Privacy Policy
What Scanfolk collects, why it is needed, and the choices you have when you sign in or create a QR code.
At a glance
Effective: September 10, 2026
- Google sign-in requests only basic profile and email information.
- QR content and Creative prompts are processed to build, save, and validate your results.
- Short-link product analytics records link ownership, counts, and scan times—not IP addresses or precise location.
- Scanfolk does not sell personal information or Google user data.
1. Scope
This Privacy Policy explains how Scanfolk handles personal information when you visit scanfolk.com, sign in, create QR codes, save work, use short links, or contact support.
Scanfolk is the service operator described in this policy. If you do not agree with these practices, please do not use the service.
2. Information we collect
Account information may include your email address, display name, profile photo, authentication provider, account identifier, credit balance, and account timestamps.
Product information may include QR destinations or other payloads, prompts, templates, colors and layout settings, saved generations, result URLs, stickers, scan-verification status, errors, and credit activity.
When you contact support, we receive the information in your message and any files or details you choose to provide.
3. Google user data
If you choose Sign in with Google, Scanfolk requests basic OpenID Connect scopes for your Google profile and email. This can include your Google account identifier, name, email address, and profile photo when Google provides it.
We use that information only to authenticate you, create or connect your Scanfolk account, display account identity, protect the sign-in flow, and provide account features. Scanfolk does not access your Gmail, Google Drive, or contacts, and it does not post to your Google account.
Google sign-in records and sessions are stored and managed through Supabase Auth. We do not sell Google user data, use it for targeted advertising, or share it except with service providers needed to operate authentication and the service, as described below.
4. QR content and generated results
We process the content you submit to build a QR code. For Creative generation, this may include a destination, prompt, template choice, visual settings, and uploaded source material. That content may be sent to our generation infrastructure and model providers to produce and validate the requested result.
Saved generations and stickers remain associated with your account. Generated image files can be stored at public asset URLs so that they can be displayed or downloaded; anyone with such a URL may be able to access the file.
Do not submit secrets, sensitive personal information, or content you do not have permission to use.
5. Short links and scan analytics
If you enable a Scanfolk short link, we store its code, destination, owner, tracking setting, click count, last-accessed time, and scan timestamps. Scanfolk does not record IP addresses or precise location in its product scan-event table. The table also does not include referrer or user-agent fields.
Infrastructure providers may process request metadata for security, reliability, abuse prevention, and operations under their own terms and privacy notices. Direct static QR codes do not need a Scanfolk redirect to work.
6. How we use information
We use information to provide sign-in and account features, create and store QR results, operate credits and saved history, redirect enabled short links, show scan counts, support users, prevent abuse, secure and debug the service, and comply with legal obligations.
We do not sell personal information. We do not use Google user data for advertising.
7. Service providers and disclosures
We use service providers to operate Scanfolk, including Google for optional sign-in, Supabase for authentication, database, storage, and server functions, Modal and model infrastructure for Creative generation, and hosting or network providers for delivery and security.
We disclose only the information reasonably needed for those providers to perform their services. We may also disclose information when required by law, to protect rights and safety, or as part of a business transaction subject to appropriate safeguards.
8. Retention and deletion
We generally retain account records and saved content while your account is active and as needed to provide the service, secure it, resolve disputes, and meet legal obligations. Retention periods vary by record type and operational need.
You may ask to access, correct, or delete your account information by contacting support@scanfolk.com. We will verify the request before acting. Deletion may not be immediate for backups, security logs, credit or transaction records, and records we must retain by law. Short links and public asset URLs may need to be deactivated separately.
9. Your choices and security
You can choose not to sign in with Google, avoid optional short-link tracking, and request account-data access, correction, or deletion. You may also disconnect Scanfolk from your Google Account settings, although Scanfolk may still retain records described in this policy.
We use reasonable administrative and technical safeguards, but no internet service can guarantee absolute security. Keep your account credentials and access links private, and contact us if you suspect unauthorized use.
10. Children, changes, and contact
Scanfolk is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided personal information, contact us so we can review it.
We may update this policy as the service changes. We will revise the date above and provide additional notice when appropriate.
Questions or privacy requests: support@scanfolk.com.