Last Updated: February 18, 2026
Non-Affiliation Disclosure
CheckCaseStatus.com is an independent, third-party service and is NOT affiliated with, endorsed by, or connected to the U.S. Department of Homeland Security (DHS), U.S. Citizenship and Immigration Services (USCIS), or any U.S. government agency. Case status data is retrieved from the official USCIS Torch API under the USCIS API Terms of Use.
This Privacy Policy applies to all users of CheckCaseStatus.com ("Service", "Platform", "we", "us", or "our"), operated by KOL.XYZ LLC, a company incorporated in the State of Nevada, United States. This policy covers individual users (applicants checking their own case status), firm users (immigration firms, law offices, and their members), and developer API consumers. Regardless of your role, this policy applies to you.
1. Information We Collect
We collect the following specific types of personal information to provide our services:
- Identity Information: Name (optional, user-provided), email address.
- Case Information: USCIS Receipt Numbers (e.g., EAC2390000001) and case status data retrieved from the USCIS API.
- Financial Information: Payment transactions processed through Stripe. We do NOT store credit card numbers or full payment details on our servers; Stripe handles all payment data per PCI DSS standards.
- Device & Technical Information: Browser type, operating system, IP address (for security, rate limiting, and fraud prevention).
- Usage Information: Pages visited, features used, timestamps (for service improvement and analytics).
- AI Chat History: Messages exchanged with the AI assistant, stored to provide conversation continuity.
- Uploaded Files: Images, PDFs, or audio recordings voluntarily submitted by users for AI processing. These files are stored temporarily for processing and then retained in your account until you delete them.
We do NOT collect: precise geolocation data, medical or health information, genetic data, biometric data, family history information, device contacts, Social Security Numbers, A-Numbers, or any information beyond what is listed above.
2. USCIS API Data Source & Compliance
Case status data is sourced exclusively from the official USCIS Torch API operated by the U.S. Department of Homeland Security. We strictly comply with the USCIS API Terms of Use, including:
- OAuth 2.0 Client Credentials authentication with all API keys, secrets, and tokens stored securely on our backend servers.
- No API requests to USCIS originate from client-side applications. All USCIS API communication occurs exclusively on our server infrastructure.
- Proper HTTPS response handling for all API status codes, including structured error responses per RFC 9457.
- Rate limiting and intelligent caching to minimize unnecessary API calls to USCIS systems.
- Demo ID header (
demo_id) support for the USCIS production access review process.
Data retrieved from the USCIS API includes: case status text, status descriptions, form type, and case history timeline. We do NOT use USCIS API data for: selling to third parties, advertising targeting, creating personal identity profiles, or any purpose other than displaying case status to the authorized user and generating AI-assisted analysis.
3. How We Use Your Data
Our Promise: We never sell your immigration data to any third party. Your data is used exclusively for the following purposes:
- Querying and displaying your immigration case status via the official USCIS API.
- Generating AI-powered case analysis and multilingual translations.
- Sending case status change notifications (email and in-app), when you opt in.
- Managing your account, membership tier, and processing payments.
- Improving service quality through aggregate, anonymized usage analytics.
- Providing customer support when you contact us.
Your Data-Sharing Choices
You have full control over how your data is used and shared:
- Notifications: You may opt in or out of email and in-app notifications for case status changes at any time via the Settings page.
- AI Analysis: AI-powered analysis is optional and on-demand. You choose when to request AI analysis of your case.
- Case Monitoring: Only cases you explicitly bookmark are monitored. You can remove bookmarks at any time.
- Data Export: You may export your case data in standard format (JSON) at any time from your account settings.
Risks, Benefits, and Limitations of Data Sharing
- Risks: Sharing your receipt number or case status with others could reveal sensitive immigration details about you and related family members or dependents listed on the same case.
- Benefits: Our service provides faster case status awareness, AI-guided interpretation, and proactive status change alerts.
- Limitations: AI analysis is informational only and does not constitute legal advice. USCIS API data may have processing delays. We cannot guarantee the accuracy or completeness of AI-generated content.
4. Data Security
- Encryption at Rest: All sensitive data, including Receipt Numbers and personal information, is encrypted at rest using AES-256 encryption.
- Encryption in Transit: All data is transmitted via secure TLS 1.2+ (HTTPS) connections. We enforce HTTPS on all endpoints.
- Server-Side Key Storage: All USCIS API keys, OAuth tokens, and secrets are stored exclusively on our backend servers. No credentials are exposed to client-side code.
- Access Control: Backend systems are accessible only to authorized personnel via multi-factor authentication. All access is logged and audited.
- Infrastructure: Our application is hosted on Railway (backed by Google Cloud Platform) with automated backups and monitoring.
5. AI Disclaimer
We use AI language models (via OpenRouter) to provide case status analysis and multilingual translation. Important disclosures:
- AI processes only case status text retrieved from the USCIS API; it does not have access to your full name, Social Security Number, A-Number, or any encrypted personal identifiers.
- AI-generated content is for informational purposes only and does NOT constitute legal advice.
- Users should consult a qualified immigration attorney for legal decisions.
6. Third-Party Services
We use the following trusted third-party service providers, each of which is contractually bound to comply with the terms of this Privacy Policy:
- USCIS Torch API (U.S. Government): Official case status data retrieval. Governed by USCIS API Terms of Use.
- Stripe, Inc.: Secure payment processing (PCI DSS Level 1 certified). Stripe processes payment data directly; we never store card details.
- OpenRouter / AI Providers: AI-powered case analysis and translation. Only case status text (no PII) is sent for processing.
