Reputable QR code generators are safe. Real risk falls into three buckets: quishing (fake or replaced codes), untrustworthy free tools (ads, data overreach), and provider dependency (your codes dying if the vendor disappears). Most guides cover only the first two.
That third bucket is the one worth pausing on before anything else, because it's the one every major "QR code safety" article conveniently defines out of scope — and it happens to be the risk their own subscription business model creates. This guide covers all three in full, with sourced statistics, a scan-safety checklist, a generator-vetting process, and the provider-dependency argument nobody selling you a QR platform wants to finish.
What quishing is and how it actually works
"Quishing" — a portmanteau of QR and phishing — is phishing delivered via QR code instead of a link in an email or text message. An attacker places a malicious code somewhere you'll trust it: a sticker slapped directly over a legitimate code on a parking meter or restaurant table, a fake code printed on a flyer left on a windshield, a QR image embedded in a scam email pretending to be a delivery notice or a two-factor authentication prompt. Scan it, and it leads to a page built to steal credentials, card details, or personal data — sometimes a convincing clone of a real login page, sometimes a fake payment portal for a parking fine or toll that doesn't exist.
The critical thing to understand: the danger is never the QR code format itself. A QR code is a machine-readable container for a link, nothing more — the same class of object as a hyperlink or a short URL. It has no code-execution capability, no ability to install anything just by being scanned. The entire threat lives in the destination the code points to, which means quishing is fundamentally the same category of attack as email phishing or SMS phishing ("smishing"), just delivered through a different, harder-to-inspect wrapper.
That wrapper is exactly why quishing works better than the attacker's older methods, from the attacker's own point of view
- You can't read a QR code with your eyes. A suspicious URL sitting in an email —
paypaI-secure-login.ru, say — is often visibly wrong to a careful reader. The same URL hidden inside a QR pattern is completely invisible until after you've already scanned it, at which point your phone typically shows you a preview, but plenty of people tap through without reading it. - Scans overwhelmingly happen on phones, where the full destination URL is harder to inspect at a glance than on a desktop browser with a visible address bar, and where security software (ad blockers, phishing-domain blocklists, browser extensions) is often thinner or entirely absent compared to a managed work laptop.
- Physical placement borrows trust it hasn't earned. A code on what looks like official signage — a parking meter, a utility notice, a restaurant's own table tent — inherits the perceived authority of that location, even though anyone can print and stick a sticker onto a public surface in about thirty seconds.
- It bypasses email security filtering. A QR code embedded as an image inside an email routinely slips past text-based phishing filters that scan for malicious URLs in the email body, because the actual destination URL never appears as plain text anywhere the filter can read it — it's baked into pixels.
How big is the quishing threat, actually? (With sources
Quishing is genuinely growing, and it's worth citing the figures that come from named, checkable sources rather than the vague "500% increase!" style stat that circulates without attribution across marketing blogs and gets copy-pasted forward indefinitely. The following are compiled by Uniqode's security research from named third-party sources, cited here accordingly
| Statistic | Figure | Original source (as cited by Uniqode) |
|---|---|---|
| QR phishing campaign growth, 2023–2024 surge | Up to 270% per month | Microsoft |
| Share of all phishing attacks using a QR code, 2025 | ~12% | KeepNet Labs |
| Surge in malicious-QR phishing emails, Aug–Nov 2025 | More than fivefold | Kaspersky |
| QR-fraud reports in the UK, 12 months to April 2025 | ~800 reports, ~£3.5 million in losses | Action Fraud (UK) |
| QR scam cases in Australia | 28 cases, combined losses over AU$100,000 | Australian Competition and Consumer Commission (ACCC) |
| Consumers who believe QR codes are safe to scan | 58% | Uniqode's own State of QR Codes 2026 survey (vendor's first-party research, not independent) |
| Consumers willing to share data via QR code vs. marketers who disclose usage | 83% willing / only 34% of marketers disclose | Same Uniqode survey |
A word of caution on the scarier numbers circulating elsewhere on the internet — "500%+ increases," "executives 40× more likely to be targeted." Those figures show up across a number of cybersecurity-vendor blog posts and get repeated without ever naming the underlying study, dataset, or methodology behind them. That doesn't necessarily mean they're fabricated, but it does mean they can't be verified, and repeating an unattributed number as fact is exactly the kind of unverified claim this guide is trying to avoid. Treat any quishing statistic without a named institution behind it with real skepticism — the sourced figures above, tied to Microsoft, KeepNet Labs, Kaspersky, Action Fraud, and the ACCC, are a meaningfully more reliable basis for understanding the actual scale of the threat than round, dramatic numbers with no attribution.
