(SECUSO) Privacy Friendly QR-Scanner with minimal permissions
About this app
QR Codes become more and more important. In some areas they have even replaced the traditional barcode. A QR Code is able to store up to seven thousand characters and therefore is qualified for more complex content, e.g. vCards. Hence nowadays QR Codes can nowadays be found on nearly every advertisement poster and animate the user to scan it with his smartphone. Thus, it is no longer necessary take a hand written note, it is enough to scan the QR Code. Correspondingly, there are already many QR Code scanner apps available in the Google Play Store. It belongs to the Privacy Friendly Apps group developed by the research group SECUSO at Technische Universität Darmstadt. More information can be found an secuso.org/pfa
Our Privacy Friendly QR Scanner App differs with respect to two aspects:
1. The Privacy Friendly QR Scanner App only requires the minimum amount of permissions, namely: Most of the QR Code scanner apps available in the Google Play Store need several permissions on top of the ones needed: e.g. reading contacts or your call log and retrieving data from the Internet. Most of these requirements are not necessary for the functionality they actually are supposed to provide.
2. The Privacy Friendly QR Scanner App supports its users in detecting malicious links: QR Codes provide new possibilities for an attacker, as QR Codes can contain malicious links, i.e. links to phishing webpages or webpages from which malware would automatically be downloaded. Therefore it is important to carefully check the link before accessing the corresponding webpage. Since it is difficult for the user to spot malicious links, the Privacy friendly QR Scanner App supports the user by highlighting the domain (e.g. in that case for https://www.secuso.org, secuso.org would be highlighted). To avoid not checking the link and in particular the highlighted domain carefully, the app provides information about possible fraud and its users need to confirm that they checked the link and it is trustworthy. Note, the information shown after scanning an URL based QR Code is not customized for every URL. Hence, it should be considered as an advice for the user how to behave in general.
The Privacy Friendly QR Scanner App supports most of the usual qr code types. Bar codes and other widely used codes are also supported.
The app belongs to the group of privacy friendly apps, that are developed by the SECUSO research group. More information can be found at https://secuso.org/pfa
You can reach us via BlueSky - https://bsky.app/profile/secusoresearch.bsky.social Mastodon - @SECUSO_Research@bawü.social https://xn--baw-joa.social/@SECUSO_Research/ Job opening - https://secuso.aifb.kit.edu/english/Job_Offers.php
Licensed under GPL-3.0-only, by SECUSO - Security Usability Society.
What's New in v4.6.19
Imported from the F-Droid repository index.
Version history
Feb 24, 2026 · 7 MB · Android API 17–34 · code 102
Imported from the F-Droid repository index.
SHA-256 2ca9502e0247175cc7d5bcb052a44f4222d3b977b411bad666b382148bd31eac
Oct 18, 2025 · 7 MB · Android API 17–34 · code 101
Imported from the F-Droid repository index.
SHA-256 f4fbfcc404a56ff627930e2e32d21199fb535c5ac2a925900b95eaa8d370e37c
Aug 7, 2025 · 6.9 MB · Android API 17–34 · code 100
Imported from the F-Droid repository index.
SHA-256 bbe90d607459dbd644ced0a2ce95b8948b385612cfaac8e658b015aa6bb84785
Will it run on your device?
73%
- Runs on a broad range of modern Android versions.
- ABI coverage is focused on newer 64-bit devices.
Installation Guide
Open Settings on your Android device
Go to Security → Unknown sources (or Install unknown apps)
Enable "Allow from this source" for your browser or file manager
Open the downloaded APK file from your Downloads folder
Tap "Install" and wait for installation to complete
Launch the app from your home screen
Make sure to re-enable Unknown Sources restrictions after installation for security.
How to install this safely
How to verify the file you downloaded
Before you install anything, confirm the file is the one described here. On a computer, run shasum -a 256 your-download.apk (macOS or Linux) or certutil -hashfile your-download.apk SHA256 (Windows), then compare the output character-for-character with the SHA-256 on this page. If a single character differs, the file is not the build we recorded — delete it.
What the signing certificate proves
Every Android app is signed with a private key that only its developer holds. The fingerprint on this page is a hash of the matching public certificate, and it proves continuity rather than identity: it tells you a build came from whoever signed the earlier ones. Android enforces this at install time — if a package claiming to be com.secuso.privacyFriendlyCodeScanner is signed with a different key, the system will refuse to install it over your existing copy. A fingerprint that changes between releases is worth pausing on, because a repackaged app that has been modified by someone else cannot keep the original signature.
How to roll back to an earlier version
If the current release misbehaves, 4.6.18 is the last build before it. Android will not install an older version code over a newer one, so you must uninstall QR Scanner (PFA) first — which clears its local data unless you have a backup. Reinstall the older APK only if its signing fingerprint matches the build you already trust, and check the API range: an older release may target an Android version your device has moved past.
Why we list sources instead of hosting everything
The official store channel is almost always the right choice: it updates automatically and carries the publisher's own distribution guarantees. A direct APK is useful when a device has no store access, when a rollout has not reached your region, or when you need a specific version — and only when the publisher has authorized that copy. APKBrowse does not list pirated, cracked, or unauthorized rebuilds of QR Scanner (PFA), and a listing is removed when the evidence for it stops holding up.
Get QR Scanner (PFA)
Every source we list for com.secuso.privacyFriendlyCodeScanner is legality-reviewed. Pirated or cracked builds are never offered.
Other sources
F-Droid listing
officialF-Droid builds this app from source and signs it. This is its official listing, with older builds and full release notes.
Source code
verified publisherThe upstream repository this build is compiled from.
We check legality and signature continuity, but device behaviour still varies. Install at your own discretion.
App Information
Security Verification
We record provenance; we do not run malware scans. Verify the hash yourself before installing.
SHA-256 Hash
2ca9502e0247175cc7d5bcb052a44f4222d3b977b411bad666b382148bd31eac
Signing certificate
759d2d25785a6df4cd6619692b37f00532ba19b26df20a4ef5b22128c7f151bc
Permissions Required
What each permission lets QR Scanner (PFA) do. A highlighted one is worth a second look — not necessarily wrong, just worth asking whether this app needs it.
Previous Versions
The signing certificate fingerprint for this release is on record, so a build that does not match it did not come from this publisher.
More Media Audio apps
More from F-DroidReport a problem with this listing
A listing is only as good as its corrections. If a source is broken, a signature looks wrong, or this app should not be here, tell the moderation team.