Legal

Privacy

Last updated 14 July 2026

What we store about you

Your account: name, email address, and a hash of your password. If you enable a second factor we store the credential needed to check it (a passkey public key, or a TOTP secret). We never see or store your password itself.

What we store when someone scans your code

A scan is a public event — anyone who points a phone at a printed code triggers one, and they have no relationship with us. So we keep the minimum that makes analytics useful and nothing that identifies the person scanning:

The salt changes daily and the hash also mixes in the code's id, so the same visitor produces a different value tomorrow, and a different value on a different code. It is a deduplication signal — enough to say "this looked like one person scanning twice today" — and it cannot be used to follow anyone between days, between your codes, or across the web. We do not run ads, we do not sell data, and we do not embed third-party trackers on scan destinations.

Who processes it

Keeping and deleting

Scan events accumulate for as long as the code exists. Delete a code and its scan history goes with it; close your account and your personal data, organizations, and codes are deleted.

Deleting an account stops the codes redirecting. If you have printed a code, archive it instead — an archived code keeps resolving forever under our permanence guarantee, and stops collecting anything beyond the counts.

Your rights

You can export or delete your data at any time from your account, or by writing to privacy@evertag.app. If you're in the UK, EU, or California you have statutory rights of access, correction, deletion, and portability; the address above is how you use them.

Changes

If we change what we collect, we'll update this page and note the date. Material changes get an email.