Legal · Updated October 11, 2026

Privacy policy

What Kifuna collects when you use it, visit the site or scan a code, why, who else handles it and how long it's kept.

The short version

Selling
We don't sell personal information.
Scans
Counted by hour, device and rough place. We never record the IP address of someone who scans a code.
The site
One cookie of our own with a random ID. On our public pages and sign-up steps, Google's ad tag, and Microsoft Clarity, which records how you use them but never what you type or your account's details. Global Privacy Control turns both off.
Ads
Our ad reporting service learns how you found us and, once you have an account, your email address. When you start a plan, it and Google's ad tag tell Google Ads when and how much, with the ad click and a scrambled form of your email. Global Privacy Control turns that off.
Your data
Download it, or delete your account, from your Account page at any time.

Who we are

Kifuna LLC (“Kifuna”, “we” or “us”) runs kifuna.com and the kifu.to short links in Kifuna's QR codes. This policy covers the people who use Kifuna, the people who visit kifuna.com, and the people who scan a Kifuna code or report one. Questions go to [email protected].

What we collect, and why

Your account

Your email address; your password, stored only as a one-way hash we can't read; your Apple or Google account ID if you sign in with them; when you confirmed your email; and an email change you haven't confirmed yet. For each browser you sign in on, we keep the IP address and browser details it signed in from. We use these to run your account and keep it secure, and to email you about your account, codes and payments. We don't send marketing email.

Your codes

What each code opens (a web address, a PDF, contact-card details, a Wi-Fi network's name and password, or text), its design and name, its short link and its history of changes. We use them to make, publish and keep your codes working. Contact cards and PDFs are shown to anyone who scans the code.

To keep scanners safe, we send every web address a code opens, including a contact card's website and the links in a PDF, to Google Web Risk, which checks it against Google's lists of dangerous sites, and our link checker visits it. We check PDFs for scripts and attached files, and Amazon Web Services scans them for malware, before anyone can open them.

Payments

Stripe takes your card or wallet details, and we never see your full card number. We keep Stripe's references for your customer record and plan, the amount and date of each payment and refund, your receipts, and a description of the payment method such as “Visa ending in 4242, expires 12/2030”. We use them for billing, receipts and our accounts.

When someone scans a code

For each code with a short link, we count scans in hourly totals by what the scanner got (the page, the “isn't active” page or the safety warning), the code's version, the kind of device (phone, tablet, computer or other), the operating system family (such as iOS or Android) and the rough country, region and city that Cloudflare estimates from the network address. We never store the IP address, the browser's details, cookies or anything else that tells one person from another, so the counts are of scans, not people. Requests we recognize as bots aren't counted. Each scan carries a random ID, which we keep for 31 days so it's never counted twice. The counts are shown to the code's owner.

When you visit kifuna.com

A cookie of ours holds a random ID for your browser. With it we keep the version of the site's design you were shown, your kind of device (worked out from your browser's details, which we don't store) and whether your browser sends Global Privacy Control. When you arrive from another site or an ad, we note the Google click ID, the campaign tags and the ad's campaign, ad group, keyword and device type in the address, the page you landed on, the name of the site you came from (never its full address) and the time. We also note the steps you reach: landing, designing a code, creating an account, checkout and paying. We use these to learn which ads lead to paying customers, where people leave the sign-up steps and how designs compare. If you create an account or sign in, they become part of your account.

Google's ad tag

Our home page, the pages about what codes are for, help, pricing, these policies, the designer, the account step and checkout load Google's ad tag. It keeps the Google ad click that brought you in cookies on kifuna.com, so Google Ads can tell which clicks lead to purchases. When you first pay for a plan, the page after checkout uses it to tell Google Ads the order's reference and value, once, with a scrambled (hashed) form of your email address that Google can match to its own users. We scramble it before the page sends it, so your address itself never reaches the tag. Like anything loaded from Google, the tag sends Google the page's address, the address you came from, your IP address and browser details, and Google's own cookies, which Google handles under its privacy policy. We've turned off ad personalization for it, so our pages don't add you to Google's advertising audiences. It never loads on kifu.to or any page a scanner sees, on your account's own pages other than the one after your first payment, for bots, or if your browser sends Global Privacy Control or you've opted out.

