Smart QR Scan Privacy Policy
Privacy Policy
Smart QR Scanner & Barcode
Developer / Data Controller: Tigar Apps
Effective date: 5 August 2026 | Last updated: 10 August 2026
Privacy at a glance
- QR/barcode scanning, gallery decoding, scan history, generated codes, inventory information and most settings are handled locally on your device.
- Camera frames and gallery images used for scanning are not uploaded to us.
- No user account is required, and we do not ask you to create an account with us.
- We do not intentionally collect your name, email address, phone number, contacts, precise GPS location, photos, files, passwords or account credentials through the App.
- The App uses Google Firebase services for analytics, crash diagnostics, installation/configuration functions and push notifications.
- The App uses Google AdMob / Google Mobile Ads SDK to display ads. Advertising technology can process IP-derived approximate location, app/ad interactions, diagnostics and device or advertising identifiers.
- Where required, we use Google User Messaging Platform / Google Consent Management Platform tools to request consent or provide privacy choices before eligible personalized advertising or related processing.
- We do not sell personal and sensitive user data for monetary consideration.
1. Introduction, Scope and Data Controller
Tigar Apps respects your privacy and is committed to handling personal information responsibly, transparently and securely. This Privacy Policy explains how information is accessed, collected, processed, used, stored, shared, retained and protected when you install or use Smart QR Scanner & Barcode (the "App").
This Privacy Policy also explains your privacy rights and choices under applicable privacy and data protection laws, including, where applicable, the EU General Data Protection Regulation (GDPR), UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), other applicable U.S. state privacy laws, and relevant Google Play requirements.
By using the App, you acknowledge that information may be handled as described in this Privacy Policy. Where applicable law requires consent for a particular type of processing, we will request the required consent or provide the applicable privacy choice before that processing takes place.
1.1 About the App
Smart QR Scanner & Barcode is a QR-code and barcode utility application that provides features such as real-time camera scanning, scanning from selected gallery images, scan history, QR/barcode generation, inventory-related tools, CSV import/export, local link-safety checks, preferences and related utility functions.
The App does not require users to create or register an account to use its main features. However, the absence of an account does not mean that no technical information is processed. Depending on the feature, device settings, region, consent choices and integrated third-party SDKs, limited device, app-usage, diagnostics, installation, notification, consent and advertising information may be processed as described in this Privacy Policy.
We do not intentionally require users to provide their name, email address, telephone number, contacts, passwords or other direct account-registration information merely to use the App's main scanning functions.
1.2 Developer and Data Controller Information
For purposes of applicable data protection laws, where Tigar Apps determines the purposes and means of processing personal information, the responsible developer/data controller is:
Developer / Publisher / Data Controller: Tigar Apps
Application: Smart QR Scanner & Barcode
Privacy Contact Email:
fluteapp85@gmail.com
Data Deletion Request Page:
https://tigarapps.blogspot.com/delete-account
Tigar Apps is responsible for the processing for which it determines the purposes and means. Third-party service providers, including Google Firebase, Google AdMob / Google Mobile Ads, and Google User Messaging Platform / consent technologies, may process information on our behalf as processors/service providers or, for certain purposes and depending on applicable law and their own processing activities, as independent controllers.
The remaining sections of this Privacy Policy explain the categories of information handled, purposes and legal bases of processing, third-party recipients, international transfers, retention, deletion methods, security measures and user rights.
Because the App currently does not provide account registration, there is no App account to delete. The deletion webpage above is provided for applicable privacy/data-deletion requests. If account creation is introduced in the future, we will update the App, this Privacy Policy and the applicable Google Play disclosures and deletion mechanisms as required.
2. Information Processed Only on Your Device
The following information is processed locally and is not intentionally transmitted to or collected by us:
2.1 Camera frames
When you scan a QR code or barcode, the App analyzes camera frames in real time on your device using on-device barcode-scanning technology. Frames are processed transiently for scanning and are not saved by us or uploaded to our servers.
2.2 Gallery images
If you choose an image from your device, the App uses the Android system picker to access the image you selected, analyzes it on the device, and does not upload the image to us for scanning.
