Privacy policy
Last updated: September 13, 2026 · Applies to susqr.com
- Uploaded QR images are deleted after 24 hours. The decoded link and verdict are kept so results pages and the scam map work.
- No account is needed. If you sign in, we store your email address and link your scans to it. We never sell or rent it.
- The site is free because it shows ads (Google AdSense) and includes Amazon affiliate links. Both use cookies; you can opt out of personalised ads below.
- To check a link we send it to security services such as VirusTotal, Google Safe Browsing, and urlscan.io. We never send your name, email, or IP address with it.
What we collect
| Data | Why | Kept for |
|---|---|---|
| The QR image you upload | To decode it | 24 hours, then deleted automatically |
| The decoded link or text, plus our scan results | To show your results page and improve detection | 24 hours for anonymous scans; until you delete your account for signed-in scans |
| Your IP address and browser type | Rate limiting, abuse prevention, error logs | Up to 90 days in server logs |
| Your email address (only if you sign in or ask for a results email) | Sending your one-time sign-in code and results; keeping your scan history | Until you ask us to delete it |
| Where you found a bad QR code (only if you tell us) | The public scam map | Indefinitely, but locations are rounded to about 1 km and are never tied to your email publicly |
Who else sees the link you scan
Checking a link means asking specialists about it. We send the URL, and only the URL, to: VirusTotal, Google Safe Browsing, urlscan.io (which opens the page in its own sandbox and returns a screenshot), URLhaus by abuse.ch, PhishTank's public phishing list, Cloudflare and Quad9 DNS filters, and public domain-registration (RDAP) records. If you type a city or ZIP code when reporting a sighting, that text goes to OpenStreetMap's Nominatim service to find coordinates. None of these receive anything that identifies you.
Cookies, analytics, and ads
susQR uses three kinds of cookies:
- Session cookie (ours): keeps you signed in and protects forms. Essential.
- Google Analytics: tells us which pages are used and how the scanner performs. IP addresses are anonymised by Google. You can block it with Google's opt-out add-on.
- Google AdSense: shows the ads that keep the scanner free. Google and its partners may use cookies to show ads based on your visits to this and other sites. Opt out of personalised advertising at Google Ads Settings or aboutads.info (EU: youronlinechoices.eu). Visitors in the EEA, UK, and Switzerland are asked for consent before any ad cookie is set. How Google uses data from sites that use its services is described at policies.google.com/technologies/partner-sites.
Some pages contain Amazon affiliate links, marked as such. As an Amazon Associate, susQR earns from qualifying purchases; Amazon sets its own cookies when you follow those links.
What we don't do
- We don't sell, rent, or trade personal data.
- We don't put the links you scan on the public map. Sightings show the kind of scam and a rounded location only.
- We don't need, and don't ask for, passwords. Sign-in uses a one-time emailed code.
- We don't show ads on the sign-in or account pages.
Your choices
- Scan without signing in and nothing is linked to you.
- Delete your account and history: email [email protected] from the signed-in address. We remove it within 7 days.
- Unsubscribe from any email with the link in its footer.
Security and hosting
All traffic is encrypted (HTTPS). The site is served through Cloudflare, which sees connection metadata as any CDN does. Emails are sent through SMTP2GO. Data is stored in the United States.
Children
susQR is not directed at children under 13 and we don't knowingly collect their data.
Changes and contact
We'll update the date at the top when this policy changes. Questions: [email protected].