Legal

Privacy Policy

Applies to every Zivanor app and to zivanor.com · Last updated: 7 October 2026

In short

  • Zivanor apps work on your device. There is no account and no sign-up.
  • What you scan, create and store stays on your phone. We never see it.
  • An app goes online only after you tap a button that says it will, or when you turn on an optional feature that says it does.
  • No analytics, no crash reporting, no tracking by us. The free version shows one ad banner from Google AdMob, with your consent where the law requires it.
  • You can email us at any time about your data: support@zivanor.com.

Who we are and what this policy covers

This policy covers every app published under the Zivanor name by VisionHost International B.V. ("we", "us"), currently Zivanor QR, and the website zivanor.com. We are the controller of any personal data described here.

VisionHost International B.V.
Postbus 53105, 2505 AC Den Haag, The Netherlands
Visiting address: Zichtenburglaan 31, 2544 EA Den Haag, The Netherlands
support@zivanor.com

Every Zivanor app follows the same approach: it works entirely on your device, has no account and needs no server to do its job. Where a detail below differs between apps, the app's own screen (Settings → Privacy, or similar) says so.

What stays on your device

Everything you scan, create or store is kept only in the app's local storage on your phone. Unless you use a feature that is clearly described as sending it somewhere, none of it is sent to us or to anyone else:

This data is included in your phone's own backup (Android Auto Backup or Apple's iCloud device backup) exactly like any other app's data, so it can be restored on a new phone. We have no access to that backup. It belongs to your Google or Apple account and is covered by their terms.

Camera and photos

The camera permission is the only runtime permission a Zivanor app asks for. Camera frames are analysed on your device to find codes and are discarded immediately. They are never stored and never sent anywhere. When you use "Scan from image", the app reads only the photo you pick through the system picker, which needs no permission. When you save a code you created to your photos, the app uses add-only access to your photo library on iOS; it cannot read your other photos.

Online actions you start yourself

A Zivanor app makes a network request only when you tap a button that says it will. Nothing is fetched or sent automatically in the background. In Zivanor QR these actions are:

WhenWhat is sentTo whom
You tap "Check where this goes" on a scanned link The link itself. Your IP address is visible to that server, as with any web request. No cookies, no identifiers The server the link points to
You tap "Look up product" on a food barcode The barcode number, plus a request header with the app name, its version and our support email address, which Open Food Facts requires from every app Open Food Facts, an independent non‑profit database
You tap "Look up book" on an ISBN The ISBN number only Open Library, a project of the Internet Archive

None of these requests include your name, a device identifier, your location, or any other code or card you have stored. Every answer is treated as untrusted text. You can switch these buttons off at any time in Settings → Online.

Sharing a card with someone

If you use "Share card", the card's details are encoded directly into the QR code or link you show or send. The link looks like https://zivanor.com/qr/c#…. The card data sits in the part after the #, which browsers never send to a server. If the person you share with has the app, it opens the card directly. If they open the link in a browser instead, the browser loads a small page from zivanor.com; our hosting provider then sees their IP address in its normal server log (see This website) but never the card data. A card's PIN and balance are never included in a shared link.

Advertising

The free version of a Zivanor app shows one small ad banner, provided by Google AdMob. Zivanor Pro removes it. We do not show interstitial, full‑screen or rewarded ads.

Purchases

Zivanor Pro is a one‑time purchase processed entirely by the Google Play Store or the Apple App Store under their terms. We do not receive your name, email address or payment details. To check whether your purchase is active and to restore it on a new phone, the app uses RevenueCat, which receives the store's purchase receipt together with an anonymous identifier generated on your device. RevenueCat's privacy policy: revenuecat.com/privacy. The purchase is tied to your store account, not to anything you scan or store.

App lock

If you turn on the app lock in Settings, the unlock prompt (Face ID, fingerprint or your device passcode) is handled entirely by your phone's operating system. The app only receives a yes or no answer. We never see, store or transmit biometric data or your passcode. On iPhone, the Face ID permission is requested only when you turn this feature on.