Two other data points worth sitting with rather than skipping past: the near-even split in that Uniqode survey between how many consumers think QR codes are safe (58%) and how many are willing to hand data through one (83%) suggests most people scan first and think about trust second — which is precisely the behavioral gap quishing is designed to exploit. And the 34% disclosure figure among marketers is a separate, quieter problem this guide returns to in the privacy section below: even entirely legitimate QR code usage often isn't clearly explained to the person scanning.
Real-world quishing patterns to recognize
Beyond the raw statistics, it's worth knowing the specific shapes quishing scams tend to take, because recognizing the pattern is often faster than reading a URL character by character
- The parking/toll scam. A sticker with a fake QR code is placed directly over the legitimate payment code on a parking meter, toll notice, or municipal parking app sign. Scanning it leads to a convincing fake payment page that captures card details. This is consistently one of the most-reported quishing patterns across multiple fraud-reporting agencies, precisely because parking payment already trains people to expect "scan a code, enter a card number" as a normal flow — removing the hesitation that might otherwise catch a scam.
- The delivery-notice email. A fake "your package couldn't be delivered" or "customs fee required" email contains a QR code instead of a clickable link, specifically to slip past email security filters that scan for malicious text URLs. Scanning it leads to a phishing page mimicking a shipping carrier's login or payment portal.
- The fake two-factor prompt. A scam email or message claims a login attempt needs "verification" via QR scan, mimicking legitimate QR-based 2FA flows that some services genuinely use — exploiting the fact that scanning a code to authenticate is a real, familiar pattern for a growing number of services.
- The overlay sticker on legitimate signage. Restaurant table codes, event posters, and gym check-in codes get a fake sticker placed directly over the real one. Because the surrounding signage is genuine, the fake code inherits full visual trust from its real neighbor.
- The QR code in a physical letter or flyer. Scam letters designed to look like they're from a bank, government agency, or utility company include a QR code as the primary call to action, again specifically to route around the fact that a printed letter can't be scanned for malicious text the way an email can.
None of these patterns require any technical sophistication from the QR code itself — every one of them is a social engineering attack wearing a QR code as a delivery mechanism. That's worth remembering when evaluating any quishing-prevention advice: the fix is never a QR-specific technology fix, it's the same URL-inspection and skepticism habits that defend against any phishing attempt.
How to check if a QR code is safe to scan
| Step | What to do | Why it matters |
|---|---|---|
| 1. Preview the URL | Let your camera's preview show the link before opening it — don't tap through blind | Most quishing dies right here if you actually read the destination before opening it |
| 2. Check the domain | Confirm it matches the brand or organization you expect; watch for lookalike spellings and unfamiliar subdomains | Scammers routinely use misspelled domains or unrelated hosting that a careful glance catches |
| 3. Inspect the physical code | Look closely for a sticker placed over an original code — check for a raised edge, mismatched paper texture, or slight misalignment | Overlay stickers are the single most common real-world quishing attack pattern |
| 4. Resist urgency | Treat "scan to avoid a fine," "scan to claim your prize," or "verify immediately" language as a red flag | Manufactured urgency is the hallmark of nearly every phishing scam, QR-delivered or not |
| 5. Never enter secrets | ❌ passwords, card numbers, or personal identifiers on a page reached via an unexpected or unsolicited scan | The end goal of the overwhelming majority of quishing attacks is a credential or payment form |
| 6. Treat HTTPS as a floor, not a guarantee | A padlock icon means the connection is encrypted — it says nothing about whether the destination is trustworthy | Scam sites routinely use free HTTPS certificates; encryption and legitimacy are unrelated properties |
| 7. Use your phone's built-in link-safety features | Most modern camera apps and QR scanner apps flag known-malicious domains automatically before you open them | A free, passive layer of protection that catches known bad actors without any effort from you |
The single most protective habit on this list is step 1: a URL you actually read before opening it defuses the majority of quishing attempts on the spot, because the entire attack depends on the victim not seeing the destination before committing to it. Every other step matters, but none of them help if step 1 gets skipped.
The privacy side: what can a generator actually see?
