Legal
Privacy Policy
Version 1.0 · Last updated 5 October 2026
This Privacy Policy explains how Arcteligent LLC (“we”, “us”) collects, uses, shares and protects personal information when you use BespokeQR (the “Service”), including information about people who scan QR codes made with the Service. It is part of our Terms of Service.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
Each section starts with a plain-English summary; if a summary and the full text differ, the full text applies.
1. Who we are
Arcteligent LLC, a Wyoming limited liability company, operates BespokeQR and is the “controller” (or “business”) responsible for the personal information described here. Contact us about privacy at legal contact email. Postal address: postal address.
2. Data about account holders
- Account: your email address (used to sign you in by email link) and an account ID. If you sign in with a third-party provider in future, the basic profile details it shares.
- Billing: your plans, purchases, invoices, credit balance and credit history, and a Stripe customer ID. Payments are handled by Stripe; we never receive or store your full card number. Stripe may collect your name, billing address and payment details under its own privacy policy.
- What you create and upload: code names, Destinations and their change history, art prompts and the prompts we generate from them, design settings, generated images and design files, your brand kit (business name, industry, colours) and any logo you upload.
- Usage and records: AI usage records (which model, cost), link-check results, notifications and emails we send you, and records of which versions of our Terms and Privacy Policy you agreed to and when.
- Technical data: IP address, browser and device information, and request logs, collected by our hosting and sign-in providers when you use the Service (see section 10 for how long they’re kept), and the cookies described in section 8.
3. Data about people who scan codes
People who scan a BespokeQR code haven’t signed up for anything, so we keep what we collect about them to a minimum. When someone scans a Code (or opens its Short link), our redirect service records:
- the time of the scan, which Code was scanned, and whether it was forwarded or shown a “not live” or “paused” page;
- the country, derived by our network provider (Cloudflare) from the IP address; we don’t record city or precise location;
- the device type (mobile, tablet, desktop or automated “bot”) and operating system family (for example iOS or Android), derived from the browser’s user agent;
- the domain of the referring website, if the browser sends one (usually none for camera scans), without its path or query; and
- a visitor hash: a one-way, salted code made from the IP address, user agent and the date, used only to count unique visitors per day. It changes every day and is designed so that it can’t practically be used to identify a person or link their visits across days.
We do not store scanners’ IP addresses in our database, and we don’t set cookies on people who scan a code and are forwarded. The IP address is used momentarily to work out the country, to compute the visitor hash and to rate-limit abuse, and it can appear in our hosting provider’s short-lived request logs (section 10).
How it’s used: to show the Code’s owner aggregate analytics (scans per day, countries, device types, unique visitors), to filter out bots, and to protect the Service from abuse. Code owners see totals and breakdowns, never individual scanners. We don’t use scan data for advertising or to build profiles of people.
How long: scan records are kept for as long as the Code exists in its owner’s account, and are deleted with the Code or the account.
4. Destination monitoring
To check that Codes work, our servers automatically request each Code’s Destination when it is set or changed, when you press “Re-check now”, when a Code goes live, and about once a day while a Code is live. For each check we store: the URL checked, the final URL after redirects (and the redirect steps), the HTTP status, the page title, any error, how long it took, and when it ran. We also look up the Destination’s domain name through Cloudflare’s DNS service. Checks identify themselves as automated. These results are kept for as long as the Code exists.
5. Safety screening
When you set or change a Destination, we send the URL to Google’s Web Risk service to check it against lists of malware, phishing and other unsafe sites. Google processes the URL under its own terms. We store when the check happened.
6. AI processing
- Art generation: your idea, the prompt (including any edits), an image of your QR code pattern, and, if you choose “Use my brand kit”, your business name, industry and colours are sent through OpenRouter to image models (currently Google’s Gemini models).
- Prompt writing and refining: your idea or requested change, and brand details if you choose, are sent through OpenRouter to a text model (currently Anthropic’s Claude).
- Logo screening: when you upload a logo, the image and your business name are sent through OpenRouter to an AI model (currently Anthropic’s Claude) to check for well-known third-party brands.
- We don’t use your content to train our own AI models. OpenRouter and the model providers process requests under their own terms and privacy policies, which may allow them to keep requests for a limited time (for example for abuse monitoring). Style designs (no AI) are made entirely by our own software and aren’t sent to AI providers.
7. Service providers
| Provider | What they do for us |
|---|---|
| Cloudflare, Inc. | Hosting and network (our app, short links and image processing run on Cloudflare Workers), file storage (R2: uploads, designs, exports), caching, queues, DNS lookups for link checks, and request logs. |
| Supabase, Inc. | Database (accounts, codes, designs, scan records) and email sign-in. |
| Stripe, Inc. | Payments, subscriptions, invoices and the billing portal. |
| Resend (Plus Five Five, Inc.) | Sending our service emails. |
| OpenRouter, Inc. | Routing AI requests to model providers. |
| Google LLC | AI image generation (Gemini, via OpenRouter) and link safety screening (Web Risk). |
| Anthropic, PBC | AI text models (Claude, via OpenRouter) for prompt writing, refining and logo screening. |
We don’t use third-party analytics, advertising or tracking tools on the Service. Our fonts are served from our own site. We may also disclose personal information if required by law, to protect rights, safety and security, or as part of a merger, acquisition or sale of assets (in which case this policy continues to apply to it).
