Skip to main content

Tool

The Last Slide

A QR code, a contact card and scan statistics nobody else sees: why I built qr4prez.

The qr4prez logo: a leather-bound tablet, engraved in an antique style, displaying a large QR code. Create my contact QR code ↗

The talk ends. A few people walk up to the stage, phones in hand. Pleasantries are exchanged, then comes the awkward part: spelling out an email address over the crowd noise, hunting for a LinkedIn profile among a dozen namesakes, handing over a business card that will end its life at the bottom of a jacket pocket. I lived that scene after every talk for years.

qr4prez was born from that scene. It is a small web tool: you fill in a form once and get a QR code, that black-and-white checkerboard a phone camera knows how to read, to put on your last slide. The audience scans it with the phone camera and your contact card lands straight in their address book, photo, title and links included. As a bonus, a private page counts the scans: how many, when and from which city.

The tool lives at deraison.ai/qr4prez. It is free and bilingual, with no account to create.


Motivation

The paper business card has two flaws. The first is well known: it gets lost. The second bothered me more: it tells you nothing. Once handed out, you can hardly know whether it was ever used, whether someone dug it up three weeks later, or whether it survived the washing machine.

The digital answer has existed for a long time: the vCard, a standardized text file every phone knows how to read. It holds the name, phone number, email, employer, even the photo. The QR code is the bridge: the camera turns the checkerboard into a link, the link opens the vCard. Neither brick is new in its own right; what was missing was an assembly I wanted to use.

I wanted three things. A single action for the audience: no app to install, nothing to fill in on their side, just the camera. Feedback for me: a way to know whether that last slide earns its place. And control over the data: everything hosted on my own server, the machine that stays on around the clock to serve my pages. No third-party service collects my audience's contact details; no cookies, no trackers, those little spies that recognize a visitor from one site to the next.

That combination did not exist. Online QR generators come by the dozen, but they keep your data on their machines, ask for an account, slip in a subscription. None of them tells you what becomes of the QR once the room empties, which was the whole point for me. Business-card exchange apps, for their part, impose their app on both ends. qr4prez goes the other way: self-hosted, account-free, with private scan statistics, released into the public domain. Anyone can install it on their own server and make it theirs.

It is also a finished tool rather than a weekend mockup: bilingual interface; a recap email after creation (the three links outlive the closed tab); protection against automated request floods; a complete set of favicons and sharing tags (the clean preview when the link lands in a messaging app); careful server-side logging. The distance between a prototype and a tool you dare to show sits in that pile of invisible details.


How it works

It starts with a form: name, job title, email, phone, a square photo. To make the wait less administrative, the empty fields suggest a different personality each time: Marie Curie, Grace Hopper, Nina Simone, Alan Turing… These suggestions stay dimmed examples; they are never submitted on your behalf.

Screenshot of the qr4prez form: identity fields, square photo and the day's suggested personality.

The form: five required fields, one square photo and a suggested personality to set an example.

The photo taught me the project's humility lesson. Some versions of iOS, the iPhone operating system, silently drop the entire photo from a vCard when the JPEG file, the usual photo format, contains a technical comment left by the software that prepared the image on the server. No error message: the contact arrives, faceless. So the photo is decoded, resized to 400 × 400, re-encoded cleanly; the offending comment is then stripped byte by byte from the final file, lest a single phone drop the face again. Nobody will ever see that work, which is exactly the point of doing it.

Each card then receives an address that cannot be guessed. The idea rests on a hash function, a mathematical grinder that turns any text into a fixed-size fingerprint, so unpredictable that changing one letter of the text scrambles the whole fingerprint. qr4prez hashes the first name, last name and submission instant with SHA-256, one such function, published and battle-tested for years. It then keeps the first 16 characters of the fingerprint, written in hexadecimal, the sixteen-symbol alphabet of computing (digits 0 to 9, then letters a to f). Each symbol answers four yes-or-no questions, four bits; sixteen symbols add up to 64. Sixty-four two-way choices give a number of possible addresses that reads:

$$2^{64} \;\approx\; 1.8 \times 10^{19}$$

Eighteen billion billion. The risk worth checking carries a lovely name, the birthday paradox: in a group, two people share a birthday far more often than intuition suggests; likewise, two cards could land on the same address. The probability of a collision among \(n\) cards never exceeds:

$$\Pr[\text{collision}] \;\le\; \frac{n(n-1)}{2} \cdot \frac{1}{2^{64}}$$

With one million cards, that is about \(2.7 \times 10^{-8}\): three chances in a hundred million. The address also carries no personal information: neither name nor date appears in it, only the fingerprint survives.

On the audience side, the effort stays minimal. The phone scans the QR, opens the card's address, the server serves the vCard and then records the visit.

A real, working QR code pointing to deraison.ai/qr4prez.

This one works: scan it and you land on qr4prez.


Where the scans come from: geolocation

This is the part that surprises people the most, so it deserves an exact account. No phone transmits its GPS position when it scans a QR code; that would be impossible without explicit permission anyway. What the server receives is the numeric address every connected device carries for the duration of its connection, so that answers can find their way back to it: the IP address (Internet Protocol). That address says nothing about the apartment, much less about the person, but a great deal about the network operator: internet providers publicly declare which address ranges they run in which region. Directory services cross-reference those declarations and answer, for a given address, a country, a likely city, and the coordinates of that city's center.

The resulting accuracy deserves an honest comparison. A phone's GPS locates within a few meters; IP geolocation locates a city, with regular misses. A mobile subscriber can surface at their operator's uplink, two hundred kilometers away. A corporate network drags everyone back to headquarters. And a virtual private network (Virtual Private Network or VPN), that tunnel that makes a connection surface somewhere else, ships the scan to another country outright. The map therefore tells a geography of audiences, not an address book. That is plenty for what it is asked to do: say whether the Lyon talk left traces or whether a presentation kept circulating abroad three weeks later.

The statistics page, visible only to the card's owner, assembles all of it: four counters, a world map where nearby scans collapse into numbered clusters, a city ranking, then the detail of every visit with its local time, device, operating system, browser and network operator.

The qr4prez statistics page: four counters (12 scans, 12 unique visitors, 10 cities, 8 countries), a world map where nearby scans collapse into numbered clusters and a city ranking led by Paris.

A demonstration card's statistics page: the map, the clusters and the city ranking. Coordinates are city centers, not device positions.

That leaves the question that settles everything: how far can you measure without becoming intrusive? Three guardrails answer it. Scans arriving within a minute of creation are ignored, because that is you checking your own QR, not a new contact. A disclaimer under the map states that the pins are approximate city centers. And new-generation IP addresses (IPv6), four times longer than the old ones (128 bits instead of 32), are truncated on display: only the first 48 bits stay visible. The number of addresses that opening covers is:

$$2^{128-48} \;=\; 2^{80} \;\approx\; 1.2 \times 10^{24}$$

The displayed line therefore points at an operator and a region, never at a subscriber. A statistics page needs nothing more to say that a scan came from Lyon.


Conclusion

My talks now end with a QR code. The after-talk line still forms, thankfully: it is where the substance gets discussed, objections raised, ideas traded. The exchange of contact details, meanwhile, takes two seconds and no longer mangles a single email address.

If you give talks, lectures or defenses, try it: deraison.ai/qr4prez. Fill in the form once, put the QR on your last slide, then watch, afterwards, the scans draw the map of your audience.