Walt is published by Embedded Engineering ApS, a company registered in Denmark. This policy covers three things: how the walt.is website handles data when you join the waitlist or take out a membership, and how the Walt Android and iOS apps handle data on your device.
Website & waitlist·Android app·iOS app
Website & waitlist
Controller
Embedded Engineering ApS, Godsbanegade 31, 1722 Copenhagen, Denmark (CVR 45749355) is the data controller for personal data collected through walt.is. Privacy contact: privacy@walt.is.
What is collected and why
When you join the waitlist, Walt collects the email address you submit. It is used to manage the waitlist and to send product updates about Walt. No other personal data is collected through the form.
Lawful basis
Processing is based on your consent under GDPR Article 6(1)(a). You give consent by submitting the waitlist form after reading the inline notice on the form. You can withdraw consent at any time using the unsubscribe link in every email, or by emailing privacy@walt.is. Withdrawal does not affect processing that already took place under your earlier consent.
Who processes your data
Walt uses the following processors to operate the website and send waitlist emails:
- Resend — delivers waitlist confirmation and product update emails. Resend is a US company; the data protection addendum is available at resend.com/legal/dpa.
- Vercel — hosts the walt.is website and serverless functions that handle waitlist submissions. Vercel is a US company. Their DPA is available at vercel.com/legal/dpa.
- Plausible — provides cookieless, EU-hosted website analytics. No cookies are set, no cross-site identifiers are used, and visitor IPs are not stored.
International transfers
Resend and Vercel are based in the United States, so your email address and waitlist submission metadata are transferred to the US for processing. Transfers rely on the EU Standard Contractual Clauses incorporated in each provider's data protection addendum. Walt is actively working to move waitlist email delivery and website hosting to EU-based providers; this section will be updated when that migration is complete.
Retention
Your email is kept on the waitlist until you unsubscribe. After unsubscribe, the address is retained for a short grace period (up to 30 days) to honor the unsubscribe and prevent accidental re-subscription, and is then deleted from active systems. Provider backups roll off on each provider's own schedule.
Membership payments
Walt membership is optional. If you choose to subscribe, payment is handled by Paddle, our authorised reseller and Merchant of Record — Paddle is the seller of record for the transaction (see the legal disclosure). The checkout runs in an embedded frame hosted by Paddle on a separate domain (buy.paddle.com); the email and payment details you enter there are submitted directly to Paddle as its own controller. The lawful basis for this processing is performance of your membership contract under GDPR Article 6(1)(b).
Inside the checkout frame the only cookies set are strictly necessary functional and security cookies that Paddle uses to process the payment and prevent fraud. No advertising, analytics, or session-recording scripts are loaded in the checkout. How Paddle handles your data is described in its privacy policy.
Cookies and tracking
walt.is sets no cookies of its own and uses no cross-site trackers; Plausible analytics is cookieless. The one exception is the membership checkout: if you choose to subscribe, Paddle's embedded checkout frame sets strictly necessary functional and security cookies to process the payment and prevent fraud (see Membership payments). No advertising, analytics, or tracking cookies are used anywhere on the site.
Your rights
Under GDPR you have the right to:
- access the personal data Walt holds about you,
- have inaccurate data corrected,
- have your data deleted,
- receive your data in a portable, machine-readable form,
- object to processing,
- withdraw consent at any time without affecting prior lawful processing.
To exercise any of these rights, email privacy@walt.is. You also have the right to lodge a complaint with the Danish supervisory authority, Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark.
Android app
The following sections describe how the Walt Android app handles your data.
What the current release does
The current release of Walt is a passes wallet. You can import digital passes (boarding passes, event tickets, loyalty cards, and similar .pkpass files), PDF documents, photos, and plain barcodes into the app, view their details, and display their codes. Items are added by opening a .pkpass file from another app, sharing an image, a .pkpass or PDF file, or a link to Walt through the Android share sheet, picking a file or a photo from inside the app, scanning a code or snapping a photo with the camera, or typing a code in by hand.
Everything you import is stored in Walt's private app-sandbox storage on your device, encrypted at rest, and excluded from Android Auto Backup and device-to-device transfer. Walt does not transmit pass data, pass barcodes, pass contents, or the images and documents you import off your device. There is no Walt account and no server-side database of your passes.
Network access
Walt for Android makes two kinds of network request, and no others.
The first happens only when you ask for it. If you add a pass from a download link, the app shows you the link and asks you to confirm before it fetches anything; on confirmation it makes a single anonymous HTTPS request to that address to download the file. The request carries no cookies, no credentials, and no identifier for you or your device, and nothing from your wallet is sent with it.
The second is the diagnostics upload described in the next section. It is off by default and never runs unless you turn it on.
Camera and photos
Scanning a code with the camera decodes the frames on your device and discards them. If you snap a photo or import one from your library, that image is kept in your wallet on your device and is never uploaded. Walt does not ask for access to your photo library; the system picker hands Walt only the image you chose.
Diagnostics and analytics
Walt records a small, bounded log of app diagnostics on your device so that it can be sent later if you choose to send it. This local log holds at most a couple of hours of recent activity and is overwritten as it fills. Nothing leaves your device from it unless you switch diagnostics on.
