Privacy policy

Last updated: September 13, 2026 · Applies to susqr.com

The short version
  • Uploaded QR images are deleted after 24 hours. The decoded link and verdict are kept so results pages and the scam map work.
  • No account is needed. If you sign in, we store your email address and link your scans to it. We never sell or rent it.
  • The site is free because it shows ads (Google AdSense) and includes Amazon affiliate links. Both use cookies; you can opt out of personalised ads below.
  • To check a link we send it to security services such as VirusTotal, Google Safe Browsing, and urlscan.io. We never send your name, email, or IP address with it.

What we collect

DataWhyKept for
The QR image you uploadTo decode it24 hours, then deleted automatically
The decoded link or text, plus our scan resultsTo show your results page and improve detection24 hours for anonymous scans; until you delete your account for signed-in scans
Your IP address and browser typeRate limiting, abuse prevention, error logsUp to 90 days in server logs
Your email address (only if you sign in or ask for a results email)Sending your one-time sign-in code and results; keeping your scan historyUntil you ask us to delete it
Where you found a bad QR code (only if you tell us)The public scam mapIndefinitely, but locations are rounded to about 1 km and are never tied to your email publicly

Who else sees the link you scan

Checking a link means asking specialists about it. We send the URL, and only the URL, to: VirusTotal, Google Safe Browsing, urlscan.io (which opens the page in its own sandbox and returns a screenshot), URLhaus by abuse.ch, PhishTank's public phishing list, Cloudflare and Quad9 DNS filters, and public domain-registration (RDAP) records. If you type a city or ZIP code when reporting a sighting, that text goes to OpenStreetMap's Nominatim service to find coordinates. None of these receive anything that identifies you.

Cookies, analytics, and ads

susQR uses three kinds of cookies:

Some pages contain Amazon affiliate links, marked as such. As an Amazon Associate, susQR earns from qualifying purchases; Amazon sets its own cookies when you follow those links.

What we don't do

Your choices

Security and hosting

All traffic is encrypted (HTTPS). The site is served through Cloudflare, which sees connection metadata as any CDN does. Emails are sent through SMTP2GO. Data is stored in the United States.

Children

susQR is not directed at children under 13 and we don't knowingly collect their data.

Changes and contact

We'll update the date at the top when this policy changes. Questions: [email protected].