Privacy Policy
What is stored, why, and what is deliberately not stored.
Last updated 2026-09-03
The short version
Passportkit stores the least it can while still being useful. It never asks for a full passport number, and it cannot show one, because it never had one.
We do not sell your data. We do not use it for advertising. We do not build a profile of you.
What is stored
Your account: an email address and the sign-in method you chose.
Your records: the names you give the people on your plan, and for each document the issuing country, a nickname, the dates, and the last four characters of the number. Insurance adds the provider, the cover and the dates. Currency adds what you bought, where and for how much. Trips add destinations, dates and who is travelling.
Support: the messages you send us and our replies.
Deliberately not stored: full document numbers, scans, photographs of documents, and machine-readable-zone data. This is why a leak of our database would not let anybody travel as you.
Where it is held
Records are held in a managed Postgres database operated by Supabase, protected by row-level security so that a request can only reach rows belonging to the account that made it.
A copy is cached on your own device so the app works at a border with no signal. That cache holds the same limited fields and is removed when you sign out.
Who else sees it
Nobody, other than the processors that run the service on our behalf: Supabase for the database and authentication, and Apple or Google for payments.
RevenueCat handles subscription state. It receives an account identifier and what you bought — never your documents.
The app itself contains no analytics or advertising SDK. Nothing you enter into it is measured, and no profile of you is built from it. The website is a separate matter, covered below.
The website
passportkit.com uses Google Analytics to count visits and see which pages people read. It runs only if you accept it — decline and no analytics script loads and no analytics cookies are set. You can change your mind at any time from the link in the footer.
If you accept, Google receives your IP address, the pages you visited and general details of your device, and sets cookies to recognise your browser on a later visit. Google acts as our processor for this and may transfer the data outside the UK and EU under its standard contractual clauses.
This is the website only. It is not connected to your account, and the app remains free of any analytics SDK — none of your documents, trips or currency records are involved.
Notifications
Expiry reminders are worked out on your device and scheduled locally. The dates they are based on are not sent anywhere to produce them, and no push server is involved.
Family plans
A family plan lets one person record documents belonging to others. Those records belong to the account that entered them and are visible to whoever holds it.
Record someone's documents only with their agreement, and expect to be asked to remove them.
How long it is kept
Records are kept until you delete them or close your account. Deleting an account removes its records; backups age out within 30 days.
Support conversations are kept for two years so a later question has its history.
Two things survive deletion: records of payments, which we are required to keep for tax and accounting, and anything else the law requires us to retain. Neither contains your documents.
Your rights
You can see everything held about you inside the app, correct any of it, export it, or delete the account outright from Privacy & Security.
If you are in the UK or EU you also have the right to complain to your data protection authority. We would rather you told us first: support@passportkit.com.
Children
Passportkit is not for children to hold accounts. An adult may record a child's passport on a family plan, which is a record kept by the adult rather than an account belonging to the child.
← All legal documents