Canary
Privacy Policy
TL;DR
Canary does not collect your personal information. It does not require an account, does not track your location, and does not store the content of your scans anywhere outside your device.
Canary does NOT collect
- Your name, email, phone number or any other account information
- The URLs or content of QR codes you scan
- Your location
- Your contacts or calendar
- Any device identifier linked to your identity (no IDFA, no IDFV)
What Canary does when it scans a QR
When you scan a QR code, Canary analyzes the QR content through a Canary-developed heuristic framework within the app.
For most QR types — contacts, calendar events, WiFi networks, plain text — analysis is performed entirely on your device and nothing is transmitted externally.
To improve risk assessment, Canary also relies on external security services who catalog and publish lists of fraudulent or suspicious entities. This keeps Canary current with malicious URLs, crypto wallets, and more.
Network requests to these external services pass through a proxy server operated by Mitch & Murray Holdings LLC. Only the data relevant to each check is transmitted — no user or device data, and no other user-identifying information is sent to the external provider. Providers see only the relevant data from the Canary server.
Raw QR content and URLs are not retained by these servers after a check is complete.
Third-party reputation services
Google Safe Browsing
When you scan a URL QR code, the destination URL is checked against Google Safe Browsing to identify known malicious sites.
Subject to Google’s Privacy Policy.
MistTrack
When you scan a cryptocurrency payment QR code, the wallet address is checked against MistTrack to identify addresses associated with reported fraud.
Subject to MistTrack’s Privacy Policy.
No external reputation check is performed unless it is relevant to the QR type being scanned. A contact card scan, for example, triggers none of the above. Phone and SMS numbers are checked using on-device analysis only — no phone number is sent to any external service.
What Canary collects
Every scan already routes through our own servers — so your phone never touches a suspicious site directly, and so Canary can check live reputation databases. That same round-trip is the moment Canary records one small, anonymous telemetry tick. The aggregate of those ticks is exactly what powers the live activity counter on our home page — and it can’t be tied to you. It counts; it never watches.
This telemetry tick contains:
- A randomly generated device identifier (reset when you reinstall the app)
- The type of QR code scanned (URL, WiFi, contact, etc.)
- The risk level assigned to the scan (safe, verify, caution, unsafe, danger)
- Which Canary heuristic signals fired during analysis
- Whether an external reputation check was performed for a URL or crypto wallet
The telemetry tick contains no URL content, no QR code content, no personal information, and no information that could identify you. The device identifier is anonymous and not linked to your Apple ID, name, email, or any other identity.
In-app messages
Occasionally Canary shows an in-app message — for example, about a new feature or where to find us. If one appears, Canary sends an anonymous count of whether it was shown, tapped, or dismissed. This carries no device identifier and nothing that identifies you; it tells us only whether a message was useful.
Website analytics
Our website (canaryscanner.com) records basic, anonymous, cookieless analytics: the pages visited, your approximate region (country), and which link or QR code referred you. This contains no personal information and sets no cookies. It is used only to understand how people find and use the site.
Scan history
Canary stores your scan history locally on your device. This data never leaves your device and is not accessible to Mitch & Murray Holdings LLC or any third party. You can delete your scan history at any time from within the app.
Children’s privacy
Canary is not directed at children under 13. We do not knowingly collect any information from children.
Changes to this policy
If we make material changes to this policy, we will update the effective date above. Continued use of Canary after changes constitutes acceptance of the revised policy.
Contact
Questions about this policy: [email protected]