Last updated: March 28, 2026
Passeporté ("the App") is developed by Pavel Kanzelsberger. This policy explains how the App handles your data.
Your document data never leaves your device. The only data transmitted is anonymous crash reports to help us fix bugs. No personal information, document data, or photos are ever sent anywhere.
The App does not collect, transmit, or share any personal data. Specifically:
Document data read from NFC chips (including personal details, photos, and MRZ data) is stored exclusively on your device using the following security measures:
kSecAccessControlBiometryCurrentSet).kSecAttrAccessibleWhenUnlockedThisDeviceOnly and is excluded from iCloud, iTunes, and Finder backups.The App uses Face ID or Touch ID solely to authenticate access to stored documents. Biometric data is processed entirely by the iOS Secure Enclave and is never accessed or stored by the App.
If you re-enroll your biometrics (e.g., set up a new Face ID), the Secure Enclave encryption keys are automatically invalidated, permanently erasing all stored document data.
The App uses the device camera solely to scan the Machine Readable Zone (MRZ) on passport data pages. Camera frames are processed on-device using Apple's Vision framework for text recognition. No images or video are stored, transmitted, or retained beyond the active scanning session.
The App reads NFC chips in biometric passports (via BAC/Basic Access Control) and eID cards (via PACE/Password Authenticated Connection Establishment). All NFC communication occurs directly between the device and the document chip. No data is relayed to any external service.
The App may schedule local notifications to alert you before document expiry dates. These notifications are processed entirely on-device by iOS and do not involve any server communication.
The App uses Sentry for crash reporting and error tracking. When the App crashes or encounters a technical error (such as a failure to read a document chip), a crash report is sent to our self-hosted Sentry instance. These reports contain:
Crash reports never contain document data, personal details, photos, MRZ content, or any information read from your passport or eID chip. The Sentry instance is self-hosted at our own infrastructure and is not shared with any third party.
The only third-party service used is a self-hosted Sentry instance for crash reporting as described above. No data is shared with Sentry Inc. or any other external party. The App also uses open-source cryptographic libraries for chip communication protocols.
The App does not knowingly collect data from children. Since the App collects no data from anyone, no special provisions for children are necessary.
You can delete any stored document at any time from within the App. Deleting the App from your device permanently removes all stored data. There is no external data to request deletion of.
If this privacy policy changes, the updated version will be posted at this URL. Since the App makes no network connections, it cannot notify you of policy changes directly.
If you have questions about this privacy policy, contact:
Pavel Kanzelsberger
[email protected]