- Railway / Google Cloud Platform: Application hosting and infrastructure.
- Cloudflare, Inc.: DNS, CDN, DDoS protection, and SSL/TLS termination.
Third-party use or disclosure of user information — including de-identified, anonymized, or pseudonymized data — is strictly prohibited without active consent from the user. These providers may only process data as instructed by us and for the specific purposes described above.
We do NOT share personal data with data brokers, advertisers, marketers, or partners not listed above.
We do NOT sell user data for profit or other monetary transactions. No data is sold to any third party under any circumstances.
De-identified or anonymized data may be used internally for aggregate analytics (e.g., understanding usage patterns) but is never shared with external parties without explicit user consent.
7. Data Retention & Deletion
- Case Status Data: Cached for up to 24 hours for performance. Historical data retained until 12 months after case completion or user deletion request, then automatically purged.
- User Account Data: Retained while your account is active. After a deletion request, all personal data is permanently removed within 30 days.
- AI Chat History: Retained while your account is active. Deleted with your account or upon request.
- Uploaded Files: Retained while your account is active. Deleted with your account or upon request.
- Payment Records: Retained for 7 years per U.S. financial regulations (IRS requirements).
- Server Logs: Retained for 90 days, then automatically purged.
- Dormant Accounts: If your account is inactive for 24 consecutive months, we will send a notification to your registered email. If no response is received within 30 days, your account and all associated data will be permanently deleted.
8. Your Rights
You have the following rights regarding your personal data. To exercise any of these rights, email support@checkcasestatus.com or use the relevant feature in your account Settings page. We will respond within 30 days.
- Right to Access: Request a copy of all personal data we hold about you.
- Right to Correction: Request correction of inaccurate or incomplete information.
- Right to Deletion: Request permanent deletion of your personal data at any time. Data will be removed within 30 days.
- Right to Portability: Export your case data, chat history, and account data in standard JSON format.
- Right to Opt-Out: Unsubscribe from notifications and marketing communications at any time.
- Account Closure: Close your account at any time via the Settings page or by emailing us. Upon closure, all personal data will be permanently deleted within 30 days, except payment records required by law.
California Consumer Privacy Act (CCPA)
California residents have additional rights under the CCPA:
- Right to Know: What personal information is collected, used, shared, or sold.
- Right to Delete: Request deletion of personal information.
- Right to Opt-Out of Sale: We do not sell personal data, so this right is automatically satisfied.
- Right to Non-Discrimination: We will not discriminate against you for exercising CCPA rights.
9. Cookies & Tracking
We use essential cookies only:
- Authentication session token
- Language preference
- Theme preference (light/dark)
- Security tokens (CSRF protection)
We do NOT use advertising tracking cookies, third-party analytics trackers, or fingerprinting technologies.
10. Children's Privacy
Our service is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If we discover that we have collected personal information from a child under 13, we will promptly delete it. If you believe a child under 13 has provided us personal information, please contact us immediately at support@checkcasestatus.com.
11. Data Breach Notification
In the event of a data breach that compromises your personal information, we will:
- Notify affected users via email within 72 hours of discovering the breach.
- Provide a clear description of the breach, what data was affected, and the steps we are taking to mitigate the impact.
- Provide specific instructions for actions you should take to protect yourself (e.g., changing passwords, monitoring accounts, placing fraud alerts).
- Report the breach to relevant regulatory authorities as required by applicable law, including the California Attorney General if California residents are affected.
12. Business Transfer & Ownership Changes
If KOL.XYZ LLC is involved in a merger, acquisition, sale of assets, or change of ownership:
- We will notify all users via email at least 30 days before any transfer of personal data to a new entity.
- The acquiring entity must agree to honor the terms of this Privacy Policy, or users will be given the option to:
- Export their data before the transfer takes effect.
- Permanently delete their account and all associated data before the transfer.
- If the new entity's privacy practices differ materially from this policy, we will obtain your active consent before transferring your data.
13. Data Sharing Impact on Others
Sharing immigration case information (receipt numbers, case status, AI analysis) with others may reveal sensitive personal details about your immigration status and history. This may also have an impact on family members or dependents listed on the same case or related applications (e.g., derivative beneficiaries on I-130, I-485, or I-539 petitions). Please exercise caution when sharing such data outside this platform.
If you use our API or Firm Portal to manage client cases, you are responsible for obtaining proper consent from your clients before entering their immigration data into our system.
14. Section 508 Accessibility
We are committed to making our service accessible to all users, including those with disabilities, in compliance with Section 508 of the Rehabilitation Act. Our platform meets WCAG 2.1 Level AA standards, including:
- Text and background colors meeting minimum contrast requirements of 4.5:1.
- Keyboard navigation support for all interactive elements.
- Screen reader compatible semantic HTML structure.
- Font size of 14px or larger throughout the application.
- Responsive design for desktop and mobile readability.
15. Policy Changes
We may update this Privacy Policy periodically. For material changes:
- We will obtain your active consent via email or in-app notice.
- We will provide a plain-language summary of what has changed.
- The updated policy will include the effective date and a changelog of modifications.
- Continued use of the service after the notice period constitutes acceptance of the updated policy.
16. Contact
For privacy-related questions, data requests, or concerns:
- Email: support@checkcasestatus.com
- Website: https://checkcasestatus.com
- Operator: KOL.XYZ LLC, registered in the State of Nevada, United States.
CheckCaseStatus.com is operated by KOL.XYZ LLC, a U.S.-incorporated company registered in Nevada.