Privacy Policy
Last Updated: September 18, 2026
Passboards, Inc. (“Passboards,” “we,” “us” or “our”) makes an iPhone app and a website (www.passboards.com) that let a group of people put their photos and videos from a trip, a party or a club into one shared board. This Privacy Policy explains, in plain language, what information we collect when you use the Passboards app and website (together, the “Services”), what we do with it, who else sees it, how long we keep it, and the choices and rights you have. It is written to describe what the app and our servers actually do today. If we build something that changes it, we will update this page first.
The short version: we collect what we need to run a shared photo service, plus one thing we hold but do not use yet (the private capture coordinates described in 2(d)). We do not use Location Services, we do not use advertising identifiers, we do not show ads, we do not sell your information and we do not track you across other companies’ apps or websites.
1. Who Is Responsible
Passboards, Inc., PO Box 127, Danville, CA 94526, United States, is the company responsible for your information (the “data controller,” in the words of European law). You can reach us at [email protected].
2. What We Collect
(a) Your account. When you sign up we ask for your name, a username, your email address and a password, and you can add a profile photo and a short bio. Sign-in is handled by Firebase Authentication, a Google service. At sign-up your password is sent to our server once so that we can create your Firebase account; we do not store it. Firebase stores your email address and a hashed form of your password, and issues the sign-in token the app uses to talk to our servers. We do not offer Sign in with Apple or Google sign-in. You confirm at sign-up that you are at least 18.
(b) What you post. Boards, the photos and videos you post to them, post titles and captions, comments, @mentions and people you tag, likes and saves, follows and follow requests, club memberships, events and RSVPs, club announcements and any place you choose to attach to a post, board or event. Direct messages are covered in (i).
(c) Your photos and videos, and the files themselves. When you post a photo we make a resized copy (up to 1600 pixels on the long side) to show in the app; videos are re-encoded to a 720p-class copy. Before anything is uploaded the app strips the location, camera and device metadata (EXIF and similar) from the file, so the copies we store and show contain none of it. If you subscribe to Passboards Premium, the original file is also kept, metadata-stripped, up to 4 GB per file (see Section 8).
(d) Where a photo was taken — kept private. When you post a photo or video, the app reads the location that your iPhone’s Photos library recorded for it (if any) and sends those coordinates to us along with the post. We store them in a separate, private table. They are never shown to anyone — not to other members, not on share cards, not on the website, and not to you inside the app — and no part of the app can read them back. They exist so that we could offer a location feature later (for example, a map of a trip); if we ever build one, we will update this policy and tell you before any of this data becomes visible. These coordinates are deleted when the post is deleted, and with your account.
(e) Places you choose. Separately from (d), you can pick a place name for a post, board or event. A place you pick — its name and, if the name resolves to one, its coordinates — is part of the post and is visible to everyone who can see that post, board or event, including on the web share card.
(f) Finding friends from your contacts (optional). If you choose to find people you know, the app hashes the email addresses and phone numbers in your address book on your phone (SHA-256, one way) and sends only those hashes — at most 10,000 — to our servers, which compare them against the hashes of Passboards users’ own emails and phone numbers and return the matches. Names and raw addresses never leave your phone, and we do not keep the hashes you upload. We do store a hash of your own account email (and of a phone number, if one is ever on your account — the app does not ask for one today) so that friends can find you the same way. You can turn this off with the “Let others find me by my contacts” switch in the app; when it is off, nobody can find you through their contacts.
(g) Push notifications. If you allow notifications, the app registers a push token for your device with Firebase Cloud Messaging (Google) and we store that token so we can send notifications about activity on your boards, clubs and messages. Turning notifications off in iOS Settings stops them.
(h) Settings and choices. Whether your profile is private, whether you are discoverable by contact, whether read receipts are on, whether your blue check is shown, and your email preferences.
(i) Direct messages. The content of your one-to-one messages, reactions, posts, boards and profiles you share into a chat, and read receipts (if you have them on; turning them off also stops you seeing other people’s). Messages are stored on our servers so they can be delivered and shown on your devices; they are not end-to-end encrypted. Deleting a conversation removes it from your account; the other person’s copy stays with them.
(j) Premium subscription records. If you buy Passboards Premium, Apple handles the payment and we never see your card or bank details. Apple sends us a record of the subscription: transaction identifiers, the product you bought, purchase and expiry dates, whether it will auto-renew, and status changes (renewal, cancellation, billing problems, refund). We keep this history so we know what you are entitled to and to reconcile with Apple.
(k) Email. We use your email address to send account emails (a welcome email, and a one-time “welcome back” email with a password-reset link if we have had to restore your account) and, unless you opt out, occasional product updates. Product-update emails have an unsubscribe link, and mail apps can unsubscribe you with one click. Our own emails are delivered by Postmark; we record when an email was sent and whether it was delivered, bounced or marked as spam, and we stop sending to addresses that bounce or complain. Password-reset emails you request from the sign-in screen are sent by Firebase (Google).
