At a glance
- Google sign-in requests only basic profile and email information.
- Direct Standard QR rendering runs in your browser; tracked and Creative results use server services.
- Short-link product analytics records link ownership, counts, and scan times—not IP addresses or precise location.
- Scanfolk does not sell personal information or Google user data.
1. Scope
This Privacy Policy explains how Scanfolk handles personal information when you visit scanfolk.com, sign in, create QR codes, save work, use short links, or contact support.
Scanfolk is the service operator described in this policy. If you do not agree with these practices, please do not use the service.
2. Information we collect
Account information may include your email address, display name, profile photo, authentication provider, account identifier, credit balance, and account timestamps.
Product information may include QR destinations or other payloads, prompts, templates, colors and layout settings, saved generations, result URLs, stickers, scan-verification status, errors, and credit activity.
When you contact support, we receive the information in your message and any files or details you choose to provide.
3. Google user data
If you choose Sign in with Google, Scanfolk requests basic OpenID Connect scopes for your Google profile and email. This can include your Google account identifier, name, email address, and profile photo when Google provides it.
We use that information only to authenticate you, create or connect your Scanfolk account, display account identity, protect the sign-in flow, and provide account features. Scanfolk does not access your Gmail, Google Drive, or contacts, and it does not post to your Google account.
Google sign-in records and sessions are stored and managed through Supabase Auth. We do not sell Google user data, use it for targeted advertising, or share it except with service providers needed to operate authentication and the service, as described below.
4. QR content and generated results
Direct Standard QR rendering and export run in your browser. Creating a tracked Standard QR sends its destination and visual settings to Scanfolk to allocate a redirect and save the generation to your account. For Creative generation, content such as a destination, prompt, template choice, visual settings, and uploaded source material may be sent to our generation infrastructure and model providers to produce and validate the requested result.
Saved generations and stickers remain associated with your account. Generated image files can be stored at public asset URLs so that they can be displayed or downloaded; anyone with such a URL may be able to access the file.
Do not submit secrets, sensitive personal information, or content you do not have permission to use.
5. Short links and scan analytics
If you enable a Scanfolk short link, we store its code, destination, owner, tracking setting, click count, last-accessed time, and scan timestamps. Scanfolk does not record IP addresses or precise location in its product scan-event table. The table also does not include referrer or user-agent fields.
Infrastructure providers may process request metadata for security, reliability, abuse prevention, and operations under their own terms and privacy notices. Direct static QR codes do not need a Scanfolk redirect to work.
5a. Website analytics
The website uses Google Analytics to measure visits and product actions such as generation and download. This is separate from optional short-link scan tracking: turning off scan tracking does not turn off website analytics.
Google Analytics may use cookies and collect browser and device information. For signed-in activity, the application can send a pseudonymous account identifier. Product event parameters describe categories and settings; they are designed not to include QR payloads, Creative prompts, Wi-Fi passwords, or other free text.
The configured page address and referrer omit query strings and fragments. Infrastructure and analytics providers may process request metadata under their own privacy notices; the absence of IP or location fields in Scanfolk's product scan-event table does not describe every provider's data processing.
6. How we use information
We use information to provide sign-in and account features, create and store QR results, operate credits and saved history, redirect enabled short links, show scan counts, support users, prevent abuse, secure and debug the service, and comply with legal obligations.
We do not sell personal information. We do not use Google user data for advertising.
7. Service providers and disclosures
We use service providers to operate Scanfolk, including Google for optional sign-in and website analytics, Supabase for authentication, database, storage, and server functions, Modal and model infrastructure for Creative generation, and hosting or network providers for delivery and security.
We disclose only the information reasonably needed for those providers to perform their services. We may also disclose information when required by law, to protect rights and safety, or as part of a business transaction subject to appropriate safeguards.
8. Retention and deletion
We generally retain account records and saved content while your account is active and as needed to provide the service, secure it, resolve disputes, and meet legal obligations. Retention periods vary by record type and operational need.
You may ask to access, correct, or delete your account information by contacting support@scanfolk.com. We will verify the request before acting. Deletion may not be immediate for backups, security logs, credit or transaction records, and records we must retain by law. Short links and public asset URLs may need to be deactivated separately.
9. Your choices and security
You can choose not to sign in with Google, avoid optional short-link tracking, and request account-data access, correction, or deletion. You may also disconnect Scanfolk from your Google Account settings, although Scanfolk may still retain records described in this policy.
We use reasonable administrative and technical safeguards, but no internet service can guarantee absolute security. Keep your account credentials and access links private, and contact us if you suspect unauthorized use.
10. Children, changes, and contact
Scanfolk is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided personal information, contact us so we can review it.
We may update this policy as the service changes. We will revise the date above and provide additional notice when appropriate.
Questions or privacy requests: support@scanfolk.com.
Need clarification?