2.3 Scan results and scan history
QR/barcode contents you scan, including text, URLs and other encoded content, are stored locally in the App's on-device database when history is enabled or used. We do not intentionally transmit scanned contents to our servers or use them for advertising profiles.
2.4 Generated codes
QR codes and barcodes you create, together with their local design/customization data, are stored or processed on the device unless you intentionally export or share them using an Android sharing or file-selection feature.
2.5 Inventory information
Product names, SKUs, barcode values, prices, quantities/stock levels and other inventory information you enter are stored locally. CSV import/export is performed only using files and locations you select through Android's file picker or sharing features.
2.6 App preferences
Preferences such as language, theme, sound, vibration and feature toggles are generally stored locally.
2.7 Link-safety checks
If the App flags common risk signals in a scanned link, such as insecure HTTP or a suspicious-looking domain, that heuristic check is performed locally. This feature does not guarantee that a link is safe.
2.8 User-initiated sharing
When you intentionally choose to share a scan result, generated code, image or exported file with another app, person or service, Android sends the selected information to the destination you choose. That transfer is initiated by you and is governed by the receiving service's privacy practices.
3. Permissions and Sensitive Device Access
The App may request only permissions needed for features you choose to use.
| Access / Permission | Why it is used | What happens to the data |
|---|---|---|
| Camera | To scan QR codes and barcodes in real time. | Camera frames are analyzed on-device for scanning and are not intentionally uploaded to us. |
| Photo / media selection through Android system picker | To let you choose an existing image for QR/barcode decoding. | Only the item you select is accessed for the requested function; it is processed locally for scanning. |
| Files through Android system file picker | To import or export CSV or other user-requested files. | The App acts on the file/location you select. We do not operate a cloud file-storage service for this content. |
| Notifications | To deliver service or app-related notifications if you allow them. | Android notification permission is requested where the operating system requires it; Firebase Cloud Messaging may process an installation-specific registration token. |
The App does not need precise GPS location for its core scanning features. If a future version begins requesting new sensitive permissions or collecting new categories of personal data, we will update the App disclosures, Google Play Data Safety information and this Privacy Policy as required.
4. Information Transmitted Through Google Services
Although your scan content and locally stored inventory are not intentionally uploaded to us, the App integrates Google services that automatically process limited device, app, diagnostics, analytics, messaging, consent and advertising information. The exact data can depend on SDK version, device settings, region, consent status and how a feature is configured.
4.1 Google Analytics for Firebase
Google Analytics for Firebase may process information such as:
- app interaction and usage events, such as app launches, screens viewed and feature interactions;
- device and app information, such as device model, operating system and App version;
- pseudonymous app or installation identifiers; and
- coarse geographic information derived from network information, where available and permitted.
We use analytics to understand aggregate App usage and improve functionality. We do not intentionally send QR/barcode contents, inventory records, photos or files as analytics event values.
4.2 Firebase Crashlytics
Crashlytics may process:
- crash stack traces and diagnostic logs;
- relevant app state and device state at the time of a crash;
- device model and operating-system information;
- Crashlytics/Firebase installation identifiers; and
- developer-defined diagnostic information if configured in the App.
We use this information to identify, diagnose and fix technical problems.
4.3 Firebase Cloud Messaging (FCM)
FCM may process the App version, Firebase installation information and a push-notification registration token associated with the App installation so notifications can be delivered to your device.
4.4 Firebase Remote Config
Remote Config may process information such as country code, language, time zone, platform/OS version, Firebase App ID, package name, Remote Config SDK version and Firebase installation information so configuration values can be delivered and, where configured, targeted appropriately.
4.5 Firebase Installations
Firebase services can generate and process a Firebase Installation ID (FID), a per-installation identifier used to support Firebase functionality. It is not intended to be your name or a government-issued identifier.
