does not invent data that was never saved, and it omits password hashes, session tokens, and visitor hashes.
Questions go through the contact form.