Summary
TL;DR What stays, what leaves
- Stays on device: the text you encode, your generated codes, your scan/create history (stored locally), and any code you scan with the camera.
- Leaves the device, only when you act: the single photo you submit for an Authenticity Check (sent to our analysis service to build your report), and your App Store purchase receipt (sent to validate a subscription or purchase).
- We do not ask you to create an account, and we do not use your data to track you across other apps or websites. We show no ads, do not use the advertising identifier (IDFA), and no advertising or attribution SDK runs or sends data in the app.
- iOS permissions we may request: Camera, Photos (Add Only), Contacts, and Calendar — each only for the action you choose.
Effective date: June 8, 2026
Details
1. On-device by default
Creating QR codes and barcodes, scanning codes with the camera or from a photo, and your history all run on your iPhone. The text you type (URLs, Wi-Fi passwords, contact details, etc.), the codes you generate, and the codes you scan are processed locally and saved only in a local Realm database inside the app's sandbox. They are never uploaded and are removed when you delete the app.
2. Data we send off your device
Authenticity Check photo When you use the Authenticity Check, you take or choose a photo, crop the item, and tap Submit. At that moment — and only then — the app sends that single cropped image (plus a request type) to our automated, AI-assisted image-analysis service, operated by LeadSphere at www.leadsphere.app, so it can generate your report. We do not attach your name, account, device identifier, IDFA, or contacts. Live camera frames are never recorded or uploaded automatically.
Purchase receipt If you buy a subscription or the lifetime option, Apple processes the payment. To confirm and restore your purchase, the app sends your App Store receipt, the app's bundle identifier, and your App Store country/region code to our server at www.leadsphere.app. We never receive your card number or full Apple ID.
App configuration & diagnostics The app uses Google Firebase to fetch remote configuration for the subscription screen, and Firebase Analytics to collect usage data, diagnostic / crash information, and a Firebase installation / app-instance identifier. We use this only to understand how the app is used and to improve it — never to build an advertising profile, and never shared with data brokers.
We ask our analysis service to process your submitted photo only to produce your report and not to use it to identify you. To request deletion of a submitted photo or receipt record, email us (see "Contact").
3. iOS permissions we use
- Camera — to scan QR codes / barcodes and to capture a photo for an Authenticity Check.
- Photos · Add Only — requested only when you tap "Save", to write a generated code image to your library. We do not read your existing photos.
- Contacts — only if you choose to add a scanned or created contact card.
- Calendar — only if you choose to add an event from a QR code.
Choosing a photo from your library uses the system photo picker, which hands the app only the single image you select — the app never browses your library.
4. We do not track you
QBCode does not show the App Tracking Transparency prompt, does not read the advertising identifier (IDFA), and does not link an advertising or attribution profile to you. We do not sell your data, and we do not combine it with data from other companies' apps or websites for advertising.
5. Service providers & third parties
- LeadSphere, Inc. — our own backend, which receives the Authenticity Check photo and the purchase receipt described in section 2.
- Apple — processes subscription and in-app purchases and provides the App Store receipt.
- Google Firebase — Remote Config (subscription screen settings) and Firebase Analytics (usage data, diagnostics, and an app-instance identifier) described in section 2.
On-device open-source libraries (e.g. SnapKit, RealmSwift, lottie-ios, Alamofire, the QRCode renderer) run locally; Alamofire is the networking library that carries the uploads in section 2.
6. Children's privacy
QBCode is rated 4+ and is not directed to children. We do not knowingly collect personal information from children. Please submit only photos of products/items for an Authenticity Check, not photos of people.
7. Data retention & deletion
Everything stored locally (history, settings) is deleted when you delete the app. For data sent to our server (a submitted photo or a purchase receipt record), you can request deletion by emailing us. Purchase records may be retained as needed to support refunds, fraud prevention, and legal obligations.
8. Changes to this policy
If we change what QBCode does with your data, we will update this page and the effective date above, and highlight material changes in the app.
9. Contact
Questions, or a deletion request? Email support@leadsphere.app. We typically reply within two business days.