← QBP Scanner
Legal

QBP Scanner — Privacy Policy

Effective date: 10 September 2026 Operator: Murat Kuşlu, İzmir, Türkiye Contact: murat.kuslu@outlook.com

QBP Scanner is a QR, barcode, DataMatrix and document scanner for iOS. This policy describes exactly what the app does with your information. It is written to be read, not to be skimmed past, and every statement in it describes behaviour that is actually implemented in the app.

Who is responsible

QBP Scanner (“the app”) is developed and published by Murat Kuşlu, an individual developer based in İzmir, Türkiye (“we”, “us”, the operator). For any question about this policy or about your information, write to murat.kuslu@outlook.com.

Where the GDPR applies, the operator is the data controller for the limited processing described below. In practice there is very little to control: the app has no server of its own and holds no personal data about you.

The short version

There is no account and no sign-up. There is no analytics SDK, no advertising, and no tracking of any kind. Camera frames are decoded on your device and are never uploaded. Your scan history, documents and PDFs live in the app on your device.

Four things do leave the device, and only in the circumstances described below: an optional iCloud backup into your own iCloud; the number of a scanned retail barcode, sent to the Open Food Facts open database to look up the product; HEAD requests to a scanned link and its redirect chain, to tell you where the link leads before you open it; and anything you deliberately send to a webhook URL you configure yourself. Purchases are processed by Apple and validated through RevenueCat.

The rest of this document explains each of those in detail.

No account, no tracking, no ads

  • The app has no account system. You cannot sign up, sign in, or create a profile, and there is nothing for us to associate with you.
  • The app contains no analytics SDK — no usage statistics, session recording, crash-reporting service or behavioural measurement of any kind.
  • The app contains no advertising and no advertising SDKs.
  • The app does not track you across apps or websites, and does not use the Advertising Identifier (IDFA). The App Privacy Manifest bundled with the app declares NSPrivacyTracking = false with an empty list of tracking domains.

The single data type declared in the app's privacy manifest is Purchase History, linked to the anonymous purchase identifier described in section 10, used only for app functionality (knowing whether your subscription is active) and explicitly not used for tracking.

Scanning happens on your device

When you scan a code or a document, the camera feed is processed on your device by Apple's Vision framework, which is part of iOS. Barcode and text recognition run locally. Camera frames are never transmitted, uploaded, stored on any server, or shared with us or anyone else. The same is true when you scan a code out of an image in your photo library, and when the app performs optical character recognition on a scanned document.

The app does not require an internet connection to scan. Scanning works entirely offline; only the optional features in sections 6 to 9 involve the network.

What is stored on your device

Your scan history, folders, scanned documents, generated PDFs and page images are stored in the app's own sandbox on your device. Nothing in that store is sent to us.

  • Scan history and folders are held in a local database inside the app's container.
  • Generated PDFs are written to the app's Documents folder, which means they are visible to you in the iOS Files app under On My iPhone › QBPScanner. Because the app supports opening documents in place, other apps you choose can also open those PDFs from that folder. This is a convenience for you, not a transfer to us.
  • Page images and thumbnails for scanned documents are stored in the app's support directory.
  • Settings (including your preferences and any webhook URL you enter) are stored in the app's local preferences.

Deleting the app deletes this local data. See section 14 for the full picture, including iCloud.

iCloud Backup (optional)

The app offers an optional iCloud backup. It is off by default and only becomes active if you turn it on in Settings.

When it is on, your scanned codes, your folders and your scanned documents — including the bytes of the generated PDFs — are mirrored, through Apple's CloudKit, into the private database of your own iCloud account. That data is stored under your Apple ID, in your iCloud storage, governed by Apple's Privacy Policy. We have no access to it whatsoever — no administrative view, no copy, no ability to read or recover it. Page images and thumbnails are not mirrored; they are regenerated locally from the PDF.

If you turn iCloud backup off, the app stops mirroring new data, but anything already in your iCloud stays there until you remove it. You remove it yourself, from your device, under Settings › [your name] › iCloud › Manage Account Storage, or by deleting the app's iCloud data from that screen.

Retail product lookup

When you scan a retail product barcode (an EAN or UPC code), the app looks the product up so it can show you what the code refers to. To do that, it sends the barcode number itself to Open Food Facts (world.openfoodfacts.org), a third-party, independent, open food products database. This lookup happens automatically when a retail barcode result is displayed.

  • What is sent: the barcode number and the list of fields the app wants back. Nothing else.
  • What is not sent: no name, no email, no account (there is none), no device identifier, no location, and no other scan of yours.
  • As with any request to a website, Open Food Facts' servers can see the IP address your request comes from.
  • If the product has a photo, that image is then loaded from Open Food Facts' image servers to display it.

Open Food Facts is an independent open database and is not operated by us. Product information shown in the app is contributed to and maintained by that project, and its accuracy and completeness are theirs, not ours — see section 6 of the Terms. Their handling of requests is governed by their own privacy policy. Credit and thanks to the Open Food Facts contributors, whose work makes this feature possible.

Link safety check

A QR code that contains a URL does not show you where it goes. To close that gap, when the app displays a scanned URL it checks where the link actually leads before you open it.

It does this by issuing HEAD requests — requests that ask only for a response's headers and never download the page — and following the redirect chain manually, one hop at a time, to a maximum of five hops. Redirects are never followed automatically; the app stops at each step, records where it was pointed, and decides whether to continue. It then reports the final destination to you.

