Legal

Privacy Policy

Last modified: October 6, 2026

What we never collect

We do not collect or retain any data entered by users while utilizing the keyboard. Your keystrokes are never logged, stored or transmitted. The app's local history database holds scanned values only – never anything you type.

The keyboard also switches its own prediction off entirely on sensitive field types – password fields, visible-password fields, email address fields, URI fields and filter fields – so text entered there is not processed at all.

Scanning happens on your device

Barcode and text recognition run entirely on your device. The recognition models are bundled inside the app itself, so no camera frame and no image leaves your phone – not to us, not to Google, not to anyone. The camera permission exists only so the app can look for a barcode in the live preview.

There is exactly one exception, and it only exists if you create it. AI scanning, an optional feature of the Pro version, sends a photograph to a cloud AI service to be read. It is switched off until you switch it on. Section 3 sets out precisely what is sent, to whom, and what happens to it afterwards.

At a glance

What we handle depends entirely on which parts of the product you use. These situations are genuinely different, so each is covered separately below.

SituationWhat leaves your device
Keyboard app,
signed out (default)
No scanned data and nothing you type, unless you set up one of the integrations below. Anonymous usage and crash diagnostics only, plus advertising in the free version.
Keyboard app,
signed in (optional)
Your scans sync to your cloud account, together with your email address and display name.
AI scanning (Pro, off by default)Only once you switch it on: a photograph you take, sent to a cloud AI provider to be read, together with the instruction you wrote. The provider does not retain it and does not train on it.
Integrations you set up (optional)Scans are sent to a server address you or your administrator chooses. We are not the recipient.
Enterprise enquiry form (optional)Only the contact details you choose to enter, plus basic device and app information.
Web dashboardYour account details, your synced scan history, and billing data handled by Stripe.

Keyboard App (Android)

Barcode & QR Keyboard

1. About our app

Welcome to Barcode & QR Keyboard – the swift and enjoyable solution for effortless barcode scanning. This Android software keyboard comes equipped with an integrated barcode reader, delivering a seamless experience.

2. Camera access

The app requests access to your phone's camera solely to read barcodes and QR codes. Camera frames are examined in memory by recognition models bundled inside the app and are then discarded. They are never saved to storage, never uploaded, and never transmitted to us or to any third party.

That is true of every scan the app performs by default. The one exception is AI scanning, the optional Pro feature in section 3: if, and only if, you switch that on, taking an AI scan captures a photograph and sends it to a cloud AI provider to be read.

3. AI scanning (Pro version, and only if you switch it on)

AI scanning is an optional feature of the Pro version. It lets you write an instruction once – “just the serial number”, “the VIN” – and have the app return that one value. It is the only part of the app that sends an image off your device, which is why it is set out separately here.

It is off until you switch it on. If you never switch it on, nothing in this section applies to you, and the camera behaviour described in section 2 holds without exception.

Once you have switched it on, here is what happens each time you take an AI scan:

  • The app captures a photograph and sends it to a third-party cloud AI provider, which reads it and returns the value. Whatever is in the frame is in that photograph, so treat it as you would any other picture of a document.
  • The instruction you wrote in settings is sent with it, because it is what tells the provider what to look for.
  • The provider reads the image and returns an answer. It does not retain the image and does not use it to train any model. The photograph is not added to your scan history either – the history stores only the value that came back.
  • Because the reading happens on a server, AI scanning needs an internet connection. Ordinary barcode and text scanning does not, and carries on working entirely on the device.

AI scanning requires you to be signed in, so using it also engages section 6: the value that comes back is a scan like any other and syncs to your account. Switch AI scanning off and the app stops capturing and sending photographs; switch it back on and it resumes. Nothing you type on the keyboard is involved at any point.

4. Scan history on your device

The app keeps a history of your scans in a database on your phone so you can find earlier results. This database contains scanned values only – it never contains text you have typed. It stays on your device and is removed when you uninstall the app. You can clear it yourself at any time from the History screen, either one entry at a time or all at once. If you export your history, the app writes a CSV file into its own private storage and hands it to you through the Android share sheet, so you can send it wherever you choose. It is not sent to us. Clearing local history is not the same as deleting your account, which is covered in section 13.

