No receipt number requested or stored

Privacy that is specific enough to verify

GreenLight does not ask for or store your USCIS receipt number. Protected inputs reject receipt-shaped values before they can be decoded, saved, analyzed, emailed, or synced. Selected case details sync only after sign-in, and every outside processor has a named job.

See the technical data flow →Read the full policy →
Rejected

Receipt numbers

Protected inputs block receipt-shaped values before an API, database, analytics event, email, or AI request can accept them.

Opt-in

Account sync

Selected allowlisted case fields sync after sign-in. Labels and checklist completion stay on that browser/device.

Deliberate

Community sharing

Saving a status never publishes it. You choose whether to contribute an account-free milestone observation.

Exact account boundary

What can sync after sign-in

No mystery bucket called “case data.” These are the current fields.

Case type
Field office
Filing date
Priority date (optional)
Visa category (optional)
Country or chargeability area (optional)
Audience or case segment (optional)
Internal case ID and server timestamps

Device-only: custom case labels and checklist completion state.

What happens next

Decoder, history, and Community are separate actions

1

Decode

Receipt-free text goes through GreenLight's API. Known statuses use GreenLight's knowledge base; unknown text may use DeepSeek.

2

Save privately

If you choose to save, GreenLight stores a fixed safe summary and classification—not your pasted text or AI prose.

3

Share deliberately

A separate Timeline action can contribute account-free milestone facts. Cohorts under 5 observations stay suppressed.

Named processors

Who handles what

GreenLight does not sell or rent customer data. These providers perform specific operating jobs.

Authentication and database

Supabase

Handles sign-in, selected signed-in case records, safe history, preferences, entitlements, and owner-scoped generated letters.

Provider policy →
Hosting and security

Cloudflare

Delivers the app and can process request, network, cache, security, and operational log data.

Provider policy →
AI processing

DeepSeek

Processes unknown receipt-free decoder input and receipt-free RFE drafting input when you request AI help. Its policy says data is stored in the People's Republic of China.

Provider policy →
Email delivery

Maileroo

Processes the recipient, rendered message, delivery headers, and delivery information for enabled email.

Provider policy →
Product analytics

PostHog

Processes masked production analytics, heatmaps, session replay, product events, and error or performance signals.

Provider policy →
Payments

Stripe

Processes checkout, card and billing information, subscriptions, one-time purchases, refunds, and required transaction records.

Provider policy →
Questions

Privacy FAQ

Does GreenLight store my USCIS receipt number?

GreenLight does not ask for or store your USCIS receipt number. Protected inputs reject receipt-shaped values before they can be decoded, saved, analyzed, emailed, or synced.

What case details sync after I sign in?

GreenLight can sync your case type, field office, filing date, optional priority date, optional visa category, optional country or chargeability area, audience or case segment, and an internal case ID. Supabase creates server timestamps. Custom labels, browser timestamps, profile-repair flags, and checklist completion stay on that device.

What happens to text I paste into the decoder?

The receipt-free text goes through GreenLight's API. Known statuses use GreenLight's server-side knowledge base. Unknown text may be sent to DeepSeek for an explanation. GreenLight does not store the pasted text or put it in analytics. If you save a result, GreenLight stores a fixed safe summary and classification instead of your raw text or AI prose.

Does saving a status publish it to Community Pulse?

No. Community sharing is a separate action you choose. Sharing starts with an authenticated request that includes the owned case and history IDs so GreenLight can verify the contribution. The resulting public observation has no account, case, history, email, IP, or receipt-number field. A separate private HMAC receipt prevents repeat observations from the same case, and public cohorts with fewer than 5 observations are suppressed.

Does GreenLight sell my data?

No. GreenLight does not sell or rent customer data. The service providers named in the Privacy Policy process limited data to host the app, provide AI results, deliver email, measure product use, or process payments.

Decode without entering a receipt number

No account required. Unknown receipt-free text may use the disclosed DeepSeek fallback and is not stored in your GreenLight account.

Try the Status Decoder →