4.6 Google AdMob / Google Mobile Ads SDK
For advertising, analytics, ad measurement, frequency capping, security and fraud prevention, the Google Mobile Ads SDK may automatically process or share with Google information including:
- IP address, which may be used to estimate approximate/general location;
- user product interactions, such as app launches, taps and ad/video interactions;
- diagnostic/performance information, such as launch time, hang rate or SDK performance information;
- device and account-related identifiers, which may include the Android Advertising ID, App Set ID and other identifiers where applicable; and
- device and App information needed to serve, measure, secure and limit the frequency of ads.
The availability and use of advertising identifiers can depend on Android version, user settings, consent, child-directed-treatment settings and the App's SDK configuration. Users can reset or delete the Android Advertising ID through supported Android privacy controls.
4.7 Google User Messaging Platform / Consent Management Platform
Where applicable, Google's consent/privacy messaging technology displays privacy choices and stores or transmits consent signals and related technical information needed to honor those choices. The message shown can depend on region, device, prior choice and applicable privacy rules.
5. Purposes and Legal Bases
We use or permit processing of the information described above only for the following purposes:
| Purpose | Examples | Legal basis where GDPR / UK GDPR applies |
|---|---|---|
| Provide requested App functions | Scanning, local history, code generation, import/export and notifications you enable. | Where applicable, performance of a service requested by you (GDPR Art. 6(1)(b)); otherwise legitimate interests in providing and operating the App (Art. 6(1)(f)), subject to applicable law. |
| Security, stability and debugging | Crashlytics diagnostics, fraud/invalid-traffic prevention, operational reliability. | Legitimate interests in securing and maintaining the App (GDPR Art. 6(1)(f)), unless consent or another legal basis is required by applicable law. |
| Analytics and product improvement | Understanding aggregate feature usage and technical performance. | Consent (GDPR Art. 6(1)(a)) where required by ePrivacy or other applicable law; otherwise legitimate interests (Art. 6(1)(f)) where legally permitted. |
| Advertising and ad measurement | Serving ads, measuring delivery, preventing fraud and limiting repetition. | Consent (GDPR Art. 6(1)(a)) where legally required; another lawful basis will be used only where permitted by applicable law. |
| Personalized advertising | Using permitted identifiers or signals to select ads based on interests or activity. | Consent (GDPR Art. 6(1)(a)) where required. Personalized advertising is not requested where legally required consent has not been obtained. |
| Legal compliance | Responding to lawful legal process and enforcing legal rights. | Compliance with legal obligations (GDPR Art. 6(1)(c)) and/or legitimate interests (Art. 6(1)(f)), as applicable. |
Consent can be withdrawn where processing relies on consent. Withdrawal does not make processing that occurred before withdrawal unlawful.
6. Advertising, Consent and Privacy Choices
6.1 Ad-supported App
The App displays advertising through Google AdMob / Google Mobile Ads SDK, which can include banner, native, interstitial, app-open and rewarded ad formats depending on the App version and feature flow.
6.2 EEA, United Kingdom and Switzerland
Where required, the App uses Google's consent/privacy messaging solution to present disclosures and collect privacy choices for advertising and related storage or processing. Personalized ads are requested only where required consent has been obtained. Depending on applicable law, user choice and Google ad-serving capabilities, users who do not consent may receive non-personalized or limited ads instead.
6.3 Consent withdrawal / privacy options
Where a consent or privacy message applies, the App should provide a discoverable privacy-options entry point so you can revisit your choices. If such an entry point is displayed in your version of the App, use it to reopen the consent message and change or withdraw eligible choices. You may also contact us at fluteapp85@gmail.com for assistance.
6.4 U.S. state privacy choices
In jurisdictions where the use of advertising identifiers for cross-context behavioral advertising is legally treated as "sale," "sharing" or "targeted advertising," eligible users may have a right to opt out. Where applicable and configured, Google's privacy messaging can provide an opt-out mechanism. See Section 12 for additional rights.
6.5 Android advertising controls
Android may allow you to reset or delete your Advertising ID and manage other ad-privacy settings through your device's privacy controls. The exact path depends on your Android version and device manufacturer.
7. Data Sharing and Service Providers
We do not sell personal and sensitive user data for monetary consideration.
Information described in Section 4 may be processed by Google services integrated into the App:
- Google Firebase provides analytics, crash reporting, installations, configuration and cloud messaging services.
