Skip to the content
Barcodehammer
English

Privacy policy

Last updated: 30 July 2026. Applies to the Barcodehammer app (Android and iOS).

In short

Everything happens on your own device, and the app does not collect, share or transmit any personal data. No accounts, no advertising, no trackers, no analytics. Everything stays on your own device, and the history is stored there encrypted. Tickets can also go into a vault that only opens with your fingerprint, face, PIN or pattern.

1. What data is collected?

None. The app itself makes no connection. There is no server for anything to arrive at.

The internet permission is in the app file. Barcodehammer does not request it; it comes from Google's scanning library (ML Kit) that recognises the codes, which puts the permission in its own part of the file. That library can send usage data about itself to Google over it. What you scan or create is not in that data: it stays on your device.

For the one-off purchase of Pro, the com.android.vending.BILLING permission is in the app file as well. That purchase goes through the Play Store app on your device: Google handles the payment and Barcodehammer only learns whether it has been paid. No payment details pass through the app.

Concretely: no registration or credentials, no advertising identifiers, no analytics or crash reporting, no location data, contacts, calendar or microphone, and no cookies.

2. What stays on your device?

The history of what you scanned and created, whatever you put in the ticket vault, and your language and theme choice. History and vault are stored encrypted with AES-256-GCM, each in its own file in the app's private folder; the keys are held in the operating system's secure storage (Android Keystore, iOS Keychain) and never leave it.

Why that matters: a scanned code can contain anything, such as a wifi password, a login code or a home address. That does not belong on disk in readable form.

3. The ticket vault

The vault is a separate, encrypted list for codes you would rather not have on display, such as concert or travel tickets. The lock reaches all the way to the key: it is released only after your fingerprint, face, PIN or pattern, and every unlock asks again. Without that authentication there is nothing to read, not even for someone who takes the file off the device. The vault closes again as soon as you leave the app or tap the padlock yourself.

The app never sees your fingerprint. The dialog you place it on belongs to Android itself; the app is only told that it succeeded. No biometric data is read, stored or transmitted.

This requires the USE_BIOMETRIC permission and a device running Android 10 or later with a screen lock set up. If that is missing, the app says so and creates no vault. If a new fingerprint or face scan is added to the device later, Android discards the key and the vault becomes unreadable. That is deliberate, and the app warns you beforehand.

4. Deleting

You can remove individual entries, or the entire history at once after a warning. In the latter case the key is replaced as well, so that anything left of the old file on disk can no longer be read. The vault has its own such option, which works the same way.

Uninstalling the app removes everything it stored.

5. Backup, export and sharing

At your request the app writes data outside its own folder. This never happens on its own.

  • Backup: history and tickets in a single file, encrypted with a password you choose yourself (AES-256-GCM, key derived with PBKDF2). You decide where the file goes. Keep that password safe: without it the file cannot be opened by anyone, the app's author included. Note that inside that file your tickets are protected by the password and no longer by your fingerprint.
  • Export: a code you created, as PNG, SVG or PDF, to the location you point at.
  • Bulk list: the counted codes from a bulk session as an xlsx file, in the place you point out. That is an ordinary Excel file without a password: what is in it is readable afterwards to anyone who can reach that file.
  • Sharing: a code as an image or as text, to an app of your choosing.
  • Mailing a comment: the button at the top right puts a mail ready in your own mail app, addressed to the maker. Below your own text it adds the version of the app, what Android says about itself, the screen you came from, the language and whether Pro is on. Nothing more, and nothing from the history or the ticket vault. The app does not send that mail itself: you do, and you see everything before you press send.

What happens to such a file once it has left the app is up to you and to the app or service you chose for it.

6. The camera

The camera is used only to read codes. No photos or videos are taken, stored or transmitted; the image is analysed live to recognise a code in it.

7. Sharing with third parties

Nothing is shared, sold or transferred, for the simple reason that nothing is collected and the app has no network connection.

8. Children

The app is suitable for all ages and collects data from no one, children included.

9. Changes

Any significant change, for instance if a feature requiring internet were ever added, will be made clear in the app and on this page before that feature becomes available.

10. Contact

appsbeheerder@lichtgolf.nl

Read on