Cookies
Effective 2026-10-04. There are two, both strictly necessary.
What we set
| Cookie | Purpose | Lifetime | Type |
|---|---|---|---|
smp_session |
Keeps you signed in. Contains an opaque token; we store only its hash. HttpOnly, so JavaScript cannot read it. | 30 days, extended as you use the site | Strictly necessary |
smp_csrf |
Protects your account from cross-site request forgery, by letting the app prove a request came from a page we served. | 30 days | Strictly necessary |
Why there is no cookie banner
Both cookies are strictly necessary to provide a service you have asked for, which is the one category that does not require consent under the ePrivacy Directive or the GDPR. We set no advertising, analytics or third-party cookies, so there is nothing to consent to and a banner would be theatre.
Local storage
We store one preference in your browser's local storage: your light or dark theme choice. It never leaves your device and is not sent to us.
When you scan a code
Scanning a ScanMePlz code sets no cookies at all. The redirect is stateless. See the privacy policy for what is recorded.
Website analytics
We use Cloudflare Web Analytics, which is cookieless and does not fingerprint visitors. It gives us page view counts and referrers in aggregate, and nothing that identifies a person.
How to remove them
Both cookies can be cleared from your browser's site-data settings at any time. The only effect is that you will be signed out and will need to sign in again. Nothing about your account, your codes or your scan history lives in a cookie, so clearing them loses nothing.
If you block cookies entirely for this site, the free generator and every marketing page still work normally — those need no cookies at all. Signing in will not work, because a session cookie is how a browser proves it is signed in.
What we will never add
We are committing here, not just describing today: no advertising cookies, no cross-site tracking pixels, no third-party analytics that fingerprint visitors, and no sale or sharing of behavioural data. If that ever changed it would require a consent banner, which is itself a reasonable signal to watch for.
The reason is not purely principle. A QR platform sits between a business and the people who scan its codes, which is an unusually sensitive position — those people never chose to interact with us. Collecting as little as possible is the only defensible way to occupy it. The privacy policy sets out exactly what a scan records.