メインコンテンツへスキップ
QR GUARDIAN

Legal · QR Guardian

プライバシーポリシー

最終更新
2026-08-15
Controller
Veritas Digital LLC
Location
USA

This document is published in English, which is its canonical and authoritative version. The heading and labels on this page appear in your selected language for convenience only.

Scope of this policy

This privacy policy covers two things: the QR Guardian Android application (“the app”) and this website, qr.veritasdigital.tech (“the site”). Both are operated by Veritas Digital LLC, the data controller for any processing described here. This policy is effective as of August 15, 2026.

The short version: the app needs no account, shows no advertising, keeps your scan history on your device, and — for every link you scan — automatically runs a small number of reputation and domain-age checks against public or Google-operated infrastructure, described precisely in Sections 3 and 5. The site uses no analytics and no marketing cookies. The rest of this document spells that out precisely.

What the app does

QR Guardian scans QR codes and barcodes and analyzes their content to detect phishing, malware and other risks before you open a link. A first layer of analysis runs entirely on your device, using no network at all. When the content is a URL, the app also automatically runs the network checks described in Section 5 — Google Safe Browsing, domain-age and certificate-history lookups, and shortener resolution — to strengthen the verdict. These checks are not currently optional or configurable in the app; there is no airplane-mode-only mode. The app requires no account and collects no identity data.

Data the app processes

The following categories describe everything the app touches. They mirror the Data Safety declaration on the app’s Google Play listing.

  • Scanned or shared URLs

    Handling
    Processed in transit for analysis. Never stored on our servers — we operate no server that keeps them.
    Shared with
    For every URL, automatically and without a separate prompt: the full URL is sent to Google Safe Browsing; the domain only is sent to the RDAP registration directory and looked up in public Certificate Transparency logs; and if the URL is a shortener, the app contacts the linked server(s) directly (up to 5 hops) to find the real destination. See Section 5 for exactly what each of these does.
    Purpose
    Threat verification — detecting phishing, malware and similar risks before you open a link.
  • NFC tag contents

    Handling
    Read only when you tap a tag with the app open, and analysed on your device by the same engine that analyses QR codes. Never stored on our servers. The app never writes to or locks a tag.
    Shared with
    Not shared with anyone.
    Purpose
    Threat verification — a tampered NFC tag is the same attack as a sticker placed over a QR code.
  • Anonymous usage counters

    Handling
    Aggregated on your device. Sending them is optional and off unless you enable it; the identifier is a random value you can erase at any time, and it is not the advertising ID.
    Shared with
    Only if you opt in, and then only aggregate counts — never URLs, never contents.
    Purpose
    Knowing which features are used, so the product improves without profiling anyone.
  • Scan history

    Handling
    Stored only on your device, in a local database. Never uploaded anywhere.
    Shared with
    Not shared with anyone.
    Purpose
    Your personal reference. You can delete individual entries or the entire history at any time.
  • Images (gallery import / generator logo)

    Handling
    Processed entirely on your device to decode a QR from a photo or to place your logo on a generated code.
    Shared with
    Not shared and never uploaded.
    Purpose
    Reading QR codes from images and customizing generated codes.

Data we do not collect

We do not collect your name, email address, phone number, postal address, location, contacts, photos (beyond the on-device processing you initiate yourself), or any identifier of your personal identity. There are no user accounts, so there is no account data. Your scan history never leaves your device.

Third parties

For every URL you scan, the app automatically runs the following checks — none of them require an account, a sign-in, or a separate prompt, and none of them are currently configurable in Settings:

  • Google Safe Browsing — the full URL you scan is sent to this service to verify whether it is known to be malicious. Google’s privacy policy: policies.google.com/privacy.
  • RDAP — to find out how long ago a domain was registered, the app queries the public registration directory mandated by ICANN. Only the domain travels, never the full URL with its path or parameters.
  • Certificate Transparency (crt.sh) — public, mandatory logs of every issued TLS certificate. The app consults them to tell an established domain from one that only started serving HTTPS days ago. Only the domain travels.
  • Shortener / redirect resolution — if the link is a shortener (bit.ly and similar), the app follows the redirect chain itself, one hop at a time, up to 5 hops, so the security checks above run against the real destination and not the shortener that hides it. This means the app contacts the destination server(s) directly. Each request is a lightweight HEAD request (no page content is downloaded), sends no cookies, and follows no more than 5 hops before giving up.

We sell no data to anyone, and we share nothing beyond what is listed above. Because these checks are not yet optional, using the app means accepting that the URL or its domain will reach the services above; if that is a concern for a specific link, do not scan it.

No advertising

The app shows no advertising. Until version 1.3 it was ad-supported through Google AdMob; version 1.4.0 removed the advertising SDK entirely. As a result the app no longer uses the advertising identifier, no longer shares any device identifier with an ad network, and no longer needs a consent management platform, because it processes no data for advertising purposes.

Development is sustained by voluntary donations. Every security feature is free, complete and identical for everyone — there is no paid tier that unlocks protection.

Security

All network traffic from the app travels encrypted over HTTPS/TLS. Unencrypted (cleartext) traffic is blocked at the configuration level of the app itself, not merely by convention.

Your rights and controls

  • Delete your scan history — History → “Delete all”, at any time, or remove individual entries.
  • Delete the automatic log — Settings → Log → “Clear log”.
  • Complete removal — uninstalling the app deletes all locally stored data, because that is the only place it exists.
  • No per-check toggle yet — the network checks listed in Section 5 currently run for every URL and cannot be turned off individually inside the app. If you want to scan a code without any network activity, disable your device’s network connection before scanning; the on-device analysis in Section 2 still runs and gives a verdict, just without the network-backed signals.

For any request — access, deletion, or questions about this policy — write to sos@veritasnexuslegal.com. Depending on where you live, you may have statutory rights to access, correct, or erase personal data; since we hold essentially none, most requests are satisfied by the in-app controls above.

This website

The site you are reading now is deliberately quiet about data:

  • No analytics, no marketing cookies, no trackers. We do not measure you, profile you, or embed third-party advertising or social widgets on this site.
  • One functional cookie. A single cookie (NEXT_LOCALE) remembers your language choice for up to one year. Details in the cookie policy.
  • Server access logs. Like virtually every web server, ours records standard access logs (IP address, requested URL, timestamp, user agent) for security and abuse prevention. These logs are kept only briefly for those purposes and are then deleted; they are not used for analytics or profiling.

Children

Neither the app nor the site is directed at children under 13, and we do not knowingly collect data from children.

Changes to this policy

If we make material changes, we will publish the updated policy at this address and update the date at the top. Continued use of the app or the site after a change means the updated policy applies.

Contact

Veritas Digital LLC · sos@veritasnexuslegal.com. A human reads every message.