Quishing is an attacker problem — someone hostile placing a bad code in your path. Privacy is a different question entirely: what does a legitimate QR code generator, one you're using to create your own codes, actually see and log?
When you create a code, the generator obviously sees whatever destination you point it to — that's unavoidable and true of any tool that generates a link. What's more interesting, and less understood, is what happens when someone else scans a code you've made. For a dynamic code, the provider's redirect server logs scan metadata: a timestamp, an approximate location derived from the scanning device's IP address (typically city-level, not precise GPS), and coarse device information like whether it was iOS or Android. Full mechanics of what gets tracked and how it's typically reported back to you are covered in this site's scan tracking guide. This is genuinely normal, standard analytics practice — comparable to what any link-shortening or web-analytics tool logs — and it is event-level data, not identity-level data. A QR code by itself does not capture a scanner's name, phone number, email address, or any personally identifying detail. If a landing page the code leads to then asks the visitor to fill out a form, that's the page collecting data, a decision made by whoever built that page — not something the QR code or its generator did.
Where real privacy risk concentrates is specifically in untrustworthy free tools, and the traps are consistent enough across the category to list plainly (the fuller breakdown of free vs. paid tool trade-offs generally is in free vs. paid QR code generators):
- Tools that require a credit card to activate a "free" plan. A legitimately free tool doesn't need payment details up front; requiring a card for a $0 plan is a strong signal the business model is auto-billing after a trial window most users won't notice closing.
- Tools that inject a full-screen ad on your destination page before redirecting. Some free dynamic-code generators insert their own advertising interstitial between the scan and your actual destination — meaning a customer scanning your restaurant's menu code sees someone else's ad first. This is a genuinely common practice worth checking for specifically before committing to a free platform, since it directly damages the experience you built the code to deliver.
- Tools vague or silent about what scan data they retain, for how long, and whether it's sold or shared. A reputable generator states its data practices in a findable privacy policy; a tool that doesn't publish one, or whose policy reads as boilerplate copied from elsewhere, is a signal to look elsewhere.
- Tools that quietly change ownership. A generator acquired by a different company can inherit a different (often laxer) data-handling policy without ever notifying existing users — worth checking the "about" or company page periodically for any generator you rely on for an active, in-use dynamic code.
The fix mirrors how you'd vet any piece of software handling data: use a provider with a clear, specific, findable privacy policy, and treat "free" combined with "requires a card" as an immediate yellow flag rather than a convenience.
A short vetting checklist before choosing a generator
Beyond the safety and privacy points above, a few concrete things worth checking in under five minutes before committing to any QR code generator — free or paid
- Does it require a credit card for the free tier? If yes, understand exactly when and how much it auto-bills before providing one.
- Does the privacy policy specifically mention QR scan data — not just generic website-visitor data? A policy that never mentions QR-specific data collection at all may not have thought through the question, which isn't reassuring.
- Does the company have a visible, findable "about" page and a real support contact? An anonymous tool with no identifiable company behind it is harder to hold accountable if something goes wrong, and harder to trust with an active dynamic code your printed material depends on.
- Does scanning a code you generate immediately show an ad or upsell interstitial before reaching your destination? Test this yourself with a throwaway code before committing to using the platform for a real print run.
- Is pricing and the cancellation/downgrade policy stated clearly, or does it require creating an account and entering payment details to even see what a plan costs? Opacity at this stage tends to predict opacity later.
Static vs. dynamic: genuinely different safety profiles
The two QR code types don't just differ on editability — they carry meaningfully different risk profiles, and it's worth being explicit about why. A static code has no server anywhere in the loop: nothing logs the scanner, nothing can change underneath the printed pattern, nothing can go down because there's no "up" for it to depend on in the first place. A dynamic code adds a redirect layer you don't fully control, and that one addition is what enables both dynamic's best feature (post-print editing, real scan data) and its subtlest risk category (the dependency risk covered in full below). For a security-sensitive, genuinely permanent placement — a Wi-Fi password on a wall, a vCard on a business card, a link to a page that will never move — a static code is the objectively lower-risk choice by design, not just a cheaper one.
The risk safety articles won't name: provider dependency
Here's the gap this guide exists to close. The most thorough safety content in this space — Uniqode's security guide runs roughly 4,800 words and covers quishing about as exhaustively as any single article does — defines "safe" as protection from outside attackers and stops precisely there. It never once asks the reverse question: what does its own service continuity, or a customer's lapsed subscription, mean for the QR codes that customer already printed and shipped? That omission isn't an oversight in an otherwise thorough piece — it's a structural blind spot, because that specific risk is created by the subscription business model itself, and the company selling the subscription has no commercial incentive to file its own product's failure mode under "safety."
