On this page: What a code reveals · If you make codes · If you scan codes · The payment scam · What this site does
What a QR code reveals
Start with the thing most people get backwards: a QR code is not private, and it was never designed to be. It is a printed string of characters that anyone can read.
Anyone with a phone can decode any code and see exactly what is inside it. There is no encryption, no password and no access control in a plain QR code. If you can photograph it, you can read it.
That means the contents of a code should be treated as public the moment it is in the world:
- A Wi-Fi code contains your network password in readable form.
- A contact code contains your name, phone number and email address.
- A Bitcoin code contains a payment address, which is a public identifier tied to a transaction history.
- A location code may contain coordinates — and if it is on your front door, so does the place you live.
- A link code contains the URL, including any tracking parameters.
Designing with that understood removes most of the risk. The question is never "is this secret?" — it is "am I comfortable with anyone who sees this object knowing this?"
If you make codes: two decisions that matter
1. Static or short-link?
This is the most consequential privacy decision, and it is usually presented as a feature comparison rather than a privacy one.
A static code — the kind QRMint makes — contains your destination directly. When someone scans it, their phone goes straight to your page. Nobody else is involved. Nobody counts the visit, and nobody learns who scanned it.
A short-link code points at the provider's domain instead. Every scan is routed through that provider's servers before being redirected to you. That gives you editable destinations and scan statistics — genuinely useful for a large campaign — but understand the trade: the provider sees every scan, including the scanner's IP address and device details, and they can build a picture of who you are reaching. Your visitors are also now subject to that provider's privacy policy, which they never agreed to.
If you handle sensitive audiences — a medical practice, a support service, a political campaign — routing every scan through a third party's analytics is a meaningful privacy decision, not a technical detail.
2. What you put in the code is permanent
A printed static code cannot be edited. If you encode a personal mobile number and then change numbers, the code keeps showing the old one. If you encode a Wi-Fi password and then rotate it, the code is dead.
That cuts both ways. It is why a static code cannot be switched off or held to ransom — but it is
also why you should encode a role address rather than a personal one. Use
info@yourbusiness.com, not your personal Gmail. Use a landline or a business number,
not your mobile. The code will outlive your current preferences.
3. Review what a link code carries
Marketing platforms love to append tracking parameters to URLs. If your link contains something
like ?utm_source=qrcode&ref=12345, that is now printed in plain text on your
physical object, and it is visible to anyone who scans and inspects it. Strip identifying
parameters before you generate the code if the object is public.
If you scan codes: how to stay safe
Scanning is low risk if you adopt two habits. Most of the danger comes from codes that were physically tampered with, not from the format itself.
Preview before you act
Modern phone cameras show you the destination URL before opening it. Read it. If a code on a parking meter shows a domain you do not recognise, do not tap through — that sticker was very likely placed over the original by someone else.
Check payment details against a second source
Payment codes are where the real money is lost. Before paying a large amount:
- Compare the destination address against one you obtained independently — a printed invoice, the company's official website, a phone number you already had.
- Verify the amount in your wallet, not just the code.
- Send a small test amount first if the sum is significant.
Treat a code on public display with mild suspicion
QR stickers placed over legitimate ones — on parking meters, charging points, restaurant tables — are one of the most common real-world attacks. Check whether the sticker is a physical overlay sitting on top of an original. Loose, bubbled, misaligned or oddly-sized stickers are a warning sign.
Be sceptical of codes that arrive unsolicited
A code in a letter, an email attachment, a direct message or a package insert that you did not expect is a delivery mechanism, in the same way a link in a strange email is. The code itself is harmless; the page it opens may ask for credentials or payment.
The payment scam worth knowing about
The highest-value QR scam is simple and effective: a criminal replaces a legitimate payment code with their own, pointing at a wallet they control. A customer scans what looks like the genuine code and pays the wrong person. Once a cryptocurrency payment is broadcast, it cannot be reversed by anyone.
It is worth stating clearly because it is a property of printing a payment code, not of any particular tool. The defence is procedural, not technical: for any payment above a trivial amount, confirm the address and amount through a channel other than the code you are looking at. A code printed on the same object as the payment instruction can only ever verify itself.
What QRMint does about it
Three properties of this tool are relevant to the above, and all three are verifiable rather than simply asserted.
Your content is never transmitted
The generator runs entirely in your browser. When you type a Wi-Fi password or a contact card into it, that data is used to compute a pattern on your own device and nothing else. There is no API call, no form submission, no server-side rendering and no logging of code content.
You do not have to believe that. Open your browser's developer tools, switch to the network tab, and generate and download a code while watching the request list. Nothing carries your payload. The practical consequence is that we cannot leak, sell or be compelled to disclose something we never receive.
Nothing to renew, nothing to revoke
Because there is no redirect service, no account and no database row holding your code's destination, there is no mechanism by which a code you have printed can be switched off. That removes a whole class of risk that subscription-based generators carry: if a provider closes, or you stop paying, every code you printed with them stops working at once.
The corollary is that you also cannot edit a printed destination. That is the honest trade, and for anything printed once and used for years it is the right side of it.
The checks run before you download
A code that does not scan is a security problem in its own right, because it invites people to retry with a different app, or to trust a replacement sticker someone else provided. QRMint measures contrast, verifies the four-module quiet zone, computes the module density and caps a logo to what the error-correction level can actually recover. When something is unreadable, the export buttons lock.
The short version
- A QR code is public. Never encode anything you would not print on a poster.
- Prefer static codes: no middleman sees your visitors, and nothing can be revoked.
- Encode role addresses, not personal ones. Printed codes outlive your preferences.
- Preview the destination before tapping, especially on public displays.
- Verify payment details through a channel other than the code itself.
- Your data never leaves your device on this site — and you can verify that yourself.
Related reading
- Choosing the right QR code type — including which types need no internet connection.
- Design that still scans — safe colour, shape and logo choices.
- Privacy and cookies notice — exactly what this website stores.