Last updated 5 August 2026

Privacy Policy

The short version: we store your account and the codes you make, we don't track you, we don't sell anything, and you can take your data or delete it whenever you like.

1. Who we are

QRGenrator is operated by Symentic Tech, the data controller for the personal data described here. For any privacy matter, contact info@symentictech.com. We'll respond within one month, as UK GDPR requires.

2. What we collect, why, and on what basis

DataWhyLawful basis
Email address, password (hashed with bcrypt)To create your account and sign you inContract
Google account id, name and picture (only if you use Google sign-in)To let you sign in with GoogleContract
QR codes you save — the link and the stylingSo your codes are there when you come backContract
Images you upload as logosTo place them in your codes and let you reuse themContract
Session records — expiry, browser, IP addressTo keep you signed in and detect account misuseLegitimate interests (account security)
Your cookie choicesSo we don't ask on every visitLegal obligation / consent

Providing this data is necessary to use an account. You can use the editor and download a code without an account at all — in that case your design stays in your own browser and never reaches us.

3. What we don't do

  • We don't track scans of the codes you create.
  • We don't run advertising, analytics or third-party trackers.
  • We don't sell, rent or share your data with anyone.
  • We don't use your content to train AI models.
  • We don't email you marketing.
  • We don't make automated decisions or profile you in any way that produces legal effects.

4. Our legitimate interests, explained

Where we rely on legitimate interests (session records, for account security), we've weighed our interest against your rights. Our interest is keeping accounts from being hijacked. The data is minimal — an expiry time, a browser string and an IP address — it isn't used to profile or market to you, and it is deleted with the session. We consider this is what you would reasonably expect from a service that signs you in.

You have the right to object to this processing at any time. See section 8.

5. Who processes your data

We use a small number of processors, each bound by a data processing agreement and permitted to act only on our instructions:

ProcessorPurposeLocation
Neon (database hosting)Stores your account, codes and uploadsEU (London region)
Amazon Web ServicesHosts the application serverUK (London region)
Google (only if you use Google sign-in)Verifies your identitySee Google's privacy policy

Your data is stored in the UK and EEA. We do not transfer personal data outside the UK/EEA. We may disclose data if legally required to do so, or to establish or defend legal claims.

6. How long we keep it

DataRetention
Account, codes and uploadsUntil you delete them or close your account
Sessions7 days, or 60 if you chose “keep me signed in”
Password reset tokens30 minutes, then invalid
Everything, after account deletionDeleted immediately — we keep no backup copy

7. How we protect it

Passwords are hashed with bcrypt and are never readable by us or recoverable. Session tokens are stored only as SHA-256 hashes, so a database leak would not yield working sessions. Traffic is encrypted with TLS. Access to production systems is limited to those who need it.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and tell you directly where the risk is high, as UK GDPR requires.

8. Your rights

Under UK and EU data protection law you have the right to:

  • Access — get a copy of your data. There's a button for this in settings.
  • Rectification — correct anything inaccurate.
  • Erasure — delete your account and everything in it. Also a button in settings.
  • Portability — take your data elsewhere. The export is machine-readable JSON.
  • Restriction — ask us to pause processing while a dispute is resolved.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — at any time, without affecting processing already carried out.

Exercising these rights is free. Email info@symentictech.com, or use the buttons in settings for the two most common ones.

If you're unhappy with how we've handled your data you can complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113). We'd appreciate the chance to put it right first.

9. Where your data comes from, and what we don't do with it

We collect personal data directly from you. The only exception is Google sign-in, where Google passes us your account id, email, name and picture because you asked it to.

We carry out no automated decision-making or profiling that produces legal effects or similarly significantly affects you.

10. Cookies

We set one essential cookie to keep you signed in. Full details, including every browser-storage key we use, are in our cookie policy.

11. Children

The Service isn't directed at children under 13 and we don't knowingly collect their data. If you believe a child has given us personal data, contact us and we'll delete it.

12. Changes

If we change this policy materially we'll update the date above and, where the change affects consent, ask you again rather than assuming.