Privacy Policy
Last updated: 2026-09-07. Applies to the Scan2Check Android application
(eu.lacora.scan2check) and to www.scan2check.com.
In short#
Scan2Check has no accounts, no analytics, no advertising and no server of ours. We do not receive your scans and we cannot see them. The app sends data to one place only: the HTTP endpoint that whoever deploys the app has configured it to use.
What the app stores on the device#
- A device identifier. On first launch the app generates a random 8-character identifier. It is not derived from your hardware, your Google account or any advertising ID. It cannot be read by other apps, is not resettable from inside the app, and is permanently destroyed when you uninstall.
- Its settings — the endpoint URL, accepted barcode types, timeout, custom HTTP headers, sounds and any form definition, exactly as supplied in the settings QR code that was scanned.
Nothing else is stored. No scan history is kept on the device.
What the app sends, and to whom#
A freshly installed app has no endpoint configured and transmits nothing at all.
Once an operator scans a settings QR code, the app sends the following to the endpoint configured in it, and to no other destination:
- the value of each scanned barcode,
- the device identifier described above,
- the answers to any on-screen form the configuration defines,
- and, if a second "application opened" endpoint is configured, the app's current settings when it starts.
That endpoint belongs to the organisation that deployed the app, not to us. It is that organisation which decides what is collected, why, how long it is kept and who else sees it — in data-protection terms, they are the controller of that data. If you are using Scan2Check at work, at an event or as part of a service, direct any question about your data to them. We have no access to their systems and cannot retrieve or delete anything from them.
Transport security. Scan2Check connects only to the endpoint the deploying organisation
configures, and that organisation chooses the protocol. https:// endpoints are encrypted in
transit. Plain http:// is also supported, because many deployments run entirely on a private
internal network where that is a deliberate choice. The app imposes neither — the decision
belongs to whoever issues the settings QR code.
Camera#
The camera is used for one purpose: recognising a bar code or QR code in the live preview. Recognition runs entirely on the device, using a barcode model bundled inside the app — no image or video frame is uploaded anywhere, and no frame is written to storage. Only the decoded text of a code is ever transmitted, and only to the configured endpoint.
The app asks for camera permission the first time you tap SCAN CODE. If you decline, scanning is unavailable; nothing else about the app changes.
What the app does not do#
- No account, no sign-up, no login.
- No analytics, crash reporting or usage tracking of any kind.
- No advertising. The app contains no advertising SDK, and the Android advertising ID permission is explicitly removed from it.
- No location access, no contacts, no files, no microphone.
- No data of any kind is sent to the app's developers.
Permissions#
| Permission | Why |
|---|---|
| Camera | To recognise bar and QR codes |
| Internet | To send scanned codes to the configured endpoint |
| Vibrate | To signal a pass or fail result by touch |
Retention and deletion#
Uninstalling the app permanently deletes everything it holds — the device identifier and the stored settings. Records created by scans live in the deploying organisation's system; ask them about retention and deletion there.
Third-party components#
The app is built with Google's ML Kit Barcode Scanning (bundled, on-device), the AndroidX and Jetpack Compose libraries and the OkHttp HTTP client. None of these is configured to report usage to its vendor.
Children#
Scan2Check is an operational tool for workplaces. It is not directed at children and we do not knowingly process children's data.
Website#
www.scan2check.com is a static documentation site. It sets no advertising or tracking cookies.
Changes#
Material changes will be reflected here with a new "last updated" date.
Contact#
Questions about this policy: info@lacora.eu
If you scanned codes using a device given to you by an employer, a venue or a service provider, please contact them about your data — not us. We do not hold it.