Pixqode

Pixqode Privacy Policy

Effective 22 September 2026. This policy covers the Pixqode: QR & Barcode Scanner app for iOS and Android and the website pixqode.betheapp.com. It says exactly what the app sends, to whom, for how long it is kept, and how to use your rights. It matches the App Store privacy labels and the Google Play Data safety form; if one of them changes, all three change together.

1. Who is responsible

The controller is BeInMedia, the publisher of Pixqode. For every privacy question or request write to pixqode@betheapp.com. We answer within 30 days at the latest.

2. The short version

3. What stays on your device

The contents of a code, the links you scan, your history, folders, created codes and settings are stored only on your device. The "Delete all my data" button in Settings erases them in one step. Uninstalling the app erases them too. We cannot see or recover them.

4. What we process and why

DataPurposeLegal basis (GDPR)Retention
Anonymous usage events (app opened, scan started, scan succeeded or failed, purchase screen shown) - never the content of a code or a linkUnderstand which features work and fix what does notLegitimate interest, Art. 6(1)(f)2 months, then deleted
Crash and performance reports - no personal identifier, no scan contentFind and fix crashesLegitimate interest, Art. 6(1)(f)90 days
A Firebase user ID, created anonymously when the app first starts, and the sign-in provider you linked (Google or Apple), if anyIdentify your installation to our server, so that purchases and sync belong to youContract, Art. 6(1)(b)Until you delete the account
Your email address, only if you sign in with Google or Apple and the provider shares itShow which account you are signed in with, and answer account requestsContract, Art. 6(1)(b)Until you delete the account
Usage statistics under your user ID: first and last seen, app version, platform, OS version and localeKeep the server compatible with the app versions in use, and count active installationsLegitimate interest, Art. 6(1)(f)Until you delete the account
Purchase and subscription status, and the store's purchase token, under your user IDCheck your purchase with Google Play or the App Store and unlock Pro for the person who paidContract, Art. 6(1)(b)Until you delete the account; the stores keep their own payment records
A link you send to the deep link check (Pro only, only when you ask)Follow redirects and check the site's reputationContract, Art. 6(1)(b)Not stored and not logged; discarded once the answer is returned
A barcode number you look up (only when you ask)Show product informationContract, Art. 6(1)(b)A "not found" answer is cached for 7 days; the barcode is not linked to you
Encrypted sync data (optional: signed-in Pro users who turn sync on)Syncing your history between your devices. It is encrypted on your device with a key made from your sync passphrase, which never leaves your deviceConsent, Art. 6(1)(a)Until you delete the account, which deletes it at once
Server security logs (IP address, time, request path), handled by Cloudflare when your device connects to our serverProtect the service from abuse, and deliver itLegitimate interest, Art. 6(1)(f)Our server keeps no request logs; Cloudflare keeps its own under its terms

5. Sub-processors

We use these providers, each under a data processing agreement, and no others:

ProviderWhat it does for usData it receivesLocation
Google Firebase AnalyticsAnonymous usage events, with advertising ID collection turned offUsage events, device model, OS version, countryEU and USA
Google Firebase CrashlyticsCrash reportsStack trace, device model, OS versionEU and USA
Google Firebase Remote ConfigFeature settings delivered to the appAn installation ID, app versionEU and USA
Google Firebase AuthenticationYour user ID, and signing in with Google or AppleA user ID, the sign-in provider, your email address if you sign in, IP addressEU and USA
Cloudflare (Workers, D1)Hosting our server and its databaseUser ID, email address, usage statistics, purchase status, encrypted sync data, IP addressCloudflare's global network; the database location is set when the database is created
Google Web RiskReputation check inside the Pro deep link checkThe link being checkedEU and USA
Open Food FactsProduct information for a barcodeThe barcode number onlyFrance
Apple App Store and Google PlayPayment, billing and refunds, as independent controllersYour store account's payment data, which we never seeTheir own terms

6. Transfers outside the EU

Some providers above process data in the USA. Those transfers rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses. You can ask us for a copy of the safeguards.

7. How long we keep data

8. Your rights under the GDPR

Wherever you live, you can use these rights by writing to pixqode@betheapp.com. We answer within 30 days.

9. Children

Pixqode is not directed at children under 13 (under 16 in the EU where national law sets that age) and we do not knowingly collect their data. If you believe a child created an account, write to us and we will delete it.

10. Security

All traffic is encrypted with TLS 1.2 or later, and this site enforces HTTPS with HSTS. Sync data is encrypted on your device before it is uploaded, with a key made from your sync passphrase, so our server stores only data it cannot read. Our database at Cloudflare is encrypted at rest.

11. Changes to this policy

When this policy changes we update the date at the top, and we tell you in the app before a change that affects what we collect takes effect.

12. Contact

BeInMedia - Pixqode, pixqode@betheapp.com. See also our Terms of Use and the 特定商取引法に基づく表記.