To its credit, one competitor's blog — QR Code Generator — comes close to saying it outright. Paraphrasing their own admission: because businesses commonly print QR codes onto physical assets, a printed code can easily outlive the tool that generated it; if a generator shuts down, changes ownership, or lets its own redirect domain lapse, the codes already printed and distributed can become invalid — with consequences spanning packaging runs, event signage, printed catalogs, and direct mail campaigns already in customers' hands. That is a remarkably candid admission for a vendor in this space to publish on its own blog. But the article stops exactly there. It never asks the obvious next question, the one this guide is built to answer: which business model actually avoids this failure mode?
The answer follows the same underlying logic laid out in what happens when a QR code company shuts down: a dynamic code's survival depends entirely on a server you don't control staying online and staying paid, indefinitely, for as long as the printed material carrying that code remains in circulation. Whether the specific trigger ends up being the vendor folding outright, getting acquired and having its product line sunset, quietly letting a redirect domain expire during a rebrand, unilaterally changing its terms of service, or simply you missing a renewal notice buried in an inbox — the end result for every code affected is identical: a dead link where a working one used to be. Paying a subscription doesn't eliminate this risk category; it only changes which specific trigger is statistically most likely to eventually fire, and shifts part of the risk onto your own billing-management diligence rather than removing it. "Reliability" is a legitimate, load-bearing part of what "safe" should mean for a QR code — and it's the specific part the subscription model structurally cannot defend without undermining its own pitch.
Why this gets left out of every subscription vendor's safety content
It's worth being explicit about the incentive structure here rather than just asserting it, because the pattern is consistent enough across three separate competitors surveyed for this article that it's clearly systemic rather than coincidental. A vendor whose entire revenue model depends on recurring payment has a direct, structural disincentive to write a paragraph that says "your codes could stop working if this payment lapses, and here's what that looks like in practice." Writing that paragraph honestly would mean explaining to a prospective customer, before they've paid anything, exactly what happens to their printed material the moment they stop paying — which is not a message any subscription business volunteers unprompted. The gap isn't a matter of the security researchers at these companies missing an obvious angle; the researchers who wrote Uniqode's 4,800-word guide clearly know what they're doing across every other dimension of QR safety. It's a matter of that specific paragraph being commercially unwelcome to publish, regardless of how thorough the rest of the piece is.
What provider dependency looks like as an actual failure
Concretely, provider dependency plays out as one of a few recognizable scenarios, each worth having in mind before choosing a generator for anything printed at real volume or for a long shelf life
- The vendor shuts down entirely. The redirect server goes offline permanently. Every dynamic code that vendor ever generated stops resolving, all at once, with no warning window in most cases beyond whatever notice period the company's terms of service happened to promise (often none, for a smaller or free-tier provider).
- The vendor is acquired and the product is sunset. A common outcome for smaller QR platforms specifically — the acquiring company folds the feature into a different product or discontinues it outright, sometimes with a migration window, sometimes without one.
- The redirect domain lapses or changes. Even without the company disappearing, a domain-registration lapse or a rebrand that moves to a new short domain can silently break every previously printed code still pointing at the old domain.
- You miss a renewal. The most common trigger by volume, and the one entirely within the customer's own control to avoid or accidentally cause: an expired card on file, an unnoticed billing email, or a deliberate but forgotten cancellation, all of which can take an active dynamic code offline with no further action from the vendor at all.
- A plan downgrade or feature-gating change. Less catastrophic than a full shutdown, but still a reliability failure: a vendor restructures its tiers, and a feature or scan-volume allowance a printed campaign was depending on quietly stops being available at the price already being paid.
Every one of these is a "your printed code stopped working" outcome. None of them is a hacking, phishing, or external-attacker event — which is exactly why they don't show up in articles that define "safe" as "protected from attackers" and never widen the definition further.
Two worked scenarios, across both risk categories
Abstract categories are easier to evaluate against a real sequence of events. Here are two, chosen because they represent the two halves of "safe" this guide argues belong together but rarely get discussed side by side.
