Privacy policy

In short

  • All tools run in your browser or on your device. Barcodes, images, GS1 data and ZPL are not transmitted to us.
  • We use no tracking, no analytics services and load no content from other servers (no external fonts, no CDNs). The only cookie is the sign-in cookie of the community, set only when you sign in.
  • When you visit the website, our web server processes technically necessary access data (see below).

Controller

Tobias Goral, Carrer Fastenrath 176, 08032 Barcelona, Spain
Email: info@tob-apps.com

Visiting the website

When you open a page, your browser sends technically necessary data to our web server: IP address, date and time, requested address, referrer and browser identifier (user agent). This data is stored in server log files to deliver the website and keep it secure.

  • Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in secure and reliable operation)
  • Retention: 14 days, then deleted. In access logs, IP addresses are shortened before they are stored (last part removed). Error logs may contain the full IP address.
  • Hosting: The server is operated by dogado GmbH, Dortmund, Germany.

Tools on this website

Barcode generator, decoder, quality inspector, GS1 parser, ZPL viewer and all calculators work entirely in your browser. Entered data, uploaded images and camera images do not leave your device.

Camera: The barcode decoder uses the camera only after you allow it in your browser. Images are analysed locally, not stored and not transmitted.

ZPL viewer share links: The ZPL is placed in the link after the # character. Browsers do not send this part to the server. You decide whom you send the link to.

Community accounts

If you create an account in the community, we store:

  • Email address (to confirm the account and to reset the password; never shown publicly)
  • Display name and the date you joined (shown publicly)
  • Password as a salted scrypt hash, never in plain text
  • Your questions, answers, edits and reports (questions, answers and edit history are public; reports are seen only by moderators)
  • Sign-in sessions: a random token in a cookie named session (HttpOnly, Secure, only sent to /api/), valid for 30 days or until you sign out. It is technically necessary for signing in, so no consent banner is needed.

Legal basis: Art. 6 (1) (b) GDPR (providing the community you sign up for). Emails (confirmation, password reset) are sent from our own mail server. We send no newsletters.

You can download all your account data as JSON and delete your account at any time on the account page. Deleting removes your email address, password and sessions immediately; your posts remain visible as “deleted user” so that existing answers keep their context. If you also want your posts removed, contact us (see the legal notice).

Images in posts: images you add to a question or answer are stored on our server and are public like the post. Before upload your browser re-encodes them, and the server removes all metadata again (EXIF such as GPS location and camera data, text chunks, comments). They stay when you delete your account, like your posts. Images sent to the API’s decode endpoint are processed in memory and not stored.

Similar questions and suggested articles are computed on our server from the text of the questions (word overlap). No text is sent to AI or other external services.

API keys: if you create keys for the Developer API, we store each key’s name, first characters and a hash of the key (never the key itself), when it was created and last used, and the number of requests per key and day. The contents of API requests and responses are not stored or logged. Revoked keys and their counters are kept for your export until you delete your account; deleting the account revokes all keys.

Rate limits keep sign-in attempts per IP address and email address in the server’s memory for up to one hour; they are not stored.

App “Inspector Barcode”

  • Barcodes are read on the device. Camera images are not stored and not transmitted.
  • The scan history is stored only on your device. You can delete single scans or the whole history in the app at any time. Uninstalling the app deletes it as well.
  • The app needs the camera permission only for scanning.
  • Sharing only happens when you trigger it, through your device’s share function.
  • There is no account, no tracking and no analytics.

Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). Please contact the controller named above.

You can also lodge a complaint with a data protection supervisory authority, for example in your place of residence or with the Spanish data protection authority responsible for us, the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es.

Last updated

October 6, 2026