Trust center

Security, privacy and reliability

A public summary of current security controls, data handling, operating limits, legal documents and third-party service roles.

Security controls

  • Private R2 objects delivered by short-lived signed URLs
  • HttpOnly Cookie + BFF trust boundary for production sessions
  • Creem webhook signature verification and idempotent entitlement grants
  • Automated multi-decoder scan validation at original and the selected validation size before delivery
  • Blind watermarking for traceability before delivery validation
  • Feedback form anti-abuse throttling and operator audit records

Privacy controls

  • Trial QR payload points to Magic QR Studio; formal payload is locked until unlock
  • Formal payloads are encrypted at rest when stored internally
  • Purchase-consent records keep the legal version, accepted wording, timestamp, IP/location when available and a hashed user agent
  • Retention cleanup removes expired works and time-limited operational records; billing, refund, dispute and legal evidence is retained only as needed

Operating limits

Compliance documents

Service providers, independent controllers and optional integrations

This list reflects the current project architecture. Optional services operate only when enabled in deployment configuration.

Contact Support

[email protected]