The QR code contains the panic stack trace text, directly encoded into a URL and a parameter. When you scan it, it goes to the website, which takes the parameter, decodes it and displays it as plain text.
Personally, I think it’s a terrible idea compared to just showing the logs, because now you need internet and a phone with a camera to read a kernel panic log.
Edit: yes, it was Systemd who implemented it.



The theory is that the site just hosts a small JS snippet that locally decodes and shows you your logs.
But yeah, now that you mention it, it would be trivial for the site to get and store the logs, and you wouldn’t even notice.