5. Using the app signed out (the default)

You do not need an account to use the keyboard, and most people never create one. While you are signed out:

  • Scan results stay on your device. We do not receive them and we do not store them.
  • Nothing you type on the keyboard is collected, stored or transmitted.
  • The app still sends the anonymous usage and crash diagnostics described in section 9, and the free version still shows advertising as described in section 10.
  • The one exception is the optional integrations in section 8. If you or your administrator configure one, scans are sent to the server address you chose – whether or not you are signed in.
  • AI scanning is not available while you are signed out. It requires an account, so no photograph is captured or sent in this state.

6. Using the app signed in (optional cloud sync)

Signing in is optional and it is what turns on cloud sync. From that point on, every scan you make is written to Google Cloud Firestore:

  • The scanned value, its barcode format, the time of the scan, your device model and the app version. The value stored is the final one the keyboard produced, after any trim, prefix or suffix rules you have configured have been applied.
  • If you belong to an organisation, the same record is also written to your organisation's collection with your user ID, email address and display name attached, so that your team can see who scanned what.

This is the whole point of signing in, and it is entirely your choice. Sign out and the syncing stops. Your typed input is still never collected, signed in or not.

If you have switched on AI scanning (section 3), the value it returns syncs in exactly the same way as any other scan. The photograph it was read from is not synced and is not stored.

7. Accounts and authentication

  • Sign-in uses Firebase Authentication, either with Google Sign-In or with an email address and password.
  • Accounts cannot be created in the app. If you do not have one, the app sends you to the web dashboard to register.
  • The first time you sign in, a profile record is created for you holding your email address, display name, plan, your monthly scan counter, a cloud-sync status flag and the date the record was created.
  • The app also signs in anonymously in two situations that have nothing to do with your personal account: to check whether an ad-free subscription is active, and, in the enterprise edition, to validate a device licence. Anonymous sign-in creates no personal account and carries no personal data.
  • Firebase App Check with Play Integrity is used to verify that the app's network requests come from a genuine installation rather than from an attacker.

8. Optional integrations that send scans elsewhere

The app can be connected to your own systems. These features are off by default. When you – or an administrator managing your device – switch one on, scanned values are sent to a destination that you choose and that we do not control or receive:

  • Send scans to your endpoint. Every scan is posted to the web address you configure, together with any user name and password you have entered for that endpoint. Those credentials are stored on your device and sent with each request so your server can authenticate it.
  • Endpoint lookup. The scanned value is sent to a lookup service you define, and the answer is shown in the app. If your organisation manages the app, this configuration is delivered to the device from your organisation's settings.
  • Lookup images. If a lookup result contains a picture, the app downloads it from whatever address the result names.
  • Search the web for a scan. If you use the option that turns a scan into a web search, the app opens your browser at a Google search for that value. This happens only when you ask for it, and it means the scanned value is passed to Google as a search term.

Once data reaches a destination you have configured, it is governed by that destination's own privacy practices, not by this policy. Please choose endpoints you trust, and prefer encrypted (HTTPS) addresses.

9. Usage analytics and crash reporting

  • Firebase Analytics records screen-view events, for example "Scanning started" or "History started", so we can see which features are actually used. It does not receive scanned content.
  • Firebase Crashlytics reports crashes so we can fix them. Crash reports include your scanner preference values as diagnostic keys – settings such as auto-focus, flash and batch scanning. They contain no scanned data and no personal data.

This data is used only to understand and improve the app, and is accessible only to the developer. Both apply to the free and the enterprise editions.

10. Advertising (free version only)

The free version of the app, distributed on Google Play, is supported by advertising.

  • Google AdMob serves banner advertisements inside the app, subject to Google's privacy policy. It is the only advertising network in the app.
  • The app requests the Android advertising identifier permission. AdMob uses this resettable identifier to select and measure advertisements. You can reset or delete it at any time in your Android settings.
  • Because AdMob is part of Google's advertising stack, the app also carries Google's Privacy Sandbox permissions on Android: the Topics API, which supplies coarse interest categories for advertising, and the attribution API, which measures whether an advertisement led to an action. It also carries Google Play's install-referrer permission, which tells us which campaign led to an installation.
  • The app never asks for your location. Note, however, that Google's advertising SDK can derive an approximate location from your IP address, as described in Google's own advertising disclosures. That is Google's processing, not ours, and it is not based on any location permission in this app.
  • Consent. In the EEA and the UK the app uses Google's User Messaging Platform (UMP) consent SDK to ask for your consent before any personalised advertising is served, and it records your choice. You can change that choice later from within the app.
  • Opting out entirely. The ad-free subscription removes all advertising from the app. The enterprise edition contains no advertising code at all.

