Privacy Policy
Qrr helps cafés and restaurants publish digital QR menus. Here is what we store to run your menu, what is shared with service providers, and what your guests’ visits involve.
Last updated: October 11, 2026
1. Who we are
Qrr (“QR Menu Generator Qrr”) is an iPhone app provided by Metin Arslantürk (“we”, “us”). This policy covers the app, the public menu pages at menu.arslanturk.dev, and this website, qrr.arslanturk.dev. For privacy questions or requests, contact contact@apps.arslanturk.dev.
2. Your account and optional sign-in
You can use Qrr without signing in. The app generates a random device identifier and stores it in your iPhone’s Keychain, so the same account is available again after reinstalling the app (and on a new iPhone restored from an encrypted backup). You can optionally back up the account with Sign in with Apple or an email and password, which lets you recover it and use it on other iPhones. Our backend, which runs on Cloudflare Workers (qrr-api.arslanturk.dev), keeps for your account:
- the random device identifier(s) linked to the account, and short-lived one-time codes when you choose “Use on another iPhone”;
- if you choose to back up your account: your sign-in email address and a salted, one-way hash of your password (we never store the password itself), and/or the stable user identifier and (relay) email address provided by Sign in with Apple;
- your business profile: business name, country, business email address, type of venue and logo;
- your menus: titles, sections, dishes, prices, descriptions, ingredients, labels, translations, design settings, venue information you choose to show (such as address, phone, Wi-Fi details, opening hours, Instagram and website) and QR code settings;
- the photos you add (dish photos, cover photo and logo), stored on Cloudflare R2;
- subscription status used to unlock Premium, and usage counters for AI features and uploads (request type, status, duration and time).
Your business email is used only to contact you about your account. It is never shown on your menu.
3. Your public menu
Menus are designed to be public. Everything you publish (business name, logo, menu content, photos and venue information) is visible to anyone who opens your menu link or scans your QR code, and may be indexed by search engines. Don’t add information you don’t want to be public. You can hide a menu at any time (“Menu is online” switch) or delete it.
4. AI features
When you use “Write with AI”, translation, or AI dish photos, the relevant texts are sent through our backend to Google’s Gemini API, which generates the result on our behalf: dish or section names, descriptions, ingredients, the venue type and name for context, and the languages involved. Your own photos are never sent to the AI. We do not store prompts or AI outputs on our servers except as part of your menu when you save them. AI-generated photos are returned to your app and are only uploaded if you choose to use them. Qrr asks for your permission before the first AI request, and you can turn AI features off at any time in Settings. See Google’s privacy policy and the Gemini API terms.
5. Your guests
When a guest opens your menu, we count a view for that menu, day and QR code (for example “Table 4”) so you can see scan statistics. We do not store guests’ IP addresses, names or any identifier with these counts. Cloudflare processes connection data such as IP address to deliver and protect the pages. The menu page loads fonts from Google Fonts, so the guest’s browser connects to Google’s servers. A guest’s language choice is remembered only in their own browser.
6. Payments and RevenueCat
Apple handles in-app payments; we never receive payment-card details. RevenueCat manages and validates Qrr Premium. It receives your random Qrr account ID, purchase and transaction history and technical purchase information (app and SDK version, platform, product identifiers, transaction dates, currency and storefront) for purchase validation, restoration and entitlement management. See RevenueCat’s privacy policy and Apple’s privacy policy.
7. App usage analytics
Qrr uses Mixpanel to understand how the app is used. We send a closed list of events such as app opens, onboarding steps, paywall views and purchase outcomes, menus, sections and dishes created, updated or deleted, photo uploads, AI requests and their outcomes, theme and language changes, QR codes created, shared, saved or printed, statistics viewed, review requests and account deletion. Events include counts and categories (for example the number of languages or the venue type), the app language, device region setting and Premium status, with your random account ID, timestamps and technical details such as app and OS version. Mixpanel derives approximate location (country, region, city) from the IP address. We never send menu texts, business names, emails or photos to Mixpanel. See Mixpanel’s privacy policy.
8. No ads and no tracking
Qrr shows no ads, does not track you across other companies’ apps or websites, does not use the advertising identifier and does not sell personal information.
9. Camera and Photos
Qrr uses the camera only when you choose to take a photo for your menu, and adds images to your photo library only when you save a QR code. You can change these permissions at any time in your iPhone’s Settings.
10. This website and support
This website is hosted by Cloudflare, which processes connection data to deliver and protect it. It uses no analytics scripts, advertising trackers or cookies. If you email support, we use your email and message to respond. See Cloudflare’s privacy policy.
11. Retention and deletion
We keep your account data while your account exists. In the app, open Settings and choose “Delete account & data” to permanently delete your sign-in details, business profile, menus, QR code settings, photos, statistics and usage records from our servers; your menu links stop working immediately. Deleting a single menu deletes its content and statistics. Apple’s and RevenueCat’s transaction records are kept by them for purchase restoration, fraud prevention and legal obligations. Active subscriptions must be cancelled separately in your Apple Account settings.
12. Your rights
Depending on where you live (for example under the GDPR, UK GDPR or CCPA), you may have the right to access, correct, export or delete your personal data and to object to or restrict processing. Most data can be edited or deleted directly in the app; for anything else, email us. You may also lodge a complaint with your local data protection authority.
13. Children
Qrr is a tool for businesses and is not directed to children under 13 (or the minimum age in your country).
14. Security and transfers
Data is encrypted in transit (HTTPS) and stored with Cloudflare. Our service providers may process data in the United States and other countries, with appropriate safeguards where required.
15. Changes
We may update this policy. We will change the date above and, for significant changes, notify you in the app.