Skip to content
Back to home

Privacy policy

How StatusShift handles your information

Last updated: July 28, 2026

StatusShift asks for sensitive information because immigration forms ask for sensitive information. This policy explains what we collect, why we use it, and when we share it.

We do not sell your personal information. We do not submit your packet to USCIS for you. You decide when to download, sign, and mail your forms.

Information we collect

  • Account details, such as your email address and sign-in method.
  • Immigration answers needed for your forms, including asylum dates, A-Number, addresses, travel, family, work history, and eligibility answers.
  • Information about family members you choose to include in a separate packet.
  • Identity, contact, relationship, and other form-answer information you provide about preparers, interpreters, guardians, household members, family members, or other people.
  • Payment status and Stripe checkout details. StatusShift does not store your full card number.
  • Minimized structural review signals and provider output when you choose to use optional AI review. Saved answer values are not intended to be included in those signals.
  • Basic technical data, such as device, browser, IP address, error logs, and security events.

How we use it

  • Create, save, and update your application packet.
  • Check whether your answers fit StatusShift's supported flow.
  • Prepare downloadable USCIS forms and filing instructions.
  • Run local automated checks for supported missing or inconsistent-answer patterns and, with consent, use AI only to help phrase the minimized structural signals those checks produce.
  • Process StatusShift payments, send account or product emails, prevent abuse, and keep the service secure.
  • Improve the product without using your private answers for advertising.

Who we share it with

We share information only when needed to run the service, protect the service, or follow the law.

  • Supabase for authentication, database, and storage.
  • Vercel for hosting and server logs.
  • Stripe for payments.
  • The paid Google Gemini Developer API, called directly from the StatusShift server, when you choose to use optional AI review.
  • Sentry for error monitoring under data-scrubbing controls. Sentry is not intended to receive saved form-answer values.
  • Email providers for account, support, and reminder messages.
  • Legal or safety requests when we are required to respond.

Sensitive information

Your immigration history, family details, financial information for fee waiver questions, and medical exam related answers can be sensitive. We use this information to prepare your packet, protect your account, provide support, and run features you choose to use.

Retention and deletion

StatusShift is designed to keep case data only as long as needed for the filing flow. After you download your packet, the app may schedule case-content deletion and send a reminder before deletion. That case-content deletion is not the same as deleting your entire account, audit, consent, payment, browser, backup, log, support, or processor records.

You can contact us to request account deletion sooner. Limited records may remain when needed for security, payment, tax, legal obligations, dispute handling, or an active legal hold. Backups, logs, and processor copies may not be removed immediately and may remain until their applicable retention period expires. We do not promise deletion from a location until its deletion process has been verified.

Browser drafts and downloaded files

The intake wizard stores a working draft in your browser so you can continue later. A generated PDF or ZIP is briefly held by the browser and then saved to the device, folder, cloud backup, or other location you choose. Files and browser data outside StatusShift's servers are under your control; deleting your account does not delete those copies. Use a trusted device, sign out when finished, clear StatusShift site data on shared devices, and securely delete downloads you no longer need.

Access and export requests

Email the support address below to request access to or an export of your information. We may need to verify your identity and authority over the account before releasing sensitive records. The export process inventories StatusShift records and identifies processor sources that are included, retained for an approved reason, unavailable, or still pending. Some provider records, protected security material, another person's information, or information we are legally required to withhold may not appear as raw data in an export.

Processors, locations, and retention limits

Our service providers may process information in the United States or other locations allowed by their services, account settings, and contracts. The exact location, backup window, log retention, and deletion capability can differ by provider and service plan. A request to StatusShift does not automatically erase a provider's legally retained payment record, backup, security log, email record, or other copy. We require verified processor settings and retention evidence before enabling a data flow that depends on them, and we will update this policy before a material change in provider or data use.

For optional AI review, StatusShift sends minimized structural signals directly from the StatusShift server to the paid Google Gemini Developer API. Saved answer values are not sent, and StatusShift does not locally log AI prompts or responses. Under Google's paid-service terms, Google states that prompts and responses are not used to improve Google products and are processed under Google's applicable data-processing terms. Unless Google approves zero data retention for the project, Google retains prompts, contextual information, and generated responses for 55 days for abuse monitoring; authorized Google personnel may review flagged content. Google may still process limited request, response, usage, safety, and operational information for service operation, security, or legal obligations. Processing may occur where Google or its agents operate. StatusShift cannot promise zero provider retention or immediate deletion from Google's systems.

Your choices and rights

  • You can ask to access, correct, or delete your personal information.
  • You can ask us not to use AI review for your case by not checking the AI consent box.
  • We do not sell personal information or share it for cross-context behavioral advertising.
  • Depending on where you live, you may have extra privacy rights. We will not punish you for using those rights.

Security

We use safeguards such as authentication, encrypted storage for sensitive case sections, access controls, rate limits, monitoring, and audit logs. No online service can promise perfect security, so please use a strong password and protect your email account.

Age limit

The person who creates, signs in to, and uses a StatusShift account must be at least 18 years old. This rule applies to the account holder, not necessarily the applicant named in the forms. A parent, guardian, or other adult may use the adult's own account to prepare forms for a child or family member.

Questions

Email us at support@statusshiftapp.com.