Policies

Docs2Wallet

Privacy Policy · Updated September 29, 2026

This policy describes how the Docs2Wallet iOS app handles information when you turn a document you already have into a personal Apple Wallet pass. Docs2Wallet is published by Arison. The pass is signed with an Apple Pass Type ID certificate issued to Apple Developer Team ID MDV83ZYNR6.

Docs2Wallet makes a personal copy for your own Wallet. The pass states on its back that it was created from your document and was not issued by the event organizer.

Information that stays on your device

You can import a screenshot, a PDF, pasted text, or a ticket link you already have. Docs2Wallet reads that material on your iPhone to suggest pass fields. That reading uses Apple frameworks on the device, including Vision for text and barcodes. When Improve extraction with on-device AI is available and left on, Docs2Wallet uses Apple Intelligence through the on-device Foundation Models framework. The screenshot, PDF, and extracted text are not uploaded for that reading.

If you keep generated passes on this device, Docs2Wallet stores the pass you created in the app’s local storage, protected by iOS file protection. You can delete that local data in the app.

Calendar is optional. After a pass is handed to Wallet, you can save a matching event. That write uses EventKit on your device. Calendar contents are not sent to the signing service.

Information used to sign a pass

You review the pass before it is signed. Only after you confirm does Docs2Wallet send the fields and images for that pass to the signing service. The original screenshot, PDF, or full extraction text is not part of that request.

The signing service builds the .pkpass package, signs it with the Pass Type ID certificate, and returns the file to your device. It does not keep a database of your documents, passes, or Apple ID. The request exists for that signing step and is not retained as a stored pass.

The signing certificate

Apple Wallet accepts a pass when the pass is signed by a Pass Type ID certificate that Apple issued to a developer account. Docs2Wallet uses one certificate for the passes it creates. You can see the same identifiers on the certificate in Apple Developer, under Certificates, Identifiers & Profiles, where it is listed as a Pass Type ID Certificate.

Certificate
Pass Type ID Certificate
Pass Type ID
pass.com.threadedrealm.doc-wallet
Team ID
MDV83ZYNR6
Listed in
Certificates, Identifiers & Profiles

Those two identifiers are written into every pass.json the app signs. passTypeIdentifier must match the Pass Type ID on the certificate. teamIdentifier must match the Team ID on the certificate. Wallet uses that match to attribute the pass to this developer account. The identifiers are not your Apple ID, and they are not the name of the venue printed on the pass. The venue name comes from the document you confirmed. The certificate name is the developer account that signed the file.

The private key for the certificate stays with signing. It is not placed in the pass, and it is not sent to you.

Signing covers the files in the pass package. Docs2Wallet writes manifest.json with a SHA-1 hash of each file, then creates a detached PKCS #7 signature over that manifest with the Pass Type ID certificate. The signature uses SHA-256 and includes a signing time. The public certificate is embedded in the signature so Wallet can check it through Apple’s Worldwide Developer Relations intermediate certificate. When the check succeeds, Wallet treats the text and images in the package as issued under this Pass Type ID.

The certificate binds the pass you approved to Team ID MDV83ZYNR6 and Pass Type ID pass.com.threadedrealm.doc-wallet. It does not insert a separate copy of your personal information. Personal details appear in the pass only when they are part of the fields or images you confirmed.

What the signed pass contains

The signature covers pass.json and the images in the package. Depending on the document you confirmed, pass.json can include:

The package also includes the pass icon and any images you chose to place on the pass. Those image files are hashed and covered by the same signature. Photos you select in the app leave the device only when they are part of the confirmed pass.

A document can contain a person’s name, a confirmation code, a membership identifier, or similar details. If you leave those details in the fields you confirm, they are inside the signed pass and are covered by the certificate in the way described above.

What the certificate does not authorize

The Pass Type ID certificate lets Wallet trust this pass as signed by this developer team. It does not give Docs2Wallet access to the other passes in your Wallet, your Apple ID, iCloud, or apps other than the photos, files, and calendar events you choose inside Docs2Wallet.

The signed pass does not include a webServiceURL or an authenticationToken. Your device does not call Docs2Wallet later to refresh the pass, and Docs2Wallet does not receive a device library identifier or a push token for it. The pass also does not include an NFC payload.

The certificate record in the Apple Developer portal lists the Pass Type ID and the team. It does not list your tickets.

Docs2Wallet does not use the information from your document to track you across apps or websites, and it does not use it for advertising. Docs2Wallet does not sell that information.

Retention and sharing

On the signing service, the confirmed pass is processed to produce the file that returns to your iPhone and is not kept as a stored pass. On your iPhone, a pass you asked the app to keep remains until you delete it, turn off keeping generated passes, or use Delete all data. Removing the pass from Wallet is a separate step in the Wallet app.

Apple receives the pass when you add it to Wallet. Apple’s handling of Wallet is described in Apple’s Privacy Policy. Docs2Wallet does not send Apple the original screenshot as part of signing.

Your choices

Docs2Wallet is not directed to children under 13. Where privacy law gives you a right to ask about the information described here, email the address below. Because the signing service does not keep the pass, deletion of a pass you already created is done on your device and in Wallet.

Changes

If this policy changes, the updated date on this page will change with it. The current version is September 29, 2026.

Contact

Questions about this policy or about Docs2Wallet: arison.dev@gmail.com.