Microsoft Clarity

The same pages as Google's ad tag load Microsoft Clarity, which records how people use them so we can see where our pages confuse people or get in their way: the pages you visit and how you move between them, where you click, tap and scroll, how your mouse moves, how long pages take to load and any errors they hit, replayed as recordings and summed up as heatmaps. It also sends the version of the site's design you were shown, and when you reach each sign-up step: designing a code, creating an account, checkout and your first payment, which the page after it reports. Clarity hides everything you type and everything about your account before it leaves your browser: email addresses, passwords, what your codes open and how they look, your payment details (which are in Stripe's own fields, out of Clarity's reach) and the messages we show you. It doesn't get your account or a name for you. Like anything loaded from Microsoft, it sends Microsoft the page's address, including the ad click ID and campaign tags it may carry, the address you came from, your IP address and browser and device details, and Microsoft's own cookies. Microsoft uses this data under the Microsoft Privacy Statement, which allows its own purposes, including advertising. Clarity never loads on kifu.to or any page a scanner sees, on your account's own pages other than the one after your first payment, for bots, or if your browser sends Global Privacy Control or you've opted out.

Our ad reporting service, and the orders it tells Google Ads about

We send our ad reporting service each landing and step above as it happens: a number it knows your browser or account by (not our cookie's ID), the click ID, campaign tags and ad details from the address, the design version you saw, and, once you have an account, your email address. No IP address and no browser details go with them. It compares them with what our ads cost, and with your plan, payments and refunds, which it reads from our Stripe records.

When you start a plan, it tells Google Ads, so Google can measure and improve our ads: the click ID of an ad you clicked in the 90 days before and a scrambled (hashed) form of your email address that Google can match to its own users, whichever it has, with when you paid, the value we put on the order and its reference. Google's ad tag may report the same order from your browser, as above, and Google counts it once. Renewals aren't sent. If your browser sends Global Privacy Control, we don't give it your click IDs or email address from then on, so it has nothing to tell Google with.

Reports, reviews and messages

Running the service

Cookies

Ours are:

kifuna_visitor
The random ID for your browser described above, for 395 days, never extended.
session_id
Keeps you signed in on that browser until you sign out.
_kifuna_session
Protects forms from forgery and holds the code you're designing before you have an account. It ends when you close your browser.
time_zone
Your browser's time zone name, such as America/Chicago, so scans are counted in your days, for 1 year.

Where Google's ad tag loads, it sets cookies whose names begin _gcl_, such as _gcl_au and _gcl_aw, on kifuna.com for 90 days, to keep the ad click that brought you. Where Microsoft Clarity loads, it sets _clck, a random ID for your browser, for 1 year, and _clsk, which joins one visit's pages, for 1 day, on kifuna.com, and Microsoft may set its own on clarity.ms, such as MUID. Stripe sets its own cookies on the checkout and payment-method pages, to prevent fraud. Cloudflare, which protects kifuna.com, may set its own to tell people from bots.

Who else handles it

These companies run parts of Kifuna for us and get only what their part needs:

Amazon Web Services
Hosting, the database, file storage, malware scanning of PDFs and sending email, in the United States
Cloudflare
kifuna.com's network and bot protection; the kifu.to short links, contact cards and PDFs that scanners open; and counting scans
Stripe
Payments
Google
Web Risk safety checks, Google Ads conversions and its ad tag, Sign in with Google if you use it, and our support email
Apple
Sign in with Apple, if you use it
Microsoft
Clarity, which records how people use our public pages and sign-up steps, described above
Sentry
Error reports, with personal information removed, and our server logs
Our ad reporting service
Compares ad spending with visits and orders, and tells Google Ads about new orders. It gets the visits, steps and email address described above, and reads our Stripe records of your plan, payments and refunds

Google uses the conversions it's sent under its own terms, to measure and improve our ads. Otherwise we share personal information only when the law requires it, to protect people from harm or to enforce our terms, and with a company that takes over Kifuna, which must keep this policy's promises.