- Google AdMob / Google Mobile Ads provides advertising, ad measurement, analytics, security and fraud-prevention functions.
- Google User Messaging Platform / Google CMP provides consent and privacy-choice functionality.
For Firebase services, Google may act as a service provider/processor for relevant processing and may use approved subprocessors. For advertising and certain related purposes, Google and participating advertising technology providers may act under their own privacy terms and, depending on the context, may be independent controllers. The list of advertising partners presented to a user can depend on the consent message and the AdMob configuration.
Google privacy information:
We may also disclose information if required by applicable law, a valid legal process, or where reasonably necessary to protect users, our rights, the security of the App, or to investigate fraud or abuse.
8. Google Play Data Safety Summary
The following summary is intended to keep this Privacy Policy consistent with the App's disclosed SDK behavior. The Google Play Console Data Safety form must still be completed based on the exact App build and every SDK/library actually included in that build.
| Google Play data category | Expected handling for the described App | Main purpose |
|---|---|---|
| Approximate location | May be collected/shared through Google advertising or analytics technologies from IP/network-derived information. Precise GPS location is not intentionally collected. | Advertising, analytics, fraud prevention, service configuration. |
| App interactions | Collected by analytics and may be collected/shared by the advertising SDK. | Analytics, product improvement, advertising and measurement. |
| Crash logs / Diagnostics | Collected through Crashlytics and may also be processed/shared by Google Mobile Ads for SDK/app performance. | App functionality, analytics, security, diagnostics and fraud prevention. |
| Device or other identifiers | Firebase installation identifiers and advertising-related identifiers may be processed; advertising ID availability depends on device settings, consent and configuration. | App functionality, analytics, notifications, advertising, measurement and fraud prevention. |
| Photos / videos selected for scanning | Accessed and processed on-device for the requested scan; not intentionally transmitted to us for scanning. | App functionality. |
| Files / documents selected for import/export | Handled through user-selected Android file locations and not intentionally uploaded to our servers. | App functionality. |
| Scan contents, local history and inventory data | Stored locally and not intentionally transmitted to us. | App functionality. |
| Name, email, phone, contacts, account credentials | Not requested or intentionally collected by the App in its current form. | Not applicable. |
Data sent through the Google SDKs described above is transmitted using encrypted connections. Local-only processing that never leaves the device is generally not treated as "collection" for Google Play Data Safety disclosure purposes, but SDK transmission off the device must be declared according to Google Play's current definitions and applicable exceptions.
9. International Data Transfers
Google services may process information in the United States and other countries outside the country where you live. Where applicable, Google states that it uses recognized transfer mechanisms, contractual safeguards and/or data-transfer frameworks for relevant international transfers. Privacy protections can vary by jurisdiction.
If EU/EEA, UK or Swiss data protection law applies, transfers should be handled using a legally recognized transfer mechanism, such as applicable Standard Contractual Clauses, adequacy decisions or recognized data privacy frameworks, where available and appropriate.
10. Data Retention
- On-device data: scan history, generated codes, inventory and local preferences remain until you delete them, clear App storage, or uninstall the App, subject to any Android backup/restore behavior described in Section 14.
- Google Analytics: retention depends on our Google Analytics property configuration and Google's applicable retention rules. Standard Google Analytics properties currently provide configurable retention periods for user-level data (commonly 2 or 14 months). We aim not to retain user-level analytics data longer than reasonably necessary for App improvement and operation.
- Firebase Crashlytics: Google states that Crashlytics keeps relevant crash stack traces, associated crash data and identifiers for approximately 90 days before beginning removal from live and backup systems.
- Firebase Cloud Messaging / installation tokens: installation-related tokens or identifiers are retained as needed to provide the service and can become invalid, be rotated or be deleted in accordance with Firebase behavior and App lifecycle events.
- Remote Config / Firebase Installations: handled in accordance with Firebase service operation, deletion capabilities and Google's applicable retention practices.
- Advertising data: retained by Google and relevant advertising providers according to their applicable retention policies, legal obligations, user choices and product configuration.
