1. Scope
This Privacy Policy describes how the MyCases service operator identified in the applicable order, invoice, or service agreement (the “Service Operator”, “we”, “us”) processes information when you use the MyCases product (the “Service”).
2. Information We Collect
- Account information: email address, display name, authentication identifiers (invite code, OAuth provider identifier when applicable).
- USCIS case data: receipt numbers you enter, form type, nicknames, public case status returned by USCIS, and status history retrieved on your behalf.
- Beneficiary and folder metadata you organize inside the product.
- Team and staff data when you invite collaborators (email, display name, role, membership status).
- Document input for AI-assisted parsing: when you upload a receipt image or file, the content is sent to a hosted AI provider for one-time parsing/extraction so we can populate case fields. The Service is not a long-term document archive today; source files are not retained as an addressable document store, and any processing by the external AI/hosting processors is subject to their own terms.
- Notification channel configuration you provide (Telegram chat id, WeCom webhook, email address when the outbound email channel is enabled for your project). Delivery records store masked recipients only.
- Billing and usage data required to operate paid plans (plan, seats, subscription status, usage counters). Card data is handled entirely by Stripe.
- Operational logs such as request timing, error signals, and coarse device information used for reliability and abuse prevention.
3. How We Use Information
- Provide case lookup, status history, and change notifications.
- Organize cases via beneficiaries, folders, and team membership.
- Operate billing, quotas, and plan entitlements.
- Protect the Service, detect abuse, and support you.
- Comply with applicable legal obligations.
4. Third-Party Categories
We rely on the following categories of processors:
- Managed hosting and database (Supabase-managed infrastructure).
- Payments (Stripe).
- Product hosting and delivery (Lovable-managed platform).
- Public USCIS data sources used to look up your cases at your direction.
- Optional notification channels that you configure yourself (Telegram, WeCom webhooks).
- AI providers used for document parsing and translation of case status.
We do not claim any specific external certifications on your behalf. We do not sell your personal information.
5. Data Retention and Your Choices
You can export the case list as CSV today. Full account-wide export and self-serve deletion of all associated records are being implemented and are not yet self-serve; in the interim you can submit a request via /contact.
6. International Users, Children, and Regional Rights
The Service is not directed to children. Depending on where you reside, you may have rights to access, correct, or delete personal data, and to object to certain processing. We handle such requests in good faith and within a reasonable time. This section is a summary and is not legal advice.
7. Security
See our Security page for the specific technical controls currently in place. No online service can guarantee absolute security.
8. Contact
For privacy questions or requests, please use /contact. For data export or deletion requests, use the data request form.