Privacy
Last updated 7 September 2026
How PasserJack handles your account information and saved content, the providers involved, and your choices about your data.
How we use your information
PasserJack uses your information to save and synchronize content, provide sharing and connected-agent features, secure your account, process payments, and respond to support requests.
We do not sell your personal information or use your saved content for advertising. PasserJack does not use your content to train models. There are no advertising or third-party analytics scripts in the application. Optional image analysis involves a separate provider, described below.
Information we store
Account and access information: your Google account identifier, verified email address, name and profile picture; sign-in sessions and provider credentials; API keys and connected-app authorizations; device names, platform and browser details, and activity timestamps. We do not receive your Google password. API keys and device access tokens are stored as hashes. Browser sessions and Google sign-in credentials use separate authentication storage.
Saved content: text, links, code, files, titles, notes, tags, previews, timestamps, the device or agent that supplied an item, and its sharing and expiry settings. Files also have metadata such as their name, type, size and dimensions. Named parts of an item can have revision history. When image analysis is enabled, we store its descriptions, extracted text, labels and other structured results.
Sharing and notifications: trusted-contact email addresses, protected recipient identifiers for restricted links, link expiry and revocation settings, view counts, and signed-in recipient open records. Notification registration details let us reach devices that have enabled push. Email delivery records include the message type and a protected recipient identifier; the sending provider receives the address and message.
Support conversations: the subject, messages, attachments, and optional browser details you choose to send, along with request status and reply history. These are readable by PasserJack support and its authorized support agents; they are separate from your encrypted Vault. Conversations stay with your account until account deletion. Your account export includes customer-visible support history and attachments, but not internal operational notes. Email notifications link back to the conversation without including its contents.
Billing and service operation: Stripe customer and subscription identifiers, plan and billing-period information, usage totals, and operational records used to diagnose errors, prevent abuse and measure service costs. Payment card details are handled by Stripe. Vault reads performed for authorized agents are recorded with the time and calling credential, without recording the content in that audit trail.
Board and Vault protection
Board content is stored in a form the service can read, so it can provide search, previews and sharing. Vault content uses a different protection model: its saved bodies, files and thumbnails are encrypted under keys protected by your trusted devices and recovery code.
Vault captures made through the browser are encrypted on your device before upload. Some capture paths, including API and agent submissions, send content to the server for encryption to your vault's public key. The server processes that plaintext during capture, then stores encrypted content. These paths do not have the same protection before storage as a capture encrypted on your device.
Vault metadata is not encrypted: titles, notes, tags, item kind, filenames, sizes, timestamps, and account and sharing relationships remain available to the service. Keep sensitive information in the content rather than its label or filename.
Agents cannot read your saved vault content by default. If you explicitly unlock the vault for agents, your browser provides the server with a derived read key for the duration you select: 15 minutes, 1 hour or 8 hours. During that window, a credential with Read my vault permission can obtain content on your behalf. The held key stays in server memory and is cleared when the window closes or expires. This permission is called secrets in the API.
Service providers and notifications
Google supplies sign-in identity information. Stripe processes payments and subscription management. Railway hosts the application, database and object storage used for files. These providers process the information needed to perform their respective roles.
Resend delivers billing, sharing and vault-reset emails. It receives the recipient address and message; a sharing email can also include the sender's identity and the share URL. OpenAI provides the image analysis described below.
If you enable notifications, delivery uses your browser's push service or Apple's notification service. Notifications can show snippets of ordinary Board content. Vault notifications do not include decrypted content, but may show a plaintext title, note or tag. Your operating system's notification settings control what appears on your lock screen.
Image analysis and your choice
Where image analysis is enabled for eligible paid accounts, images are sent to OpenAI to generate descriptions and extract text for search. The account setting is enabled by default. Vault content and legacy encrypted attachments are excluded.
The request contains a resized image, our analysis instructions, and technical information about the image's type, dimensions and analysis level. We do not add your account email, filename, title, notes, tags or other saved items to the request. Information visible within the image itself is necessarily included.
OpenAI states that API inputs and outputs are not used for model training by default unless the customer opts in. Its default abuse-monitoring logs may retain customer content for up to 30 days, with exceptions where retention is required by law. This describes the provider's published default policy, not a claim that PasserJack has special zero-retention terms.
To turn analysis off, open Settings, then Privacy, and turn off Describe and read my images. This deletes existing analysis results from PasserJack and removes queued work. A request already sent to the provider may finish, but its result is not saved after the opt-out. Your original images remain. Turning analysis back on does not restore deleted results.
Data stored on your device
PasserJack uses sign-in cookies and local browser storage for account selection, settings, trusted-device keys and pending captures. The service worker caches application assets and an offline page; it does not provide an offline backup of your account.
Pending offline captures, including captures intended for the Vault, can be stored in plaintext on your device until they are encrypted and sent when connectivity returns. Protect access to your device. Clearing site data can remove unsent captures and the keys that make that browser a trusted vault device.
Downloaded files and copies made by other applications remain under your control or those applications' control. Deleting an item from PasserJack does not erase those copies.
Retention and deletion
Saved items remain until you delete them or their chosen expiry is reached. Archiving keeps an item. Expired items become unavailable through normal reads; background cleanup removes their stored records and files later.
Deleting an item removes its active record, associated sharing and history records, and schedules or attempts removal of its files, derivatives and retained file versions. Storage cleanup can take longer if a provider operation fails. Deletion is not a promise of immediate physical erasure from every storage system, backup or recipient's device.
Previous named-part versions are limited to the newest 20 and become eligible for cleanup after 30 days. Deletion synchronization records contain identifiers and a deletion time, not the deleted content, and become eligible for cleanup after 30 days. These cleanups run with service activity, so records can remain beyond those thresholds.
Vault agent-read history remains until the item or account is deleted. Image-analysis call records contain account and file identifiers, model, timing and cost information, without the image or generated answer; they become eligible for cleanup after 90 days. Monthly usage totals are retained separately. Generated analysis remains with its item until deletion or your analysis opt-out.
Account deletion is handled by support and includes the account's content and access records. Billing providers may retain transaction records for their own legal, tax and dispute obligations. Contact us for the scope and handling of an account-deletion request, including any records that must be retained.
Your choices and requests
You can delete items, manage share links, revoke devices, API keys and connected apps, turn off image analysis, and cancel renewal through the billing portal. Subscription cancellation and account deletion are separate actions.
For a copy of your data, account deletion, or questions about your personal information, contact PasserJack support. Support may need to verify that the request concerns your account. Do not send passwords, API keys or your vault recovery code. Vault plaintext can only be exported from a device that can open it; support cannot reconstruct a lost vault key.
Children
PasserJack is not intended for children under 13, and we do not knowingly collect their information.
Policy changes
We update this page and its revision date when our practices change. Contact us if you have a question about this policy or how a change affects your account.
Questions about this policy? Contact PasserJack.