  • The servers contacted are those of the scanned link and of each host it redirects to. Those servers can see your device's IP address and the fact that a request was made, exactly as they would if you had opened the link in a browser.
  • The result of the check is sent to us — never. There is no reporting back, no reputation service of ours, and no log.
  • The verdict is advisory only. It tells you where a link resolves to; it is not a malware scan and cannot guarantee that a destination is safe. Opening the link is always your own deliberate tap.

Webhook (optional)

For people who want to pipe their scans into their own system, Settings lets you enter a webhook URL of your own choosing. This field is empty by default and the feature does nothing until you fill it in.

Once a URL is configured, each scan is sent to that address as an HTTP POST containing the decoded payload along with the code's symbology, its detected type, a title, the source of the scan, and the time it was scanned. It continues for every scan until you clear the field.

The endpoint is yours. You choose it, you control it, and you are responsible for it — for its security, for what it does with the data, and for the lawfulness of sending scan contents there. We have no involvement in and no visibility of that traffic. Do not configure a webhook you do not trust, and remember that whatever you scan while it is set will be sent there.

Purchases and subscriptions

QBP Scanner offers an optional paid tier, QBP Pro, sold as an auto-renewing subscription on a weekly or a yearly plan. Each plan includes a free introductory trial (currently three days) for eligible new subscribers, as configured in App Store Connect and shown to you on the purchase screen before you buy.

All payments are processed by Apple. We never see, receive or store your payment card, your Apple ID credentials, or your billing address. Billing, renewal and refunds are entirely Apple's.

To validate purchases and keep your subscription status correct across your devices, the app uses RevenueCat, a third-party subscription infrastructure provider, which acts as our processor. RevenueCat receives an anonymous app user identifier generated on your device — not your name, not your email, not your Apple ID — together with purchase and receipt information from the App Store (which product was bought, when, whether it is active, whether a trial was used). This is the “Purchase History” entry in the app's privacy manifest: linked to that anonymous identifier, used only to make the app work, and not used for tracking.

  • Managing or cancelling: on your device, under Settings › [your name] › Subscriptions. A subscription renews unless you cancel it at least 24 hours before the period ends.
  • Refunds: handled by Apple, through reportaproblem.apple.com. We cannot issue refunds for App Store purchases.
  • Restoring: use “Restore Purchases” in the app's Settings, signed in with the Apple ID that made the purchase.

On-device encryption

The app can encrypt a scanned payload on your device using a password that you choose. The encryption is performed locally with authenticated AES-GCM encryption, using a key derived from your password with a salted HKDF-SHA256 derivation. The password is never stored by the app and never transmitted anywhere.

There is no recovery. Because we never hold your password and never receive the encrypted data, nobody — including us — can decrypt your content or reset your password. If you lose the password, the encrypted payload cannot be recovered by any means. Keep it somewhere safe.

Permissions

iOS asks for each of these permissions the first time it is needed, and the app requests them only in response to an action you take. You can change any of them later in Settings › QBPScanner. Declining a permission disables only the feature that needs it.

PermissionWhen it is asked forWhat it is used for
Camera When you open the scanner. Reading codes and capturing document pages. Frames are processed on device and never leave it.
Contacts Only when you tap to save a scanned contact card. Writing that one contact. The app does not read, browse or upload your contacts.
Calendar Only when you tap to add a scanned event. Adding that one event. The access is write-only — the app cannot read your calendar.
Photos Only when you tap to save a code you created. Saving that one image. The access is add-only — the app cannot read your photo library.

The app requests no location access, no microphone access, and no read access to your photo library or contacts.

Children

QBP Scanner is not directed at children under 13 and is not designed or marketed for them. We do not knowingly collect personal information from children under 13 — in fact, we do not collect personal information from anyone, of any age, because the app has no account and no server. If you are a parent or guardian with a question about this, please write to us.

Retention and deletion

We hold nothing, so there is nothing on our side to retain or delete. Your data is retained where you keep it:

  • On your device: scans, folders, documents, PDFs and settings stay until you delete them in the app, or until you delete the app. Deleting the app deletes this data.
  • In your iCloud: if you turned on iCloud backup, remove the app's data from Settings › [your name] › iCloud › Manage Account Storage. Deleting the app alone does not clear what is already in iCloud.
  • At RevenueCat: purchase records tied to the anonymous identifier are retained for as long as needed to maintain subscription entitlements. Write to us if you want that record deleted and we will request it.
  • At Apple: purchase and billing records are held by Apple under its own policy.
  • At your webhook endpoint: whatever you sent there is retained according to your own arrangements. We cannot delete it.

Your rights

If you are in the European Economic Area or the United Kingdom, the GDPR and UK GDPR give you rights of access, rectification, erasure, restriction, portability and objection. If you are in Türkiye, the Personal Data Protection Law No. 6698 (KVKK) gives you equivalent rights, including the right to learn whether your personal data is processed and to request its deletion.

Because the app holds no personal data on any server of ours, most of these requests are satisfied directly and immediately by you: your data is on your device and in your own iCloud, entirely under your control, and deleting it there is complete deletion. There is no copy for us to hand over, correct or erase.

For anything not covered by that — including a request regarding the anonymous purchase record held by RevenueCat — write to murat.kuslu@outlook.com and we will respond within the period the applicable law requires. You also have the right to lodge a complaint with your local supervisory authority (in Türkiye, the Kişisel Verileri Koruma Kurumu).

Changes to this policy

If the app's behaviour changes in a way that affects this policy, the policy is updated and the effective date at the top of this page is changed. Material changes will also be noted in the app's release notes. The current version is always the one published at this address.

Contact

Murat Kuşlu
İzmir, Türkiye
murat.kuslu@outlook.com

See also the QBP Scanner Terms of Use.