Effective date: September 27, 2026 | Developer: Jan Aguja
This Privacy Policy describes how the Kodigo app ("the app", "we") handles your information. Kodigo is a phonebook for payment QR codes and barcodes, built around a simple premise: everything you save lives on your device, and we don't run a backend that could collect it even if we wanted to.
1. Information We Collect
Kodigo has no user accounts and no analytics, advertising, or crash-reporting SDKs. We do not collect, and cannot identify you from, your usage of the app.
The app does make a small number of network requests, none of which involve your saved data:
- Institution registry updates. Kodigo periodically fetches a small
public JSON file from
janapps.comthat keeps bank/e-wallet names and colors up to date without needing an app update. This is a plain file download — it contains no personal data, and the request identifies nothing about you beyond what any web request does. - Pro purchase, if/when available. The one-time "Pro" unlock is handled through Apple's or Google's in-app purchase system and RevenueCat, which validates the purchase. See Section 3.
2. What's Stored On Your Device
Payment and barcode data you save. The decoded content of each code (account numbers, payee names, bank/wallet identifiers, amounts, etc., exactly as encoded in the original QR or barcode), a label, and which contact it's filed under — kept in a local database on your device only.
Contact photos and, optionally, the original photo of a scanned code. Stored as image files in the app's private storage on your device only.
Institution aliases. If you name a bank/wallet Kodigo doesn't recognize, that name is saved locally so it applies the next time.
App settings. Things like whether App Lock is on, your auto-cleanup preference, when you last made a backup, and a cached copy of the public institution registry.
None of the above is sent to us, to any analytics service, or to any third party — Kodigo has no backend server to send it to.
3. Third-Party Services
RevenueCat (purchases_flutter) manages the one-time "Pro"
unlock. If and when you make or restore that purchase, RevenueCat receives purchase and
receipt information from Apple's App Store or Google Play — needed to confirm your
entitlement — but never receives your saved codes, contacts, notes, or photos.
Kodigo does not integrate any analytics, advertising, or crash-reporting SDKs, and does not use Google Sign-In or any other authentication provider, because there is no account to sign in to.
4. Permissions
Camera. Used only to scan QR codes and barcodes. Frames are processed on your device by your OS's built-in recognizer and never uploaded anywhere.
Photos. Adding a code from an existing photo uses your device's system photo picker, which only gives Kodigo access to the specific photo(s) you pick — never your whole library. Saving an exported code to Photos (so a bank app can pick it up) writes an image Kodigo created itself, which it later removes again per your auto-cleanup setting; Kodigo only ever touches images it created for this purpose.
Face ID / fingerprint / device passcode. If you turn on App Lock, unlocking is handled entirely by your device's operating system. Kodigo never sees or stores your biometric data or passcode — the OS just tells the app "yes" or "no."
Contacts. "Import from Phone Contacts" opens your device's own native contact picker — Kodigo never reads your address book directly, and only sees the one contact you choose. The name and photo you pick are copied into Kodigo's own local storage at that moment; Kodigo doesn't keep a live link back to that phone contact, doesn't sync with it later, and never writes anything back to your address book.
5. Data Retention and Deletion
Everything Kodigo stores lives in the app's private, sandboxed storage on your device. Deleting a code or contact inside the app removes it immediately. Uninstalling the app, or clearing its data through your device's system settings, removes everything — there is no account or server-side copy for us to delete, because none exists.
Backups. Kodigo can export everything you've saved into a single
.qrkeychain file, encrypted with a passphrase you choose (recommended and on by
default). You decide where that file goes — your own cloud drive, a messaging app, email to
yourself — using your device's normal share sheet. Kodigo never uploads a backup on its own,
and we don't keep or have access to any copy of it.
"Help support this QR" reports. If you tap "Help add support for this QR" or "Something's wrong with these details," Kodigo shows you a preview of a report before anything is sent. Names, account numbers, and other personal values are replaced with placeholder characters, keeping only the structure of the code (which fields it uses, its country and scheme). Nothing is sent unless you tap Send, and sending opens your own email app addressed to [email protected] — Kodigo doesn't have a server to receive this itself.
6. Children's Privacy
Kodigo is not directed at children and doesn't knowingly collect data from anyone, since — as described above — it doesn't collect personal data from anyone at all.
7. Changes to This Policy
We may update this policy from time to time. The effective date at the top of this page will be updated accordingly, and any material change will be noted in the app's release notes.
8. Contact
For any privacy-related questions, contact:
Jan Aguja
Independent Developer — Philippines
[email protected]