PRIVACY POLICY QR Decoder Effective Date: July 24, 2026 Last Updated: July 24, 2026 Canonical web version: https://afkerianinteractive.github.io/qr-decoder/privacy-policy.html Spanish version: https://afkerianinteractive.github.io/qr-decoder/privacy-policy-es.html 1. OPERATOR AND SCOPE This Privacy Policy explains how Jesus Afkerian, a natural person operating under the AFKERIAN INTERACTIVE brand (“I,” “me,” or “my”), handles information in connection with the QR Decoder mobile application (the “App”). Jesus Afkerian is the individual publisher and operator of the App. AFKERIAN INTERACTIVE is the brand under which he operates; this Policy does not identify a corporation, limited liability company, partnership, or other separate legal entity as the operator. This Policy applies to the App and to privacy, deletion, and support communications concerning the App. Google Play, Android, Google, device manufacturers, storage providers, advertising providers, and other third parties operate under their own terms and privacy policies. Privacy contact: afkerian.support@gmail.com 2. LOCAL-FIRST OPERATION; NO FIRST-PARTY ACCOUNT OR BACKEND The App is a local-first QR, barcode, document, optical-character-recognition (“OCR”), file, and archive utility. The App does not require or provide a user account administered by me. I do not operate a first-party server, cloud database, or synchronization service that receives, hosts, or synchronizes your App profile, scan history, documents, files, or generated content. The App does not include subscriptions or in-app purchases. During ordinary use, the App does not require you to provide me with your name, postal address, telephone number, contacts, payment-card information, health information, biometric information, or government-issued identification. This does not mean that no information leaves the device. The third-party advertising, analytics, crash-reporting, installation, session, consent, and machine-learning services described below automatically process certain technical information. 3. CAMERA, FILES, SCANS, OCR, AND OTHER USER CONTENT 3.1 Camera and user-selected content The App requests camera access when you initiate a camera-based scan. The camera is declared as an optional device feature so that non-camera functions may remain available on compatible devices without a camera. The App may access images, documents, folders, or other files when you select them through Android system interfaces or use a function that requires them. Access is limited by the permissions and locations granted through Android or the selected storage provider. 3.2 Content processed locally Depending on the feature you use, the App may process locally: - QR codes and barcode content; - QR creator inputs and generated QR images; - camera frames and user-selected images; - scan history, favorites, inventory records, and batch-scan results; - document scans, OCR input, recognized text, and generated PDFs; - identification-document scans and extracted fields; - PDF, Word, Excel, JSON, text, source-code, and other supported files; - ZIP or archive contents, extracted files, and passwords entered for an archive operation; - file names, content URIs, and storage locations selected by you; and - App preferences, language, advertising-frequency state, and related local settings. The App does not automatically upload this content to a server operated by me. 3.3 Local machine-learning processing The App uses Google ML Kit and related Google scanner components for barcode scanning, OCR, and document-scanning functions. Google states that ML Kit input data, including images, video, and text, and the resulting outputs are processed on the device and are not sent to Google servers. ML Kit may contact Google to obtain bug fixes, updated models, and hardware-accelerator compatibility information. It may also send performance, utilization, security, and abuse-prevention metrics to Google. 3.4 Local storage and exported files Scan history and certain App records may be stored in local App databases. Generated images, PDFs, documents, spreadsheets, exports, or extracted files may be stored in App-controlled storage or in a location you select. The App requests that Android not back up App-controlled data. Files saved outside App-controlled storage may nevertheless be backed up, transferred, synchronized, or retained by Android, your device manufacturer, your Google account, or the storage provider you selected. 3.5 Clipboard, sharing, and external destinations When you copy information, it is placed on the Android clipboard and may be available to the operating system or other applications as permitted by Android. When you choose to share, export, print, save, upload, open, or transmit content through another application, website, communication service, file provider, or storage destination, that action is user-directed. The recipient may process and retain the content under its own terms and privacy policy. QR codes, documents, identification records, files, and archives may contain personal or sensitive information. Review content and destination details before copying, opening, exporting, or sharing it. 4. THIRD-PARTY SERVICES The current App includes or uses the following Google services and related SDK components: - Google Mobile Ads and Google AdMob; - Google User Messaging Platform (“UMP”); - Google Analytics for Firebase; - Firebase Crashlytics; - Firebase Installations; - Firebase Sessions; - Google ML Kit Barcode Scanning; - Google ML Kit Text Recognition; and - Google Play services ML Kit Document Scanner. These services may communicate with Google automatically when the App is installed, opened, used, brought to the foreground, begins a session, requests or displays an advertisement, uses a supported ML Kit function, or experiences a crash or technical problem. 