LEGAL · PRIVACY

Privacy, without the fine-print fog.

This policy explains what Mosaqo handles, why it is needed and what stays entirely on your device.

Effective July 27, 2026Applies to Mosaqo services and the Chrome extension

CHROME EXTENSION

Your QR content stays in your browser.

The Mosaqo Chrome extension creates and scans QR codes on-device. It has no account requirement, makes no API calls to Mosaqo, uploads no page screenshots or QR content, and runs no remotely hosted code.

01

Scope

This Privacy Policy applies to the Mosaqo website, web and mobile applications, hosted QR experiences and the Mosaqo Chrome extension (together, the “Services”). It does not cover third-party websites or services that you choose to open from a QR code or through an external link.

02

Information we handle

Information you provide to Mosaqo services

  • Account information received from a sign-in provider, such as your name, email address and provider account identifier.
  • Workspace content you choose to save, including QR destinations, contact-card fields, designs, logos, images, templates and collaboration content.
  • Messages and information you send when requesting support.

Service and scan information

  • Security and session information needed to authenticate requests and protect your account.
  • For dynamic QR codes, scan events may include time, broad device/browser category, referring context and approximate region. Raw IP addresses are not retained as scan analytics; privacy-safe network identifiers may be used to estimate unique scans.
  • Essential operational logs used to maintain reliability, investigate errors and prevent abuse.

03

Chrome extension data

The extension handles data only to provide the QR feature you request. Depending on what you choose to create or scan, this can include the active tab URL and title, visible page content, a selected image, plain text, Wi-Fi network details, vCard fields, styling preferences and a logo you select.

QR generation and decoding happen locally. A visible-page screenshot used for scanning is held only in memory for the scan and is discarded afterwards. Drafts, settings and the optional last 10 recent codes are stored in chrome.storage.local. You can clear this data from Mosaqo settings, and Chrome removes it when the extension is uninstalled.

The extension does not sell data, use data for advertising, track browsing in the background or allow Mosaqo staff or third parties to read locally processed content.

04

Why the extension requests permissions

activeTab

Temporarily reads the active tab URL, title and favicon when you invoke Mosaqo, and captures the visible tab only when you request QR scanning.

storage

Keeps your draft, visual settings, optional recent-code history and temporary context-menu payloads in chrome.storage.local on your device.

contextMenus

Adds right-click actions that you can choose to scan an image, make a QR code for an image URL or open the side panel.

scripting

Injects Mosaqo’s bundled scanner only after you explicitly choose to read a QR code from an image on the active page.

sidePanel

Displays the Mosaqo editor beside the current page after a user-initiated command.

05

How information is used

  • Provide, personalize and maintain the features you choose to use.
  • Create and manage QR codes, workspaces, exports and dynamic redirects.
  • Measure dynamic QR performance according to workspace privacy settings.
  • Authenticate users, secure sessions, prevent abuse and troubleshoot errors.
  • Respond to support, privacy and account requests.

We do not sell personal data and do not use Mosaqo data for personalized advertising, credit scoring or purposes unrelated to the Services’ user-facing functionality.

06

When information is shared

We share information only when needed to operate the Services: with infrastructure, authentication and email providers acting on our instructions; with members of a workspace when you choose to collaborate; to comply with law or protect users and the Services; or as part of a business transaction subject to appropriate safeguards.

We do not transfer data handled by the Chrome extension because that extension data remains local. Mosaqo’s use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

07

Retention and security

We keep account and workspace information while your account or workspace remains active and as needed to provide the Services, meet legal obligations and resolve disputes. Scan analytics follow the workspace’s configured retention period. Account and workspace deletion requests may use a 30-day recovery period before permanent deletion.

We use access controls, modern encrypted transport, data minimization and operational safeguards designed to protect information. No storage or transmission method can be guaranteed completely secure.

08

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict or export your personal data, and to object to or withdraw consent for certain processing. Workspace settings let you manage analytics retention, and extension settings let you clear local history and drafts.

To exercise a privacy right, email hello@mosaqo.app. We may need to verify your identity before completing a request.

09

Children and international use

Mosaqo is not directed to children under 13, and we do not knowingly collect their personal information. The Services may be operated from or supported in countries other than your own; where required, we use appropriate safeguards for international data transfers.

10

Changes to this policy

We may update this policy as Mosaqo evolves or legal requirements change. We will publish the revised version here and update the effective date. Material changes will be communicated through the Services when appropriate.

11

Contact us

Questions about this policy or Mosaqo’s data practices can be sent to hello@mosaqo.app.

Contact Mosaqo