Scanly
Legal

Privacy Policy

Last updated 15 August 2026

Scanly, published on the App Store and Google Play as QR & Barcode Scanner: Food, is a free QR and barcode scanner application developed by HDFoundry. We are committed to protecting your privacy and being transparent about how the app works.

The short version

Scanly does not require an account, and we do not collect or store personally identifiable information on our servers. Your scan history stays on your device. The one thing our backend keeps is the number of a barcode that no database could identify, so the catalogue can be filled in later. It is a bare number, with nothing attached that points back to you.

Camera and photo library access

Scanly requests access to your device camera and photo library solely to scan QR codes and barcodes. All image processing is performed entirely on your device. No photos, images, or camera frames are ever transmitted to our servers or any third party.

Crash diagnostics and analytics (Firebase)

On production builds, Scanly uses Firebase Crashlytics and Firebase Analytics (Google LLC) to keep the app stable and understand how features are used.

  • Crash diagnostics: type and location of a crash in the app code, device model, OS version, app version, and a randomly generated installation identifier (not linked to your identity). Crash data never includes your scan history or any content from your camera or photos.
  • Usage analytics: which screens and features are visited, general session duration and frequency, aggregated device type and OS version, and coarse country or region (not precise GPS).

Firebase Analytics is configured not to collect advertising identifiers where possible. You can opt out through your device's system privacy settings (iOS: Settings, Privacy, Apple Advertising; Android: Settings, Google, Ads).

How we use information

The limited data we collect is used exclusively to diagnose and fix crashes, understand which features to prioritize, improve stability and performance, and detect and prevent abuse. We do not sell, rent, or trade your personal information. If advertising is enabled in a future version, limited device data may be shared with advertising partners only as described under Advertising below.

Product lookups and third-party databases

When you scan a barcode, the barcode value (a numeric string) is sent to our own backend, which performs the lookup on your behalf. The app never contacts the databases below directly, so they receive our server's network address rather than yours. No account, device identifier, or scan history travels with a lookup. The sources we query are:

  • Open Food Facts: food product database
  • Open Beauty Facts: cosmetics and personal care database
  • Open Products Facts: general consumer products database
  • Open Library (Internet Archive): book metadata by ISBN
  • UPCitemdb: general product lookup

These services may log the barcode query as part of their standard server operations, subject to their own privacy policies. We encourage you to review those policies.

Product images are the one exception. We never copy or host product photographs. Instead the app loads them straight from the source's image server using the address that source provides, which means your device connects to that server directly and it can see your IP address in the process. If you would rather avoid this, avoid opening product detail screens.

Barcodes we could not identify

If a barcode you scan is not found in any of the sources above, our backend records the barcode number so the catalogue can be completed later. The stored record holds only the barcode, a status, how many times it has been looked up, and the first and last time it was seen. It contains no account, device identifier, IP address, or anything else that could connect it to you, and there is no way to tell which scans came from the same person or device.

Advertising

To keep Scanly free, future versions may show ads served by third-party advertising partners, such as AppLovin. When ads are enabled, these partners may collect and process limited device information, including a resettable advertising identifier, coarse location derived from your IP address, and ad interaction events, to select and measure ads. You can limit ad tracking and reset your advertising identifier at any time in your device settings (iOS: Settings, Privacy, Tracking and Apple Advertising; Android: Settings, Google, Ads). We do not share your scan history or any codes you create with advertising partners.

Data storage and security

Your scan history, including previously scanned barcodes and their associated product data, is stored exclusively in local storage on your device. This data is never uploaded to our servers, is accessible only to the Scanly app, and is deleted when you uninstall the app or clear its data. You can clear your scan history at any time from the app's settings screen. Product details fetched for a scan are kept in an on-device cache for 48 hours so that repeat lookups are fast and do not re-query the network.

Children's privacy

Scanly is not directed to children under 13 (or the applicable age of digital consent in your country). We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will take prompt action.

Your rights

Depending on your location, you may have rights to access information we hold, request deletion, opt out of analytics, and request data portability. Since Scanly does not collect personal data on our servers, most rights are exercised directly on your device by clearing app data or uninstalling the app. For any request related to Firebase data, contact us and we will assist in submitting appropriate requests to Google.

Changes to this policy

We may update this Privacy Policy from time to time. When we make significant changes, we update the date above and, where appropriate, notify you through an in-app notice. Continued use of Scanly after the effective date constitutes acceptance of the updated policy.

Contact

Questions, concerns, or requests regarding this Privacy Policy? Email [email protected]. We aim to respond within 7 business days.