Privacy Policy
Effective Date: March 21, 2026. Last Updated: October 4, 2026
Apogaeum Labs, LLC ("we," "us," "our") built sniffQR ("the App") as a Freemium application. sniffQR is available as an Android app, an iOS app, and a browser extension; this Privacy Policy covers all three, and platform-specific details are called out where they differ. This Privacy Policy explains what data the App handles, how it is used, and your rights.
The short version: We don't spy on you. sniffQR processes everything on your device. We have no servers, no analytics, no tracking, and no way to see your data. If you enable an online scanning service with your own key, it receives only what's described below - for VirusTotal that's just an anonymous fingerprint of the URL, never the URL itself. Revealing where a shortened link really leads means contacting that link's own host; you can turn that off in Settings → Redirect Analysis. Apple or Google may send us anonymous crash data if you've opted into that on your device. That's it. The legalese below says the same thing with more words.
1. Data We Collect
We do not collect, transmit, or store any personal data on our servers. Apogaeum Labs does not operate any backend servers for this App. We have no analytics, telemetry, advertising SDKs, or tracking of any kind.
All data the App processes stays on your device unless you explicitly configure a third-party service (see Section 4) or opt in to your platform's crash reporting (see Section 2).
2. Crash Data (Apple and Google)
Crash reporting is controlled entirely by your device settings and is operated by Apple or Google, not by us. We operate no crash-reporting service of our own.
On iOS: if you have opted in to share analytics with app developers (Settings > Privacy & Security > Analytics & Improvements > Share with App Developers), Apple may collect and provide us with anonymized crash logs and performance diagnostics through App Store Connect.
On Android: if you have opted in to send usage and diagnostics data (Settings > Google > Usage & diagnostics), Google may provide us with anonymized crash reports and performance data through the Google Play Console (Android vitals).
On either platform this data may include:
- Crash stack traces and exception information
- Device model and operating system version
- General app performance metrics
This data does not include your QR scan content, API keys, personal information, or any identifiable data. You can opt out at any time through your device settings.
See Apple's privacy policy and Google's privacy policy.
In the apps, Report Issue and Submit Suggestion open a form on sniffqr.com. To help us reproduce problems, the link includes your app version, device model, and OS version - nothing else. In the extension they open an email to support@sniffqr.com.
3. Data Stored Locally on Your Device
The App stores the following data locally on your device only:
- Scan history: QR code content you scan (which may include URLs, text, contact information, WiFi credentials, cryptocurrency addresses, or 2FA setup codes), scan timestamps, and threat verdicts
- API keys: credentials you enter for third-party scanning services. On the apps these are held in your device's secure storage - the Keychain on iOS, and encrypted preferences (AES-256-GCM) keyed by the Android Keystore on Android. In the browser extension there is no OS keychain to use: your key is held in browser extension storage, managed by your browser profile, and is never synced. See section 14.
- App preferences: settings and configuration choices
This data never leaves your device unless you choose to export or share it using the App's built-in share function, or configure a third-party scanning service.
You can delete all scan history at any time from within the App.
4. Third-Party Services
No scan content is sent to any threat-intelligence service unless you enable one with your own key. To reveal where shortened links really lead, sniffQR contacts the link's own web host - you can turn this off in Settings → Redirect Analysis.
When configured by you:
- Google Web Risk: scanned URLs are sent to Google for threat analysis. Google's privacy policy
- VirusTotal (optional, requires your own key): only an anonymous fingerprint (a SHA-256 hash) of the URL is checked against VirusTotal's database. The URL itself is never sent, and nothing is ever submitted. VirusTotal's privacy policy
- Custom Threat Feed: if you configure a custom threat feed, QR code content is sent to whatever server you specify. You are responsible for understanding that server's data practices.
We do not control, endorse, or assume responsibility for the privacy practices of these third-party services.
5. Information We Do NOT Collect
We do not collect, access, or process:
- Names, email addresses, or phone numbers
- Device identifiers (UDID, IDFA, IDFV)
- IP addresses
- Location data (the App does not request location permissions)
- Usage analytics or behavioral data
- Advertising identifiers
- Photos or camera data (camera input is processed in real-time for QR code detection and is never stored or transmitted)
- Cookies or web tracking technologies
Note: Apple or Google may share anonymized crash data with us if you have opted in through your device settings. See Section 2.
6. Artificial Intelligence
QR code detection on Android uses an on-device machine-learning model that never leaves your device and sends nothing anywhere. Apart from that, the App does not use artificial intelligence, machine learning, or automated decision-making to profile you or make decisions about you, and no scan data is ever used to train any model.
7. Children's Privacy
The App is not directed at children under 13 (or under 16 in the EU/EEA). We do not knowingly collect personal information from children. Because we collect no personal data from any user, there is no children's data to identify or delete. If you believe a child is using the App inappropriately, contact us at the address below.
8. Your Rights
All users:
- Delete all scan history from within the App at any time
- Disable any third-party service at any time by toggling it off in Settings
- Opt out of Apple or Google crash reporting through your device settings
- Uninstall the App to remove all locally stored data
European Economic Area, United Kingdom, and Switzerland (GDPR/UK GDPR):
- Right to access, rectify, erase, restrict, and port your data
- Right to object to processing
- Right to withdraw consent at any time
- Right to lodge a complaint with your local data protection authority
- Legal basis for processing: legitimate interest (you chose to scan a QR code) and consent (you choose to enable third-party services)
Because all data is stored locally on your device and we have no access to it, you exercise these rights directly through the App (deleting history, disabling services) or by uninstalling.