5. DATA COLLECTED AND SHARED The categories below reflect the App’s current Google Play Data safety disclosure and the documented behavior of the included third-party SDKs. 5.1 Data collected and shared The following categories may be collected and shared with Google, its affiliates, service providers, advertising partners, or other participants involved in delivering and measuring Google advertising: A. Approximate location - Source: Internet Protocol (“IP”) address and related network information. - Scope: general or approximate location, not precise GPS location. - Purposes: analytics; advertising or marketing; and fraud prevention, security, and compliance. The App does not request Android precise-location or approximate-location permission for its own functionality. B. App interactions Examples may include App launches, sessions, taps, screen or feature interactions, advertising impressions, advertising interactions, and video views where applicable. Purposes: analytics; advertising or marketing; and fraud prevention, security, and compliance. C. Diagnostics Examples may include App or SDK launch time, hang rate, energy usage, performance, error information, network state, App version, SDK version, and related technical measurements. Purposes: analytics; advertising or marketing; and fraud prevention, security, and compliance. D. Device or other identifiers Examples may include the Android Advertising ID, App Set ID, Analytics app-instance ID, Firebase installation ID, Crashlytics installation UUID, Firebase session identifiers, and other supported device, installation, advertising, or service identifiers. Purposes: analytics; advertising or marketing; and fraud prevention, security, and compliance. 5.2 Data collected but not declared as shared Crash logs may be collected for App functionality and analytics. Crash information may include stack traces, relevant App state, device metadata, timestamps, App version, operating-system information, and installation or session identifiers. In the App’s current Google Play Data safety disclosure, crash logs are identified as collected and not shared. 5.3 Data not automatically transmitted as first-party content The following content is not automatically transmitted to me or to Google Mobile Ads merely because you use the corresponding App function: - QR or barcode payloads; - camera images or frames used for scanning; - OCR source images and recognized text; - documents, identification scans, and document-scan outputs; - files, archive contents, and archive passwords; - generated QR images, PDFs, or exports; and - locally stored scan history. This statement does not cover a user-directed share, upload, export, print, external open action, support attachment, or storage destination selected by you. It also does not exclude the technical metrics sent by ML Kit, advertising, Analytics, Crashlytics, Installations, or Sessions. 6. ADVERTISING AND PRIVACY CHOICES The App is supported by Google-served advertising and may display: - a banner advertisement on the Home screen; - an occasional interstitial advertisement when returning to Home; and - an optional rewarded advertisement that may hide banner and interstitial advertisements for 60 minutes after successful completion. Advertising availability, personalization, content, frequency, measurement, and delivery may depend on your region, device, connection, consent status, privacy choices, Google configuration, and provider systems. Google states that the Google Mobile Ads SDK automatically collects and shares IP address, product interactions, diagnostic information, and device or account identifiers for advertising, analytics, and fraud-prevention purposes. Google states that this data is encrypted in transit using Transport Layer Security (“TLS”). The App requests updated consent information from UMP at launch. Advertising requests are conditioned on the consent status reported by UMP. When UMP reports that a privacy-options entry point is required, the App may provide a visible control through which you can review or change applicable advertising choices. Depending on your region and choices, advertisements may be personalized, contextual, limited, or otherwise restricted. A UMP choice concerning advertising does not necessarily disable Google Analytics for Firebase, Firebase Crashlytics, Firebase Installations, Firebase Sessions, ML Kit metrics, contextual advertising, security processing, fraud prevention, or every network communication made by the App. You may also manage advertising choices through Android advertising settings and applicable Google account, privacy, or advertising controls. 