Privacy notice
MakeQRArt (QRForge) privacy
QRForge is live as MakeQRArt at makeqr.art.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The section below explains this product’s data handling and current availability.
Account
You sign in through our authentication server (GoTrue on the studio VM at supabase.llab08.com) with e-mail, Google or Apple. We keep the account id, the e-mail address (which may be an Apple Hide My Email relay address) and, when Google or Apple supplies one, a display name. Apple supplies the name only on the first authorisation. For e-mail sign-in we store a password hash, not the password; we store no password for Google or Apple sign-in. The signed-in session is kept in a session cookie in your browser.
Saved codes
QR codes you save, and their destination URLs, are stored with your account so you can reopen and edit them.
Scans
When someone scans a dynamic code, we record the code, time, country, region and city supplied by Vercel request headers, device type, operating system, browser, language and referring URL. Location is inferred from the network request, not GPS. The scan code uses a daily salted hash of the IP address and browser user agent in server memory to estimate unique scans; the stored scan record contains the resulting unique-scan flag, not the raw IP address or hash. Hosting access logs are separate from these scan records.
Purchases and credits
Paid plans and credits are processed by Stripe. Card details are entered on Stripe’s checkout page and never reach us. We keep the Stripe customer and subscription identifiers and a credit ledger on the signed-in account so that plan status and remaining credits can be shown in the app.
AI generation (off today)
AI art is not available yet. Image generation is switched off, so prompts and images are not sent to a model today. An AI quota field may still exist on the account. If generation is switched on, this section is updated first.
Processors
Vercel hosts the app and supplies the approximate scan location. Cloudflare handles requests to studio services, and authentication runs on our own server at supabase.llab08.com. Google and Apple process sign-in when you choose those options. Stripe processes purchases when billing is enabled. Google Safe Browsing receives destination URLs for safety checks only when that integration is configured. Image generation can use Hugging Face or Replicate, but is disabled today; we will identify the active provider and the data sent to it before enabling generation.
Deleting your account
You can delete your MakeQRArt (QRForge) data in the app: saved codes, scan records, AI art records, the credit ledger, purchases and the subscription identifiers we keep. Dynamic codes stop working immediately. Only MakeQRArt data is deleted: your shared llab08 sign-in identity and data in other llab08 products remain, and those products keep working. If MakeQRArt is the only llab08 product you use, you must still write to hello@llab08.com to erase this remaining shared sign-in. If you signed in with Apple, you must confirm with Apple first and we ask Apple to revoke MakeQRArt’s access to your Apple ID before anything is deleted; if that fails, nothing is deleted, and you can try again later or write to hello@llab08.com. After a deletion, a new MakeQRArt account cannot be created with the same llab08 sign-in, Apple or Google account, or e-mail address for two years, so that free sign-up credits cannot be claimed again by deleting and re-registering. For this block record we keep only keyed hashes (HMAC-SHA256) of the account id, the Apple and Google account identifiers and the normalised e-mail address, not the values themselves, and erase them automatically after two years. The block applies to MakeQRArt only; other llab08 products are unaffected. An active Stripe subscription is cancelled before deletion. App Store and Google Play subscriptions must be cancelled through the store; deleting your MakeQRArt data does not cancel them. Stripe and the stores may retain their own payment records under their policies. To ask about the block, request erasure of the shared llab08 sign-in across products, or get help if you can no longer sign in, write to hello@llab08.com.
Hosting and retention
The web app runs on Vercel. Hosts may keep short access logs; we do not use them to identify anyone. MakeQRArt data stays until you delete it as above, and the hashed identifiers that block a new MakeQRArt account are erased two years after a deletion; the company-wide notice explains shared sign-in retention and erasure.
Contact: hello@llab08.com · Updated 8 October 2026 · All privacy notices