Advertising never receives scanned data or anything you type.

11. Purchases in the app

The ad-free subscription is sold and billed through Google Play Billing. Your payment details are handled entirely by Google and are never seen by us. We receive only the status of your subscription, so the app knows whether to hide advertising. Subscriptions bought on the web dashboard are billed separately, by Stripe – see the dashboard section below.

12. Enterprise enquiry form

The Google Play version of the app includes an optional form for businesses that want to talk to us about a licence. Nothing is sent unless you fill it in and submit it. When you do, we receive:

  • The details you enter: your full name, work email address, company, country, number of devices, the application you scan into, your MDM platform, and your free-text message
  • Basic technical context: device model, app version, locale, and the country your SIM card is registered in. That last one is a two-letter country code – it is not your phone number, not a device identifier and not your location
  • A per-installation identifier (a Firebase Installations ID), which our server uses to rate-limit submissions and prevent abuse of the form

We use this only to answer your enquiry and to protect the form from abuse.

13. Deleting your account and your data

  • Account deletion happens in the web dashboard, not in the app. Sign in at app.barcode-keyboard.eu/dashboard/settings and use the delete option there.
  • The Android app has no account-deletion control, because accounts cannot be created in the app either. The app only signs you in to an account you created on the dashboard.
  • To remove the scan history held on your phone, clear it from the History screen inside the app, or uninstall the app.
  • You can also ask us to erase your data directly. Email licensing@barcode-keyboard.eu and we will complete the erasure within 30 days.

14. Permissions the app requests, and why

  • Camera. To read barcodes, and – only if you switch on AI scanning – to take the photograph described in section 3. The camera is declared as optional, so the app still installs on a device that has none.
  • Storage – declared, but not used. The app's manifest still declares two legacy storage permissions. Nothing in the app uses them: it does not read your photos or your files, and it does not write to your gallery. They are left over from an earlier version and are being removed. The CSV export of your scan history does not need them – it is written into the app's own private storage and passed to you through the Android share sheet.
  • Flashlight and vibration. To light a barcode in poor conditions and to confirm a successful scan.
  • Internet and network state. Needed for optional cloud sync, for the integrations you configure, for AI scanning if you switch it on, for diagnostics, and for advertising in the free version.
  • Keeping the screen awake and running in the foreground. So scanning is not interrupted mid-session.
  • Google Play billing (free version). For the ad-free subscription.
  • Advertising permissions (free version). The advertising identifier and Google's Privacy Sandbox permissions, described in section 10.
  • Seeing which apps can handle a scan (free version). A narrow, listed set of checks – whether your device has something to open a link, add an entry, or dial a number – so the app can offer the right action for a scan result. It cannot enumerate the apps you have installed.
  • Google Play services permissions. Standard entries that Google's own libraries add, including one that reads Play services settings and one that reports which campaign led to an installation.

The enterprise edition requests five fewer permissions than the free version: everything relating to advertising and to Google Play billing is absent, as is the app-availability check above.

15. What the app does not do

  • It does not log, store or transmit anything you type.
  • It does not upload camera images. Recognition is performed on the device. The sole exception is AI scanning in the Pro version, which is off until you switch it on yourself and is described in full in section 3.
  • It never asks for your location. The app requests no location permission of any kind, precise or approximate. The one qualification is the one noted in section 10: Google's advertising SDK can infer an approximate location from your IP address in the free version.
  • It does not read your contacts or the list of accounts on your device.
  • It does not read your text messages or your call log, and it requests no telephony permission. It cannot read your phone number or your device's telephony identifiers.
  • It does not use your microphone.
  • It does not read your photos or your files, and it does not write to your gallery. Two legacy storage permissions are still declared in the app's manifest, but no part of the app uses them and they are being removed.
  • It cannot see the full list of applications installed on your device.
  • It sends no push notifications. It declares no messaging service and has no remote-configuration service that could change its behaviour after installation. A push-related permission does appear in the app's manifest, because Google's analytics libraries bring it with them – but nothing in the app uses it to message you.
  • It contains no social-network SDK and no advertising network other than Google AdMob. Facebook and Unity advertising components that appeared in earlier releases have been removed entirely.
  • We do not sell your personal data.

