Privacy Policy
Last updated: September 17, 2026
Your data, your choices. Learn what we collect, how we use it, and how to get a copy or request deletion.
On this page
- Who is responsible for your data
- The data we collect
- How we use your data
- Who receives data and why
- Consent and limits on sharing
- Your choices and the risks of sharing
- How long we keep data
- Request a copy, correction, or permanent deletion
- Close a record or stop alerts
- California privacy rights
- Security and breach notices
- If the business changes owners or closes
- Policy changes and your consent
Who is responsible for your data
DocPrep Immigration Forms runs this website and is responsible for the personal data it holds. We help prepare immigration forms using the facts you provide. We are not a law firm or a government agency.
For privacy requests, email docprept@gmail.com or call +1 (818) 940-0072. You do not need an account or a paid service to make a request.
The data we collect
We collect only the data needed for the task you choose.
- Contact forms: your name, phone number, email if supplied, requested service, message, language, and page where you made the request.
- Case checks: the USCIS receipt number you enter and the case status USCIS returns. Status alerts also need your email address and record of consent.
- Service records: documents you provide, notes, tasks, and messages needed to prepare your forms. These may include your address, date of birth, A-number, passport details, family details, work history, or financial and health records if your requested form needs them.
- Technical data: IP address, browser and device details, request time, and security logs. An IP address may show a rough location. We do not request precise GPS location or access your device contacts.
- Consent records: the policy version you accepted, the time, and the purpose of your consent.
- Chat: the text you send to find information on this site. The chat uses our site content; it does not send your message to an external AI model. The visible conversation stays in your browser memory until you reload or leave the site.
- We do not ask for payment card numbers, genetic data, or medical records through public forms or chat. Do not include them there. We do not collect these data types from your device in the background.
How we use your data
We use contact details to respond to you, prepare the service you request, and keep a record of that work. We use technical data to run the site and prevent abuse. We use consent records to respect your choices.
A one-time case check sends your receipt number to USCIS through our server. It does not create a subscription. Alerts are a separate choice. If you request alerts, we store your email and receipt number and check for changes on a schedule.
We do not sell your data for profit, money, or other value. We do not share it for targeted ads, rent mailing lists, or use case data to train AI models. These limits also apply to data with names removed, data made anonymous, and data linked to a code instead of a name.
Who receives data and why
Only staff who need your data for your request may access it. The following providers receive the data needed for their stated task when that feature is used. We do not give client data to advertisers or data brokers.
- Vercel hosts the website and processes web requests and technical logs to deliver and protect it.
- Supabase stores service records, uploaded files, consent records, and alert subscriptions. It also provides staff sign-in. It processes these data to provide the database and storage service.
- Cloudflare Turnstile receives technical browser and network signals to check forms for spam. Its form check loads after you give consent.
- USCIS, within the U.S. Department of Homeland Security, receives the receipt number needed to return your case status. USCIS is an independent government agency and its own rules govern its records.
- Resend processes your email address and status email contents to deliver alerts you request, when email alerts are configured.
- Google Gmail processes messages and attachments when you email our published Gmail address or we reply from it.
- Telegram receives generic staff alerts only. Our website alerts do not include your name, contact details, case number, documents, or message.
- OpenAI is used only for staff translation of public news content. The site's case lookup and chat do not send your case data or chat messages to OpenAI.
- A translator or other service partner will be named to you before your data is shared with that partner. We will explain the data and purpose and ask for your active consent first.
Consent and limits on sharing
Third parties may not use or disclose your information for any purpose without your active consent. This includes data that is de-identified, anonymous, or linked to a code. You give consent by selecting an unchecked box next to the purpose and links to these policies, then submitting the form. Alerts require a separate choice.
Service providers must be bound by written terms that require the privacy protections in this policy. They may use data only for the task you approved. They must protect it, limit access, help with deletion, and not sell it or use it for their own ads. We must confirm these terms before sending client data to a new provider.
A binding legal demand may require a disclosure without consent. We limit it to what the law requires and notify you unless the law bars notice. We cannot change the legal duties of USCIS or other public agencies.
Your choices and the risks of sharing
You can read this site without sending a request. Leave optional fields blank. You may decline alerts, withdraw consent, request a copy, or ask us to delete your data. Contact us using Your Data or the details above. Withdrawing consent stops future optional use; it does not undo a check already sent to USCIS.
Sharing data lets us respond, prepare forms, and send alerts. Without the required data or consent, we may be unable to provide that feature. You can still use official government sites directly.
Email and online services carry a risk of loss, wrong delivery, and access by others. Providers may process data in the United States or other countries. No system offers zero risk. Send only what we need and confirm the recipient before sending files.
Documents may reveal facts about relatives, sponsors, or other people, including their health or immigration history. Disclosure may affect their privacy or safety. Share another person's data only if you have authority to do so. Remove unrelated details, and do not check someone else's case without permission.