California (CCPA/CPRA):
- We do not sell or share your personal information as defined by the CCPA/CPRA
- We do not use or disclose sensitive personal information for purposes beyond what is needed to provide the App
- We do not engage in cross-context behavioral advertising
- You have the right to know, delete, correct, and opt out of the sale or sharing of personal information; however, because we collect no personal information on our servers, these rights are satisfied by default
- You will not be discriminated against for exercising your privacy rights
- Categories of personal information collected in the preceding 12 months: None
- Categories of personal information sold or shared in the preceding 12 months: None
Canada (PIPEDA):
- You have the right to access and challenge the accuracy of your personal information held by us
- Because we hold no personal information, these rights are satisfied by default
Brazil (LGPD):
- You have the right to confirmation of processing, access, correction, anonymization, portability, deletion, and information about sharing
- Because we process no personal data on our servers, these rights are satisfied by default
South Africa (POPIA):
- You have the right to access, correct, and delete your personal information
- Because we collect no personal information, these rights are satisfied by default
9. Data Security
- On the apps, API keys are stored in your device's secure storage, protected by hardware-backed encryption: the Keychain on iOS, and encrypted preferences (AES-256-GCM) keyed by the Android Keystore on Android. The browser extension cannot reach either of those - see section 14 for what it does instead
- Scan history is stored in an on-device database. The content of each scan and its results are stored with AES-256-GCM encryption on both platforms. The date, code type, verdict and warning flags are stored unencrypted so history can be sorted and filtered. On iOS the encryption key is held in the Keychain with iOS Data Protection applied on top, and on Android the key is held in the Android Keystore. On both platforms the database is excluded from cloud backup and device transfer
- All network connections to third-party services use HTTPS. In the apps the built-in services (Google Web Risk, VirusTotal) are additionally protected by TLS certificate pinning. The only connection that can be plain HTTP is to a scanned link's own address, when that link is http://, so sniffQR can show where it leads. The browser extension is not certificate-pinned - an MV3 extension cannot pin; it relies on the browser's own TLS validation. See section 14
- No data is stored on or transmitted to our servers
- When you share or export scan data, it leaves sniffQR's encrypted storage. Exported files may contain sensitive information such as passwords, 2FA secrets, and private URLs. You are responsible for protecting this data once it is outside the App.
10. Data Retention
All data is stored locally on your device. We retain nothing on our servers. You control retention entirely:
- Delete individual or all scan records from the App at any time
- Uninstall the App to remove all stored data
- API keys can be removed from Settings at any time
Apple or Google may retain crash data in accordance with their own retention policies if you have opted in to share diagnostics on your device.
11. International Data Transfers
We do not collect or store your data, so no international transfers occur through us. If you enable Google Web Risk or a custom threat feed, your scanned URLs may be processed by those services in countries outside your own, in accordance with their respective privacy policies and data transfer mechanisms. VirusTotal receives only an anonymous SHA-256 fingerprint, never the URL itself.
12. Do Not Track
The App does not track you and therefore does not respond to Do Not Track signals. There is nothing to track.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted within the App and the "Last Updated" date will be revised. Continued use of the App after changes constitutes acceptance of the updated policy.
14. The Browser Extension
The extension runs the same detection engine as the apps and reaches the same verdicts, but it runs inside a browser rather than on an operating system, and a browser does not offer everything an OS does. Where that changes what happens to your data, it is set out here rather than left to the reader to infer from the app sections above.
- Where your settings and API key live. The extension has no access to the iOS Keychain or the Android Keystore. Your settings and your Google Web Risk API key are stored in browser extension storage, which is managed by your browser profile and protected by whatever protections that profile has. They are stored locally and never synced between your devices by us. Removing the extension removes them.
- Your Web Risk key never leaves the browser except to Google. It is sent only to Google's Web Risk endpoint, to authenticate the lookup you asked for. It is never sent to us, because we have no server to send it to, and never to any other party.
- No VirusTotal, no custom threat feeds, no offline database. The extension does not offer them, so it never sends anything to VirusTotal or to any endpoint of yours. The first two are a product decision; the offline database is an MV3 platform limit, since an extension cannot hold or background-sync one.
- Transport security is the browser's. Requests to Google Web Risk are HTTPS, and TLS is validated by the browser itself. Following a scanned link contacts that link's own address, which is plain HTTP when the link is http://. The extension does not pin certificates - MV3 provides no mechanism for an extension to do so. Where the apps add pinning on top of TLS for the built-in services, the extension relies on the browser's validation alone. We would rather say that than let the apps' pinning claim be read as covering the extension too.
- Redirect resolution can be turned off. It is on by default; switch off "Follow redirects to the destination" in the extension's options.
- No history is kept. The extension writes a single verdict to local extension storage only long enough to show it, then deletes it. There is no scan history to encrypt, export or delete.
- No analytics, telemetry, advertising SDKs or accounts - the same as the apps, and the same as the rest of this policy.
15. Contact Us
If you have questions about this Privacy Policy or wish to exercise any of your rights, contact us at:
Apogaeum Labs, LLC
Email: support@sniffqr.com