Privacy Policy
Last updated: August 23, 2026
GreenLight does not ask for or store your USCIS receipt number. Protected inputs reject receipt-shaped values before they can be decoded, saved, analyzed, emailed, or synced.
Scope
This policy explains how GreenLight handles information when you visit the website, use the decoder or case tools, create an account, receive email, contribute to Community Pulse, or make a purchase. GreenLight is an informational immigration-case organization tool. It is not a law firm, legal service, or government agency.
What stays in your browser
GreenLight is local-first for selected product state. Browser storage is specific to that browser and device; clearing it on one device does not delete signed-in cloud records.
Account, authentication, and case sync
If you create an account, Supabase processes your authentication details, account email, session, and user-selected sign-in method. GreenLight can also store your interface language, audience, explicit marketing choice, and sanitized acquisition information such as a campaign source or referrer host.
A signed-in case can sync the following validated fields so your cases and safe timeline history persist across sessions:
- Case type
- Field office
- Filing date
- Priority date (optional)
- Visa category (optional)
- Country or chargeability area (optional)
- Audience or case segment (optional)
- Internal case ID and server timestamps
Custom case labels and checklist completion are excluded from cloud sync. The account owner is derived from the authenticated session; GreenLight does not accept a customer-supplied owner ID for case writes.
Decoder and AI processing
Receipt-free decoder input goes through GreenLight's API. Known statuses are resolved with GreenLight's server-side knowledge base. If no known status matches, the input may be sent to DeepSeek to generate an explanation.
GreenLight does not write the pasted decoder text or AI explanation to its database or analytics. If you deliberately save a result to signed-in history, GreenLight stores a fixed safe summary, classification, dates, and account/case links—not the raw pasted text or model prose.
DeepSeek's policy states that it processes prompts and inputs and stores data in the People's Republic of China. Do not enter a receipt number, A-number, name, address, or other sensitive personal information into an AI-assisted field.
RFE drafting tools
A receipt-free RFE draft can stay in browser storage until you request an outline or paid letter. When you request AI help, the selected category, receipt-free notice text, and receipt-free situation are sent to DeepSeek. GreenLight does not store those original draft fields on its server.
For a paid generated letter, GreenLight stores the finished markdown, category, regeneration count, purchase reference, status, and timestamps in an owner-scoped Supabase row. You can delete a generated document. A separate unused purchase or legally required billing record may remain.
Community Pulse
Saving a status does not automatically publish it. Community sharing is a separate action you choose from a signed-in case. GreenLight verifies that you own the selected case and history entry, then derives the public milestone fields on the server.
A public observation can contain case type, canonical field office, milestone, days from filing, optional petition type, and creation time. It has no account ID, case ID, history ID, email, IP address, or receipt-number field. Public cohorts with fewer than 5 observations are suppressed.
A separate private HMAC receipt prevents one case from submitting repeat observations. That receipt does not store the raw account or case ID, but it means GreenLight should not make an absolute claim that no private anti-abuse linkage exists.
Analytics, heatmaps, and session replay
GreenLight uses PostHog on production hostnames to understand page use, funnels, errors, performance, heatmaps, and masked session replay. Signed-in analytics can use your Supabase user UUID as a pseudonymous identifier and can include controlled product context such as plan, audience, canonical case type, or selected form.
GreenLight configures input masking, autocaptured text masking, and element-attribute masking. Its analytics sanitizer removes query strings, URL fragments, private referrer paths, receipt-shaped values, email and name fields, raw status text, free text, and autocaptured element text from outgoing properties.
Masking reduces collection risk but is not a reason to paste sensitive identifiers into the product. GreenLight still rejects receipt-shaped values at protected input and API boundaries.
Maileroo processes the recipient address, sender, subject, rendered HTML/plain-text message, delivery headers, and delivery information when GreenLight sends enabled email. Depending on the message, content can include a conservatively sanitized first name, canonical case type, dates or wait, field office, visa category/country, and fixed status labels or classes.
Receipt numbers and raw pasted status text are excluded. Marketing email requires recorded consent and includes one-click unsubscribe. You can manage transactional and marketing preferences from your account or an unsubscribe link.
Payments
Stripe processes checkout, card and billing details, subscriptions, one-time purchases, refunds, and transaction records. GreenLight does not receive or store your full card number.
GreenLight stores the entitlement or tier state and the Stripe customer, subscription, checkout-session, payment-intent, price/product, and timing identifiers needed to grant access and reconcile billing. Signed Stripe webhooks update those records.
Service providers
GreenLight does not sell or rent customer data. These providers process limited information to operate the service:
Security, abuse prevention, and operational data
GreenLight uses authenticated owner checks, server-side validation, database row-level security, signed webhooks, rate limits, HMAC-based deduplication or delivery claims, and restricted service credentials. Cloudflare and other infrastructure providers can process request metadata, IP/network data, security signals, and logs needed to deliver and protect the service.
Abuse counters can use salted hashes of an IP address or recipient instead of storing the raw value in the application table. No online service can promise perfect security; use a unique password and do not enter government identifiers into GreenLight.
Retention and deletion
Device data
Clear GreenLight's browser data on each device to remove local case state, labels, checklist progress, and unsubmitted drafts from that browser.
Account deletion
The account flow can delete your Supabase Auth identity and linked application rows after billing safety checks pass. You must first resolve an active subscription, open checkout, or processing payment so charges and entitlements are not orphaned.
Records that may remain
Account-free Community observations, identity-free completion receipts, and records needed for security, fraud prevention, backups, tax, billing, disputes, or legal obligations may remain. Stripe, Maileroo, PostHog, DeepSeek, Cloudflare, and Supabase can retain data under their own policies or legal duties. GreenLight cannot promise immediate erasure from every provider system or backup.
Your choices
You can use the free decoder without creating an account, choose whether to sync cases, choose whether to contribute to Community Pulse, manage email preferences, clear device data, delete generated RFE documents, and request account deletion subject to the billing boundary above.
To ask a privacy question or request help with access or deletion, email privacy@greenlighttrack.com. We may need to verify that you control the account before acting on an account-specific request.
Changes and questions
GreenLight may update this policy as the product or providers change. The current revision date appears at the top. For a visual summary, read the Privacy Promise. For the field-level version, read the Privacy Architecture. For service terms, read the Terms of Service.
Decode without a receipt number
Receipt-shaped input is rejected. Unknown receipt-free text may use the disclosed AI fallback.
Try the Status Decoder →GreenLight is not affiliated with USCIS, DHS, or any U.S. government agency. Nothing here is legal advice.