Widgets, shortcuts and the Quick Settings tile

If you place a code or card on a home‑screen widget or an app shortcut, that code is drawn on your home screen. It stays on your device, but anyone who can see your screen can see it. You choose what goes on a widget; nothing is placed there automatically.

Export, import, print and share

Exporting history or cards creates a file on your device. Printing, sharing and "Save to photos" hand the content to your phone's share sheet, printer dialog or photo library. What you send and to whom is entirely your choice, and from that point the recipient's or printer's own policies apply. Importing reads only the file you pick.

When you contact us

If you email us, we process your email address, your name if you give it, and the content of your message, solely to answer you and to improve the app. We keep support emails for up to 12 months after the matter is closed, then delete them, unless the law requires us to keep them longer. We do not add you to any mailing list.

Data retention and deletion

DataKeptHow to delete it
Scans, history, cards, notes, settings On your device, until you delete it Delete items in the app (History, Cards), use "Clear history" on the History screen, or uninstall the app. Uninstalling removes everything. Your phone's backup follows its own rules
Ad consent choice On your device Settings → Privacy → Privacy options, or uninstall
Purchase status (RevenueCat) While your purchase exists, under RevenueCat's retention rules Email us; we will ask RevenueCat to delete the anonymous record. The purchase itself stays with your store account
Advertising data (Google AdMob) Under Google's retention rules Reset your advertising ID in your phone's settings; manage ad personalisation in your Google account
Support emails Up to 12 months after the matter is closed Email us and ask
Website server logs Up to 30 days Deleted automatically

Because there is no account, there is no account to delete and nothing we hold that identifies you by name.

How we protect your data

Data on your device is protected by your phone's own encryption and by the optional app lock. Every network request the app makes uses an encrypted connection (HTTPS). The app never runs scanned content as code and only opens links with recognised, safe schemes. We do not use analytics or crash‑reporting services. The third parties named in this policy (Google, RevenueCat, Open Food Facts, Open Library) receive only the data described here and are bound by their own policies and by the app stores' rules to protect it at least as well as this policy requires.

International transfers

Google and RevenueCat process data in the United States and other countries. For transfers out of the European Economic Area they rely on the EU–US Data Privacy Framework and/or the European Commission's standard contractual clauses, as described in their privacy policies. Data that stays on your device is never transferred by us.

Your rights

Under the GDPR and similar laws you can ask us to show you, correct, delete or hand over the personal data we hold about you, to restrict or object to its processing, and to withdraw any consent you gave. For data that stays on your device there is nothing for us to give you or delete: it is already entirely under your control in the app. For anything else, email support@zivanor.com and we will answer within one month. You can also complain to your data protection authority; in the Netherlands that is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

Children

Zivanor apps are not directed at children under 13, or under the higher age your country or app store sets. We do not knowingly collect personal data from anyone, and because the apps have no account and keep data on the device, there is nothing for us to collect.

This website (zivanor.com)

zivanor.com sets no cookies and uses no analytics. Fonts and images are served from this domain, so loading a page contacts no third party. Our hosting provider keeps a standard server log (IP address, page requested, browser type, time) for up to 30 days to detect abuse and errors; we use it for nothing else. Email links open your own mail app.

Future online features

A future Zivanor app, or a future version of this one, may offer an optional feature that uses a server of ours, for example to share something with another person or to sync your data between your own devices. Any such feature will be opt‑in, off until you turn it on, described in the app before you do, and this policy will be updated to say exactly what it sends and keeps before it ships. Until then, nothing in any Zivanor app sends your data to a server we operate.

Changes to this policy

If this policy changes, we update the date at the top. If a change affects what an app sends or keeps, we announce it in the app's release notes and, for significant changes, in the app itself before the change takes effect. Continued use after a change means you accept the updated policy.

Contact

VisionHost International B.V.
Postbus 53105, 2505 AC Den Haag, The Netherlands
support@zivanor.com