(l) Support. When you use the support form on our website we receive the name, email address and question you type, by email to [email protected]. If you email us directly, we receive what you send.
(m) Technical data. Our servers see your IP address with each request and use it to rate-limit sign-ups, prevent abuse and diagnose problems. Requests reach us through Cloudflare, which sees the same connection data as a network provider. We keep ordinary server logs for up to about 30 days.
(n) Usage analytics — not yet enabled. The app includes the PostHog analytics library, which is switched off unless we configure it. If we turn it on, it will record which screens and features are used, tied to your account identifier, so that we can see what works and what does not. It does not use advertising identifiers and we do not share it with advertisers. Before we turn it on we will update this policy and ask for your permission in the app, and you will be able to switch it off in the app’s settings.
(o) The website. Our public web pages set no cookies and run no analytics. The only cookie on passboards.com is a sign-in cookie for our own staff on the private admin console. Public boards and profiles can be viewed on the website without an account (see Section 5).
3. What We Do Not Collect
- Your phone’s location. The app never asks for or uses Location Services. The only location data we hold is what is described in 2(d) and 2(e).
- Advertising identifiers (IDFA) or any advertising SDK. There are no ads in Passboards.
- Your address book in readable form (see 2(f)).
- Crash reports through a third-party crash-reporting service.
- SMS or text messages.
- Data about you from data brokers or other companies.
We do not sell your personal information, we do not “share” it for cross-context behavioral advertising, and we do not track you across other companies’ apps or websites.
4. How We Use Your Information
- To run the Services: show your boards and posts to the right people, deliver messages and notifications, match contacts you ask us to match, and keep your Premium entitlements right.
- To keep the Services safe: prevent spam and abuse, enforce our Terms of Service, respond to reports and flags, and protect our systems.
- To communicate with you: account emails, replies to support requests, and product updates you have not opted out of.
- To improve the Services, using analytics if and when they are enabled.
- To meet legal obligations.
5. Who Can See Your Content
- Public boards and public profiles can be found and viewed by anyone, including on the web at passboards.com without an account, and through the search and Explore features of the app. When a share link to one of them is pasted into a message or social app, it shows the board or profile title and a preview image. Public clubs can be found through the app’s search; on the web a club is reachable only through an invite link.
- Private boards are visible only to the people who have been added to them. Private profiles are visible only to approved followers. Private clubs are visible only to their members, and can be joined only by invitation — an in-app invite, or an invite link created by the club’s host or co-hosts.
- Posts you make to a board that belongs to someone else are visible to that board’s members, and stay on the board if you leave it. Messages you send in a club chat stay in the chat if you leave the club. Deleting your account removes your posts and comments everywhere; messages you sent remain visible to the people you sent them to, attributed to a deleted account.
- Members who subscribe to Premium can download posts on boards they belong to, including yours, at the best quality available.
- A blue check on a profile means only that the account pays for Premium. It is not a verification of identity.
Please use care before revealing anything that identifies you in the real world in a public board or profile.
6. Who We Share Information With
We share information only with the service providers we need to run Passboards, each under a contract that limits what they may do with it:
- Google (Firebase Authentication and Firebase Cloud Messaging) — sign-in and push notifications.
- Postmark (ActiveCampaign) — sending email.
- Cloudflare — the network in front of our servers (content delivery, DNS and tunneling); it processes connection data such as your IP address.
- PostHog — usage analytics, only if and when we enable it.
Apple processes your App Store purchase of Passboards Premium under its own privacy policy and sends us the subscription record described in 2(j). Your data is otherwise stored on servers we operate ourselves in the United States. We may also disclose information if the law requires it, to protect the safety of a person, to enforce our Terms, or as part of a merger, acquisition or sale of the company, in which case we will tell you before your information becomes subject to a different privacy policy. We do not sell personal information.
7. How Long We Keep It, and Deleting Your Account
- Content you post stays until you delete it or your account. Deleting a post also deletes its private capture coordinates (2(d)) and any stored original.
- You can delete your account in the app under Settings › Account Deletion (or by emailing [email protected] from your account email). Deletion is immediate and permanent: your profile and photo, the boards you own and everything on them, your posts and comments on other people’s boards and on club boards, your likes, saves, follows, notifications, push tokens, email preferences and any stored originals are removed from our live systems; your contact hashes stop being matchable; and your username and email address become available again. Clubs you own are deleted. Direct messages and club-chat messages you sent remain with the people you sent them to, shown as coming from a deleted account, so that their side of the conversation is not lost. Your subscription records are deleted too (Apple keeps its own record of your purchases), and we keep only an anonymous log that emails were sent, with the address and content removed.
- If your email address ever bounced or you reported one of our emails as spam, we keep that address on a suppression list so we never email it again, even after account deletion.
- Backups. We back up our database every night. Daily backups are kept for 14 days and weekly backups for up to 8 weeks. Copies are also exported to offline drives we keep ourselves, not to any cloud service; on those drives daily backups are removed after 90 days and weekly backups after a year, and media files you delete are held for 30 days before removal. Something you delete can therefore remain in a backup for up to about two months, and on an offline copy for up to a year, before it is gone everywhere. Backups are used only to recover from a failure, never to restore deleted accounts.
