Most "free QR code generators" work like this: you type something, it gets sent to a server, the server encodes it and sends an image back.
That works fine. But think about what people actually encode. WiFi passwords. Contact details. URLs to internal documents. Pay-by-bank links. Sometimes literally a one-time link to something private.
If the encoder runs on someone's server, then by definition that server can read it. Even if nobody is watching. Even if the privacy policy promises not to. The data simply arrives somewhere you don't control.
What "100% client-side" actually means
When I built QR Generator, I set one rule up front: the QR encoding never leaves the browser.
No POST to an API. No POST to a serverless function. No queue that might log the payload somewhere. The input you type stays in JavaScript memory, gets turned into a matrix of modules, and is rendered into a <canvas> or an <svg> that never goes anywhere.
The app is built with Next.js (App Router, running on Turbopack), but for this particular feature "server" is almost a misleading word — the generation step is pure client-side computation. React handles the form state; everything else happens locally.
// The whole pipeline, roughly.
const qr = QRCode.create(payload, {
errorCorrectionLevel: level, // L / M / Q / H
color: { dark: fg, light: bg },
});
canvasRef.current
.getContext("2d")
.drawImage(qr, 0, 0, size, size);
No network tab traffic. Open DevTools and watch it stay empty.
The interesting part: error correction vs. logos
QR codes have four error-correction levels. In plain terms, they trade redundancy for robustness:
| Level | Redundancy | Use when |
|---|---|---|
| L | 7% | Clean screen, plenty of room |
| M | 15% | Default. Good all-rounder |
| Q | 25% | Branded colors, print |
| H | 30% | Logo overlay, printed, possibly scuffed |
A logo is the interesting case, because a logo is damage. You are deliberately covering modules the scanner needs in order to read the code correctly.
So when you upload a logo, the generator bumps the error correction level automatically — the bigger your logo, the more redundancy the code needs to survive it. It's a small detail, but it's the difference between a QR code that scans every time and one that fails on a printed sticker.
PNG vs SVG, and why it matters
The other thing I care about is output quality.
PNG is what you want for screens and social posts. Raster, pixel-perfect at the size you export it.
SVG is what you want for print — a logo on a business card, a sticker, a poster. It's resolution-independent, so it stays sharp at any scale, from a 20mm sticker to a two-metre banner.
Shipping both costs nothing, and it means the tool is not forcing everyone into one compromise.
What I deliberately left out
Some things you can add that you can't take back:
- No accounts. No email, no password, no "your QR codes" dashboard.
- No storage. Nothing saved. Close the tab and it's gone.
- No scan analytics. This is the big one, and it was a real decision.
Analytics on a QR generator are tempting — you'd learn which codes people generate, from where, and when. But the whole premise of the tool is that the payload is private. Shipping behavioral tracking alongside a privacy promise would make the promise worthless. So: none.
The honest tradeoff is that I can't tell you which features get used. I know what performs from search data and what users write to me about. That's it.
Beyond the generator
The same site runs an Android app and a fairly large guides blog covering things like when NFC is actually the better choice than a QR code, scan-rate patterns, and how to verify where a QR code points before you scan it.
That blog is a deliberate SEO play, but it's also the part I find genuinely useful — most QR content online repeats the same five steps. The interesting questions are the ones about when not to use a QR code.
Honest limitations
A few things this approach doesn't solve:
- Payload size is still bounded by what a QR code can physically hold. Trying to encode a novel will not work.
- On older mobile browsers, heavy payloads plus SVG rendering can feel sluggish.
- "Private" means "doesn't reach my server." It does not mean "safe" — generate a QR code for something dangerous and it's still dangerous.
Try it
QR Generator — free, no signup, no watermark, PNG and SVG, runs entirely in your browser.
If you spot something broken or find an edge case I got wrong, I'd genuinely like to hear about it.
Built by saidtechnology — a one-person studio. I build privacy-first web and mobile tools.
Top comments (0)