Legal

Privacy Policy

Last modified: August 30, 2026

What we never collect

We do not collect or retain any data entered by users while utilizing the keyboard. Your keystrokes are never logged, stored or transmitted. The app's local history database holds scanned values only – never anything you type.

The keyboard also switches its own prediction off entirely on sensitive field types – password fields, visible-password fields, email address fields, URI fields and filter fields – so text entered there is not processed at all.

Scanning happens on your device

Barcode and text recognition run entirely on your device. The recognition models are bundled inside the app itself, so no camera frame and no image ever leaves your phone – not to us, not to Google, not to anyone. The camera permission exists only so the app can look for a barcode in the live preview.

At a glance

What we handle depends entirely on which parts of the product you use. These situations are genuinely different, so each is covered separately below.

SituationWhat leaves your device
Keyboard app,
signed out (default)
No scanned data and nothing you type, unless you set up one of the integrations below. Anonymous usage and crash diagnostics only, plus advertising in the free version.
Keyboard app,
signed in (optional)
Your scans sync to your cloud account, together with your email address and display name.
Integrations you set up (optional)Scans are sent to a server address you or your administrator chooses. We are not the recipient.
Enterprise enquiry form (optional)Only the contact details you choose to enter, plus basic device and app information.
Web dashboardYour account details, your synced scan history, and billing data handled by Stripe.

Keyboard App (Android)

Barcode & QR Keyboard

1. About our app

Welcome to Barcode & QR Keyboard – the swift and enjoyable solution for effortless barcode scanning. This Android software keyboard comes equipped with an integrated barcode reader, delivering a seamless experience.

2. Camera access

The app requests access to your phone's camera solely to read barcodes and QR codes. Camera frames are examined in memory by recognition models bundled inside the app and are then discarded. They are never saved to storage, never uploaded, and never transmitted to us or to any third party.

3. Scan history on your device

The app keeps a history of your scans in a database on your phone so you can find earlier results. This database contains scanned values only – it never contains text you have typed. It stays on your device and is removed when you uninstall the app. You can clear it yourself at any time from the History screen, either one entry at a time or all at once. If you export your history, the app writes a CSV file into its own private storage and hands it to you through the Android share sheet, so you can send it wherever you choose. It is not sent to us. Clearing local history is not the same as deleting your account, which is covered in section 12.

4. Using the app signed out (the default)

You do not need an account to use the keyboard, and most people never create one. While you are signed out:

  • Scan results stay on your device. We do not receive them and we do not store them.
  • Nothing you type on the keyboard is collected, stored or transmitted.
  • The app still sends the anonymous usage and crash diagnostics described in section 8, and the free version still shows advertising as described in section 9.
  • The one exception is the optional integrations in section 7. If you or your administrator configure one, scans are sent to the server address you chose – whether or not you are signed in.

5. Using the app signed in (optional cloud sync)

Signing in is optional and it is what turns on cloud sync. From that point on, every scan you make is written to Google Cloud Firestore:

  • The scanned value, its barcode format, the time of the scan, your device model and the app version. The value stored is the final one the keyboard produced, after any trim, prefix or suffix rules you have configured have been applied.
  • If you belong to an organisation, the same record is also written to your organisation's collection with your user ID, email address and display name attached, so that your team can see who scanned what.

This is the whole point of signing in, and it is entirely your choice. Sign out and the syncing stops. Your typed input is still never collected, signed in or not.

6. Accounts and authentication

  • Sign-in uses Firebase Authentication, either with Google Sign-In or with an email address and password.
  • Accounts cannot be created in the app. If you do not have one, the app sends you to the web dashboard to register.
  • The first time you sign in, a profile record is created for you holding your email address, display name, plan, your monthly scan counter, a cloud-sync status flag and the date the record was created.
  • The app also signs in anonymously in two situations that have nothing to do with your personal account: to check whether an ad-free subscription is active, and, in the enterprise edition, to validate a device licence. Anonymous sign-in creates no personal account and carries no personal data.
  • Firebase App Check with Play Integrity is used to verify that the app's network requests come from a genuine installation rather than from an attacker.

7. Optional integrations that send scans elsewhere

The app can be connected to your own systems. These features are off by default. When you – or an administrator managing your device – switch one on, scanned values are sent to a destination that you choose and that we do not control or receive:

  • Send scans to your endpoint. Every scan is posted to the web address you configure, together with any user name and password you have entered for that endpoint. Those credentials are stored on your device and sent with each request so your server can authenticate it.
  • Endpoint lookup. The scanned value is sent to a lookup service you define, and the answer is shown in the app. If your organisation manages the app, this configuration is delivered to the device from your organisation's settings.
  • Lookup images. If a lookup result contains a picture, the app downloads it from whatever address the result names.
  • Search the web for a scan. If you use the option that turns a scan into a web search, the app opens your browser at a Google search for that value. This happens only when you ask for it, and it means the scanned value is passed to Google as a search term.