7. FIREBASE ANALYTICS, CRASHLYTICS, INSTALLATIONS, AND SESSIONS 7.1 Google Analytics for Firebase Google Analytics for Firebase may automatically process information such as App opens, first launches, sessions, session duration, App updates, device and operating-system information, approximate geography, advertising identifiers where available, and an App-instance identifier. The audited implementation identified default automatic Analytics collection and did not identify App-authored custom Analytics events or an App-authored Analytics user ID. 7.2 Firebase Crashlytics Firebase Crashlytics may automatically process stack traces, relevant App state, relevant device metadata, timestamps, App and operating-system versions, a Crashlytics installation UUID, and related technical data needed to provide crash reporting and crash management. The audited implementation did not identify App-authored Crashlytics user IDs, custom keys, custom logs, user-content reporting, or developer-defined non-fatal events. 7.3 Firebase Installations Firebase Installations generates and collects a per-installation Firebase installation ID and related Firebase user-agent information. The identifier identifies an App installation and is not a first-party user account. 7.4 Firebase Sessions Firebase Sessions may process App metadata, operating-system and SDK information, network-connection type, device manufacturer and model, and usage measurements such as when the App enters the foreground to start a session. UMP advertising choices do not by themselves disable these Firebase services. 8. SUPPORT COMMUNICATIONS When you contact support, I may receive the information you voluntarily provide, including your email address, message, screenshots, files, diagnostic details, and other attachments. I use support information to: - respond to your request; - investigate technical or privacy issues; - prevent abuse or fraud; - maintain appropriate records; - protect legal rights; and - comply with applicable law. Do not send passwords, payment-card information, health information, government identification, archive passwords, or other highly sensitive information unless it is specifically requested and reasonably necessary. 9. PURPOSES OF PROCESSING Information processed in connection with the App may be used to: - provide and maintain App functions requested by you; - process and store content locally; - deliver, limit, personalize where permitted, secure, and measure advertisements; - manage consent and advertising privacy choices; - measure App usage, sessions, engagement, and stability; - detect, diagnose, and correct crashes, errors, or technical problems; - maintain and improve supported ML Kit functions; - prevent fraud, abuse, misuse, and security incidents; - respond to support, privacy, and deletion requests; - comply with legal obligations; and - establish, exercise, or defend legal claims. 10. DISCLOSURE; SALE; TARGETED ADVERTISING Information may be processed or disclosed to: - Google and its affiliates in connection with AdMob, UMP, Analytics, Crashlytics, Installations, Sessions, ML Kit, and related infrastructure; - service providers, subprocessors, and advertising partners involved in providing, securing, limiting, personalizing where permitted, or measuring those services; - a destination selected by you when you share, export, open, save, print, upload, or transmit content; - courts, regulators, law-enforcement agencies, or other persons when reasonably necessary to comply with valid legal process or applicable law; and - persons involved in investigating fraud, abuse, security incidents, violations, or legal claims. I do not sell personal information in exchange for money. Some privacy laws may classify certain advertising-related disclosures as a “sale,” “sharing,” “targeted advertising,” or a similar regulated activity even when no money is paid for the information. Where applicable, privacy choices may be available through UMP, Android, Google, or a legally required request process. 11. RETENTION AND DELETION 11.1 Local App data Local history, preferences, generated content, and other App-controlled data remain on the device until deleted, overwritten, cleared, or removed. Where the corresponding control is available, you can delete individual history records, generated content, or other local records inside the App. You may also clear App-controlled data through: Android Settings → Apps → QR Decoder → Storage → Clear storage/data Uninstalling the App also removes App-controlled local data, subject to operating-system behavior. 11.2 User-selected and exported files Files saved in user-selected folders, media collections, document folders, cloud-backed locations, or another provider remain there until you delete them through the App, Android file manager, media gallery, storage provider, or other application that manages that destination. Clearing App storage or uninstalling the App may not delete files previously exported outside App-controlled storage. 