LegalPrivacy

Privacy Policy

Last updated October 10, 2026

No accounts, no passwords, no email

Passmint doesn't have accounts. There's nothing to sign up for and no password to lose. On first launch the app generates a random installation ID and a separate 32-byte device token on your device. Together these authenticate the app to Passmint's backend, but neither one is your name, your email, or anything else that identifies you personally. We never ask for or collect an email address to use the app.

What stays on your device

The tickets, passes, and cards you scan, import, or type in (barcodes, dates, names, and any other field on the pass) are stored in the app on your phone, not on our servers. Editing a pass (renaming it, changing its color, fixing a field) never leaves your device: there's nothing to sync, because the backend never held that content in the first place.

Pass Studio

Pass Studio (studio.getpassmint.com) runs entirely in your browser. Everything you add there, including screenshots, PDFs, photos and anything you type, is read on your device and never uploaded. The .pmint file it makes is built on your device, optionally encrypted with a passphrase you choose, and goes only where you send it. Pass Studio keeps its own files cached in your browser so it works offline; it stores no passes on our servers.

Pass Store

Pass Store (store.getpassmint.com) is a catalogue of ready-made pass designs. It is a static page: searching and filtering happen in your browser, and nothing you type there is sent anywhere. Choosing a design opens it in Pass Studio, which follows the section above. The app's Creative templates show the same designs: the app downloads the list of designs and their pictures from getpassmint.com, and sends nothing with that request (no installation ID, no device token, no pass content).

Store logos

Store cards can show the store's logo. The logos are served only to Passmint itself, never as files anyone can open by address. The app downloads the logos of a whole country at a time from our server (the list of available logos first, then every logo of that country it does not have yet), so a request never says which store you picked. Those requests carry the app's installation ID and device token, as every request to our server does, and no pass content. Pass Studio downloads logos in your browser the same way, after a Cloudflare Turnstile check that tells a person from a script; Cloudflare runs that check under its own Turnstile privacy policy, and Pass Studio only loads it when its store list needs logos. Like every request to getpassmint.com, these pass through Cloudflare, our hosting provider's network. Once a card is made, its logo is kept on your device with the card and travels with it in a backup or a shared pass.

Cookies and browser storage

getpassmint.com, Pass Studio and Pass Store set no cookies and use no analytics, advertising or tracking tools. They keep only what they need to work in your browser's own storage (local storage and IndexedDB): your theme choice, the passes you are making in Pass Studio, the card you carry from the home page into Pass Studio, and a cache of store logos so Pass Studio works offline. This stays on your device, is never sent to us, and you can clear it at any time from your browser's settings. Pass Studio's Cloudflare Turnstile check is described under Store logos above.

Checking the app is genuine

Once per installation, the app asks Apple (App Attest) or Google (Play Integrity) to confirm that it is the genuine Passmint from the App Store or Google Play, running on a real phone, and sends that confirmation to our server. Apple and Google learn only that Passmint asked; our server keeps only when the installation was confirmed and whether through Apple or Google. Nothing about you or your passes is part of it. This protects our signing certificates from scripted misuse.

What briefly passes through our backend

Adding a pass to Apple Wallet or Google Wallet requires our backend to build and sign that wallet file. Your pass content is sent for that one request, held in memory just long enough to sign it, and then discarded. It is never written to disk and never stored at rest. If a pass uses a custom background image, that image stays on your phone: it is never uploaded, and the wallet card is built from the pass's colours and text alone.

What our backend keeps a record of

One small record per installation, and it exists so that only your device can ask us to sign your passes: your installation ID (a random value your device generates), a one-way hash of its device token (never the token itself), a count of how many passes have been signed, when the installation last contacted us, and when and how it was confirmed genuine (see above). The count is an anti-abuse limit on our own signing certificates, not a limit on you. That's the whole record: no pass fields, no account, no email address, no password. Passmint is free, so there is no billing information of any kind.

Manual backup & restore

The optional Export/Import feature in Settings creates a file containing your passes and a few display settings, encrypted on your device with a passphrase only you know, before it's handed to your phone's normal share sheet. Passmint's backend never sees this file. Because the passphrase is never transmitted or stored anywhere, if you lose it the backup can't be recovered by us or anyone else.

Crash reporting

Passmint uses Sentry for crash and error reporting. Stack traces, device information, and app version are transmitted when the app crashes. No personal identifying information is collected. This data is handled under Sentry's privacy policy.

What we don't do

We do not sell your data, scan pass contents for advertising, build an ad profile, or share pass data with anyone beyond the wallet provider (Apple or Google) needed to add that pass to your wallet.

Deleting your data

"Delete my data" in Settings erases the backend record tied to your installation immediately and permanently. If you simply delete the app, it can no longer ask us to, so we do it for you: a record whose installation has not contacted our server for 12 months is deleted automatically. If that phone opens Passmint again later, it just gets a new record. It doesn't touch passes or backups already saved on your device; delete those the same way you deleted them from the app, or from wherever you saved an exported backup file.

Changes to this policy

If this policy changes, we'll update the date above. Continued use of the app after a change means you accept the revised policy.

Contact

Questions about this policy can be sent to [email protected].