Enterprise Edition (Pro)

Licensed through barcode-keyboard.eu and deployed by your organisation

How the enterprise edition differs

Everything in the section above applies to the enterprise edition as well – the same camera handling, the same AI scanning rules in section 3, the same optional sign-in and cloud sync, the same analytics and crash reporting, the same integrations. These are the differences:

  • No advertising. The edition contains no advertising code and does not request the advertising identifier. Section 10 and the consent mechanism described there do not apply to it.
  • No in-app purchases and no enquiry form. It is not distributed through Google Play, so section 11 and the enterprise enquiry form in section 12 do not apply. Licensing is arranged directly with us.
  • Device licensing. To confirm that a device is covered by your organisation's licence, the app signs in anonymously to a separate Firebase project of ours and checks the licence pool belonging to your organisation. No personal account and no scanned data are involved in that check.
  • Fewer permissions. As a consequence of the above it requests five fewer Android permissions than the free version – every advertising and billing permission is absent – and it does not perform the app-availability check described in section 14.

Cloud Dashboard & Sync Service

app.barcode-keyboard.eu

In addition to the standalone keyboard app, we offer an optional cloud dashboard service that enables scan history synchronization, team management, and remote configuration.

Data we collect

When you create an account on the cloud dashboard, we collect:

  • Email address and display name (for authentication and team identification)
  • Scanned barcode data, including: barcode value, format, timestamp, device model, and app version (synced from the keyboard app while you are signed in)
  • Organization membership and role information (if you join or create a team)
  • Payment information is processed securely by Stripe, Inc. — we do not store credit card numbers

How we use your data

  • To display your scan history and enable CSV export
  • To enable team administrators to view scans across their organization
  • To push scanner configuration settings to team devices
  • To manage your subscription and billing
  • To contact you about your account, your subscription and important changes to the service

Data storage & security

  • All data is stored on Google Firebase (Firestore) infrastructure, encrypted in transit and at rest
  • Access to your data is controlled by Firebase Authentication and Firestore Security Rules
  • Firebase App Check (reCAPTCHA Enterprise on the web, Play Integrity in the app) is used to verify that requests originate from legitimate app instances
  • Your scan data is only accessible to you and, if you belong to an organization, to other members of that organization

Data sharing

  • Scan data is shared with members of your organization (if applicable), based on role-based access control (admin, member, viewer)
  • Payment processing is handled by Stripe, Inc., subject to Stripe's privacy policy
  • We do not sell your personal data, and we do not share it with any other third parties

Data retention

  • We keep your account details and your synced scan history for as long as your account exists. We do not apply an automatic expiry to synced scans.
  • You can delete your account at any time from the dashboard, or ask us to erase your data by email.
  • Billing records are kept for as long as tax and accounting law requires us to keep them.

Your rights (GDPR)

  • Access: View all your data in the dashboard at any time
  • Export: Download your scan data as CSV from the dashboard
  • Deletion: Delete your account from app.barcode-keyboard.eu/dashboard/settings. This is the only place deletion happens – there is no equivalent control in the Android app.
  • Portability: Export your data before account deletion
  • Objection and restriction: Ask us to stop or limit a particular use of your data
  • Any other request: Email licensing@barcode-keyboard.eu and we will respond within 30 days

Cookies & tracking in the dashboard

  • Firebase Authentication uses session tokens stored in the browser
  • reCAPTCHA Enterprise is used for security verification (App Check)
  • No advertising is shown in the dashboard and no advertising cookies are set there

This Website

barcode-keyboard.eu

Analytics on our marketing site

  • This website uses Google Analytics 4 to measure traffic and understand which pages are useful. It sets cookies in your browser and is subject to Google's privacy policy.
  • You can opt out using Google's browser opt-out add-on, or by blocking cookies in your browser.
  • This site is a public marketing site. You do not need an account to browse it, and it never receives scanned or typed data from the app.

Contact & Changes

Contacting us about your data

For any question about this policy, or to exercise any of your rights, email licensing@barcode-keyboard.eu. We aim to respond within 30 days.

Privacy policy revisions

We may occasionally update this Privacy Policy. When we do, we will notify you through appropriate channels, such as revising the date at the top of the Privacy Policy available on our website and mobile application.

Thank you for choosing Barcode & QR Keyboard – your privacy and satisfaction matter to us.