Privacy Policy
Last updated: September 4, 2026
WatchBar is built to keep your data yours — no account, no ads, no analytics, and we never sell your data. This one policy covers WatchBar on iPhone, iPad, and Apple Watch (from the App Store) and WatchBar for Android and Wear OS (from Google Play). Where the two platforms behave differently, it says so. The Wear OS companion is not part of the first Google Play release; this policy already describes it, so nothing changes when it ships.
Who we are
WatchBar is developed and published by WatchBar (Peebles Family), which is the data controller for any personal data described in this policy. You can reach us at [email protected].
At a glance
| What | iPhone, iPad & Apple Watch | Android & Wear OS |
|---|---|---|
| Barcodes, history, folders, tags, notes | Stored on your device. | Stored on your device. |
| Cloud sync | Your own private iCloud (CloudKit). On by default; switch it off in Settings. | None. Nothing is uploaded anywhere. |
| Watch sync | iPhone ↔ Apple Watch over Apple’s WatchConnectivity, device to device. | Phone ↔ Wear OS over the Wearable Data Layer (Bluetooth via Google Play services), device to device. |
| Backups | Included in your normal encrypted iOS and iCloud backups. | Not backed up automatically. Use Export to keep a copy you control. |
| Crash reports | Firebase Crashlytics, anonymous. | Firebase Crashlytics on the phone app only, anonymous. The Wear OS app sends nothing. |
| Location | Optional (“Save Location”). Stored with a code, stays in your library. | Optional (“Save Location”), approximate only. Stored with a code on your phone and, if you pair a watch, on your watch. |
| Account, ads, analytics, tracking | None. | None. |
What WatchBar stores
Everything you create while using WatchBar is kept on your device. That includes:
- The barcodes you save, with their names, notes, folders, and tags
- Your generation and scan history
- PLU lookups and quiz scores
- When you scan a picture from your photo library, a small downscaled copy of that picture, attached to that one history entry
- If Save Location is on, the approximate place where a code was generated or scanned
- Your settings
Sync and backup
iPhone, iPad and Apple Watch
If iCloud sync is enabled — it’s on by default, and you can turn it off in Settings — your library syncs through Apple’s CloudKit into your own private iCloud account, so it appears across your devices. This uses Apple’s servers and is tied to your Apple ID. The developer cannot read your private iCloud database, and there is no separate WatchBar account or login. Your iPhone and Apple Watch also exchange data directly with each other through Apple’s WatchConnectivity framework.
Android and Wear OS
WatchBar for Android has no cloud sync. Your barcodes, folders, tags, and history exist only on your phone and are never uploaded automatically. The phone app and the Wear OS app keep each other in sync over the Wearable Data Layer, which Google Play services carries between your paired phone and watch. That traffic never touches a WatchBar server, because there isn’t one. The Android app also opts out of Android’s automatic backup, so if you want to move your library to a new device or keep a backup, use Export in Settings and then Import the file on the other device.
Crash reporting & diagnostics
The iPhone app and the Android phone app include Firebase Crashlytics, a Google service, to help fix crashes. The Wear OS app does not include it and sends nothing. When the app stops unexpectedly, Crashlytics sends Google a report containing the crash stack trace, your device model, your operating system version, and a random Firebase installation identifier. The same SDK also sends a small session record on every launch — app version, device make and model, and that a session started. None of it contains your name, your barcodes, your history, your location, anything you typed, or an advertising identifier, and none of it is tied to any account.
This is classified as “Diagnostics” or “Crash logs” data. There is currently no in-app switch to turn it off; uninstalling the app stops all future reports, and you can ask us to delete existing ones by email. Firebase’s analytics SDK is not included in any version you can install. You can read more in Google’s privacy policy.
Camera & scanning
The camera is used only while you are scanning. Frames are decoded in memory on your device and are never uploaded or saved. When you drive the phone camera as a remote scanner from your watch, downscaled preview frames stream from your phone to your own paired watch over Bluetooth, and nowhere else. Scanning a barcode from an existing picture is processed on your device too: on Android, WatchBar uses the system photo picker, so it never gains access to your photo library — only to the single picture you choose — and it keeps a downscaled copy of that picture with the resulting history entry until you delete that entry. That copy can travel to your paired Wear OS watch as part of sync, and to nothing else.
Location
WatchBar can remember where a code was generated or scanned so you can find codes tied to a place later — on iPhone that powers the Map and Nearby views. This is the Save Location switch under Location Tracking in Settings. It is on by default and you can turn it off at any time; the app only asks the system for location when it is on. On Android, WatchBar requests approximate location only. The location is stored with the barcode on your device and is deleted when you delete the barcode. It is never sent to us. It does travel with the rest of your library to your own other devices: through your private iCloud on Apple devices if sync is on, and to your paired Wear OS watch on Android.
