Google Play Policy Compliance • Privacy Shield

Privacy Policy for SuperQR

SuperQR is engineered as a pure, privacy-first, offline utility. We believe your scan history, camera frames, and personal data belong exclusively to you on your device.

Application: SuperQR (Universal QR & Barcode Scanner) Package Name: com.botcmd.superqr Publisher: Botcmd (Sachin Jakhar) Effective Date: October 10, 2026

Zero Camera Recording

Your camera stream is processed strictly in volatile device memory to parse barcodes. No photos or video feeds are ever stored or uploaded.

100% Local On-Device Storage

Scan history, favorite items, and app settings are saved only inside your device's private sandbox storage. We run zero tracking servers.

No Personal Tracking

No account sign-ups, no tracking of phone numbers or email addresses, and zero sale of personal data to data brokers or advertising networks.

Section 01

Device Permissions & Why We Need Them

To deliver instant, high-speed QR and barcode scanning, SuperQR requests a minimal set of device permissions. Each permission is requested strictly at the point of use with transparent system prompts:

  • Camera (android.permission.CAMERA): Required to detect and decode QR codes, 1D retail barcodes (UPC/EAN), Code 128, Data Matrix, Aztec, and PDF417 formats in real-time. Video frames are processed in volatile memory via client-side computer vision models and are never captured, saved, or transmitted to any server.
  • Photo Library / Gallery (READ_MEDIA_IMAGES / READ_EXTERNAL_STORAGE): Only invoked when you explicitly choose to scan an image from your device gallery. We only read the specific image file selected by you.
  • Vibration (android.permission.VIBRATE): Provides subtle haptic feedback when a code is successfully decoded or when an invalid format is encountered.
  • Internet Access (android.permission.INTERNET): Used exclusively to retrieve public product nutritional metadata from Open Food Facts when retail barcodes are scanned, and to load outbound URLs when you choose to open a link.
Section 02

Data We Collect vs. Data We Never Collect

What We Do NOT Collect:

  • We do not require user registration, logins, emails, or phone numbers.
  • We do not collect GPS, fine location, or location tracking coordinates.
  • We do not collect biometric, facial recognition, or physical identity data.
  • We do not log financial credentials, banking passwords, or UPI PINs.
  • We do not collect Advertising IDs (GAID/IDFA) for cross-app tracking.
On-Device Scan History: Every code you scan (URLs, Wi-Fi credentials, contacts, product barcodes) is stored strictly in your device's local database (AsyncStorage / SQLite sandbox). This data never leaves your device unless you manually tap "Export to CSV" or "Export to JSON" to save a file to your own storage or share it via your system share sheet.
Section 03

Third-Party Services & Outbound Integrations

SuperQR integrates with a carefully restricted set of external public services to enhance your scanning experience:

  • Open Food Facts API: When you scan a packaged food retail barcode (EAN-13 / UPC), the numerical barcode string is queried against the non-profit Open Food Facts public database to fetch product names, ingredients, Nutri-Score, and allergen data. No user identifier is sent with this query.
  • UPI Digital Payment Apps: When scanning a UPI QR code, SuperQR parses the merchant string and deep-links directly into installed banking applications (Google Pay, PhonePe, Paytm, BHIM, etc.) using standard Android system URI intents (upi://pay). SuperQR is not a payment intermediary and never handles, records, or stores bank credentials or transaction status.
  • Commercial & Affiliate Disclosures: When reviewing retail packaged goods, SuperQR may provide convenient 1-tap shortcuts to check item availability on quick-commerce and e-commerce platforms (such as Zepto, Blinkit, Swiggy Instamart, Amazon, or Walmart). If you choose to tap these links, we may receive an affiliate referral commission at zero additional cost to you. These third-party services operate under their own independent terms and privacy policies.
Section 04

Data Retention, Control & Deletion Rights

Because all personal scan records are kept exclusively in local on-device storage, you maintain 100% control over your data lifecycle at all times:

  • Individual Deletion: You can delete any individual scan entry at any time by tapping the trash icon in the History screen.
  • Complete History Wipe: You can clear your entire history database in 1 tap by tapping "Clear All" in the History screen or using "Clear All History" in the Settings screen.
  • Full App Erasure: Uninstalling the SuperQR application from your device immediately and permanently deletes all locally stored scan history, favorites, and settings from your device.

Since Botcmd does not operate a centralized backend server storing your personal scan data, there is no remote server data to delete.

Section 05

Children's Privacy Protection (COPPA Compliance)

SuperQR is a general utility application intended for general audiences. We do not knowingly collect, store, or solicit personally identifiable information from children under the age of 13 (or under the age of 16 in the European Economic Area). If you are a parent or guardian and believe that your child has submitted personal data through our support channels, please contact us immediately, and we will promptly remove such records.

Section 06

GDPR & California Consumer Privacy Act (CCPA)

Under European General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA):

  • Right to Access & Portability: You can export 100% of your scan history anytime in open standard CSV or JSON format directly from the app.
  • Right to Erasure ("Right to be Forgotten"): You can purge all records instantly via the app settings.
  • Zero Sale of Personal Data: Botcmd has never sold, rented, or transferred your personal information to third-party data brokers or marketing firms, and will never do so.
Section 07

Policy Updates

We may update this Privacy Policy periodically to reflect technological improvements, new scanner capabilities, or evolving legal frameworks. Any changes will be published on this page with an updated "Effective Date". We encourage users to review this policy periodically.

Publisher & Developer

Botcmd

Founder: Sachin Jakhar

Official Support Email

mesachinjakhar@gmail.com

Response within 24–48 hours

Official Domain

superqr.botcmd.cloud

Hosted on secure HTTPS protocol