Once data reaches a destination you have configured, it is governed by that destination's own privacy practices, not by this policy. Please choose endpoints you trust, and prefer encrypted (HTTPS) addresses.

8. Usage analytics and crash reporting

  • Firebase Analytics records screen-view events, for example "Scanning started" or "History started", so we can see which features are actually used. It does not receive scanned content.
  • Firebase Crashlytics reports crashes so we can fix them. Crash reports include your scanner preference values as diagnostic keys – settings such as auto-focus, flash and batch scanning. They contain no scanned data and no personal data.

This data is used only to understand and improve the app, and is accessible only to the developer. Both apply to the free and the enterprise editions.

9. Advertising (free version only)

The free version of the app, distributed on Google Play, is supported by advertising.

  • Google AdMob serves banner advertisements inside the app, subject to Google's privacy policy. It is the only advertising network in the app.
  • The app requests the Android advertising identifier permission. AdMob uses this resettable identifier to select and measure advertisements. You can reset or delete it at any time in your Android settings.
  • Because AdMob is part of Google's advertising stack, the app also carries Google's Privacy Sandbox permissions on Android: the Topics API, which supplies coarse interest categories for advertising, and the attribution API, which measures whether an advertisement led to an action. It also carries Google Play's install-referrer permission, which tells us which campaign led to an installation.
  • The app never asks for your location. Note, however, that Google's advertising SDK can derive an approximate location from your IP address, as described in Google's own advertising disclosures. That is Google's processing, not ours, and it is not based on any location permission in this app.
  • Consent. In the EEA and the UK the app uses Google's User Messaging Platform (UMP) consent SDK to ask for your consent before any personalised advertising is served, and it records your choice. You can change that choice later from within the app.
  • Opting out entirely. The ad-free subscription removes all advertising from the app. The enterprise edition contains no advertising code at all.

Advertising never receives scanned data or anything you type.

10. Purchases in the app

The ad-free subscription is sold and billed through Google Play Billing. Your payment details are handled entirely by Google and are never seen by us. We receive only the status of your subscription, so the app knows whether to hide advertising. Subscriptions bought on the web dashboard are billed separately, by Stripe – see the dashboard section below.

11. Enterprise enquiry form

The Google Play version of the app includes an optional form for businesses that want to talk to us about a licence. Nothing is sent unless you fill it in and submit it. When you do, we receive:

  • The details you enter: your full name, work email address, company, country, number of devices, the application you scan into, your MDM platform, and your free-text message
  • Basic technical context: device model, app version, locale, and the country your SIM card is registered in. That last one is a two-letter country code – it is not your phone number, not a device identifier and not your location
  • A per-installation identifier (a Firebase Installations ID), which our server uses to rate-limit submissions and prevent abuse of the form

We use this only to answer your enquiry and to protect the form from abuse.

12. Deleting your account and your data

  • Account deletion happens in the web dashboard, not in the app. Sign in at app.barcode-keyboard.eu/dashboard/settings and use the delete option there.
  • The Android app has no account-deletion control, because accounts cannot be created in the app either. The app only signs you in to an account you created on the dashboard.
  • To remove the scan history held on your phone, clear it from the History screen inside the app, or uninstall the app.
  • You can also ask us to erase your data directly. Email licensing@barcode-keyboard.eu and we will complete the erasure within 30 days.

13. Permissions the app requests, and why

  • Camera. To read barcodes. The camera is declared as optional, so the app still installs on a device that has none.
  • Storage – declared, but not used. The app's manifest still declares two legacy storage permissions. Nothing in the app uses them: it does not read your photos or your files, and it does not write to your gallery. They are left over from an earlier version and are being removed. The CSV export of your scan history does not need them – it is written into the app's own private storage and passed to you through the Android share sheet.
  • Flashlight and vibration. To light a barcode in poor conditions and to confirm a successful scan.
  • Internet and network state. Needed for optional cloud sync, for the integrations you configure, for diagnostics, and for advertising in the free version.
  • Keeping the screen awake and running in the foreground. So scanning is not interrupted mid-session.
  • Google Play billing (free version). For the ad-free subscription.
  • Advertising permissions (free version). The advertising identifier and Google's Privacy Sandbox permissions, described in section 9.
  • Seeing which apps can handle a scan (free version). A narrow, listed set of checks – whether your device has something to open a link, add an entry, or dial a number – so the app can offer the right action for a scan result. It cannot enumerate the apps you have installed.
  • Google Play services permissions. Standard entries that Google's own libraries add, including one that reads Play services settings and one that reports which campaign led to an installation.

The enterprise edition requests five fewer permissions than the free version: everything relating to advertising and to Google Play billing is absent, as is the app-availability check above.