9. How we use data, and legal bases
- To provide the Service (create and host Codes, forward scans, generate and verify designs, send emails you need) — necessary to perform our contract with you.
- To take payments and keep records — contract, and our legal obligations (tax and accounting).
- To keep the Service safe (screen links, prevent fraud, abuse and spam, rate-limit, secure accounts) — our legitimate interests and legal obligations.
- To show code owners scan analytics and check their links — our legitimate interest, and the code owner’s, in knowing whether codes work and are used, balanced by the data minimisation in section 3.
- To improve the Service (for example fixing errors and measuring costs) — our legitimate interests. We don’t use your content to train our own AI models.
- To comply with the law and enforce our Terms.
We send service emails (sign-in links, receipts and billing notices, go-live and link alerts). We don’t currently send marketing email; if we do, we’ll ask first where the law requires and you’ll be able to unsubscribe.
10. How long we keep data
- Account, codes, designs, uploads, prompts and link checks: while your account exists. Free Previews may be deleted earlier (Terms section 5).
- Scan records: while the Code exists; deleted with the Code or the account.
- Payment and invoice records: as long as tax and accounting laws require (generally up to 7 years), including after an account is deleted. Stripe keeps its own records under its policy.
- Records of your agreement to our Terms and Privacy Policy: while your account exists and afterwards for as long as needed to establish or defend legal claims.
- Request and security logs kept by our hosting and sign-in providers (which can include IP addresses): for a limited period, typically days to weeks.
- Backups: deleted data can remain in backups until they roll off on our providers’ backup cycle.
- Account deletion: ask us at legal contact email from your account email. We’ll delete or anonymise your personal information within 30 days of verifying the request, except what we must keep for legal, tax, fraud-prevention or dispute reasons. Deleting your account stops your Codes from forwarding.
11. Your rights (including California and EU/UK)
Everyone. You can ask us to access, correct, delete or export your personal information. You can download your codes, destinations and their history, design prompts and seeds, scan counts, payments and agreement records at any time from Account → Export my data. To make any other request, email legal contact email from your account email address; we’ll verify the request (for example by confirming it with that address) and respond within the time the law requires (45 days under California law, extendable once by 45 days; one month under GDPR, extendable where allowed). You can use an authorised agent, who must show us your signed permission. If we decline a request, you can appeal by replying to our decision; we’ll respond within the time the law requires (for example 45 or 60 days, depending on your state). We won’t discriminate against you for exercising any of these rights.
California (CCPA/CPRA) and other U.S. state laws. In the last 12 months we collected these categories of personal information, for the purposes in section 9, from you, your devices and our service providers: identifiers (email address, account ID, IP address, the hashed visitor ID); customer and commercial records (plans, purchases, credits; payment details are collected by Stripe); internet or other electronic network activity (usage, scan events, device type, referring domain); approximate geolocation (country); professional or commercial information you give us (business name, industry, brand colours, logo); and user content (prompts, designs, destinations). We don’t collect sensitive personal information as defined by California law, and we don’t make inferences to profile you. We disclose these categories only to the service providers in section 7 for business purposes. We do not sell or share personal information (as “share” is defined by California law) and haven’t in the last 12 months, and we have no actual knowledge of selling or sharing information about anyone under 16. California residents may also ask about disclosures for direct marketing (Cal. Civ. Code § 1798.83); we make none.
EU/UK and similar laws (GDPR / UK GDPR). Our legal bases are listed in section 9. You have the right to access, rectify, erase, restrict or object to processing of your data, to data portability, and to withdraw consent where we rely on it. You can complain to your local data protection authority (in the UK, the Information Commissioner’s Office), though we’d like the chance to help first.
12. Children
The Service is not directed to anyone under 18, and we don’t knowingly collect personal information from children. If we learn that we have collected personal information from someone under 18 through an account, we will delete it. Contact us at legal contact email if you think this has happened.
13. Security
We protect personal information with measures appropriate to its sensitivity, including encryption in transit (HTTPS), encryption at rest by our infrastructure providers, database access restricted to our own servers, limited access to production systems, secret management for credentials, hashing scanner identifiers instead of storing IP addresses, and keeping card data entirely with Stripe. No method of transmission or storage is completely secure, so we can’t guarantee absolute security. If a data breach affects your personal information, we will notify you and the authorities as the law requires.
14. International transfers
We are based in the United States, and personal information is processed in the United States and other countries where our service providers operate, which may have different data protection laws from yours. Where the law requires, we rely on appropriate safeguards for transfers, such as the European Commission’s Standard Contractual Clauses (and the UK addendum) in our providers’ data processing terms.
15. Changes and contact
We may update this Privacy Policy. For material changes, we’ll notify you by email or in the app before they take effect, and we may ask you to agree again. The version number and date at the top show the current version. Contact: Arcteligent LLC, legal contact email, postal address.