Simple, transparent privacy practices. I collect only what's essential to provide the QR scanning service and keep your data secure.
Last Updated: October 22, 2025 - Added Forensic Evidence Tracking & Integrity Mechanisms
I collect minimal metadata to provide the QR scanning service and improve threat detection.
Currently, QRTrust operates as a free service without user accounts, so no personal account information is collected.
I collect only the minimal data necessary to provide the QR scanning service. Unlike many platforms, I don't track personal browsing habits, create advertising profiles, or share data with third-party marketers.
Required for core functionality and security
Help us improve our service performance
We do not use marketing or advertising cookies
You can control cookie settings through our cookie banner (appears on first visit) or adjust settings in your browser. Essential cookies cannot be disabled as they are required for basic security and functionality.
We maintain our own continuously updated local threat intelligence database:
✓ Privacy-First Approach: We maintain and query our threat database locally. Your URLs are NEVER sent to third-party services. All processing happens on our EU servers.
Google's threat intelligence with over 5M malware and phishing URLs
Data Location: USA/EU (Google Cloud infrastructure)
Proprietary AI model for advanced threat detection (optional)
Data Location: EU (GDPR-compliant infrastructure)
QRTrust is designed with privacy at its core. We minimize third-party dependencies and keep your data in the EU:
Local phishing database built from community reports:
Security and performance logs for service operations:
QRTrust implements enterprise-grade forensic security mechanisms to ensure the integrity and traceability of all evidence:
Every access to evidence (screenshots, archives, reports) is logged in a cryptographically secured chain.
All security-critical events are logged in a blockchain-inspired audit log.
Scheduled integrity verification runs every 6 hours to detect any anomalies.
Our forensic mechanisms comply with international security standards.
Data Retention for Forensic Evidence: Evidence files and their chain of custody records are retained for 90 days to support legal proceedings and incident investigations. All forensic data is stored encrypted on EU servers and automatically purged after the retention period.
Request copies of all data we store about you
Correct inaccurate or incomplete data
Request deletion of your personal data
Export your data in a machine-readable format
Learn what personal information we collect and why
Request deletion of your personal information
Opt-out of sale of personal information (we don't sell data)
Equal service regardless of privacy choices
To exercise any of these rights, contact our Data Protection Officer at privacy@qrtrust.eu or use our automated privacy portal.
QRTrust has never sold, rented, or traded user data to third parties for marketing purposes, and we never will. Your privacy is not for sale.
✓ No data brokers • ✓ No ad networks • ✓ No marketing partnerships
We may share data only in these limited cases:
Our privacy-respecting infrastructure:
No Data Export: All URL scans and analysis happen locally on our servers. Your data never leaves the EU.
privacy@qrtrust.eu
info@qrtrust.eu
Germany
European Union
I'll notify you of material changes to this privacy policy via:
Join municipalities, authorities or companies that already trust QRTrust.