All guides
Student data facts

Is QR to Sheets safe for student data? What it stores, who sees it, how to delete it

What QR to Sheets stores when staff scan a student code, who can see it, where it is kept, how to delete it, and how a school Google admin allows it.

By the QR to Sheets team 9 min readUpdated

Short answer

When staff scan a student's code, QR to Sheets records the scanned text, the scan time, the scanner link's name, the device type and a random device ID, and students need no account and never open the link.

Each scan becomes a row in your school's own Google Sheet, and QR to Sheets keeps a copy on servers in the United States until the workspace owner resets or deletes the workspace in Settings.

Scans are private to your workspace: QR to Sheets never sells them, never shares them with other customers or advertisers, never uses them for advertising, and uses them only to run and support the service.

A teacher who wants to scan student cards into a Google Sheet usually meets the same questions before anyone says yes: what does the tool keep, who can see it, where does it live, and how is it deleted. This page answers each one with facts a data protection lead or a district IT team can check, and it covers the free route that keeps everything inside Google.

Written by QR to Sheets, about QR to Sheets, so weigh it accordingly. Every statement describes how the product works as of 2026-10-12. It is not legal advice, and whether a tool may be used with student records is your school's or your district's decision.

What does one scan record?

A scan is the text inside a code, plus a little context. When staff scan a student's card on a scanner link, the phone sends the decoded text, the device type, a random device ID, a reference number for the scan and the time it was saved. QR to Sheets stores that, writes a row to your Google Sheet, and keeps a note of whether the row arrived.

What one scan on a QR to Sheets scanner link records, as of 2026-10-12.
ItemExampleWritten to your SheetKept by QR to Sheets
Scanned textS-10423Yes, or the parts your custom columns pick outYes
Scan time2026-10-12 08:41:07, in your workspace's time zone, written as textYesYes
Scanner link namelink:Period 3YesYes
Workspace nameThe name you gave your workspaceYes, on the default column layoutYes
Device typemobile or desktopYes, on the default column layoutYes
Random device IDA random code the phone's browser made for itselfOnly on links with custom columnsYes
Scan IDA reference code for the rowYes, on the default column layoutYes
What one scan on a QR to Sheets scanner link records, as of 2026-10-12.

What a scan does not record

  • Student names, unless your codes contain them. The scanned value is whatever the code holds, so a card that holds an ID number records an ID number.
  • Photos. The camera picture is read on the phone, and only the decoded text is sent. Scan from a photo works the same way: the picture is read on the phone and never uploaded.
  • Location. The site switches location access off on every page, so the scanner cannot ask for it.
  • The scanning person's name or email. A scanner link has no sign-in. The one exception is a member who scans while signed in to your workspace: their rows carry their own email instead of a link name.
  • The phone's IP address. It is used briefly to limit how many requests one network can send, and it is not saved with the scan.

The scanner also reports a few events to your workspace's activity log, such as the page opening or the camera failing to start, together with the phone's browser and operating system. Those reports never contain a scanned value.

Encode student ID numbers, not names. A lost card then shows a number, and a class list tab can show the name next to each scanned ID inside your own Sheet.

Do students need an account or an app?

No. A teacher or member of staff scans each student's QR card with a phone browser. Students never open the link, install an app or sign in, and only the person who connects the Google Sheet signs in with Google. Each phone that scans counts as one device. Free covers one phone; Premium is $7 per phone per month. People being scanned never open the link and need nothing.

Some schools let students scan their own card at a tablet on a stand. That tablet is still one device, and your school decides who operates it; running a shared check-in tablet covers the setup.

Where is the data kept, and for how long?

  • In your Google Sheet. Rows live in the Google account that connected the Sheet, under that account's sharing settings, and they stay there whatever you later delete in QR to Sheets.
  • In QR to Sheets' own copy, on servers in the United States. It is kept until the workspace owner resets or deletes the workspace in Settings, or until you ask us to delete it.
  • On the scanning phone. The scanner keeps a backup of recent scans in that browser, up to the newest 1,000, and more while some are still waiting to send.

If the signal drops, the open scanner keeps saving scans on the phone and sends them when the signal is back, each with its original scan time. That backup is why the phone holds a copy. On a shared school phone, staff can remove it with Clear synced scans or Clear all scans from device on the scanner screen, and each clear is noted in your activity log.

Two limits, stated plainly. There is no automatic deletion schedule yet, and one scan cannot be deleted on its own from QR to Sheets' copy. Revoking or deleting a scanner link keeps the scans it collected; Reset workspace removes them all at once.

Who can see it?

  • The Google Sheet: whoever you share it with in Google. Keep it in a school account, shared only with the staff who need it.
  • The QR to Sheets dashboard: the workspace owner and the admins they invite. Members invited only to scan cannot open the dashboard.
  • A person holding a scanner link can add rows but cannot open the Sheet or the dashboard, and sees only the scans made on their own phone, because scanning adds rows without sharing the file. Treat a link like a key: revoke it in the admin when a term ends or a member of staff moves on.
  • QR to Sheets: scans are private to your workspace. QR to Sheets never sells them, never shares them with other customers or advertisers, never uses them for advertising, and uses them only to run and support the service.

What does the Google permission allow?