11.3 Clipboard and external sharing Clipboard content and information sent to another application or service are controlled by Android and the receiving destination. Use the controls provided by the device or recipient to delete those copies. 11.4 Support communications Support and privacy communications are retained only as long as reasonably necessary to respond, maintain appropriate records, prevent abuse, resolve disputes, protect rights, and comply with applicable law. 11.5 Google and other third-party data Google and other providers control retention of information processed through their services according to their configurations, account settings, contractual terms, security requirements, and legal obligations. I may be unable to identify, access, retrieve, or delete provider-held data when it is associated only with a device, installation, advertising, App-instance, crash, or session identifier. Available controls may include: - the App’s Privacy Options control where UMP requires it; - Android controls to reset or delete the Advertising ID or limit ad personalization; - Google account, advertising, privacy, and deletion controls; and - controls supplied by the applicable storage or receiving provider. 11.6 Requests to the operator To request deletion of support information or other information directly controlled by me, email: afkerian.support@gmail.com Use the subject: QR Decoder — Data Deletion Request The App does not provide a first-party account, so there is no first-party account to delete. A request does not automatically delete local files remaining on your device or information controlled by Google or another provider. 12. PRIVACY RIGHTS AND CONTROLS Depending on your residence and applicable law, you may have rights to request: - access to personal information; - correction of inaccurate information; - deletion; - a portable copy; - restriction of or objection to certain processing; - withdrawal of consent where processing depends on consent; - an opt-out from certain sale, sharing, or targeted-advertising activities; or - review or appeal of a privacy-request decision where required. These rights may be subject to legal thresholds, exceptions, identity-verification requirements, and limitations. Submit requests to: afkerian.support@gmail.com Use the subject: QR Decoder — Privacy Request I may request information reasonably necessary to verify the request, locate responsive records, prevent fraud, and protect other persons. I will not unlawfully discriminate against you for exercising an applicable privacy right. 13. CHILDREN The App is intended for adults age 18 or older and is not directed to children. The App does not currently use a technical age-verification or age-gate system. I do not knowingly solicit personal information from children through a first-party account, registration form, or profile service. Third-party SDKs may process technical identifiers automatically when the App is used. If I obtain actual knowledge that personal information from a child was processed in circumstances subject to applicable child-privacy law, I will take reasonable steps to investigate and address the information as required by law. A parent or legal guardian may contact: afkerian.support@gmail.com 14. SECURITY AND INTERNATIONAL PROCESSING I use safeguards reasonably appropriate to information directly under my control. Google states that data transmitted by the Google Mobile Ads SDK is encrypted in transit using TLS. Google also states that relevant Firebase data is encrypted in transit using HTTPS. No device, application, system, network, transmission, or storage method is completely secure. Absolute security cannot be guaranteed. Google and its service providers may process information in the United States and other countries where they maintain facilities, personnel, infrastructure, or subprocessors. Privacy laws in those countries may differ from those in your location. 15. THIRD-PARTY POLICIES AND INFORMATION Google Privacy Policy: https://policies.google.com/privacy Google Mobile Ads data disclosure: https://developers.google.com/admob/android/privacy/play-data-disclosure Google User Messaging Platform: https://developers.google.com/admob/android/privacy Firebase Android data disclosure: https://firebase.google.com/docs/android/play-data-disclosure Google Analytics data collection: https://support.google.com/firebase/answer/6318039 ML Kit Terms and Privacy: https://developers.google.com/ml-kit/terms Third-party terms, services, SDK behavior, and documentation may change independently of this Policy. 16. CHANGES TO THIS POLICY I may update this Policy when the App, its functions, its providers, applicable requirements, or information practices change. The current version will identify its effective date and last-updated date. Material changes will receive additional notice when required or reasonably appropriate. 17. CONTACT Jesus Afkerian, a natural person operating under the AFKERIAN INTERACTIVE brand Publisher and operator of QR Decoder Privacy, support, and deletion email: afkerian.support@gmail.com Website: https://afkerianinteractive.github.io/ QR Decoder: https://afkerianinteractive.github.io/qr-decoder/