Field-level map

Browser → GreenLight API → storage or processor

GreenLight does not ask for or store your USCIS receipt number. Protected inputs reject receipt-shaped values before they can be decoded, saved, analyzed, emailed, or synced. This page maps every important exception and destination.

Three handling zones

Device

Browser storage

Custom case labels: Stored in browser storage and removed from every cloud-sync payload.

Checklist completion: Checked item IDs stay in browser storage for that device.

Unsubmitted RFE draft: A receipt-free draft stays in browser storage until you request an AI outline or letter.

Private account

Supabase records

Auth identity, selected case fields, fixed safe history, preferences, entitlements, activity timestamps, and owner-scoped generated letters. Owner checks and row-level security constrain access.

Outside processor

Limited operating jobs

DeepSeek handles requested AI work, Maileroo delivers email, PostHog measures masked production use, Stripe processes payments, and Cloudflare delivers and protects the app.

POST /api/cases

Exact signed-in case payload

The server derives the owner from the authenticated session. An explicit browser allowlist excludes custom labels, browser timestamps, profile-repair flags, and future UI-only fields; the API rejects unknown keys.

Case type
Field office
Filing date
Priority date (optional)
Visa category (optional)
Country or chargeability area (optional)
Audience or case segment (optional)
Internal case ID and server timestamps

Data-flow matrix

“Server” includes GreenLight's API, durable Supabase records, or a named processor. The row says which one.

Data or actionBrowser boundaryServer or processor boundary
USCIS receipt numberNot requested; protected fields reject receipt-shaped valuesNot stored or intentionally transmitted
Selected case profileLocal case objectSupabase after sign-in through owner-checked APIs
Custom label + checklistStored on that deviceExcluded from sync
Decoder inputReceipt-rejected before submitGreenLight API; unknown receipt-free text may reach DeepSeek transiently
Saved historyUser deliberately selects SaveFixed safe summary/classification, dates, owner + case IDs; no raw text or AI prose
RFE draftingReceipt-free draft can stay local until requestedDeepSeek processes requested input; Supabase stores finished paid letter only
Community milestoneSeparate deliberate share actionAccount-free public row + private HMAC anti-duplication receipt
Product useMasked production events and replayPostHog receives sanitized events and pseudonymous signed-in ID
Deliberate public contribution

Community Pulse has a public row and a private anti-duplication receipt

The share request is authenticated and includes the owned case and history IDs so GreenLight can verify ownership and derive the milestone. The resulting public observation can include case type, canonical field office, milestone, days from filing, optional petition type, and timestamp. It has no account, case, history, email, IP, or receipt-number field.

A separate private HMAC receipt, derived with a server secret, prevents repeat observations without storing the raw account or case ID in that receipt table. Public cohorts with fewer than 5 observations are suppressed.

Enforced controls

Client and server receipt-number rejection
Strict input schemas and canonical allowlists
Authenticated owner checks and row-level security
Fixed safe status summaries instead of caller/model prose
Masked PostHog inputs, text, attributes, and private result regions
Sanitized analytics URLs and property allowlists
Signed Stripe webhooks and billing deletion gates
HMAC delivery and Community deduplication claims
Rate limits and hashed abuse counters
Thresholded Community aggregates

Processor map

Supabase

Authentication and database

Handles sign-in, selected signed-in case records, safe history, preferences, entitlements, and owner-scoped generated letters.

Provider policy →

Cloudflare

Hosting and security

Delivers the app and can process request, network, cache, security, and operational log data.

Provider policy →

DeepSeek

AI processing

Processes unknown receipt-free decoder input and receipt-free RFE drafting input when you request AI help. Its policy says data is stored in the People's Republic of China.

Provider policy →

Maileroo

Email delivery

Processes the recipient, rendered message, delivery headers, and delivery information for enabled email.

Provider policy →

PostHog

Product analytics

Processes masked production analytics, heatmaps, session replay, product events, and error or performance signals.

Provider policy →

Stripe

Payments

Processes checkout, card and billing information, subscriptions, one-time purchases, refunds, and required transaction records.

Provider policy →

Deletion follows the same boundaries

Device state is cleared on each browser. Account deletion removes the Supabase Auth identity and linked application rows only after active subscription, open checkout, and processing-payment checks pass.

Account-free Community observations, identity-free completion receipts, backups, and security, tax, billing, dispute, or legally required provider records may remain. Read the authoritative Privacy Policy for the complete retention statement.

Back to Privacy Promise →Read the full policy →