Passmagic

Privacy Policy

How Passmagic handles the tickets you share and the passes you make.

Last updated 28 September 2026

At a glance

  • You do not need an account. Passmagic does not use advertising or in-app tracking, and we do not sell your personal data.
  • Your original tickets and saved passes are kept on your iPhone. They may also be included in your device backups, depending on your backup settings.
  • With your permission, ticket text is sent to our server and to AI services to make a pass. Some photos and scanned PDFs also send a resized image.
  • The pass details are sent to our server again for signing so Apple Wallet can accept the pass.

Who is responsible

Passmagic is operated by Harris Jose, an independent developer based in India ("we", "us"). This policy covers the Passmagic iPhone app and passmagic.app. Contact us at hello@passmagic.app.

Information on your iPhone

When you choose or share a screenshot, photo, PDF, email text or message, Passmagic makes a local copy and uses Apple's on-device tools to read text and barcodes. The app saves the original you shared, the pass details and the signed pass so you can view or share them later. It does not read your whole photo library: if you grant Photos access, it shows recent images for you to choose from; the system photo picker also works without full library access.

You can delete a saved pass and its associated original from the app. Deleting the app removes its local data, but copies you added to Apple Wallet, shared elsewhere or kept in a device backup are managed separately.

Information sent to make a pass

Before making your first pass, the app asks for permission to use third-party AI. If you agree, it sends the text and barcode information read from the item you selected to our server. A ticket may contain your name, contact details, booking reference, travel or event details, and the barcode value. The app also sends your local calendar date to help interpret tickets without a year.

For a camera photo, a scanned PDF or an image with very little readable text, the app may send an image of the selected ticket too. It resizes and re-encodes that image without camera or location metadata before sending it. A normal screenshot or a PDF with readable text usually sends only the extracted information.

Our server sends this information to OpenRouter, which routes it to an AI model provider. The request requires a provider endpoint with zero data retention and disallows provider data collection. The provider processes the request to return pass details. Our server does not save a ticket or pass database.

If you choose “Not now,” that pass is not made and its contents are not sent to the AI service. You can withdraw permission for future passes in the app under Settings → Read with AI. This does not undo processing that already happened.

Pass signing and Apple services

To create an Apple Wallet pass, the app sends its finished pass fields, including any personal details shown on the pass and its barcode, to our Cloudflare-hosted server for signing. The server returns the signed pass without storing a copy in a pass database. If you add it to Apple Wallet, Apple handles that copy under Apple's Privacy Policy.

For some event tickets, the app may send a venue name or address to Apple Maps to find its time zone. Apple may also give us TestFlight feedback, crash information and limited app analytics according to your Apple settings. If you contact us directly, we receive the information you choose to send.

Website and technical information

passmagic.app is hosted by Cloudflare. We do not add advertising cookies or website analytics. Cloudflare processes connection information, such as your IP address, to deliver and protect the website and API. Our server may record technical details such as request time, model used and errors to operate and troubleshoot the service. We do not intentionally log ticket text or images.

Who receives information

We use Cloudflare to host the website and API; OpenRouter and the AI provider it selects to read a ticket; and Apple for app distribution, optional Apple Wallet storage, Photos access and Maps lookups. We share information with these services only as needed for those functions. We may disclose information when legally required. We do not share it for advertising.

Retention and international processing

Originals and passes stay in the app until you delete them or the app. Our server handles ticket and pass contents while fulfilling a request and does not keep them in a database. Service providers may keep limited operational information under their own policies. Cloudflare, OpenRouter and AI providers may process information outside your country, including in the United States.

Your choices and rights

You can choose what to share, control Photos permission in iOS Settings, turn off future AI processing in Passmagic Settings, and delete passes in the app. Depending on where you live, you may also have rights to access, correct or delete personal data, object to or restrict processing, withdraw consent, or make a complaint to a privacy authority.

Email hello@passmagic.app to make a request or raise a privacy concern. Because we do not have accounts or a ticket database, we may have little server-side information to identify or retrieve. We will respond as required by applicable law.

Children and security

Passmagic is not directed at children under 13. If you are a minor, use it with a parent or guardian's permission. Data is sent to our server over an encrypted connection. We limit the ticket information we retain, but no service can promise absolute security.

Changes and contact

We will update this page and its date if our practices change. If we change what the app shares with third-party AI, we will seek any consent required before that sharing. For privacy questions or complaints, email Harris Jose at hello@passmagic.app.