Network use
The apps make network requests only for the following:
- iCloud sync (iPhone, iPad, Apple Watch), as described above.
- Crash diagnostics (iPhone and Android phone), as described above.
- Retailer product links (both platforms). When you scan a Walmart product QR code or short link, the app fetches that product page over HTTPS to read the product’s UPC and saves the UPC instead of the link. Only the link you scanned is sent, only to the retailer that issued it, and only at that moment — no account, identifier, or location goes with it, and the page is discarded immediately. The retailer sees the request the same way it would see you opening the link in a browser. On Android you can turn this off in Settings under “Look Up Product Codes”.
- QR Weight (both platforms). Before generating a QR Weight code, the app makes a single HTTPS request to the store location host you configured in Settings, purely to check that it is reachable. No account, identifier, or device location is attached, and if you never generate a QR Weight code the request never happens.
- App Store update information (iPhone and iPad).
The apps do not otherwise transmit your data.
Locked codes & biometrics
You can lock individual codes behind Face ID or Touch ID on Apple devices, or behind fingerprint, face unlock, or your device PIN on Android. Authentication is handled entirely by the operating system; WatchBar only learns whether it succeeded and never sees, collects, or stores biometric data.
Android permissions
These are the permissions WatchBar for Android asks for, and why:
| Permission | Used for |
|---|---|
| Camera | Live barcode scanning. Frames are decoded in memory and never stored or sent. |
| Approximate location | The optional Save Location setting, which stores where a code was generated or scanned alongside it. Coarse location only; WatchBar never asks for precise location. |
| Biometrics | Unlocking codes you have locked, through Android’s own biometric prompt. WatchBar only receives a yes-or-no result, never your fingerprint or face data. |
| Change Wi-Fi state | The “Connect” action on a scanned Wi-Fi QR code, which hands the network to Android’s Wi-Fi suggestion API. No data is collected. |
| Internet | The three requests listed under Network use: crash reports, the retailer product-link lookup, and the QR Weight reachability check. There is no WatchBar server. |
| Boot completed, network state, wake lock, foreground service | Keep the QR-Time widget ticking after a restart, run bulk-generation jobs, and stream the remote scanner to your watch. These grant no access to your data. |
The Wear OS app asks only for biometrics, to unlock locked codes. It has no camera, location, or internet permission.
Your controls
- Export your data as JSON, XML, plain text, or CSV at any time.
- Delete individual items, or wipe everything — on Apple devices, including your iCloud copy.
- Turn Save Location off, and on Android turn off Look Up Product Codes, in Settings. QR Weight only makes its check if you have configured a store location.
- Lock individual barcodes behind biometrics.
- Uninstalling the Android app removes everything it stored; there is no copy anywhere else.
Retention & deletion
Your data stays on your device until you delete it. Deleting a code also deletes its notes, image, and any saved location. Uninstalling removes the local copy; on Apple devices your iCloud copy remains until you delete it in the app or turn off iCloud for WatchBar. Crash reports are kept by Firebase for roughly 90 days. To have crash reports deleted sooner, or for any other deletion request, email [email protected] and we will act within 30 days.
Third-party services & components
- Apple iCloud (CloudKit) and WatchConnectivity — sync on Apple devices, governed by Apple’s privacy policy.
- Google Firebase Crashlytics — crash reports on iPhone and Android phone, governed by Google’s privacy policy.
- Google Play services — on Android, the location provider behind Save Location and the Wearable Data Layer behind watch sync. Both run on your devices.
- Zint and zxing-cpp — open-source libraries that generate and decode barcodes entirely on your device.
No advertising or tracking
WatchBar has no ads, no advertising identifier, no analytics, and no cross-app tracking. We don’t work with data brokers, and we never sell or share your personal data for advertising.
Children’s privacy
WatchBar is not directed to children under 13 and does not knowingly collect their personal information. If you believe a child has provided us with data, contact us and we will delete it.
Security
Data on your device is protected by iOS or Android. Data in iCloud is protected by Apple’s account security, and crash reports travel to Google over HTTPS. Sensitive codes can be locked behind biometrics. Because your data lives on your device, your device passcode and screen lock matter too.
Your rights
Depending on where you live — including the EU and UK (GDPR), California (CCPA/CPRA), Canada (PIPEDA), and Australia — you may have the right to access, correct, delete, or restrict the use of personal data we hold, and to complain to your local data protection authority. Because WatchBar holds no personal data about you beyond anonymous crash reports, most of these rights are yours to exercise directly on your device. For anything else, email us and we will respond within 30 days. We do not sell personal information and will not discriminate against you for exercising your rights.
Changes to this policy
When things change, we’ll update this page and the “last updated” date at the top. If a change is material — for example, new data collection — we will say so in the app before it takes effect.
Contact
Privacy questions and requests: [email protected]. Everything else: [email protected].