Trust Center
Everything we ask you to take on trust, written down and linkable. If something you need isn’t here, tell us.
Verify it yourself
Domain registration (check it against public WHOIS anytime): qrlife.me is registered through July 21, 2032 — renewed in five-year blocks, the maximum our registrar allows per order, with auto-renew on. Renewals are funded from the continuity reserve described in the 99-Year Promise.
Account security
- HTTPS everywhere — all traffic is encrypted in transit.
- Passwords are stored hashed (AWS Cognito), never in plain text.
- Optional two-factor authentication with an authenticator app — enroll in Settings, with one-time recovery codes if you lose your device. (Yes: you set up 2FA by scanning a QR code.)
- Least-privilege access — production data is limited to those who need it.
- Security reports: /.well-known/security.txt
Encryption
All data is encrypted in transit (TLS) and at rest (AWS-managed encryption). Wi-Fi network passwords and Guardian medical notes are additionally field-level encrypted with a dedicated key (AWS KMS) — so they are unreadable even with direct database access, and are only decrypted at the moment a card renders.
Subprocessors
Who touches your data, exhaustively: Amazon Web Services (hosting, storage, database, authentication, email — CloudFront, S3, Lambda, DynamoDB, Cognito, SES, KMS; US regions) and Apple App Store / Google Play (mobile distribution and in-app payment processing). That’s the whole list — if a service isn’t on it, it doesn’t have user data.
Bring your own domain
Planned for our business tier: point your own domain at your QRLife codes, so your printed links live on a domain you control.
Guardian cards and health information
Guardian cards exist to speak for you in an emergency. Anything you put on a Guardian card is shown to whoever scans it — that’s the point. Put on it exactly what you’d want a stranger helping you (or your kid, or your dog) to see, and nothing more. QRLife is not a medical device, not a medical-records system, and not a substitute for medical ID jewelry your doctor recommends. Public card pages are excluded from search engines, and medical notes are field-level encrypted at rest.