Privacy policy
Last updated: 4 June 2026
This page explains what personal data GhostQR collects and how it is handled. It is not legal advice and is pending review by privacy counsel.
Who we are
GhostQR is a dynamic QR code platform operated from Australia. For any privacy question or request, contact privacy@ghqr.au.
What we collect
Account
Your email address and a one-way hash of your password. We never store your password in readable form.
Your QR codes
The codes you create — names, styles, and (for dynamic codes) the current and previous destination URLs you set. Destinations are checked against Google Safe Browsing when you set or edit them, to keep the platform free of phishing and malware links.
Scan analytics
When someone scans a dynamic code, we record the time, a coarse country, a device category, and a daily-rotating pseudonymous identifier derived by one-way hashing. We do not store raw IP addresses or names, and the pseudonym cannot be reversed or linked across days.
Payments
Subscriptions are handled by Stripe. Card details are entered on Stripe’s systems and are never seen or stored by GhostQR — we keep only a customer/subscription reference and your plan tier.
Cookies & usage analytics
Analytics cookies are set only with your consent. See the cookie policy for the full list and how to change your choice.
The Claude / AI connector
GhostQR offers an optional connector that lets you drive your own account from an AI assistant such as Claude (Claude Code, Claude Desktop, or the API). It is off until you turn it on, and you stay in control of it:
- You generate a personal access token in your account. We store only a one-way hash of it — the token itself is shown to you once and never again.
- When you connect an AI client, that client uses your token to call our API and act on your account only, limited to the scopes (
read,write,delete) you grant. - GhostQR does not send your data to Anthropic or any AI provider. The AI client you choose makes those requests on your behalf; whatever it does with the responses is governed by that provider’s own terms and privacy policy, not ours.
- You can revoke a token at any time from your account, which immediately cuts off that connection.
How we use your data
To provide the service: authenticate you, store and serve your codes, redirect scans, show you analytics, take payment, prevent abuse, and respond to support requests. We do not sell your personal data.
Who processes it
We rely on a small set of processors: Stripe (payments), Google (optional Analytics and Safe Browsing), and our hosting and edge providers. Some of these process data outside Australia, including in the United States.
Retention
We keep account and code data for as long as your account is active. Pseudonymous scan records are kept to provide analytics. Delete a code or close your account and the associated data is removed, subject to any records we must retain for legal or accounting reasons.
Your rights
You can access, correct, export, or delete your data. Email privacy@ghqr.au and we will respond within a reasonable time.
Changes
If this policy changes materially, we will update the date above and, where appropriate, notify you.