Privacy policy
How StatusShift handles your information
Last updated: August 15, 2026
StatusShift asks for sensitive information because immigration forms ask for sensitive information. This policy explains what we collect, why we use it, and when we share it.
Information we collect
- Account details, such as your email address and sign-in method.
- Immigration answers needed for your forms, including asylum dates, A-Number, addresses, travel, family, work history, and eligibility answers.
- Information about family members you choose to include in a separate packet.
- Identity, contact, relationship, and other form-answer information you provide about preparers, interpreters, guardians, household members, family members, or other people.
- Payment status and Stripe checkout details. StatusShift does not store your full card number.
- Minimized structural review signals and provider output when you choose to use optional AI review. Saved answer values are not intended to be included in those signals.
- Basic technical data, such as device, browser, IP address, error logs, and security events.
How we use it
- Create, save, and update your application packet.
- Check whether your answers fit StatusShift's supported flow.
- Prepare downloadable USCIS forms and filing instructions.
- Run local automated checks for supported missing or inconsistent-answer patterns and, with consent, use AI only to help phrase the minimized structural signals those checks produce.
- Process StatusShift payments, send account or product emails, prevent abuse, and keep the service secure.
- Improve the product without using your private answers for advertising.
Who we share it with
We share information only when needed to run the service, protect the service, or follow the law.
- Supabase for authentication, database, and storage.
- Vercel for hosting and server logs.
- Stripe for payments.
- The Google Gemini Developer API, called directly from the StatusShift server, when you choose to use optional AI review.
- Sentry for error monitoring under data-scrubbing controls. Sentry is not intended to receive saved form-answer values.
- Email providers for account, support, and reminder messages.
- Legal or safety requests when we are required to respond.
Sensitive information
Your immigration history, family details, financial information for fee waiver questions, and medical exam related answers can be sensitive. We use this information to prepare your packet, protect your account, provide support, and run features you choose to use.
Retention and deletion
StatusShift is designed to keep case data only as long as needed for the filing flow. After you download your packet, the app may schedule case-content deletion and send a reminder before deletion. That case-content deletion is not the same as deleting your entire account, audit, consent, payment, browser, backup, log, support, or processor records.
You can contact us to request account deletion sooner. Limited records may remain when needed for security, payment, tax, legal obligations, dispute handling, or an active legal hold. Backups, logs, and processor copies may not be removed immediately and may remain until their applicable retention period expires. We do not promise deletion from a location until its deletion process has been verified.
Browser drafts and downloaded files
The intake wizard stores a working draft in your browser so you can continue later. A generated PDF or ZIP is briefly held by the browser and then saved to the device, folder, cloud backup, or other location you choose. Files and browser data outside StatusShift's servers are under your control; deleting your account does not delete those copies. Use a trusted device, sign out when finished, clear StatusShift site data on shared devices, and securely delete downloads you no longer need.
Access and export requests
Use the support form below to request access to or an export of your information. We may need to verify your identity and authority over the account before releasing sensitive records. The export process inventories StatusShift records and identifies processor sources that are included, retained for an approved reason, unavailable, or still pending. Some provider records, protected security material, another person's information, or information we are legally required to withhold may not appear as raw data in an export.
Processors, locations, and retention limits
Our service providers may process information in the United States or other locations allowed by their services, account settings, and contracts. The exact location, backup window, log retention, and deletion capability can differ by provider and service plan. A request to StatusShift does not automatically erase a provider's legally retained payment record, backup, security log, email record, or other copy. We require verified processor settings and retention evidence before enabling a data flow that depends on them, and we will update this policy before a material change in provider or data use.
For optional AI review, StatusShift sends minimized structural signals directly from the StatusShift server to the Google Gemini Developer API. Saved answer values are not sent, and StatusShift does not locally log AI prompts or responses. Provider AI remains disabled unless active billing and paid-service terms are confirmed for the exact production project. Only after that confirmation, Google states that prompts and responses are not used to improve Google products and are processed under Google's applicable data-processing terms. By default, Google retains prompts, contextual information, and generated responses for 55 days for abuse monitoring; authorized Google personnel may review flagged content. When Google approves zero data retention for the exact project, Google says content and identifiable metadata are cleared before abuse logging, but sanitized non-identifiable records may remain. Optional Gemini project logging is separate from abuse monitoring and is treated as disabled only when exact-project evidence confirms it. Google may still process limited request, response, usage, safety, and operational information for service operation, security, or legal obligations. Processing may occur where Google or its agents operate. StatusShift cannot promise zero provider retention or immediate deletion from Google's systems.
Support ticket details and message content are encrypted at rest. Technical attachments are optional and available only when the feature is enabled. We place them first in a private Supabase Storage quarantine area. Cloudmersive scans each attachment, and only a clean result moves it to a private clean Storage area. Uncommitted staged objects and upload claims are deleted after 24 hours. Rejected attachment bytes are deleted immediately after the minimal verdict and digest record commits. Clean attachments are deleted 30 days after the earlier of a ticket being resolved or closed. If a ticket is reopened before that deletion, we clear that schedule; after it is resolved or closed again, a new 30-day clock starts. Encrypted ticket and message content is deleted 12 months after a ticket is closed. New requester activity can reopen a resolved ticket and clear that content-deletion schedule. Closed tickets do not accept new requester activity. An active legal hold pauses affected deletion schedules. Resend sends support acknowledgements and replies. When inbound email is enabled, a Google Workspace mailbox may receive an inbound email copy. Support access, export, and deletion requests may be limited by identity checks, other people's information, security records, legal duties, and provider retention. We do not promise unverified provider deletion.
Your choices and rights
- You can ask to access, correct, or delete your personal information.
- You can ask us not to use AI review for your case by not checking the AI consent box.
- We do not sell personal information or share it for cross-context behavioral advertising.
- Depending on where you live, you may have extra privacy rights. We will not punish you for using those rights.
Security
We use safeguards such as authentication, encrypted storage for sensitive case sections, access controls, rate limits, monitoring, and audit logs. No online service can promise perfect security, so please use a strong password and protect your email account.
Age limit
The person who creates, signs in to, and uses a StatusShift account must be at least 18 years old. This rule applies to the account holder, not necessarily the applicant named in the forms. A parent, guardian, or other adult may use the adult's own account to prepare forms for a child or family member.
Questions?
We're here to help. Get in touch with our support team.