This Privacy Policy explains how Forge ("Forge", "we", "our", or "the app"), developed by Obelisk Agency, handles your information. Forge is a QR and barcode generator for small businesses; everything you create stays on your device. We are committed to protecting your privacy and ensuring transparency about our data practices.
1. What We Don't Do
No first-party servers. We do not operate any backend that stores your codes, products, or labels.
No cloud-stored user data. Everything you create lives on your device.
No user accounts. Forge has no sign-up, no login, no profile.
No behavioural analytics. We do not track which buttons you tap, which features you use, or how often you open the app.
No code expiry. Codes you generate work forever, they do not route through any domain we control.
2. Data Collection
The app stores the following data locally on your device in a private SQLite database:
- The codes you generate, including their content, format, customization style, and any name, category, tag, or note you attach
- Your product catalog entries (name, optional SKU, GTIN, price, photo URI, description)
- Bulk-import job history (file name, row counts, success/skip results)
- App preferences such as theme, palette, font family, font scale, language, accessibility settings, and SKU prefix
3. Data Storage
All data is stored exclusively on your device. We do not have access to your data, and it never leaves your device unless you explicitly choose to:
- Share an exported code, label, or sheet through your device's sharing features
- Back up your data to Google Drive (requires your explicit authorization)
- Export your data to a local file on your device (PNG, SVG, PDF, or backup JSON)
- Print a label or sheet via the Android print framework or a connected printer
4. Network Requests
Forge generates and renders codes entirely offline. The app may make network requests in the following optional scenarios:
- Malware/phishing blocklist updates: The app periodically downloads an updated URL blocklist (shared with our sibling QR scanner app) so the URL form can warn you before you encode a known-malicious link.
- Google Drive backup: If you choose to back up your data, the backup file is uploaded to your personal Google Drive account. This requires your explicit sign-in and authorization.
- Advertising: The free version loads banner and interstitial advertisements via Google AdMob. See section 5 below.
- Crash reporting: Anonymous crash reports are sent to Firebase Crashlytics (opt-out, see section 7).
- Consent management: In the European Economic Area, the app uses Google's User Messaging Platform (UMP) to obtain and manage your advertising consent.
5. Third-Party Services
The app integrates the following third-party services:
- Google AdMob: The free version displays banner advertisements on the My Codes, Settings, and Catalog screens, plus occasional interstitials after you export. We never show ads in the create or edit flow. AdMob may collect device identifiers and usage data according to Google's Privacy Policy. Purchasing the "Remove Ads" upgrade removes all advertisements.
- Google User Messaging Platform (UMP): Used in the European Economic Area to obtain GDPR-compliant consent for personalized vs non-personalized advertising. You can re-open the consent form at any time from Settings → Privacy → Manage consent.
- Google Play Billing: Processes the one-time "Remove Ads" in-app purchase. We do not have access to your payment information.
- Google Sign-In: Used only when you choose to back up to Google Drive. We access your email address for display purposes and your Drive storage solely for the backup file.
- Firebase Crashlytics: Anonymous crash reports help us fix bugs. No personally identifiable information is collected. See section 7 for opt-out details. We do not use Firebase Analytics or any other behavioural analytics SDK.
6. Photo Access
Forge uses Android's system Photo Picker to let you optionally pick images for two features:
- Logo overlay: When customizing a QR code, you can pick an image to overlay at the centre. The picker hands the app a URI to that single image; we never read your full photo library and we do not request the
READ_MEDIA_IMAGESor storage permissions. - Product photos: When adding a product to your catalog, you can attach a product image the same way.
The picked image URI is persisted via Android's takePersistableUriPermission so your logo or product photo survives across app launches. The image bytes are never uploaded anywhere.
7. Crash Reporting Opt-Out
Crashlytics is on by default but can be turned off.
Settings → Privacy → "Send crash reports" toggles all crash reporting. When off, no crash data is collected or sent for the rest of the install.
8. Cross-App Integration
Forge is designed to work alongside our sibling app QR Code: Scanner & Validator. Two integrations are possible:
- "Test in Scanner": An export option that opens a generated code directly in the scanner app (when installed) so you can verify it scans correctly. The handoff happens through an Android intent on your device, no servers involved.
- Shared Drive backup format: Backups created by either app can be restored by the other. The format is documented and stored only on your Drive.
9. Bulk CSV Import
The bulk-import feature reads a CSV file you select from your device storage. The file is parsed locally; no row of your CSV is ever uploaded to any server we control.
10. Children's Privacy
The app is not directed at children under 13. We do not knowingly collect personal information from children.
11. Your Rights
Access: All your data is stored locally and accessible to you at any time through the app.
Delete: You can delete individual codes, categories, products, or bulk-import jobs, or clear all data via Settings → Privacy → Clear all data.
Export: You can export your data using the backup feature in Settings.
Opt out of crash reports: Settings → Privacy → "Send crash reports".
Manage advertising consent: Settings → Privacy → "Manage consent" (EEA only).
Opt out of ads: Purchase "Remove Ads" to remove all third-party advertising.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be reflected by updating the "Last updated" date. Continued use of the app after changes constitutes acceptance of the updated policy.