14. What the app does not do

  • It does not log, store or transmit anything you type.
  • It does not upload camera images. Recognition is performed on the device.
  • It never asks for your location. The app requests no location permission of any kind, precise or approximate. The one qualification is the one noted in section 9: Google's advertising SDK can infer an approximate location from your IP address in the free version.
  • It does not read your contacts or the list of accounts on your device.
  • It does not read your text messages or your call log, and it requests no telephony permission. It cannot read your phone number or your device's telephony identifiers.
  • It does not use your microphone.
  • It does not read your photos or your files, and it does not write to your gallery. Two legacy storage permissions are still declared in the app's manifest, but no part of the app uses them and they are being removed.
  • It cannot see the full list of applications installed on your device.
  • It sends no push notifications. It declares no messaging service and has no remote-configuration service that could change its behaviour after installation. A push-related permission does appear in the app's manifest, because Google's analytics libraries bring it with them – but nothing in the app uses it to message you.
  • It contains no social-network SDK and no advertising network other than Google AdMob. Facebook and Unity advertising components that appeared in earlier releases have been removed entirely.
  • We do not sell your personal data.

Enterprise Edition (Pro)

Licensed through barcode-keyboard.eu and deployed by your organisation

How the enterprise edition differs

Everything in the section above applies to the enterprise edition as well – the same camera handling, the same optional sign-in and cloud sync, the same analytics and crash reporting, the same integrations. These are the differences:

  • No advertising. The edition contains no advertising code and does not request the advertising identifier. Section 9 and the consent mechanism described there do not apply to it.
  • No in-app purchases and no enquiry form. It is not distributed through Google Play, so section 10 and the enterprise enquiry form in section 11 do not apply. Licensing is arranged directly with us.
  • Device licensing. To confirm that a device is covered by your organisation's licence, the app signs in anonymously to a separate Firebase project of ours and checks the licence pool belonging to your organisation. No personal account and no scanned data are involved in that check.
  • Fewer permissions. As a consequence of the above it requests five fewer Android permissions than the free version – every advertising and billing permission is absent – and it does not perform the app-availability check described in section 13.

Cloud Dashboard & Sync Service

app.barcode-keyboard.eu

In addition to the standalone keyboard app, we offer an optional cloud dashboard service that enables scan history synchronization, team management, and remote configuration.

Data we collect

When you create an account on the cloud dashboard, we collect:

  • Email address and display name (for authentication and team identification)
  • Scanned barcode data, including: barcode value, format, timestamp, device model, and app version (synced from the keyboard app while you are signed in)
  • Organization membership and role information (if you join or create a team)
  • Payment information is processed securely by Stripe, Inc. — we do not store credit card numbers

How we use your data

  • To display your scan history and enable CSV export
  • To enable team administrators to view scans across their organization
  • To push scanner configuration settings to team devices
  • To manage your subscription and billing
  • To contact you about your account, your subscription and important changes to the service

Data storage & security

  • All data is stored on Google Firebase (Firestore) infrastructure, encrypted in transit and at rest
  • Access to your data is controlled by Firebase Authentication and Firestore Security Rules
  • Firebase App Check (reCAPTCHA Enterprise on the web, Play Integrity in the app) is used to verify that requests originate from legitimate app instances
  • Your scan data is only accessible to you and, if you belong to an organization, to other members of that organization

Data sharing

  • Scan data is shared with members of your organization (if applicable), based on role-based access control (admin, member, viewer)
  • Payment processing is handled by Stripe, Inc., subject to Stripe's privacy policy
  • We do not sell your personal data, and we do not share it with any other third parties

Data retention

  • We keep your account details and your synced scan history for as long as your account exists. We do not apply an automatic expiry to synced scans.
  • You can delete your account at any time from the dashboard, or ask us to erase your data by email.
  • Billing records are kept for as long as tax and accounting law requires us to keep them.

Your rights (GDPR)

  • Access: View all your data in the dashboard at any time
  • Export: Download your scan data as CSV from the dashboard
  • Deletion: Delete your account from app.barcode-keyboard.eu/dashboard/settings. This is the only place deletion happens – there is no equivalent control in the Android app.
  • Portability: Export your data before account deletion
  • Objection and restriction: Ask us to stop or limit a particular use of your data
  • Any other request: Email licensing@barcode-keyboard.eu and we will respond within 30 days

Cookies & tracking in the dashboard

  • Firebase Authentication uses session tokens stored in the browser
  • reCAPTCHA Enterprise is used for security verification (App Check)
  • No advertising is shown in the dashboard and no advertising cookies are set there

This Website

barcode-keyboard.eu

Analytics on our marketing site

  • This website uses Google Analytics 4 to measure traffic and understand which pages are useful. It sets cookies in your browser and is subject to Google's privacy policy.
  • You can opt out using Google's browser opt-out add-on, or by blocking cookies in your browser.
  • This site is a public marketing site. You do not need an account to browse it, and it never receives scanned or typed data from the app.

Contact & Changes

Contacting us about your data

For any question about this policy, or to exercise any of your rights, email licensing@barcode-keyboard.eu. We aim to respond within 30 days.

Privacy policy revisions

We may occasionally update this Privacy Policy. When we do, we will notify you through appropriate channels, such as revising the date at the top of the Privacy Policy available on our website and mobile application.

Thank you for choosing Barcode & QR Keyboard – your privacy and satisfaction matter to us.