There are two separate Google approvals. Signing in shares your name, email address and profile picture. Connecting a Sheet asks for one more permission: to open and edit only the spreadsheets you pick in Google's file picker or create through QR to Sheets. It cannot list or open any other file in that Google Drive.

Google's own admin help article on controlling third-party app access (support.google.com/a/answer/13152743, read 2026-10-12) lists the Drive permissions it treats as high-risk, such as access to every file in a Drive. The per-file permission QR to Sheets uses is not on that list, and the article gives access to user-selected files in Drive as its example of a permission that is not high-risk. The exact permissions are listed in our privacy policy.

To withdraw the permission at any time, remove QR to Sheets on your Google Account's third-party access page (myaccount.google.com/permissions). New scans stop reaching the Sheet until someone connects it again, and the rows already written stay where they are.

How do I delete it?

  • Rows in your Sheet: delete them in Google Sheets, like any other rows. Nothing in QR to Sheets deletes them for you.
  • Reset workspace, in Settings, for the workspace owner: permanently deletes every scan, scanner link, Sheet connection and registered device, plus dashboard settings, the stored Google connection and invitations. It keeps members, billing, forms and their submissions, Events guest lists and the activity log.
  • Delete workspace & account, in Settings, for the workspace owner: permanently erases the whole workspace, including form submissions, Events guests, the activity log and billing records, asks Google to revoke the Sheets permission, and removes your account if it was your only workspace.
  • By email: write to hello@qrtosheets.com, and we process deletion requests within 30 days.
  • On the phone: Clear synced scans or Clear all scans from device on the scanner screen.
  • Form submissions, if you also use QR to Sheets Forms: deleting a form deletes its submissions. Reset workspace does not delete forms or submissions.

Can a school keep everything inside Google instead?

Yes, and if no outside service may hold student data at your school, it is the right answer. A Google Form that only accounts in your school's domain can open, reached from a printed QR code, keeps every response inside your Google Workspace with no outside service involved. Google's Forms help confirms that before publishing, a form's owner can restrict access to a domain, a trusted audience or a group of users.

It breaks in predictable places:

  • Every student needs a device signed in to a school account, which rules out younger classes and shared phones.
  • Answers are self-reported. A student can submit from the corridor, or for a friend, and every response looks the same.
  • Nothing is scanned. Typed names and IDs need tidying before a formula can match them against a class list.
  • A submission made with no signal is lost rather than queued.

We sell the scanner link, so weigh this section accordingly. The scanner link suits a school that wants staff to scan cards quickly and is content for an outside service to hold a copy of the scans; the facts on this page are here so the school can decide that knowingly.

What if the school's Google admin blocks QR to Sheets?

Many Google Workspace for Education domains block third-party apps that the admin has not allowed. Google then stops whoever connects the Sheet, sometimes with the error admin_policy_enforced, and the teacher cannot change that setting.

The fix is a one-time setting your Google admin makes in the Admin console: allow QR to Sheets by its client IDs in the app access controls. The steps for your Google admin, with both client IDs are on one page you can forward. Phones that only scan need nothing approved, because they never sign in to Google, and it does not need to be allowed for students.

What should the school check before rolling it out?

  • What the codes contain: an ID number, never a name, a date of birth or a phone number.
  • That the Sheet sits in a school Google account, not a personal one, and who it is shared with.
  • Who is invited as an admin of the QR to Sheets workspace.
  • That scanner links are revoked at the end of a term, and shared phones are cleared.
  • A retention period for the scan log, applied in the Sheet itself and with Reset workspace or Delete workspace in QR to Sheets.
  • That parents are told, in the privacy notice the school already publishes.
  • Whether your district requires a signed data privacy agreement with any outside service. If it does, email hello@qrtosheets.com before you start.

For the classroom setup itself, the school attendance page walks through the cards, the links and the daily list.

Frequently asked questions

Does QR to Sheets sell or share student data?+

No. Scans are private to your workspace: QR to Sheets never sells them, never shares them with other customers or advertisers, never uses them for advertising, and uses them only to run and support the service. Rows in your Google Sheet are shared only as you share the Sheet.

Does QR to Sheets store photos or the phone's location?+

No. The camera picture is read on the phone and only the decoded text is sent, and the site switches location access off on every page. A scan records the scanned text, the time, the scanner link's name, the device type and a random device ID.

Does deleting a scanner link delete its scans?+

No. Revoking or deleting a link keeps the scans it collected, in your Sheet and in QR to Sheets' copy. Reset workspace in Settings deletes every scan in QR to Sheets at once; rows in your Sheet are deleted in Google Sheets.

Where are QR to Sheets' servers?+

In the United States. Your rows also live in your own Google Sheet, in the Google account that connected it.

Can students scan themselves?+

Yes, at a shared tablet on a stand that your school sets up, which counts as one device. Your school decides who operates its scanner links, and students never need an account or a phone of their own.

Can a teacher connect a personal Google account?+

It works, but student data belongs in a school-controlled Google account. If your school's Google admin blocks QR to Sheets, ask them to allow it once in the Admin console rather than moving student data to a personal account.

Try it on your own Google Sheet

Connect Google, create a scanner link, and share the URL with your team. The free tier covers 300 scans, and nobody you share it with has to install anything.

Start for free

No credit card required

Keep reading