At a glance
- Direct Standard generation and export run locally.
- Creative content is processed by generation infrastructure.
- An image at a public asset URL is accessible to anyone with that URL.
Where your data goes
Direct Standard: input and visual settings → your browser renderer → downloaded file. Enabling a tracked short link adds a server request to allocate a redirect and save its destination.
Creative: payload and template settings → authenticated generation service → generation infrastructure and model providers → scan verification → stored result and account History. Optional Google sign-in uses basic profile and email information through Supabase Auth; it does not request Gmail, Drive or contacts access.
Account records and public assets
Accounts, saved generation records, credits and short-link ownership are associated with authenticated users. The application uses database row-level access policies for user-owned records and server-side authorization for generation and billing operations.
Private History does not make every image file private. Generated files may be delivered at public asset URLs. Anyone with such a URL may access the file, including any payload encoded in the QR. Do not submit passwords, secrets or sensitive personal information to Creative generation.
Short-link tracking and site analytics
Scanfolk's product scan-event table records scan times, not IP addresses, precise location, referrers or user-agent fields. Infrastructure providers may process request metadata for their operations and security.
The website uses Google Analytics to measure visits and product actions such as generation and download. Product event parameters describe categories and settings; the event adapter is designed not to send QR payloads, prompts, Wi-Fi passwords or free text. Site analytics and short-link scan tracking are different systems.
Retention and deletion requests
Account records and saved content are generally retained while the account is active and as needed to operate the service, resolve disputes and meet legal obligations. There is no published fixed retention period for every record type.
Request account-data access, correction or deletion at support@scanfolk.com. Requests require verification; backups, security and transaction records may have separate retention needs. Short links and public asset URLs may need separate deactivation. See the Privacy Policy for the full disclosures.
Report a security concern
Contact support@scanfolk.com with the affected route, a description and minimal reproduction steps. Avoid including credentials or other people's private data. Scanfolk does not claim a security certification, independent audit certification or an absolute security guarantee.