Uploading is off by default. Under Settings, then Telemetry, you control three categories independently — Crash reports, Performance, and Product analytics — and each one can be Off, on for the next 3 hours, or Always. There is also a Send last 30 minutes of logs button, which sends only that window and turns nothing on. Switching a category off stops uploads for it immediately.
What the log can contain is restricted at the point it is written, not at the point it is sent. Walt only admits values that match a narrow, fixed shape — short identifiers such as an event name, a screen name, a duration, or an error type — and strips anything else. Free-form text, email addresses, phone numbers, and card-length digit sequences are rejected by that filter. Walt never records the names, contents, barcodes, images, or issuers of the items in your wallet, nor the addresses of links you fetch.
When you have switched a category on, the corresponding data is sent to the processors below. Crash reports and performance data go to a diagnostics collector operated by Embedded Engineering ApS on servers in the EU. Product analytics go to PostHog (PostHog Inc.), on its EU-hosted infrastructure, acting as a processor for Walt. Both are reached over HTTPS. The crash and performance path sends no device or installation identifier. The PostHog SDK does generate and store a random per-installation identifier so that events from one install can be counted together; it is not linked to your name, email address, account, or any pass content, and it is discarded when you delete the app.
Walt does not use an advertising ID, does not build advertising or marketing profiles, and does not sell or share this data with anyone beyond the two processors named above.
Push notifications
Walt for Android does not use push notifications. The app contains no push messaging SDK, never registers for remote messages, and never asks you for notification permission, so no push token is issued for it.
Payments
Tap-to-pay and bank-card features are a planned future capability and are not active in the current release. The app ships with no payment SDK and performs no contactless payment. Any payment functionality is pending regulatory and compliance review. When and if these features are introduced, this policy will be updated to describe how card and transaction data are handled before the functionality is enabled for users.
Data deletion
Walt stores all pass data locally on your device. There is no server-side account to delete and no central database holding your passes.
To delete your Walt data:
- Open Android Settings on your phone.
- Tap Apps and find Walt in the list.
- Tap Storage and cache, then Clear storage. This deletes all imported passes, pass barcodes, pass details, imported documents and images, app preferences, and the local diagnostics log immediately.
Or, to remove Walt entirely:
- Long-press the Walt app icon and tap Uninstall.
- Confirm. Android removes the app and all of its data.
What gets deleted: every pass, document, image, and barcode you imported, all pass details, your app preferences, the diagnostics log held on the device, and the per-installation analytics identifier.
What Walt retains after deletion: nothing from your wallet. Walt does not transmit pass data off your device, so there is no copy on any server to retain. If you switched diagnostics on at some point, the anonymous diagnostic events already sent remain in the systems described above; write to privacy@walt.is to have them removed.
Questions: contact privacy@walt.is.
iOS app
The following sections describe how the Walt iOS app handles your data.
What the current release does
The current release of Walt for iOS is a passes wallet. You can import digital passes (boarding passes, event tickets, loyalty cards, and similar .pkpass files), PDF documents, photos, and plain barcodes into the app, view their details, and display their codes. Items are added by opening a .pkpass file from another app, sharing an image, a .pkpass or PDF file, or a link to Walt through the iOS share sheet, picking a file or a photo from inside the app, scanning a code or snapping a photo with the camera, or typing a code in by hand.
Everything you import is stored in Walt's private app sandbox on your device, protected by iOS Data Protection, and excluded from iCloud and device backups. Walt does not transmit pass data, pass barcodes, or pass contents off your device. There is no Walt account, no server-side database of your passes, and no telemetry that records what passes you hold or how you use them.
Network access
Walt for iOS makes one kind of network request, and only when you ask it to. If you add a pass from a download link, the app shows you the link and asks you to confirm before it fetches anything; on confirmation it makes a single anonymous HTTPS request to that address to download the file. The request carries no cookies, no credentials, and no identifier for you or your device, and nothing from your wallet is sent with it. Apart from this, the app makes no network requests at all.
Camera and photos
Scanning a code with the camera decodes the frames on your device and discards them. If you snap a photo or import one from your library, that image is kept in your wallet on your device and is never uploaded. Walt does not ask for access to your photo library; the system picker hands Walt only the image you chose.
Push notifications
Walt for iOS does not use push notifications. The app never registers for remote notifications and never asks you for notification permission, so no push token is issued for it.
Payments
Tap-to-pay and bank-card features are a planned future capability and are not active in the current release. The app ships with no payment SDK and no contactless-payment entitlement. Any payment functionality is pending regulatory and compliance review. When and if these features are introduced, this policy will be updated to describe how card and transaction data are handled before the functionality is enabled for users.
Data deletion
Walt stores all pass data locally on your device. There is no server-side account to delete and no central database holding your passes.
To delete a single item, open it and tap Delete pass (or Delete file for a document or photo), or swipe it away in the list. To delete everything at once, remove the app:
- Touch and hold the Walt app icon on your Home Screen.
- Tap Remove App, then Delete App, and confirm. iOS deletes the app together with its whole container: every imported pass, all barcodes and details, and app preferences.
What Walt retains after deletion: nothing. Walt does not transmit pass data off your device, so there is no copy on any server to retain.
Questions: contact privacy@walt.is.