Get the app Book a demo

PRIVACY POLICY

Your details, in plain words.

Last updated: October 11, 2026

This policy says what PassB keeps about you, why we keep it, who else sees it, and how to delete it. It covers the PassB app, the page people see when you share your card, and this website, passb.app.

Who we are

PassB is a product of Omelette Inc., a company in the USA. When this policy says "we" or "us", it means Omelette Inc.

For any question about your privacy, write to contactus@passb.app.

The short version

  • We keep only what PassB needs to work: your account, your card, and a few facts about each link you share.
  • People you scan stay on your phone. We never get their details.
  • The person who opens your link needs no app and no account. Their page has no cookies and no trackers.
  • There are no ads in PassB, and we never sell your data.
  • You can stop any link at any time. When you delete your account, your data is deleted.
  • Questions? Write to contactus@passb.app.

What we collect and why

  • Your account. Your name, your email address and your password. We never keep the password itself, only a scrambled form of it (a "hash") that cannot be turned back into your password. Why: to sign you in and keep your card yours. If you sign in with Google or Apple, see Sign-in with Google or Apple.
  • Your card. What you type on it: your name, job title, company, work email, phone number, website, a few lines about you and up to 6 links, plus the color and style you pick. You can make a card without an account; then it stays on your phone only. Once you sign in, we keep your card on our server with your account. Why: so the links you share can show it, and so your card comes with you to a new phone.
  • Your private links. Each time you show your QR code or share, PassB makes a new random link. We do not keep the link's code in our database. We keep only a scrambled form of it (a hash) and its last 4 letters, so you can tell your links apart. For each link we also keep what it shows (Work or Everything), how you shared it (QR code, link or tap), when it was made, how long it works, when it was stopped, the place you met if you typed one, and how many times it was opened. Why: so the link works, and so you can see and stop your links in Shared with.
  • Cards sent back to you. The page your link opens lets the other person send you their details. We keep what they type (a name, a way to reach them and a short note) with your account, for you only. The app does not show these cards yet; a screen for them is coming. Why: so you can get back in touch.
  • Reports. If someone taps Report this card, we keep the reason they type and which link it was about. We also email it to our team at contactus@passb.app, with the name on the card, your account email and the last 4 letters of the link. We keep nothing about the person who sent the report. Why: to stop spam, fake cards and abuse.
  • Messages to us. If you use the Contact form or the Book a demo form on passb.app, we keep your name, your email, your message (for a demo, also your company, team size and note) and the type of browser you used. We also email a copy to our team. If you email us, we keep your email. Why: to answer you and help fix problems.

PassB does not ask for your home address or your birthday. It has no permission to read your contacts or to know where you are.

What stays on your phone

  • People you scan. When you scan someone's PassB code, the app opens their card from our server, the same way a web browser would. Their details, where you met and your note are then kept on your phone only. We never get them, and neither does anyone else. If you save someone to your phone's contacts, your contacts app keeps that copy. PassB is left out of Google's cloud backup. If you move to a new phone with Android's own phone-to-phone transfer, your People go with you, but your sign-in does not.
  • Your card is kept on your phone too, so your QR code works with no internet. With no internet, when you are signed out, or if a private link cannot be made, the QR code holds your card itself. Then nothing goes through us, and that share cannot be stopped later.
  • The camera is on only while you scan. The QR code is read on your phone by Google ML Kit, a tool from Google that is built into the app. No picture is saved or sent. ML Kit may send Google anonymous numbers about how it runs, never the pictures or the codes it reads.
  • Tap phones (NFC). Only while the Tap screen is open, your phone hands one new private link to a phone held next to it. Nothing else is shared, and nothing at all once you close that screen.

The page people see when you share

When someone opens your link, your card opens in their web browser. They need no app and no account.

  • They see only what you picked. Work shows your work details. Everything adds your phone number and your links.
  • The page uses no cookies and no trackers, and loads nothing from other companies.
  • It is hidden from Google and other search engines.
  • We count opens, not who opened. Each visit adds one to the link's count, and we keep nothing about who the visitor is.
  • We look at the type of phone only to show the right app store link, and we do not keep it.
  • If they send you their card or report your card, we keep only what they type, as described above.
  • Our web server's standard log covers this page too, for up to 30 days (see The website passb.app). For this page, the log includes your private link itself.

The website passb.app

  • No cookies, no analytics and no trackers.
  • Our fonts are on our own server, so your browser does not ask Google or anyone else for them.
  • Our web server keeps a standard log of visits (internet address, browser, the page asked for and the time) for up to 30 days, for security, and then deletes it. On the share page this includes the private link itself; we never keep link codes in our database.
  • If you use the Book a demo form, we keep what you send, as in Messages to us.

Sign-in with Google or Apple

You can sign in with your email and a password, or let Google or Apple sign you in. On Android, PassB offers Google. PassB for iPhone is coming soon, and will offer Apple and Google.