- Consent/privacy choices: consent signals or privacy choices may be stored on-device and/or by the relevant consent platform as needed to remember and honor your choice, subject to applicable law and platform rules.
11. Deletion and User Controls
You may also submit an applicable data-deletion request through our Data Deletion Request page or by emailing fluteapp85@gmail.com. Because the App currently does not provide user accounts, this webpage is a privacy/data-deletion request resource rather than an account-deletion mechanism.
11.1 Delete local App data
You can delete local information using deletion features available in the App, by clearing the App's storage in Android Settings, or by uninstalling the App. Uninstalling may not immediately remove copies maintained by the Android backup service if device backup is enabled.
11.2 Analytics and crash-related deletion requests
Because the App does not use user accounts, we generally do not know your real-world identity from Firebase analytics or crash identifiers. You may email fluteapp85@gmail.com to request assistance. Where technically feasible, we will use available Google/Firebase tools to address a valid deletion request. We may need an installation or technical identifier available from the App/device in order to locate relevant pseudonymous data.
11.3 Notifications
You can disable App notifications through Android's notification settings at any time. Exact menu wording varies by Android version and device manufacturer.
11.4 Advertising privacy choices
Where the App displays a consent/privacy message, use the App's privacy-options entry point, when shown, to review or change eligible choices. You may also reset or delete your Android Advertising ID using Android privacy controls where supported.
11.5 No App account
The App currently has no account-registration system. Therefore, there is no App account to delete. Our external Data Deletion Request page may be used for applicable privacy/data requests. If account creation is added in the future, we will also provide the in-app account-deletion path and external account-deletion web resource required by Google Play policy.
12. Your Privacy Rights
Depending on where you live and subject to legal conditions and exceptions, you may have rights to request access, correction, deletion, restriction, portability or objection; to withdraw consent; and to complain to an applicable data-protection authority.
12.1 EEA / EU and United Kingdom
Where the EU General Data Protection Regulation ("GDPR") or UK GDPR applies, and subject to applicable conditions and exceptions, you may have the following rights:
- Access (GDPR Art. 15): request confirmation and a copy of applicable personal data.
- Rectification (Art. 16): request correction of inaccurate or incomplete personal data.
- Erasure / Right to be Forgotten (Art. 17): request deletion where the legal conditions are met.
- Restriction (Art. 18): request restriction of processing in qualifying circumstances.
- Data Portability (Art. 20): receive eligible data in a structured, commonly used, machine-readable format where the right applies.
- Objection (Art. 21): object to certain processing, including processing based on legitimate interests and, where applicable, direct marketing.
- Automated Decision-Making (Art. 22): rights relating to certain solely automated decisions producing legal or similarly significant effects, where applicable.
- Withdraw Consent: withdraw consent at any time where consent is the legal basis, without affecting processing lawfully carried out before withdrawal.
- Complaint: lodge a complaint with the competent data-protection supervisory authority.
We will respond to requests under GDPR Articles 15–22 without undue delay and, in principle, within one month of receipt. Where permitted because of the complexity or number of requests, that period may be extended by up to two additional months; we will inform you of the extension and reasons within the initial one-month period.
To exercise an applicable GDPR/UK GDPR right, email fluteapp85@gmail.com or use our Data Deletion Request page.
12.2 California and other U.S. states
If the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), applies to us and to the processing at issue, California residents may have rights including the right to know/access, correct, delete, and obtain information about categories of personal information collected, used, disclosed, sold or shared, subject to applicable exceptions.
We do not sell personal information for monetary consideration. However, depending on how advertising technologies are configured and how applicable law defines the activity, certain uses or disclosures of advertising identifiers or similar information for cross-context behavioral advertising may be considered "sharing" or "sale" under California law. Where applicable, eligible users may opt out of such sale/sharing or targeted advertising through the privacy choices/consent mechanism made available in the App or by contacting us.
- Right to Know / Access: request information about applicable personal information we process.
- Right to Correct: request correction of inaccurate personal information, where applicable.
- Right to Delete: request deletion of applicable personal information, subject to legal exceptions.
