How Does a QR Code Store Data?

Smartphone scanning a generic nonfunctional QR-like pattern on a package workbench

A QR code stores information as a grid of dark and light square modules. The pattern represents encoded bits together with structural information that helps a scanner locate, orient, and decode the symbol. Unlike a one-dimensional barcode, which varies along one direction, a QR code uses both horizontal and vertical space. That allows it to carry more data in a compact area. The recognizable large squares in three corners are position-detection patterns; they help a camera identify the code’s orientation and boundaries even when the symbol is rotated.

Encoding begins by choosing a mode suited to the data, such as numeric, alphanumeric, byte, or—in applicable implementations—Kanji. The encoder converts the input into bits, adds indicators that describe the mode and character count, and selects a symbol version large enough for the data and error-correction level. Standard QR Code versions range from 21 by 21 modules to 177 by 177 modules, increasing by four modules per side. Timing patterns, alignment patterns in larger versions, format information, and a required quiet border help the reader understand the geometry.

The encoder does not simply place the original bits into empty squares. It divides data into codewords and adds error-correction codewords calculated with Reed–Solomon methods. The combined stream is arranged through the available modules, and a mask pattern is applied to avoid visual arrangements that would be difficult for scanners. Information stored in the symbol tells the decoder which mask and error-correction level were used. Four standard error-correction levels trade capacity for resilience: stronger correction uses more of the symbol for redundancy and leaves less room for the original message.

When a phone scans a code, its camera captures an image rather than a perfect grid. Software detects the corner patterns, estimates perspective, compensates for rotation and distortion, and samples the expected module positions. It reads the format and version information, removes the mask, reconstructs the codewords, and uses the redundant data to correct a limited number of errors. Dirt, glare, blur, low contrast, a missing quiet zone, or severe damage can still defeat decoding. Error correction improves tolerance; it does not make every altered symbol recoverable.

The decoded content may be plain text, contact information, a network configuration, or a web address. The squares themselves do not connect to the internet or prove that the destination is trustworthy. A scanning app interprets the recovered bytes and may offer an action. Because a person usually cannot read the destination directly from the pattern, attackers can place a code over a legitimate one or encode a deceptive link. Users should inspect the displayed destination, avoid entering sensitive information after an unexpected scan, and treat a QR code like any other untrusted link.

Design changes can also affect reliability. Logos, colors, rounded modules, and decorative backgrounds may be tolerated when contrast, geometry, error correction, and the quiet zone remain adequate, but aggressive styling can make a symbol unreadable. A code used on packaging must also be large enough for the expected camera distance and printing quality. The essential process is orderly: encode data, add structural and recovery information, place and mask the modules, then reverse those steps during scanning. The apparent mosaic is therefore a standardized machine-readable data format, not a random picture. Readers also depend on correct physical production. Printing can spread or shrink modules, glossy surfaces can create reflections, and curved packaging can distort the grid. Testing should use the actual material, expected lighting, camera range, and several device models rather than a perfect image on a monitor. When the encoded destination may change, a short managed redirect can preserve the printed symbol, but that service becomes another dependency that must be secured and maintained.

They are position-detection patterns that help scanning software find the symbol and determine its orientation and boundaries.

Often, within limits. Reed-Solomon error correction adds redundancy, but severe damage, blur, or poor contrast can still prevent decoding.

No. The pattern only carries data, so users should inspect the destination and treat unexpected codes like other untrusted links.

Explore more "Explainers"

Discover additional explainers across politics, science, business, technology, and other fields. Each explainer breaks down a complex idea into clear, everyday language—helping you better understand how major concepts, systems, and debates shape the world around us.