Privacy

What we don't keep

The data you encode and the images you decode are processed in memory and never stored. Barcode payloads can carry sensitive information, so responses that echo your data are marked no-store and nothing about the content of a code is written to disk or to any analytics system.

There is no advertising, no third-party tracking script, and no analytics vendor on any page.

What we do keep

Aggregate popularity counters: which barcode types are generated, from which surface (web, API, CLI, MCP). These are plain tallies with no payload content and nothing that identifies you.

If you create an account: your email address, a salted password hash, your API keys, and per-key usage counts for quota enforcement. The only cookies are strictly necessary: a CSRF token, and a session cookie when you sign in. Ordinary web-server logs (IP, path, timestamp) exist for abuse prevention and rotate out.

Questions, or want an account and its data deleted? Use the contact page — deletion requests are honored.