qr_code_2 messenqr arrow_back Back to home

What we process

  • Spaces. The space name, its random identifier, and when it was created.
  • Messages and photos. The text, optional attached photo, display name, posting time, and the participant identifier associated with the post. Location and other embedded metadata are removed from supported photos before storage.
  • Optional accounts. If you sign in, we process your email address, account name, login verification information, and session details. An account is required to upload a photo.
  • A visitor cookie. A signed random identifier and issue time, used to attribute posts and prevent repeat likes or reports. It expires after one year and is not linked to an account or email address.
  • Likes and reports. The message, visitor identifier, and time associated with each like or report.
  • A saved display name. The name typed into the message form is saved in your browser so it can be filled in next time. It is sent to messenqr only when you post it with a message.
  • Contact enquiries. If you email us, we receive your email address, message, and related email information. We use it only to understand and respond to your enquiry.
  • Request and security information. Cloudflare processes information such as your IP address to deliver and protect the service. messenqr also uses IP addresses as temporary rate-limit keys for some actions; they are not written to the application database.

Messages in a space are public

Anyone holding the QR code — or the link behind it — may see the space name, messages, attached photos, display names, posting times, and like counts. Treat a message the way you would treat a note pinned to a public board, and leave out anything you would not want a stranger to see.

What we don't do

messenqr does not use advertising or marketing pixels, and does not sell personal information.

Service providers

Cloudflare hosts the app, database, account sessions, and uploaded photos; routes contact email; and provides traffic protection, rate limiting, and operational logging. Space names, display names, message text, and attached photos are sent to OpenAI for automated safety classification before they can become public. OpenAI states that API data is not used to train its models by default. Google Fonts supplies the typefaces, so your browser connects to Google when a page loads. Google also hosts the mailbox used to receive and respond to contact enquiries.

Keeping things civil

messenqr rate-limits actions and checks space names, display names, messages, and attached photos for unsafe content. Some posts may be held privately for a moderator to approve or reject. A public message is hidden automatically after reports from three distinct visitors, and a moderator can hide a reported message.

How long information is kept

The visitor cookie expires after one year unless you clear it sooner. Your saved display name remains in your browser until you clear the site's data. Accounts, spaces, messages, attached photos, likes, reports, and participant identifiers currently have no automatic expiry. Contact emails are kept only as long as reasonably necessary to respond and maintain an appropriate record of the enquiry.

Contact us

For privacy questions, requests, or concerns, email privacy@messenqr.com. Please include only the information necessary for us to understand and respond to your request.