  • Google tells us your name, your email address and an ID number for your Google account.
  • Apple tells us your email address, or a hidden Apple address that passes mail on to you if you choose to hide yours. It tells us your name the first time only, and an ID number for your Apple account. Apple also gives us a code, so we can ask Apple to unlink PassB when you delete your account.
  • We never see your Google or Apple password. Google and Apple handle the sign-in under their own privacy policies.

Who we share data with

We share data only to run PassB:

  • Our hosting company in the USA runs the server and the database that hold your account, your card and your links, and keeps the server logs.
  • Email delivery. The emails we send, such as a code to reset your password or to delete your account, go out through our email service. Emails you send us arrive there too.
  • Google and Apple, only when you choose to sign in with them. Google ML Kit's anonymous numbers are described above.
  • The people you share your card with see what you chose to show them.

We never sell your data. There are no ads in PassB, and we do not share your data with advertisers.

The shared Omelette account

Your PassB account is an Omelette account. The same account also signs you in to our other apps, such as PubMed Hub and SciRead. If you open another Omelette app from More while you are signed in, PassB hands it a one-time sign-in pass, so you do not have to sign in again. If that app is not on your phone yet, the pass goes inside the Google Play link, and the new app reads it when it first opens. The pass works once, for that one app, for 10 minutes.

Because it is one account, deleting it deletes it in every Omelette app. Our other apps have their own privacy policy.

How long we keep data

  • Your account and your card: until you delete your account.
  • Your links end by themselves when the time you picked runs out (1 hour, 1 day or 1 week), or when you stop them. A link set to last until you stop it works until you stop it. After a link ends, we keep its record (never the code) so it can show in Shared with, until you delete your account.
  • QR links that nobody opened are deleted once they are 7 days old. We clear them the next time you share.
  • Cards sent back to you: until you ask us to delete them, or delete your account.
  • Reports: as long as the link they are about, which is until you delete your account.
  • Messages to us: kept for 1 year, then deleted automatically (or sooner if you ask).
  • Server logs: up to 30 days, then deleted.
  • Everything tied to your account is deleted when you delete your account.
  • Backups: our hosting company may keep backup copies of the database. Deleted data can stay in a backup copy until that copy is replaced.

Deleting your account

In the app, go to More, then Account, then Delete my account. If your account has no password (for example, you made it with Google), we email you a code to make sure it is you. Or write to contactus@passb.app from the email on your account, and we will delete it for you.

This deletes for good your Omelette account (in PassB and every Omelette app), your card, your links, the cards sent back to you and any reports about your links. If you signed in with Apple, we also ask Apple to unlink PassB.

What stays:

  • A blank record that an account once existed and when it was deleted. It holds no name, email or other details.
  • Messages you sent us, with the name and email you wrote in them, no longer linked to your account. They are deleted after 1 year, or sooner if you ask.
  • Copies of your card that people already saved stay on their phones. We cannot reach them.
  • People you scanned stay on your phone until you remove them or remove the app. Signing out removes your card from that phone.
  • Backup copies, until they are replaced, as above.

Your rights

Wherever you live, you can ask us to:

  • See the data we keep about you.
  • Correct it. You can also fix your card in the app at any time.
  • Delete it.
  • Export it, so you get a copy in a common file format.

In the EU and the UK, the GDPR gives you these rights. You can also ask us to stop or limit how we use your data, and you can complain to your local data protection authority. We use your data to give you the service you asked for, to keep PassB safe, and when the law requires it.

In California, the CCPA gives you the right to know, correct and delete your data, and to say no to its sale or sharing. We do not sell your data, and we do not share it for ads. We will not treat you differently for using your rights.

How to ask: write to contactus@passb.app. We may ask you to write from the email on your account, so we know it is you. We answer within 30 days.

Security

  • Everything between the app, your browser and our server travels over a locked, encrypted connection (HTTPS).
  • Passwords are kept only as hashes. So are link codes, so a copy of our database would not open anyone's card.
  • Rate limits: we limit how fast anyone can try links, send cards back or send reports, so guessing links and flooding you with spam do not work. For this we count tries from each internet address for a minute or an hour, in the server's memory only, and do not save them.
  • Private by default: your card is not a public web page. It opens only through a link you chose to share, for only as long as you choose.

Where data is stored

Your account, your card and your links are kept on our server in the United States, which we rent from our hosting company. If you live outside the USA, using PassB means your data is sent to and kept in the USA.

Children

PassB is a business card app for adults. It is not for children under 13, or under 16 in the European Union, and we do not knowingly collect data from them. If we learn that such a child has an account, we delete it. If you think a child has given us data, write to contactus@passb.app.

PassB for Teams

PassB for Teams is coming soon. It is not built yet, so it collects nothing today. As we plan it, a company admin will see only work activity and work contacts: the shares of your work card, how many times they were opened, and your work contacts (cards sent back to your work card, and cards you scan and mark as work). They will never see your personal contacts, your personal card or where you are. We will update this policy before Teams launches.

Changes to this policy

If we change this policy, we post the new version here with a new date at the top.

Contact

Omelette Inc., USA. Write to contactus@passb.app. We read every message. The rules for using PassB are in our terms of use.