How long we keep data
We use the following retention schedule. A scheduled status check does not count as new consent or user activity.
- Requests that do not lead to a service: up to 12 months after the last contact with you.
- Completed service files and supporting documents: up to 3 years after the service ends. Open matters are kept while we provide the service.
- Status alert subscriptions: up to 12 months after your last explicit consent, unless you cancel earlier. A new policy version pauses automated checks until you consent again.
- One-time status results are not saved as a subscription. The result stays in browser memory until the page is left or reloaded. Technical logs may be held for up to 30 days.
- Consent evidence stays with the related service or subscription record and follows its retention period. A minimal privacy request record may be kept for 24 months to show how the request was handled. It does not include copies of deleted case files.
- Deleted data in backups is isolated from normal use and expires within 90 days. If a backup is restored, deletion requests must be applied again before the data is used.
- A specific legal duty or legal hold may require longer retention. We limit the retained data and access, explain the reason and period unless barred by law, and delete it when the duty ends. Dormant records follow the same limits; inactivity does not extend storage.
Request a copy, correction, or permanent deletion
Open Your Data, email docprept@gmail.com with the subject Privacy request, or call +1 (818) 940-0072. Tell us whether you want a copy, a correction, deletion, or to stop alerts. Give the email or phone number you used with us. Do not send a passport, full case file, or health record with your first request.
We verify that you own the data, using a reply from a contact address already on file or a call to a known number. We ask only for what is needed to verify you. An authorized agent may make a request with proof of authority. We do not require a new account.
We acknowledge requests within 10 business days. We complete verified deletion requests within 30 calendar days of receipt. Identity checks do not restart that clock. If a legal exception prevents full deletion, we explain what remains, why, and when it can be deleted. Where a law permits extra time, we notify you before the deadline with the reason and new date.
Deletion covers relevant live service records, files, alert subscriptions, and copies held by our service providers. We confirm completion and explain backup expiry. It does not delete government records held by USCIS or copies you or independent recipients already hold.
You may request a readable electronic copy or secure transfer of your records, including any health information you gave us, before deletion. We use a verified delivery method and protect the data during transfer.
Close a record or stop alerts
Visitors do not create a public login account on this site. Staff accounts are separate. To close your client record, stop alerts, or withdraw consent, use Your Data or contact us. Ask for permanent deletion as well if you want the underlying records removed.
Stopping alerts ends future scheduled checks and email updates for that subscription. It does not cancel a government case or a separate service agreement. Staff account closure is handled by the company administrator.
California privacy rights
If the California Consumer Privacy Act applies to our handling of your data, you may ask to know, access, correct, and delete it. You may also opt out of sale or sharing for targeted ads and limit certain uses of sensitive data. You may use an authorized agent. We will not penalize you for exercising these rights.
We do not sell personal data or share it for targeted ads, including data about minors. We use sensitive data only to provide your requested service or as the law permits. A Global Privacy Control signal does not result in a sale or ad-sharing exception.
Use the contact methods in this policy to exercise your rights. Where CCPA applies, we respond within 45 calendar days of receiving a request. If permitted, we may extend by up to 45 days after telling you why within the first period. This does not change our shorter normal deletion schedule.
Security and breach notices
We use encrypted web connections, restricted staff access, and server-side storage of API secrets. We limit the data included in logs and staff alerts. Do not submit sensitive files through public chat.
If a breach affects your personal data, we notify affected users without undue delay and within any legal deadline. We use email or another suitable channel. The notice explains what happened, the data involved, steps we have taken, and actions you can take, such as changing passwords or watching for fraud. It includes a contact for help. We also notify authorities when required.
If the business changes owners or closes
We notify users before a sale, merger, transfer of ownership, or closure affects their data. We use the contact details on file and a notice on this site.
A new owner must agree to protect your data under this policy. We explain the proposed transfer and obtain active consent before an optional transfer or changed use. If the new owner cannot honor these terms, we offer a secure copy, transfer to a recipient you choose, or permanent deletion before the transfer, subject to specific legal duties.
If we close, we stop new collection and alerts. We give you a chance to obtain your records, including health information if any, and securely delete remaining data under the deletion schedule. We tell you about any records that the law requires us to retain and who is responsible for them.
Policy changes and your consent
This version adds named providers, sharing limits, retention periods, deletion steps, breach notices, and rules for business changes. It also adds separate consent for case checks and alerts.
When the Privacy Policy or Terms of Service changes, we publish a dated version and a plain-language summary here. We notify active clients and alert subscribers using their contact details. Continued use or silence does not count as consent.
We ask you to actively accept the new version with an unchecked box before a new submission. Automated alerts with an older consent version are paused until you accept the new version. For ongoing offline work, we request a clear written acceptance before applying changed terms or data uses. You may decline and request closure, a copy, or deletion.
