Skip to content
UseQR
ESC

Jump to

MOVEOPEN50 places

Acceptable Use Policy

Last updated 23 August 2026.

A QR code is a way to move a person from the physical world to a destination they cannot read in advance. That is exactly what makes the format useful, and exactly what makes it abusable. This policy says what must not be encoded or pointed at, and, unusually, but honestly, which parts of it we are actually able to enforce.

It forms part of the Terms of Service.

Prohibited uses

Do not use any UseQR surface to create, distribute or point at the following. The list is illustrative, not exhaustive: if it is illegal or intended to harm someone, it is prohibited whether or not it appears here.

  • Malware and hostile payloads

    Codes that download, install or trigger malware, ransomware, spyware, cryptominers or drive-by exploits, including deep links and app-store links used to deliver them.

  • Phishing and credential theft

    Codes pointing at pages that impersonate a bank, a government service, a delivery company, an employer, a wallet or any login screen in order to harvest credentials, one-time passcodes or recovery phrases. This is the single most common QR abuse there is, and it has a name: quishing.

  • Child sexual abuse material

    Any code that encodes, links to, advertises or facilitates access to CSAM. There is no threshold, no context and no appeal. Reports in this category are escalated immediately and referred to law enforcement.

  • Fraud and payment redirection

    Substituting a payment code so money reaches an account other than the one the payer intends: the sticker pasted over a merchant's UPI or PIX code, the fake parking meter, the altered invoice. Also: fake charity appeals, advance-fee fraud, and counterfeit checkout flows.

  • Harassment, threats and doxxing

    Codes used to target a person: publishing their home address or private data, delivering threats or abuse, or driving traffic to material intended to intimidate or humiliate.

  • Illegal goods and services

    Codes advertising or providing access to illegal drugs, weapons trafficking, stolen data or credentials, forged documents, or the sale of people or their labour.

  • Deception about the destination

    Deliberately disguising where a code leads in order to defeat a person's judgement: cloaking that shows a scanner one destination and a reviewer another, or masking a hostile link behind a trusted-looking domain.

  • Attacks on the service

    Using the hosted API, MCP server or image endpoints as an attack tool or amplifier: load generation, scraping designed to degrade availability, or pointing our server-side fetch at infrastructure you do not own in order to probe it.

What we can enforce, and what we cannot

Most policies of this kind imply a moderation capability the vendor does not have. We would rather be precise, because the difference changes where you should send a report.

Static generation is out of our reach, by design. When you build a QR code on this site, the encoding and rendering happen in your browser. Nothing is transmitted to us, nothing is stored, and there is no server-side record of it. We therefore cannot see what you generate, cannot review it, and cannot revoke it. On top of that, the tools work offline, so even a blocklist would be a speed bump rather than a control. This is the same architecture that keeps your WiFi password private; it is not a loophole we forgot to close.

What we host, we are responsible for, and we act on. These surfaces run on our infrastructure and are squarely in scope:

  • The keyless REST API and the MCP server, including the server-side URL fetch used by the decode endpoint and the qr_decode tool.
  • Hosted QR images served from our domain, the /q/… shortcut and the API image endpoints. Because these render from a URL, a hostile code can be made to live at a useqr.app address and borrow this domain’s reputation. That is abuse of something we run, we treat it as such, and it is worth reporting to us.
  • Any dynamic redirect feature we ship in future. When a scan passes through our servers on its way to a destination, we gain both the ability and the obligation to police that destination, and this policy will be enforced at the redirect.
  • The public repository, its issues and its discussions.

What enforcement looks like

There is no account to ban, so the remedies are narrower and more literal than elsewhere. Depending on severity we may: refuse to serve specific requests or destinations from the hosted endpoints; ask our host to block traffic; remove content from the repository; and, for the most serious categories, refer the matter to law enforcement without waiting to hear from the reporter.

We will not pretend to a takedown power we lack. If a malicious code was generated here but is hosted, printed or distributed elsewhere, the effective action is against the destination and its host, and the reporting page explains how to get there quickly.

Reporting a violation

If you have found something on a surface we run that breaks this policy, tell us. There is no ticket queue and no form that posts into a void. It is one inbox, read by one person, and you will get a reply.

How to report abuse → · Report a vulnerability → · Terms of Service →