Oh I see. If the URL puts the sensitive information after the anchor, like https://example.com/bsod#sensitive-info-goes-here then the browser would never send that part to the server. Everything after the anchor is just used locally by the browser to scroll the page to a specific place (or in this case for the javascript to read and process).
You'd need to check every time you scan a QR code though that the # is in the URL and it's not malformed. Trivially replacing the # with a ? would turn the private URL into one that sends all the data in the GET request. It's training users to do something risky.
Oh and it also assumes that the javascript hasn't been tampered with to upload the data somewhere.
I don't like it.