Minimum Required Only
HSX QR Creator requests only the permissions its features need. Permissions are used solely for app features and never for data collection.
File Access
Only when you choose a file to read, or choose where to save a code. There is no background scanning of your drives.
Clipboard Access
Used when you paste into the app, copy a code out, or read a code from the clipboard. The optional clipboard watch feature is off by default and can be switched off at any time in Settings.
Camera
Only while you are using the live camera scan on the Scanner page. Frames are read on your device to find a code and are never recorded, saved, or transmitted.
Screen Capture
Only when you start a screen scan and select a region yourself. The captured region is read on your device and is not saved or transmitted.
Network Access
Used for exactly two things, and nothing else.
Every outbound connection, in full
- Optional address lookup (OpenStreetMap Nominatim). Only on the Location page, and only when you ask the app to turn an address into coordinates or coordinates into an address. It sends the address or coordinates you typed and nothing else: no account, no identifiers, no other content. You can switch this off completely with the Work offline only setting.
- Microsoft Store licence check. The app asks Windows whether your trial or purchase is valid. This is handled by Microsoft; we receive nothing from it.
Creating and reading QR codes never requires a connection. With the offline setting enabled, the address lookup is disabled and only the Store licence check remains.
Greeting cards and the card page
A greeting code contains a link to a card page so the person scanning it sees a designed card instead of raw text. The greeting itself is written into the part of the link that follows the # symbol, and browsers never send that part to the server. The card is therefore assembled on the scanner's own device, and the words of your greeting reach no server, including ours.
The host does see an ordinary web request for the page, in the same way any website visit is seen: an IP address, a timestamp, and the browser type. It does not see the greeting. You can point the app at your own server or a network address instead of ours in Settings, and greeting codes will use that host.