Privacy
Effective October 7, 2026
pastport is built so your inbox and your ticket details stay on your phone. This page explains what the app reads, what it stores, and what anyone else can see.
Signing in
You sign in with Google. pastport receives your name and email address to create your account. Signing in does not give pastport access to your Gmail.
Gmail (optional)
If you choose to connect Gmail, pastport asks for read-only access (gmail.readonly). It can't send, delete, or change any email.
- The app searches for emails that look like tickets (for example from Ticketmaster, AXS, SeatGeek or DICE) and reads only those.
- Emails are read and parsed on your phone. Email contents are never sent to pastport's servers.
- From each ticket email the app keeps the event details: name, venue, city, date and, if present, your seat. It also keeps the seller, order number and email IDs so it doesn't import the same night twice. That information stays on your phone.
- The Gmail access token is stored in your phone's Keychain. You can disconnect Gmail at any time in the app (Account → Ticket emails) or at myaccount.google.com/permissions.
What is uploaded
When you're signed in, cards you have opened sync to pastport's database (hosted by Supabase) so they're backed up and can be shared:
- the event details on the card (name, venue, city, date, seat if known) and its tier;
- the photo or video you added to the card;
- your profile (name and the handle you choose) and who you follow.
Cards you haven't opened yet, and ticket-email details like the seller, order number and email IDs, are never uploaded.
To grade a card, the app sends the event's name, date, venue and city to pastport's server, which looks the artist or team up in public sources (MusicBrainz, ESPN and YouTube). Nothing about you is included in those lookups.
Who can see your cards
Only people who follow you, and only cards you've posted. This is enforced by the database itself, not just the app. Cards you haven't posted are visible only to you.
Photos
pastport asks for photo access only when you choose to add a photo or clip. It uses that access to suggest photos from the night of an event. Only the photo or clip you put on a card is uploaded.
What we don't do
- No ads, and no selling or renting your data.
- Data from Gmail is not used for advertising, is not transferred to anyone else, and is not read by people, except with your permission, for security reasons, or as required by law.
- No Gmail data is used to train AI models.
pastport's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Deleting your data
Deleting a card in the app also removes it, and its photo or clip, from the server. Deleting the app removes everything stored on your phone. To delete your account and everything synced to it, email [email protected] from the address you signed in with, and it will be deleted within 30 days.
Beta
pastport is in beta. If you install it through TestFlight, Apple may share crash reports and feedback you choose to send.
Changes and contact
If this policy changes, the date at the top will change too. Questions: [email protected].