Scenario one: the overlay-sticker attack on a legitimate business's own code. A parking garage runs a static QR code on signage at every exit, linking to its own payment portal — a code they control entirely, on a domain they own. An attacker prints a near-identical sticker with a lookalike domain and applies it directly over several of the garage's real codes during a weekend when foot traffic is low and staff aren't actively monitoring the signage. Over the following two weeks, a number of customers scan what they believe is the garage's real code, land on a convincing fake payment page, and enter card details that go straight to the attacker. The garage's own code was never compromised — nothing about their QR generator, their account, or their domain was touched. The entire attack lived in the physical layer: a sticker placed over an otherwise-safe code. This is precisely why step 3 of the scan-safety checklist above (inspect the physical code for tampering) matters as much as any digital precaution, and why quishing defenses are only partly a "which generator do I use" question — physical signage needs the same kind of routine visual inspection as a payment terminal.
Scenario two: the provider-dependency failure nobody budgeted for. A regional food brand prints a dynamic QR code on 40,000 units of packaging with a two-year shelf life, linking to a recipe and nutrition page that the brand updates seasonally. The generator they used offers a mid-tier subscription, billed monthly, tied to a card on the marketing department's expense account. Fourteen months into that packaging's two-year shelf life, the company that issued that expense card changes card providers during a routine finance-system migration — an event entirely unrelated to QR codes or marketing — and the old card silently stops working. The subscription lapses without anyone on the marketing team noticing, because the lapse notification email goes to an inbox nobody checks closely during a systems migration. For the remaining months that packaging stays on shelves and in pantries, every scan of that code fails, with no obvious way for a confused customer to know why, and no way for the brand to know how many failed scans occurred, since the analytics dashboard itself is part of the now-inactive account. Nothing about this failure involved an attacker, a security flaw, or anything a "safety" audit focused on quishing would have caught — it was a pure reliability failure, of exactly the kind the previous section argues belongs inside the definition of "safe" and almost never does.
The lesson from placing these two scenarios next to each other: a QR code safety review that only asks "could an attacker exploit this" and never asks "could this simply stop working through an entirely mundane, non-malicious failure" is evaluating half the risk. Both scenarios cost the businesses involved real money and real customer trust. Only one of them would show up in a conventional quishing-focused security audit.
Common mistakes when evaluating QR code safety
- Treating "quishing-aware" and "safe" as the same thing. A business that trains staff to spot tampered stickers and phishing URLs has addressed one risk category, not all three covered in this guide — provider dependency and free-tool privacy overreach need separate attention.
- Choosing a generator based only on brand recognition, without checking its actual privacy policy or business-continuity signals. A well-known name reduces the odds of an outright scam tool, but says nothing about what happens to your codes if that company changes ownership or pricing structure.
- Repeating unattributed statistics — the "500% increase" style figures with no named source — as if they were verified facts, which spreads the same unreliable numbers further rather than relying on the sourced figures a reader can actually check.
- Assuming HTTPS alone means a destination is trustworthy. As covered above, encryption and legitimacy are unrelated properties; a scam page can have a valid padlock icon just as easily as a real one.
- Not budgeting for the provider-dependency risk at all when choosing a generator for a long print run. A code going on packaging with a multi-year shelf life deserves more scrutiny of the vendor's stability and billing structure than a code on next week's flyer — treating every use case identically under-provisions the ones that actually carry real financial exposure.
- Assuming a scan failure is always the user's fault (bad lighting, dirty lens, low battery) without checking the account or subscription status first. As scenario two above shows, a sudden, unexplained wave of scan failures is at least as likely to be a lapsed payment or an expired domain as a physical printing issue.
Reducing every layer of risk
| Risk layer | Who it targets | How to reduce it |
|---|---|---|
| Quishing | Anyone scanning a code, including your own customers | Preview URLs before opening, check domains, watch for tampered stickers, never enter secrets after an unexpected scan |
| Bad free tools | People making codes | Use a reputable generator with a clear privacy policy; avoid "free" plans that require a card or inject ads on your destination page |
| Provider dependency | Your already-printed codes | For genuinely permanent placements, use static codes; for editable codes, favor a one-time-purchase or self-hostable redirect over an open-ended subscription |
For that third layer specifically, a one-time-purchase code like OwnQR at $15 removes the missed-renewal trigger outright — there's no recurring charge to lapse in the first place — and a static code removes server dependency entirely by design. Between the two, they cover the two most reliable ways to make sure "safe" also means "still working next year," which is the exact dimension of safety the rest of the market leaves out.
