Privacy & Data FAQ

Frequently asked questions about how NeatPass handles your data, privacy, and security.

2 min read

NeatPass was built with privacy as a core principle. Your tickets stay on your device, processed by on-device AI, with no cloud uploads and no tracking.

The short version

Everything happens on your iPhone. Your tickets never leave your device. We collect no data. The only network connection is a brief hash exchange when adding to Apple Wallet.

On-Device Processing

AI Runs Locally

The AI model is bundled with the app (~1GB). Text extraction, barcode detection, and pass creation all happen on your iPhone.

No Cloud Processing

Your PDFs and images are never uploaded. There's no cloud API, no server seeing your tickets.

Works Offline

Import and process tickets without internet. Only adding to Apple Wallet needs a brief connection.

What Happens When Adding to Wallet

Apple Wallet passes must be cryptographically signed to work. This is the only time NeatPass connects to the internet.

How Signing Works

Only a Hash Is Sent

NeatPass sends a hash (cryptographic fingerprint) of the pass to our signing server. The actual content, barcode, images, and personal details stay on your device.

Hashes Are One-Way

A hash cannot be reversed. It's mathematically impossible to reconstruct your ticket from the hash. It only proves the pass hasn't been tampered with.

Signature Returned

Our server returns a cryptographic signature. The signed pass is assembled entirely on your device.

Why signing is required

Apple requires all Wallet passes to be signed with a developer certificate. This prevents counterfeit passes. Our server only handles the signature, never your ticket data.

We Never See

Your tickets

PDFs, images, screenshots you import

Event details

Names, dates, venues, seat numbers

Barcode data

The actual content of your barcodes

Personal info

Names, emails, booking references

Your behavior

How you use the app

We Never Collect

Analytics

No usage tracking or metrics

Crash reports

Only if you choose to send them

Tracking IDs

No profiles built, no cross-app tracking

Location

Never accessed

Anti-abuse protection

A device ID is stored temporarily to verify signing requests come from the app. It's not linked to you and is auto-deleted 12 months after your last use.

Data Storage

All data is stored locally on your device, protected by iOS encryption. No cloud sync, no external servers. Delete passes anytime or uninstall the app and everything is gone.

See data management for details on storage and backups.

Common Questions

Summary

All AI processing happens on your device
Tickets and personal data never leave your iPhone
Only a hash is sent for Wallet signing (no ticket content)
No analytics, no tracking, no accounts
Delete the app and your data is gone

More Information

See our full Privacy Policy for the legal details. Learn about data management for storage specifics. Read about the on-device AI model and offline mode.