Legal and trust

Privacy policy

Last updated 22 July 2026

Your passport is private by default. This policy explains who is responsible for your information, what Autismy stores, and the choices available to you.

Who is responsible for your information

Autismy is operated by Karan Dharamshi, an independent developer based in the United Kingdom. Karan Dharamshi is the data controller for the family service described in this policy.

For privacy questions, rights requests, or a correspondence address, email support@autismy.app.

Who can hold an account

Autismy accounts are for adults aged 18 and over. An autistic adult may create their own passport. A parent, legal guardian, or authorised carer may create a passport for someone they support, including a child.

If you create a passport about another person, you must be authorised to manage the information. You should involve the person wherever appropriate, respect their wishes, and avoid recording information that is not needed.

Information Autismy may hold

  • Account details, such as your name, email address, sign in provider, and account identifier.
  • Profile details, such as a name, preferred name, date of birth, relationship, diagnosis status, and emergency contact.
  • Passport content, including communication, sensory, support, school, healthcare, and urgent support information.
  • Information you choose to add to routines, check ins, feedback, or uploaded documents where those features are available.
  • Sharing and security records, such as when a link is created, opened, expired, or revoked. These records may include an IP address, device or browser information, and a request identifier.
  • Basic product analytics after you consent, without passport field content.
  • Messages you send to support.

Health and other sensitive information

Passport content may reveal health information and is likely to include special category personal data. Autismy processes this information to provide the passport features deliberately requested by the account holder.

The intended legal bases are performance of the service contract for account and core service administration, legitimate interests for proportionate security and service protection, and consent where required. For special category passport information, Autismy relies on explicit consent where appropriate. Consent can be withdrawn by removing content or deleting the passport or account.

The appropriate legal bases and conditions will be documented in Autismy's data protection impact assessment before public launch.

How information is used

  • To create, save, preview, print, and share passports.
  • To authenticate accounts and keep the service secure.
  • To send service messages requested by the user.
  • To respond to support, privacy, safety, and accessibility requests.
  • To understand general feature use after analytics consent.
  • To investigate errors, abuse, and security incidents.

Autismy does not sell passport information and does not use passport content for advertising.

Sharing controlled by the account holder

Passports stay private until an account holder downloads information or creates a sharing link. The account holder selects a view and can set an expiry date or revoke a link.

Anyone who receives or is forwarded an ordinary sharing link may be able to open it. A recipient may save, copy, photograph, print, or forward information they can see. Revoking a link cannot retrieve copies already made by a recipient. Read the safety and sharing guidance before sharing sensitive information.

Service providers

Autismy uses specialist providers to operate the service. These may include Clerk for authentication, Supabase for database and storage infrastructure, Vercel for web hosting, PostHog for consent based product analytics, Resend for transactional email, Sentry for optional error reporting, and Apple for iOS distribution and sign in.

Each provider receives only the information needed for its role. Provider arrangements, locations, retention settings, and contracts will be recorded in Autismy's processing register before public launch.

International transfers

Some service providers may process information outside the United Kingdom. Where this happens, Autismy will use an applicable legal transfer mechanism and assess the protections offered by the provider. Final provider locations and safeguards will be documented before public launch.

Analytics and cookies

Optional product analytics are not started until consent is given. Analytics events are designed not to include passport field content. You can change the analytics choice through the accessibility and privacy control.

Essential storage may still be used for authentication, security, accessibility preferences, and other functions needed to provide the service.

How long information is kept

Account and passport content is kept while the account is active. A deleted passport is removed from active systems. Deleting an account removes its associated active records, including passports, links, and account level logs, subject to limited records that must be retained for legal or security reasons.

Backups, where used, are intended to rotate within 30 days. Support messages and security records may follow separate documented retention periods. These periods will be verified in the retention schedule before public launch.

Your rights

Depending on the circumstances, you may have rights to access, correct, erase, restrict, object to processing, receive a portable copy, and withdraw consent. You may also raise a concern about information recorded about you by another account holder.

Use the in product controls where available or email support@autismy.app. Identity may need to be verified before a request is completed.

You can complain to the UK Information Commissioner's Office. Visit ico.org.uk for current guidance.

Changes to this policy

This policy will be updated as the service and its provider arrangements are finalised. Material changes will be communicated through the website or service where appropriate.