Trust Center

Everything we ask you to take on trust, written down and linkable. If something you need isn’t here, tell us.

Privacy Policy
What we collect, what we never do (sell your data), and how deletion works.
Terms of Service
The plain-English rules — including §5A: codes are forever, accounts need a heartbeat.
The 99-Year Promise
The written disaster-recovery plan behind every code we host: continuity reserve, prepaid domains, dead-man switch.
Support
A human answers — support, billing, abuse reports.
Who's behind QRLife
The founder, the LLC, and the one-hop ownership chain.
Status page
Coming soon — public uptime for the scan infrastructure.

Verify it yourself

Domain registration (check it against public WHOIS anytime): qrlife.me is registered through July 21, 2036 — the maximum the .me registry allows, topped up every year as the cap moves, with auto-renew on. Renewals are funded from the continuity reserve described in the 99-Year Promise.

Every link and QR code QRLife generates lives on qrlife.me or one of its subdomains (card.qrlife.me, api.qrlife.me, files.qrlife.me, …). We own a handful of other domain names from earlier experiments; they still resolve so nothing ever breaks, but no code is issued on them by default and the 99-Year Promise covers qrlife.me and its subdomains only.

Account security

  • HTTPS everywhere — all traffic is encrypted in transit.
  • Passwords are stored hashed (AWS Cognito), never in plain text.
  • Optional two-factor authentication with an authenticator app — enroll in Settings, with one-time recovery codes if you lose your device. (Yes: you set up 2FA by scanning a QR code.)
  • Least-privilege access — production data is limited to those who need it.
  • Security reports: /.well-known/security.txt

Encryption

All data is encrypted in transit (TLS) and at rest (AWS-managed encryption). Wi-Fi network passwords and Guardian medical notes are additionally field-level encrypted with a dedicated key (AWS KMS) — so they are unreadable even with direct database access, and are only decrypted at the moment a card renders.

Safe Scan link protection

Every destination URL is checked against Google Safe Browsing — Google’s live database of malware and phishing sites — at three points: when a code is created, every time its destination is edited, and when you use the in-app scanner. Flagged URLs are blocked outright, and accounts that repeatedly attempt them are suspended. One honest caveat: if Google’s service is ever unreachable, we fail open — we let legitimate activity continue rather than blocking everyone — because we choose availability over theater, and we tell you that here instead of hiding it. That same caveat is stated on our pricing page and belongs anywhere Safe Scan is described.

No tracking cookies, no ad pixels

We set no tracking cookies and no advertising pixels — no third-party ad networks, no analytics trackers following you between sites, and no data broker relationships. In fact we set exactly one cookie, named qrlife_locale, which remembers the language you picked — open your browser's developer tools and check. Signing in does not use a cookie at all; your session is held in your browser's local storage. That is why you have never seen a cookie consent banner here: there is nothing to consent to. We also do not fingerprint the people who scan your codes: your scanners are counted, never identified, and never targeted with advertising.

No scan limits

Every QRLife code has unlimited scans, forever — on every plan, including free. We do not meter scans, we do not throttle a code that gets popular, and we will never send you a bill because something you printed worked. This is promise #7 on the 99-Year Promise: codes you have already created can never be metered retroactively. The one exception is abuse — scan traffic that is part of fraud or a Terms of Service violation gets stopped. Legitimate use is never metered.

Subprocessors

Who touches your data, exhaustively: Amazon Web Services (hosting, storage, database, authentication, email — CloudFront, S3, Lambda, DynamoDB, Cognito, SES, KMS; US regions) and Apple App Store (live — distributes our iOS app; distribution only, no payments: the app contains no in-app purchases, so Apple processes nothing for us). Google Play joins that list the day the Android app is publicly listed; the app is submitted and in review today, and Google Play handles no user data yet. That’s the whole list — if a service isn’t on it, it doesn’t have user data.

Bring your own domain

Planned for our business tier: point your own domain at your QRLife codes, so your printed links live on a domain you control.

Guardian cards and health information

Guardian cards exist to speak for you in an emergency. Anything you put on a Guardian card is shown to whoever scans it — that’s the point. Put on it exactly what you’d want a stranger helping you — you, someone in your care, or a pet — to see, and nothing more. QRLife accounts are for people aged 13 and over (Terms section 2); a Guardian card made for someone younger or for an animal is made and managed by the adult who owns the account. QRLife is not a medical device, not a medical-records system, and not a substitute for medical ID jewelry your doctor recommends. Public card pages are excluded from search engines, and medical notes are field-level encrypted at rest.