- Deleting your account does not cancel a Passboards Premium subscription; cancel it in your Apple Account (formerly Apple ID) subscription settings.
8. Passboards Premium and Stored Originals
If you subscribe to Premium, the original files of the photos and videos you post (metadata-stripped, up to 4 GB each) are kept in addition to the standard copies, and you can download any post you have access to at the best quality that exists for it. If your subscription ends, we do not delete or downgrade the originals already stored because of that; new posts keep only the standard copy, and downloads stop until you subscribe again. Originals are deleted when you delete the post or your account.
9. Children
Passboards is for adults. You must be at least 18 to create an account, and we do not knowingly collect information from anyone under 18. If we learn that an account belongs to someone under 18, we delete it and its information. If you believe a child is using Passboards, email [email protected].
10. Your Choices
- Profile privacy, “Let others find me by my contacts”, read receipts and the blue check are all switches in the app.
- Push notifications can be turned off in iOS Settings.
- Product-update emails have an unsubscribe link in every message.
- You can edit your name, username, bio and profile photo in the app, and delete individual posts, comments, boards and conversations at any time.
11. Your Rights
Wherever you live, you can ask us to tell you what personal information we hold about you, to correct it, to delete it, or to give you a copy of it in a portable form. Most of this you can do yourself in the app; for anything else, email [email protected] from the email address on your account. We will verify that the request comes from the account holder before acting on it, respond within the time the law allows (normally 30 days, or 45 days for California requests), and we will never treat you differently for exercising your rights. You may use an authorized agent to make a request on your behalf; we will ask for proof that you authorized them.
California residents (CCPA/CPRA). In the last 12 months we have collected the categories of personal information described in Section 2: identifiers (name, username, email, hashed phone/email, account and device identifiers, IP address), account and subscription records, the content you post and send (including photos and videos, which may contain your image), the private capture coordinates described in 2(d), usage data if analytics are enabled, and the settings you choose. We collect it from you, from your device, and from Apple and Google in the course of sign-in and purchases, for the purposes in Section 4, and disclose it to the service providers in Section 6 for business purposes only. We do not sell personal information, we do not share it for cross-context behavioral advertising, and we have no actual knowledge of selling or sharing the personal information of anyone under 16. We do not use or disclose sensitive personal information for purposes other than providing the Services. You have the right to know what we collect and how we use and disclose it, to delete it, to correct it, to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights. To exercise them, email [email protected] with “California privacy request” in the subject line, or use the tools in the app.
Residents of other US states with privacy laws have the same rights described above. If we refuse a request, you can appeal by replying to our decision, and we will tell you how to complain to your state attorney general.
European Union, EEA and United Kingdom residents (GDPR / UK GDPR). Our legal bases are: performance of our contract with you (running the Services you signed up for, including Premium); your consent (matching your contacts, push notifications and product-update emails — each of which you can withdraw at any time in the app or in iOS Settings — and usage analytics, which we will ask for in the app before enabling them); our legitimate interests in keeping the Services secure and free of abuse, in communicating with you about your account, and in holding the private capture coordinates described in 2(d) so that a future location feature would not require you to re-upload your photos (you can avoid this by removing the location from a photo before posting it), balanced against your rights; and compliance with legal obligations. You have the rights to access, rectify, erase and port your data, to restrict or object to processing, and to withdraw consent, and you may lodge a complaint with your national data protection authority (in the UK, the Information Commissioner’s Office). We do not make decisions about you by automated means that have legal or similarly significant effects. We have not appointed a representative in the EU or the UK; contact us directly at [email protected]. Your data is processed in the United States, as described in Section 13.
12. Security
Traffic between the app, the website and our servers is encrypted in transit. Passwords are stored by Firebase Authentication in hashed form; our servers handle your password only once, at sign-up, and never store it. Media is served through signed, expiring links. Access to production systems and backups is limited to the people who operate Passboards. No system is perfectly secure; if we learn of a breach affecting your personal information we will notify you and the authorities as the law requires.
13. Where Your Data Lives and International Transfers
Our servers are in the United States, and the providers in Section 6 process data in the United States and, in some cases, in other countries where they operate. If you use Passboards from outside the United States, your information is transferred to and processed in the United States, whose laws may differ from those of your country. Where the law requires a specific safeguard for such transfers (for example, for EU, EEA, UK or Swiss residents), we rely on the mechanisms recognized under that law, such as the standard contractual clauses in our agreements with those providers.
14. Changes to This Policy
We will update this policy when the Services change in a way that affects your information. We will post the new version here with a new “Last Updated” date and, for material changes, tell you in the app or by email before they take effect. Where a change needs your consent under the law where you live, we will ask for it.
15. Contact
Questions, requests or complaints: [email protected], or by mail to Passboards, Inc., PO Box 127, Danville, CA 94526, United States.