- Right to Opt Out of Sale/Sharing: opt out where our processing constitutes a sale or sharing under applicable law.
- Right to Limit: where applicable, request limits on certain uses/disclosures of sensitive personal information.
- Right to Non-Discrimination: we will not unlawfully discriminate against you for exercising an applicable privacy right.
For verifiable requests to know/access, correct or delete, we will respond within the period required by applicable law. Under the CCPA/CPRA, covered businesses generally must confirm receipt within 10 business days and respond substantively within 45 calendar days; the response period may be extended by an additional 45 days when legally permitted and with appropriate notice. Requests to opt out of sale/sharing must be handled as soon as feasibly possible and within the period required by applicable law.
Submit a privacy request by email at fluteapp85@gmail.com or, where applicable, through our Data Deletion Request page.
12.3 Other jurisdictions
If the privacy law where you live provides additional rights, you may contact us to exercise those rights. We will respond as required by applicable law.
13. Children's Privacy
The App is a general-purpose utility and is not directed specifically to children under 13 or the equivalent minimum age defined by applicable local law. We do not knowingly ask children to provide their name, email address, phone number or account information through the App.
If we learn that personal information has been collected from a child in a manner that violates applicable law, we will take reasonable steps to delete it. A parent or guardian can contact us at fluteapp85@gmail.com.
Google Play target-audience note: If the App is declared in Google Play Console as targeting children, or both children and older users, additional Google Play Families requirements apply, including rules concerning ad SDKs, age screening, identifiers and personalized advertising. The Play Console target-audience declaration must always truthfully match the App's intended audience and actual implementation.
14. Security and Android Backup
We use reasonable technical and organizational safeguards appropriate to the nature of the App. Data transmitted through the Google SDKs described in this policy is sent over encrypted network connections such as HTTPS/TLS. Local App data is stored within Android-managed application storage or user-selected storage locations, subject to Android security controls and device configuration.
Android or a device manufacturer may include eligible App data in a device/cloud backup and restore service. Such backup processing is controlled by the operating system, device settings and the backup provider rather than by our own App server. You can manage device backup options in Android/device settings.
No method of storage or transmission is completely secure. We cannot guarantee absolute security, but we will take reasonable steps to address security issues within our control.
15. Third-Party Links and Scanned Content
QR codes and barcodes can contain URLs, contact details, text or other content created by third parties. If you choose to open a scanned URL, you may leave the App and interact with a third-party website or service. That third party controls its own content and privacy practices.
Any local link-risk warning offered by the App is a heuristic aid only. It is not a guarantee that a URL, website, file or destination is safe, legitimate or free from malware, phishing or other risks.
16. Automated Processing
We do not use the App's locally stored scan contents or inventory data to make automated decisions that produce legal or similarly significant effects about you. Advertising providers may use automated systems to select, measure or limit ads subject to applicable consent and privacy rules.
17. Changes to This Privacy Policy
We may update this Privacy Policy when the App, SDKs, legal requirements or our data practices change. We will update the "Last updated" date above. Where required by law or Google Play policy, we will provide additional notice or obtain consent before materially different processing begins.
You should review this policy periodically. A new version will apply from the effective date stated in the updated policy.
18. Contact Us
Developer / Data Controller: Tigar Apps
App: Smart QR Scanner & Barcode
Privacy email:
fluteapp85@gmail.com
Data Deletion Request Page:
https://tigarapps.blogspot.com/delete-account
For privacy questions, GDPR/UK GDPR requests, CCPA/CPRA requests, consent questions, or data-deletion requests, contact us using the email or deletion-request page above.
If you contact us about a privacy right, include enough information to describe your request. Please do not send passwords, government ID numbers, payment-card details or other unnecessary sensitive information.
Implementation accuracy notice
This policy describes the App behavior and third-party services identified above. Privacy compliance depends on the released App matching these disclosures. If you add or remove an SDK, enable mediation, add account/login features, upload scan history to a server, collect location, change advertising behavior, target children, or add another form of data collection, you must review and update this policy, the in-app disclosures/consent flow and the Google Play Data Safety declaration before or when the change is released.