Privacy Policy
Effective date: 14 August 2026
The QR Toolkit is a Chrome extension published by AakashkiDuniya for generating and scanning QR codes and barcodes. This policy applies specifically to The QR Toolkit.
1. Information processed locally
The extension may process the following information on the user's device:
- Text entered for QR generation.
- Website URLs, phone numbers, email addresses, SMS details, Wi-Fi details, and vCard information entered by the user.
- Logos selected for placement within generated QR codes.
- Images selected, uploaded, dropped, or supplied through a user-invoked context-menu action.
- Camera frames while the user has actively started camera scanning.
- Generated QR images and decoded QR or barcode results.
- Extension preferences and local scan history.
- A locally maintained daily QR-generation counter.
This information is used to generate QR codes, decode QR codes and barcodes, display results, create exports, and remember local preferences or scan history.
QR content, uploaded images, logos, camera frames, generated QR files, decoded results, scan history, preferences, and generation counts remain on the user's device. They are not uploaded to or stored by the publisher.
2. Free allowance and Google Sign-In
Users may generate up to three QR codes per day without an account.
Google Sign-In is required to continue generating QR codes after the free daily allowance has been used. QR scanning remains available without signing in.
The daily generation counter is stored locally in Chrome extension storage. It is not sent to the publisher, Google, Cloudflare Worker, or Cloudflare D1.
3. Google account information
When a user signs in with Google, the extension receives or processes:
- Google account identifier.
- Verified email address.
- Profile name.
- Optional profile picture.
- A temporary Google OAuth access token used to verify the sign-in.
The Google OAuth access token is used transiently during authentication and is not stored in Cloudflare D1.
The verified account information is used only to create and manage access to The QR Toolkit.
4. Cloudflare processing and storage
Authentication requests are processed through the publisher's Cloudflare Worker.
Cloudflare D1 stores:
- Google account identifier.
- Verified email address.
- Profile name.
- Optional profile picture.
- Account creation time.
- Last-login time.
- Account status.
- Hashed application session-token records.
- Session creation and expiration timestamps.
Application sessions expire after 30 days.
Cloudflare does not receive or store QR contents, uploaded images, logos, camera frames, generated QR files, decoded scan results, scan history, browsing history, or QR-generation counts.
5. Data sharing and third-party services
The QR Toolkit uses:
- Google, to authenticate users through Google Sign-In.
- Cloudflare, to process authentication requests and store account and session information.
The publisher does not sell user data.
User data is not used for advertising, analytics, creditworthiness, lending, or unrelated profiling. QR contents, uploaded images, camera frames, generated codes, and scan history are not shared with the publisher or third parties.
When a user invokes a right-click image scan, Chrome may retrieve the selected image from its original website so the extension can decode it locally. The extension does not upload that image to a publisher-controlled service.
6. Chrome permissions
The extension requests the following permissions:
storage— saves local preferences, scan history, authentication state, and the local daily-generation counter.activeTab— accesses the active page only after the user invokes a page-related QR action.contextMenus— provides user-invoked actions for generating or scanning QR codes.clipboardWrite— copies generated images or decoded text only after the user clicks a copy action.identity— authenticates users through Google Sign-In after the free daily-generation allowance.<all_urls>host permission — supports user-invoked page screenshot scanning and cross-origin retrieval of a selected image for local decoding.
No page content is uploaded to the publisher's service.
7. Data retention and deletion
Local preferences, scan history, authentication state, and generation counts remain in Chrome extension storage.
Users may delete scan history through the extension. They may remove all local extension data by clearing the extension's data through Chrome settings or uninstalling the extension.
Cloudflare-stored account information remains until the account is deleted. Application session records expire after 30 days.
Users may request deletion of their Cloudflare-stored account information by emailing akashsh0925@gmail.com.
Deletion removes the associated user account and session records from Cloudflare D1.
8. Security
Authentication requests are transmitted over HTTPS.
Application session tokens are stored in hashed form in Cloudflare D1. The extension does not store Google passwords.
No method of electronic transmission or storage is completely secure, but reasonable measures are used to protect account and session information.
9. Children's privacy
The extension is not directed at children under 13, and the publisher does not knowingly collect personal information from children under 13.
10. Changes to this policy
Material changes to this privacy policy will be reflected by updating the effective date shown at the top of this page.
11. Contact
For privacy questions, support, or account-deletion requests, contact akashsh0925@gmail.com.