How QRocodile handles your data – short version: it stays on your device.
Philipp Katz, Daniel Esser, Norbert Sroke Weinbergstraße 64 01129 Dresden Germany Email: hello@qrocodile.io (Information pursuant to Art. 13 GDPR)
QRocodile runs entirely in your browser. Your QR code content – URLs, WiFi passwords, contact details, or any other data you enter – is never sent to our servers. Everything is processed locally on your device. We do not collect, store, or process any personal data through the QR code generator.
We do not use cookies, tracking pixels, or any form of user tracking. There are no session cookies and no third-party trackers on this website. Our analytics tool (Umami) is cookieless and does not track individual users.
You can use all features without creating an account. We do not store any personal information because we never ask for it.
This website is hosted on servers in Germany (Hetzner Cloud). When you visit the website, server log files are automatically collected: – IP address (anonymized) – Date and time of access – Page visited – Browser type and version – Operating system – Referrer URL Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security and stable operation of the website). Log files are automatically deleted after 14 days and are not shared with third parties.
We use Umami, a privacy-focused, self-hosted analytics tool. It collects anonymous page view data (pages visited, referrer, browser type, country) without cookies, without personal identifiers, and without tracking across sites. No IP addresses are stored. You cannot be identified from this data. The analytics server is self-hosted on our own infrastructure in Germany. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in analyzing website usage to improve our service). Since no personal data is processed, no consent is required.
All resources including fonts are hosted locally on our servers. Your browser does not connect to Google, Facebook, or any other third-party service.
When you contact us by email, the data you provide (email address, name, message content) will be stored to process your inquiry. This data will not be shared without your consent. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries).
The QR Code API is the one part of QRocodile that requires personal data. To issue an API key, we store your email address together with the key's cryptographic hash, its creation date, its last-used date, and a request counter. The key itself is never stored in a recoverable form. Your email address is used to issue and replace the key, to attribute and limit usage, and to contact you about the API (for example about limits or breaking changes). We do not send marketing email and do not share the address. During signup we also store a short-lived verification code (hashed) that is deleted as soon as it is used, and in any case within 24 hours. Requests to the API are logged as metadata only — key identifier, timestamp, output format and size. The content you encode into a QR code is not stored. Legal basis: Art. 6(1)(b) GDPR (performance of a contract — providing the API you signed up for) and Art. 6(1)(f) GDPR (legitimate interest in preventing abuse of a free service). Retention: for as long as the key exists. Write to hello@qrocodile.io to have your key revoked and your address deleted; we do this promptly and it removes your access to the API.
You have the following rights regarding your personal data: – Right of access (Art. 15 GDPR) – Right to rectification (Art. 16 GDPR) – Right to erasure (Art. 17 GDPR) – Right to restriction of processing (Art. 18 GDPR) – Right to data portability (Art. 20 GDPR) – Right to object (Art. 21 GDPR) The QR code generator itself collects no personal data, so these rights apply to data from direct communication (e.g., emails) and to QR Code API keys (see above). Contact us at hello@qrocodile.io.
You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data. The competent authority depends on the state (Bundesland) in which the data controller is located.
We may update this privacy policy from time to time. Changes will be reflected on this page. Last updated: May 2026.