What to do if you've already scanned something suspicious
If you've scanned a code and only afterward suspected it might be malicious, a short, calm sequence matters more than panic
- Close the page immediately if you haven't entered anything yet — no data has been given up at that point, and simply closing the tab ends the exposure.
- If you entered a password, change it immediately on the real site (typed manually or via a bookmark, never by scanning the same code again), and change it anywhere else you reused that same password.
- If you entered payment card details, contact your card issuer to flag the transaction and consider a replacement card — most issuers can do this in a single call and it's a low-friction, low-cost precaution relative to the risk of leaving a compromised card active.
- Report the physical code if it was on public signage — a sticker over a parking meter or public sign — to the property owner, venue, or relevant municipal authority, since a sticker attack usually keeps working on the next passer-by until someone removes it.
- Report a phishing email containing a QR code the same way you'd report any phishing email, through your email provider's built-in reporting tool — this helps that provider's filters catch the same pattern for other recipients going forward.
None of these steps are QR-specific — they're the same response playbook as any other phishing incident, because as established throughout this guide, that's fundamentally what quishing is.
Primary sources
The quishing statistics cited in this guide are drawn from named third-party institutions wherever possible, compiled via Uniqode's security research rather than lifted secondhand from unattributed vendor-blog roundups: Microsoft (QR phishing campaign growth during the 2023–2024 surge), KeepNet Labs (share of 2025 phishing attacks using QR codes), Kaspersky (the August–November 2025 surge in malicious-QR phishing emails), the UK's Action Fraud (national QR-fraud reporting figures), and Australia's ACCC (Australian QR scam case data). Two additional figures — the 58% "QR codes feel safe" statistic and the 83%/34% data-sharing gap — come from Uniqode's own State of QR Codes 2026 survey, labeled here as first-party vendor research rather than independent third-party data, since Uniqode both commissioned that survey and sells a QR platform. Statistics from BitLyft's quishing content, circulating figures like "500%+ increase" and "40× more likely," were deliberately excluded from this guide because BitLyft's own article does not name the underlying study or institution behind them — a pattern worth watching for generally in this content category, where dramatic unattributed numbers spread faster than the sourced ones.
The bottom line
QR code generators are safe when you pick a reputable one and scan with basic caution: quishing is a destination problem, solved by checking links and watching for tampered physical codes; privacy overreach is a bad-tool problem, solved by avoiding shady free generators that demand a card or inject ads. But "safe" should also mean reliable, and that's precisely where the standard industry advice goes quiet — your dynamic codes are only as durable as a server staying online, staying paid, and staying under a vendor that doesn't fold, get acquired, or change terms out from under you. Extend your own definition of safety to include provider dependency, the way the vendors selling you the subscription conspicuously don't, and choose accordingly: static for anything genuinely permanent, or a one-time purchase to remove the renewal cliff on anything that needs to stay editable.
Frequently asked questions
Are QR code generators safe to use?
Reputable generators are safe. The risks are quishing (attackers faking or replacing your codes), untrustworthy free tools that inject ads or auto-bill, and provider dependency — dynamic codes stop working if the vendor disappears or your subscription lapses. Pick a trusted tool and, for permanent print, prefer static codes or a one-time purchase.
What is quishing?
Quishing is QR-code phishing. An attacker places a malicious code — a fake sticker over a real one, or a code in a scam email — that leads to a page built to steal credentials or payment details. The risk is the destination the code points to, not the QR format itself.
How do I check if a QR code is safe to scan?
Preview the URL before opening it, confirm the domain matches the brand you expect, look for stickers placed over original codes, be suspicious of urgency, and never enter passwords or payment details on a page you reached only through an unexpected QR code.
Can a QR code give me a virus?
Scanning itself won't install anything — it opens a link. The danger is what that link leads to: a phishing page, a malicious download, or a scam form. Treat a QR destination exactly as cautiously as any link from an unknown source.
Is it safe to make my own QR codes?
Yes, with a reputable generator. Beyond avoiding shady free tools, the main thing to plan for is reliability: dynamic codes depend on the provider's servers, so for anything printed long-term, use a static code or a one-time-purchase provider to avoid codes dying on a lapsed subscription.
Do QR code generators collect my data?
When people scan a dynamic code, the provider logs scan metadata — time, approximate location, device type — which is normal and not identity-level. Real privacy overreach comes from untrustworthy free tools that inject ads or demand payment details, not from scan analytics themselves.