Back to Qrap

Privacy Policy

Last updated 2026-09-19

Qrap lets you pass a URL, a block of text, or a file between two devices you have paired by scanning a QR code. There are no accounts. This page describes what the service handles, what it records, and for how long. It covers both the Qrap website and the Qrap browser extension.

What happens to the content you send

Content is encrypted in your browser before it leaves your device, and the key travels only inside the QR code — never to the server. The relay cannot read what you send.

A file is held, encrypted, only for as long as the transfer needs it. A session exists for the length of one pairing and is deleted, contents included, when it ends, expires from inactivity, or either device closes it.

What is recorded, and for how long

A metadata record that a transfer happened is kept, as required by applicable law. For each event — creating a session, pairing, relaying a message, uploading or downloading a file, ending a session — that record holds:

  • the time, the session id, and the event type
  • your IP address
  • a coarse location: country and city, not a precise position
  • a coarse device description, such as “iOS/Safari” rather than your full browser string
  • the pseudonymous per-browser id the app generates
  • the size of the transfer in bytes

These records are deleted automatically 90 days after they are written.

Separately, when a device accepts the Terms of Service, that acceptance is recorded: the time, the session, the pseudonymous device id, and which version of the terms was accepted. That record contains no IP address and no location, and is kept for one year.

What is never recorded

Nothing kept includes message bodies, filenames, the encrypted payload, or access tokens. The address of the page you were visiting is not recorded, and neither is anything inside the transfer itself.

There are no accounts, so none of this is tied to a name, an email address, or a profile.

What the browser extension stores on your device

The extension keeps your own settings in your browser’s local storage. They stay on your machine and are not sent anywhere:

  • the sites you have switched the “from phone” button on or off for
  • phones you have approved for pairing
  • the pseudonymous per-browser id used to pair devices
  • which version of the terms you accepted
  • a troubleshooting toggle, off by default

The extension does not read or record your browsing history, and no part of it runs on a page until you click its toolbar button, press its shortcut, or use the “from phone” button on a site you switched it on for.

Who else handles this data

Qrap runs on infrastructure operated by Cloudflare (the relay) and Vercel (the website). They process data only to deliver the service, on our behalf. No data is sold or handed to anyone else for their own use.

Why this data exists

To make a transfer between two devices work, to meet retention obligations, and to be able to answer a lawful request. Nothing recorded is sold, shared for advertising, or used to build a profile of you, and none of it is used to assess creditworthiness or for lending.

Contact

Questions about this policy, or a request concerning data relating to you, can go to qrap.support@gmail.com. Qrap is operated by an individual, not a company. Because there are no accounts and records carry no name or email address, a request will usually need the session id concerned for anything to be findable.

Changes to this policy

If this policy changes, the date at the top of the page changes with it. Material changes to what is recorded would also change the Terms of Service, which carry their own version.