Pixqode Privacy Policy
Effective 22 September 2026. This policy covers the Pixqode: QR & Barcode Scanner app for iOS and Android and the website pixqode.betheapp.com. It says exactly what the app sends, to whom, for how long it is kept, and how to use your rights. It matches the App Store privacy labels and the Google Play Data safety form; if one of them changes, all three change together.
1. Who is responsible
The controller is BeInMedia, the publisher of Pixqode. For every privacy question or request write to pixqode@betheapp.com. We answer within 30 days at the latest.
2. The short version
- Your scans, your scan history, your folders and the QR codes you create stay on your device. They are not sent to us.
- The only permission the app asks for is the camera, and only to read codes. It does not ask for your location, contacts, photos or notifications.
- There is no advertising identifier: the Android app does not declare AD_ID, the iOS app does not read the IDFA, and there is no cross-app tracking. We do not sell data and we do not show personalised ads.
- Every install gets a random user ID from Firebase Authentication, without a name, email or password. Under it we keep your purchase status and basic usage statistics (first and last seen, app version, platform, OS version, locale). We also collect anonymous usage events and crash reports. None of it contains what you scan.
- Signing in is optional. You can link a Google or Apple account to your user ID; we then also keep the email address that provider shares with us. Encrypted sync is available to signed-in users who give separate consent. You can delete the account in the app or on the web at pixqode.betheapp.com/delete-account.
3. What stays on your device
The contents of a code, the links you scan, your history, folders, created codes and settings are stored only on your device. The "Delete all my data" button in Settings erases them in one step. Uninstalling the app erases them too. We cannot see or recover them.
4. What we process and why
| Data | Purpose | Legal basis (GDPR) | Retention |
|---|---|---|---|
| Anonymous usage events (app opened, scan started, scan succeeded or failed, purchase screen shown) - never the content of a code or a link | Understand which features work and fix what does not | Legitimate interest, Art. 6(1)(f) | 2 months, then deleted |
| Crash and performance reports - no personal identifier, no scan content | Find and fix crashes | Legitimate interest, Art. 6(1)(f) | 90 days |
| A Firebase user ID, created anonymously when the app first starts, and the sign-in provider you linked (Google or Apple), if any | Identify your installation to our server, so that purchases and sync belong to you | Contract, Art. 6(1)(b) | Until you delete the account |
| Your email address, only if you sign in with Google or Apple and the provider shares it | Show which account you are signed in with, and answer account requests | Contract, Art. 6(1)(b) | Until you delete the account |
| Usage statistics under your user ID: first and last seen, app version, platform, OS version and locale | Keep the server compatible with the app versions in use, and count active installations | Legitimate interest, Art. 6(1)(f) | Until you delete the account |
| Purchase and subscription status, and the store's purchase token, under your user ID | Check your purchase with Google Play or the App Store and unlock Pro for the person who paid | Contract, Art. 6(1)(b) | Until you delete the account; the stores keep their own payment records |
| A link you send to the deep link check (Pro only, only when you ask) | Follow redirects and check the site's reputation | Contract, Art. 6(1)(b) | Not stored and not logged; discarded once the answer is returned |
| A barcode number you look up (only when you ask) | Show product information | Contract, Art. 6(1)(b) | A "not found" answer is cached for 7 days; the barcode is not linked to you |
| Encrypted sync data (optional: signed-in Pro users who turn sync on) | Syncing your history between your devices. It is encrypted on your device with a key made from your sync passphrase, which never leaves your device | Consent, Art. 6(1)(a) | Until you delete the account, which deletes it at once |
| Server security logs (IP address, time, request path), handled by Cloudflare when your device connects to our server | Protect the service from abuse, and deliver it | Legitimate interest, Art. 6(1)(f) | Our server keeps no request logs; Cloudflare keeps its own under its terms |
5. Sub-processors
We use these providers, each under a data processing agreement, and no others:
| Provider | What it does for us | Data it receives | Location |
|---|---|---|---|
| Google Firebase Analytics | Anonymous usage events, with advertising ID collection turned off | Usage events, device model, OS version, country | EU and USA |
| Google Firebase Crashlytics | Crash reports | Stack trace, device model, OS version | EU and USA |
| Google Firebase Remote Config | Feature settings delivered to the app | An installation ID, app version | EU and USA |
| Google Firebase Authentication | Your user ID, and signing in with Google or Apple | A user ID, the sign-in provider, your email address if you sign in, IP address | EU and USA |
| Cloudflare (Workers, D1) | Hosting our server and its database | User ID, email address, usage statistics, purchase status, encrypted sync data, IP address | Cloudflare's global network; the database location is set when the database is created |
| Google Web Risk | Reputation check inside the Pro deep link check | The link being checked | EU and USA |
| Open Food Facts | Product information for a barcode | The barcode number only | France |
| Apple App Store and Google Play | Payment, billing and refunds, as independent controllers | Your store account's payment data, which we never see | Their own terms |
6. Transfers outside the EU
Some providers above process data in the USA. Those transfers rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses. You can ask us for a copy of the safeguards.
7. How long we keep data
- Usage events: 2 months.
- Crash reports: 90 days.
- Server security logs: our server keeps none; Cloudflare's own logs follow its terms.
- Links sent to the deep link check: not stored.
- Purchase status and usage statistics: until you delete the account.
- Account (your user ID, and your email address if you signed in): until you delete it. Deleting it removes all its data from our server at once, including encrypted sync data, and deletes the Firebase user. We do not yet delete unused anonymous user IDs automatically; you can ask us to at any time.
8. Your rights under the GDPR
Wherever you live, you can use these rights by writing to pixqode@betheapp.com. We answer within 30 days.
- Access (Art. 15): a copy of the data we hold about you.
- Rectification (Art. 16): correct inaccurate data.
- Erasure (Art. 17): delete your data. The account can be deleted in the app under Settings → Account, or without the app at pixqode.betheapp.com/delete-account.
- Restriction (Art. 18): limit how we process your data.
- Portability (Art. 20): receive your data in a machine-readable format. Your history can also be exported to CSV in the app.
- Objection (Art. 21): object to processing based on legitimate interest, including the usage events.
- Withdrawing consent (Art. 7(3)): turn sync off at any time; this does not affect what was done before.
- Complaint (Art. 77): you can complain to your local data protection authority.
9. Children
Pixqode is not directed at children under 13 (under 16 in the EU where national law sets that age) and we do not knowingly collect their data. If you believe a child created an account, write to us and we will delete it.
10. Security
All traffic is encrypted with TLS 1.2 or later, and this site enforces HTTPS with HSTS. Sync data is encrypted on your device before it is uploaded, with a key made from your sync passphrase, so our server stores only data it cannot read. Our database at Cloudflare is encrypted at rest.
11. Changes to this policy
When this policy changes we update the date at the top, and we tell you in the app before a change that affects what we collect takes effect.
12. Contact
BeInMedia - Pixqode, pixqode@betheapp.com. See also our Terms of Use and the 特定商取引法に基づく表記.