Selling and sharing

We don't sell personal information, and we never have. Telling Google Ads about an order, Google's ad tag on our pages and Microsoft Clarity, whose data Microsoft may use for advertising, may count as “sharing” for advertising under California law. To opt out, turn on Global Privacy Control in your browser: we treat it as a request to opt out for that browser and your account. From then on we don't give our ad reporting service your click IDs or email address, so it can't tell Google about your orders, and our pages stop loading Google's ad tag and Microsoft Clarity for them. You can also ask us at [email protected]. A click ID or email address the service received before you opted out stays with it, and it may still use one for a later order. A conversion Google already has stays in Google Ads.

How long we keep it

Your account
While it exists. A browser's sign-in record goes when you sign out there, change your password or delete the account.
Your codes
While your account exists, and for 12 months after your codes stop, then deleted. Each short link stays reserved for good, holding only its last status, so no one else ever gets it.
PDFs
A code's current PDF, the one before it and the live one, deleted with the code. A PDF that fails our checks is kept 30 days. Deleted files can be recovered from storage for 30 days.
Designs never saved
A code designed without an account is deleted after 30 days if no account claims it.
Scan counts
2 years, or sooner with the code or the account. Scans waiting to be counted, up to 14 days.
Visits
Not tied to an account: 395 days. Tied to one: while it exists. Deleting the account deletes its landings and ad click IDs at once; its steps are kept without it, for totals, until they're 395 days old.
Ad reporting
Landings and steps wait for our ad reporting service only until it takes them, usually seconds, and deleting your account first drops them. What it has received, including click IDs and your email address, it keeps with no end date, and deleting your account doesn't delete it.
Clarity
Microsoft keeps Clarity's recordings 30 days, and its click and heatmap data 9 months; a recording we mark to keep stays as long as its click data.
Payment records
After you delete your account, we keep a record of each charge and refund (the amount, date and Stripe's references, without your name or email) for our accounts and taxes. Stripe keeps its own records under its privacy policy.
Reports
The scrambled network address 7 days; the details and the reporter's email 90 days; the rest, and the safety record of actions on codes, 2 years. Evidence for a legal review is kept until the review ends.
Contact messages
The message, email address, code and check results 90 days; the rest 2 years. The email in our support inbox stays as long as we need it to help you and keep our records.
Fair-use counters
As long as the limit's window, 1 day at most.
Server logs
30 days.
Backups
Deleted data can stay in database backups for up to 14 days.

Your choices and rights

For California residents

California law gives you the rights above: to know what we collect and how we use and disclose it, to delete it, to correct it, to opt out of its sale or sharing, and not to be treated differently for using them. In the last year we collected:

Identifiers
Email address, Apple or Google account ID, the IP address of each sign-in, cookie IDs and ad click IDs
Commercial information
Your plan, payments and refunds
Internet activity
The pages you landed on, the site you came from and the steps you reached; through Google's ad tag, the pages it loads on; and through Microsoft Clarity, how you use them
Approximate location
The rough place of each scan, counted for the code's owner and never tied to a person
Your content
What your codes open, and messages you send us
Sensitive information
Your account's sign-in details, used only to sign you in

They come from you, your browser, Stripe, Apple, Google and Cloudflare, for the purposes above. We disclose them to the companies in Who else handles it, for those purposes. Our ad reporting service shares click IDs and a hashed email address, with the values we put on orders, with Google for advertising, Google's ad tag shares the pages it loads on and, with your first order, a hashed email address, and Microsoft Clarity shares how you use the pages it loads on, as Selling and sharing describes. We sell none of them.

Children

Kifuna is for businesses and adults. We don't knowingly collect personal information from anyone under 16. If you think a child has given us some, write to us and we'll delete it.

Security and where data is kept

Every connection uses HTTPS. Passwords are stored only as one-way hashes, uploaded files in private, encrypted storage, and card details only at Stripe. Only the people who run Kifuna can reach the systems. Kifuna is for customers in the United States, and our data is stored there; Cloudflare handles requests in its data centers around the world. If a breach affects your information, we'll tell you as the law requires.

Changes to this policy

We'll post any change here with its date, and email account holders at least 30 days before a change that matters takes effect.