Privacy Policy
Last updated: June 9, 2026
MyCaseWatch (“we”, “our”, “us”) is committed to protecting your privacy. This policy explains what information we collect, how we use it, and your rights with respect to it. By using MyCaseWatch you agree to this policy.
1. Information We Collect
We collect the minimum information needed to provide the service:
- Account information — your email address and a bcrypt-hashed version of your password. We never store your password in plain text.
- USCIS receipt numbers — the receipt numbers you enter to check case status, stored against your account.
- Case status history — raw API responses from USCIS for each case check you perform, stored to build your timeline and detect status changes.
- Notification preferences — your settings for email alerts and summary frequency.
- Billing information — if you subscribe, Stripe processes your payment. We store only the Stripe customer ID, subscription status, and renewal date — never your card number.
- Email log — a record of status-alert emails sent to you (timestamp, subject, receipt number) for audit and support purposes.
We do not collect your name, phone number, address, social security number, A-number, or any other immigration document details beyond the receipt number you provide.
2. How We Use Your Information
- To authenticate you and maintain your session
- To fetch your case status from the USCIS API on your behalf
- To store and display your case history timeline
- To detect status changes and send you email alerts when you've opted in
- To process subscription payments through Stripe
- To send periodic case summaries if you've enabled them
- To monitor service health and investigate errors
We do not use your data for advertising, profiling, or sale to third parties.
3. Third-Party Services
We share limited data with the following third parties, solely to operate the service:
- USCIS API — your receipt number is sent to the USCIS case status API to retrieve your case information. This is the core function of the service.
- Stripe — payment processing. Stripe receives your email address and payment details. Stripe's privacy policy applies to data Stripe processes.
- Resend — email delivery. Your email address and the content of status-alert emails are transmitted through Resend to deliver messages to your inbox.
- Vercel — hosting and infrastructure. Your requests pass through Vercel's servers, which may log request metadata (IP address, timestamp) per their data processing terms.
4. Data Retention
We retain your account data for as long as your account is active. Case history and email logs are retained indefinitely to support the timeline feature and our audit log.
If you delete your account (by contacting us at the address below), we will delete your account record, associated case history, settings, saved cases, and email log within 30 days.
5. Security
Passwords are hashed using bcrypt (cost factor 10) before storage. All communication between your browser and our servers uses HTTPS with HSTS enforced. Authentication tokens are stored in HTTP-only, Secure, SameSite cookies that JavaScript cannot access. Database queries use parameterised statements to prevent SQL injection. We apply rate limiting on authentication and API endpoints to limit credential-stuffing attacks.
No system is perfectly secure. If you believe you've discovered a security vulnerability, please report it to security@mycasewatch.com before disclosing it publicly.
6. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Opt out of email alerts at any time (via the unsubscribe link in any alert email, or via Settings)
- Cancel your subscription at any time through the billing portal
To exercise these rights, contact us at privacy@mycasewatch.com.
7. Cookies
We use a single HTTP-only cookie (mycasewatch_token) to maintain your login session. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
Your theme preference (light/dark) is stored in localStorage, not transmitted to our servers.
8. Children
MyCaseWatch is not directed at children under 13. We do not knowingly collect information from children under 13. If you believe we have inadvertently collected such information, please contact us and we will delete it promptly.
9. Changes to This Policy
We may update this policy from time to time. We will update the “Last updated” date at the top of this page and, for material changes, notify registered users by email. Your continued use of the service after a change constitutes acceptance of the updated policy.
10. Contact
Questions about this policy? Email us at privacy@mycasewatch.com.