Last Updated: September 8, 2026
This Privacy Policy explains what information this app collects, how it is used, and the choices you have. Please read this policy carefully. If you do not agree with the terms of this Privacy Policy, please do not use the app.
This policy applies only to the application identified below, and to no other app or website:
Throughout this policy, “Scanly”, “the app” and “we” refer to Scanly - QR Generator & Barcode, published by Umesh Ghimire.
Information you provide: none. The app has no registration, no login, no profile and no contact form. It does not collect personal information such as your name, email address, phone number or address.
Some features let you type text that is then stored on your device only — for example the content of a QR code you are creating, a note you attach to a scan, or a tag name. If you choose to put personal details into a QR code you are designing, such as a contact card, that text is saved in the app's local storage on your phone and is not sent anywhere.
Information collected automatically. The following is collected by Google AdMob in order to show advertising:
The app itself contains no analytics software, no crash reporting software, no advertising network other than AdMob, and no tracking pixels. The developer does not operate a server and receives no data about you.
Information we deliberately do not collect:
The app does not request storage, photo library, location, contacts, microphone or calendar permissions. Scanning a picture from your gallery uses the Android system photo picker, which hands the app only the single image you select and gives it no access to the rest of your photos. Saving a contact or adding a calendar event from a scanned code opens the relevant Android app with the details filled in, so that you complete the action there; the app never reads your contacts or calendar.
Scan history, generated codes, tags, notes, counting sessions and your settings are held in private application storage on your device, which other apps cannot read. Nothing in that storage is transmitted off the device by the app.
You can move your own data yourself, and only when you ask for it:
The app's safety checks run offline on your device. One optional check uses the network, and a second exists in the code but is switched off in the released app. Both are described here so that nothing is hidden from you.
Following shortened links. A shortened link hides where it really goes, which is how many QR code scams work. When you scan one, the app can follow it to reveal the true destination. This runs only for a fixed list of well known shortening services, such as bit.ly, t.co, tinyurl.com and goo.gl. An ordinary scanned address is never sent anywhere. The request carries no cookies, no referrer, no identifier and no scan history, only the shortened link itself, sent to the shortening service that issued it. You can switch this off in Settings.
Reputation lookup, which is not active in the current release. The app contains support for optionally checking a scanned address against Google Safe Browsing, but it is not enabled in the version published on Google Play. The feature requires an API key that is not included in the released build, so the option does not appear in Settings and no scanned address is ever sent to Google Safe Browsing. It is described here so that this policy stays accurate if it is switched on in a future version. If that happens it will remain off unless you turn it on, because it is the one feature that would send a scanned address to a third party. Were you to enable it, the address you scanned would be sent to Google for checking and handled under Google's Privacy Policy.
The privacy dashboard. Because these are the kind of claims that are easy to make and hard to trust, the app includes a privacy dashboard under Settings that records every network request it has ever made, with a running count. It is a measurement rather than a promise, and you can check it at any time.
The app is free, and advertising pays for it. Ads are supplied by Google AdMob. Google may use an advertising identifier and related device information to select and measure ads. Google's handling of that data is governed by Google's Privacy and Terms and by AdMob's policies.
If you are in the European Economic Area, the United Kingdom, Switzerland or a United States state with applicable privacy legislation, the app presents a consent form from Google's User Messaging Platform before personalised ads are requested, and your choice is respected and remembered. You can change it later from Settings.
You can reset or delete your advertising identifier at any time in Android Settings, under Privacy and then Ads, which also lets you opt out of personalised advertising across the whole device.
Where ads never appear: the app does not place an advert on a scan result, on a safety warning, or over the camera. Watching an optional rewarded advert removes all ads for six hours.
Opening a scanned link, looking up a product barcode with a search provider, calling a scanned number or sending a scanned email hands the action to another app or website. Once you leave the app, this policy no longer applies and the privacy policy of the destination does. The app never opens a scanned link automatically; you always choose.
The app is not directed at children. Because it shows advertising, it is rated for users aged 13 and over, and it is not designed or intended for use by children under 13. The developer does not knowingly collect information from children. If you believe that a child has provided information through this app, please contact us at me.umeshuser@gmail.com.
Because the app holds no data about you on any server, there is no account for the developer to look up, correct or erase. Requests under the GDPR, the UK GDPR or the CCPA and CPRA that concern advertising data should be directed to Google, as the party that processes it. Anything else can be resolved from within the app using the controls above. You are welcome to write to the address below with any question about this.
Data stored on your device is kept until you delete it or uninstall the app. The developer retains nothing, because the developer receives nothing. Retention of advertising data is determined by Google.
The app's data sits in private application storage that other apps cannot read. Backups that you create are encrypted with a passphrase you choose, and that passphrase is never stored or transmitted. You can optionally require a fingerprint or face check before your history can be viewed. No method of transmission over the Internet or electronic storage is completely secure, but because nothing is sent to a server, there is no central store of your scans to be breached.
We may update this Privacy Policy from time to time as the app changes. We will notify you of any material changes by updating the "Last Updated" date at the top of this page, and the current version will always be available at this address. Material changes will also be reflected in the app's Google Play listing.
If you have any questions or concerns about this Privacy Policy, you can contact us at:
Application: Scanly - QR Generator & Barcode
Developer: Umesh Ghimire
Email: me.umeshuser@gmail.com