QR Trust — Privacy Policy
App: QR Trust
Developer: Qerberos LLC
QR Trust checks whether the link inside a QR code is safe before you open it. This policy explains what the app collects, why, and what control you have. QR Trust does not require an account and does not collect your name, email address, or any information that identifies you personally.
What we collect
When you scan a QR code, the app sends the following to our servers so the link can be checked:
- The scanned URL — the link contained in the QR code.
- A random device identifier — a random value generated on your device and stored in the iOS keychain. It is not derived from your device's hardware and is not linked to your identity.
- Approximate location — latitude and longitude accurate to roughly 100 metres, plus your country code. This is optional and is only sent if you grant location permission. The app works without it.
What we do not collect
- Camera images. The camera is used on your device to recognise QR codes. Photographs and video are never uploaded or stored.
- Contact details. No name, email address, phone number, or account.
- Payment details. QR Trust Pro subscriptions are processed by Apple. We receive only whether a subscription is active, never your payment information.
- Advertising identifiers. The app contains no advertising or third-party analytics trackers.
Why we collect it
- To answer your question. The scanned URL is checked against third-party threat intelligence databases and against our own reputation analysis, so we can tell you whether the link is safe.
- To improve detection. Approximate location helps us identify scam campaigns that target particular regions, which improves results for everyone.
- To avoid repeat work. The device identifier lets us group scans from the same device so we can rate-limit abuse and count how often a URL has been checked.
We do not sell your data, and we do not use it for advertising or profiling.
Who we share it with
To assess a link, we may send it outside our own systems:
- The full URL is sent to a third-party AI service, which returns a reputation assessment.
- The domain name alone, not the full URL, is sent to a public domain registration lookup service to determine how long the domain has existed.
In both cases we send the link only. Your device identifier and your location are never shared with these providers. Checks against our own copy of a public phishing database run entirely on our servers, so nothing leaves for those. We also use infrastructure providers to host the service and our database. We do not otherwise disclose data to third parties except where required by law.
How long we keep it
Scan records are retained only as long as needed to operate and improve the service. Aggregated statistics that cannot be traced back to any device or person, such as total counts of safe and unsafe scans, may be kept indefinitely.
Your choices
- Location is optional. Decline the permission prompt, or turn it off later in iOS Settings, and scanning continues to work.
- Deletion. You can request deletion of the data associated with your device at any time. See our Data Deletion Request page.
- Uninstalling QR Trust stops all further collection immediately.
QR Trust Pro
QR Trust Pro is an optional subscription that supports our threat research. It unlocks no additional features, and every part of the app works without it. Purchases, renewals, and cancellations are handled by Apple under Apple's own terms and privacy policy.
Children
QR Trust is not directed at children and we do not knowingly collect data from children.
Changes to this policy
If we change how we handle data we will update this page and revise the date below.
Contact
Questions about this policy or about your data: info@qerberos.com
Last updated: September 2026