This Privacy Policy explains how Kuar Labs ("we," "us," "our") collects, uses, shares, and protects information when you use kuar.codes and related APIs (the "Service"). By using the Service, you agree to the practices described here.
1. What We Collect
We collect the following categories of data:
- Account data — your name and email address when you register, whether via email/password or OAuth (Google/Apple).
- Scan analytics — each time a QR code you own is scanned, we record a timestamp, coarse geographic region (country/city derived from IP; the raw IP is not stored), and device class derived from the user-agent string (e.g., "iPhone," "Android," "Desktop"). We do not build individual user profiles from scan data.
- QR assets stored in R2 — SVG and PNG files generated by the QR builder are stored in Cloudflare R2 object storage under your account.
- Billing data — if you subscribe to a paid plan, payment and billing information is processed and stored by Polar; we receive only non-sensitive metadata (subscription tier, renewal dates) to manage your account state.
- Usage & product analytics — we use PostHog to collect product-usage events (page views, feature interactions) so we can improve the Service. PostHog data is pseudonymous and linked to your account ID, not your email.
2. How We Use Your Data
- To provide, operate, and improve the Service.
- To display scan analytics dashboards so you can understand how your QR codes are performing.
- To send transactional emails (email verification, password reset, billing receipts).
- To enforce our Terms of Service and prevent abuse.
- To comply with legal obligations.
We do not sell your personal data to third parties.
3. Third-Party Processors
We share data with the following sub-processors to operate the Service:
- Cloudflare — infrastructure hosting, CDN, Workers compute, R2 object storage, and transactional email (Cloudflare Email Routing / Workers). Data is processed under Cloudflare's DPA.
- Polar — subscription billing and payments. Polar is the merchant of record for Pro subscriptions.
- PostHog — product analytics and session insights. PostHog is a self-hostable, privacy-friendly analytics platform; data is retained according to PostHog's data retention settings on our account.
4. Cookies and Auth Sessions
The Service uses an HttpOnly, Secure session cookie to maintain your logged-in state. This cookie is set by Better Auth and is strictly necessary for the Service to function; it does not track you across third-party sites. We do not use advertising cookies or third-party tracking pixels.
5. Data Retention
Account data is retained while your account is active. Scan analytics records are retained for 24 months rolling. QR assets in R2 are deleted within 30 days of account closure. Billing records are retained for as long as required by applicable tax and financial regulations (typically 7 years).
6. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, port, or delete your personal data. To exercise any of these rights, email us at privacy@kuar.codes. We will respond within 30 days. You may also delete your account directly from the dashboard settings page, which will initiate the deletion of your data as described above.
7. Security
All data in transit is encrypted via TLS. Passwords are hashed before storage. API keys are stored as hashed values and never exposed in plain text after initial creation. R2 assets are stored in private buckets accessible only through authenticated requests. We conduct periodic security reviews.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent in-app notice at least 14 days before the changes take effect. Continued use of the Service constitutes acceptance.
9. Contact
Questions about this Privacy Policy? Contact our privacy team at privacy@kuar.codes or write to us at hello@kuar.codes.