Nibras QR privacy policy
Effective date: 11 October 2026 · App version 1.0.0
1. Overview
Nibras QR is an Android app for creating, designing and scanning QR codes and barcodes. It is local-first: the core features (create, design, scan, templates, saved codes, history, export) work offline and only on your device. This policy explains which data leaves your device and when.
2. Controller and contact
The data controller is Nibras Code (nibrascode.com). For privacy, data or deletion questions: nibrascode@gmail.com.
3. Camera and images
The camera is used only while you have the scanner open. Codes are recognised on the device by Google ML Kit, offline; camera frames are not stored or sent anywhere. Images you pick from the gallery are also decoded only on the device. You can revoke the camera permission at any time in your device settings.
4. Data stored on your device
Codes you create and save (content, name, design, any logo/background image you add, tags), your scan history, language, theme and app settings are stored in the app's private storage on your device. We cannot see them. You can remove them in the app or by uninstalling it.
5. Scan results and link safety
A scanned link is opened in the browser only when you tap “Open”. The suspicious-link check (shortened links, IP addresses, http, punycode, etc.) runs on the device, offline; links are not sent anywhere for checking.
6. Account (optional) — Sign in with Google
You can use the app without an account. If you sign in with Google, sign-in is handled by Supabase (authentication service) and we process: email address, name, profile picture URL, your Google account identifier and an internal user ID. We use them to run your account, link your Pro status to it and (on Pro) to sync. Session tokens are stored on your device.
7. Cloud sync (Pro, signed-in users)
When you are signed in with Pro, your saved codes (name, type, content, design including logo and background images, tags, timestamps) are stored in a Supabase database linked to your account so they sync across devices. Only you can access them (row-level access rules).
8. Dynamic QR codes and scan statistics (Pro)
When you create a dynamic QR code, its short link, name, destination URL and settings (on/off, expiry date, scan limit) are stored in Supabase. When anyone scans your dynamic code, only the following is recorded for statistics: time of the scan, device type (mobile/tablet/desktop) and operating system (derived from the browser user-agent). Country, precise location and IP address are not recorded in the statistics. Hosting infrastructure may keep request metadata (such as IP) in technical logs for a short time.
9. Payments (Google Play and RevenueCat)
Pro subscriptions and the one-time purchase are processed by Google Play Billing; payment details (cards etc.) are handled only by Google and never seen by us. We use RevenueCat to manage subscription status: RevenueCat receives an app user ID (your Supabase user ID if signed in, otherwise an anonymous ID), purchase information and basic device/app information. On our server we store only your Pro status, expiry date, product and store name.
10. Ads, analytics and selling
The app shows no ads and contains no advertising or analytics tracking SDKs. We do not sell, rent or share personal data for advertising.
11. Third-party processors
Google (Sign in with Google; ML Kit runs on-device), Google Play (distribution and payments), Supabase (authentication, database and server functions; data stored in the EU, Frankfurt region), RevenueCat (subscription status). Their policies: policies.google.com/privacy, supabase.com/privacy, revenuecat.com/privacy.
12. Retention and deletion
On-device data stays until you delete it or uninstall the app. Account data, synced codes, dynamic links and their scan statistics are kept while your account exists. You can delete your account in the app: Account › “Delete account”. This immediately deletes your account, cloud codes, dynamic links (they stop working), scan statistics and the Pro record on our server. Data in backups is removed automatically within a limited period. Google Play and RevenueCat keep purchase records under their own policies and legal obligations. Deleting the account does not cancel a subscription — cancel it in Google Play › Payments & subscriptions. If you cannot sign in, email nibrascode@gmail.com (details: nibrascode.com/privacy/nibras-qr/delete-account).
13. Security
All network traffic is encrypted (HTTPS/TLS). In the database each user can access only their own data; server keys are never shipped in the app.
14. Children
The app is not directed to children under 13 and we do not knowingly collect their personal data. If you believe such data was collected, contact us and we will delete it.
15. Your rights
To access, correct or delete your data, or object to processing, email nibrascode@gmail.com. We reply within 30 days.
16. Changes
If this policy changes, the new version will be published on this page with a new date; important changes will also be shown in the app.