Privacy
Last updated 7 August 2026.
The short version
Static QR codes are generated entirely in your browser and never reach our servers. Dynamic codes need an account. We record how people use the site, including session recordings — details below, and you can opt out.
What we store
- Your account — email address and a hashed password. Passwords are hashed with PBKDF2-SHA256 and a per-user salt; we cannot read them.
- Your dynamic codes — the name, destinations and routing rules you enter.
- Scans of your codes — timestamp, country, device type and which destination was served. No cookies are set on the person scanning, and no personal data about them is stored.
- Static codes — nothing. They are generated in your browser and never sent to us.
Analytics and session recording
We use Umami, which we host ourselves. Your data stays on our infrastructure — there is no third-party analytics company receiving it, and no data-processing agreement with an outside vendor.
We record sessions. That means we capture your interactions with the site — pages viewed, clicks, scrolling, and typing into fields that are not masked. Password and payment fields are masked and never recorded. We use this to see where the product confuses people. Recordings are kept for 30 days and then deleted.
How to opt out. We respect the Do Not Track setting in your browser. Turn it on and we collect no analytics and record no sessions. Most browsers have it under privacy settings.
Analytics are cookieless. We do not use advertising trackers or sell data to anyone.
We send transactional email only — currently just password resets. No marketing email, no list.
Your data
You can delete any code, along with its scan history, from your dashboard. To delete your account entirely, or to ask what we hold on you, email rick@honkforhelp.com.
Changes
If this policy changes materially we will update the date above. Kodo is operated by Shovelware.