Last updated: · Version: privacy-2026-10-11
Who is responsible
AsylumStats, also called Asylum Tracker, is operated by an individual sole proprietor in Florida, USA. That operator is responsible for personal data described in this notice and is the controller where data-protection law uses that term. Contact: [email protected].
This notice covers the website, site accounts, and the shared account used by the developer portal. We are independent of EOIR, USCIS, DOJ, and DHS. We do not provide a government case-status service or legal representation.
What we collect and why
Account identity: email address, name, preferred language, account status, linked provider identifier and linking dates, and a provider avatar URL if supplied. We use these to sign you in, link verified identities, and display your account. The current interface uses initials rather than loading your remote avatar. We do not receive your Google password or retain provider access, refresh, or ID tokens after sign-in validation.
Your choices: saved judge, court, and nationality profiles; alert preferences; optional marketing choices; and the versions and dates of legal notices you accepted or acknowledged. These support the features you choose. Saved interests may reveal sensitive inferences, even without a case number. We do not require nationality, immigration status, custody details, or hearing dates to register.
Technical and security data: IP address and browser/request information may reach our hosting and network providers. The account service keeps limited sign-in times, hashed email/IP fingerprints, and session or abuse-prevention records. Public data requests include filters such as court, judge, or nationality codes. We use technical records to serve requests, diagnose failures, enforce limits, and protect access.
Support: information you choose to send us and our replies. Developer accounts also have API key identifiers and digests, usage/quota records, key operations, and audit events. Keep raw keys private. When payments are available, billing records include customer/subscription identifiers, plan, invoices, payment status, and limited payment-method details; Stripe handles card entry. We do not store full card numbers or security codes.
We get these data from you, your chosen sign-in provider, your browser, and service providers handling authentication, payments, or delivery. Public agency datasets are a separate source for statistics; account deletion does not alter those public records.
Your case: local first, sync only by choice
We do not ask you to send A-numbers or immigration documents, and we do not want them. Do not send them to support or add them to account fields. If you choose to use the planner’s local A-number or notes fields, those values stay in your browser.
The planner keeps its record in browser local storage. Its date calculations run on your device. It can request aggregate statistics using selected public codes and filters, but does not upload your A-number, notes, documents, or personal planner dates. Anyone with access to your browser profile may see local data. Clearing storage or losing the device can erase it.
Case sync is optional and separately enabled. The current interface has no case-upload control. If you explicitly turn on an available sync feature, the allowed record contains court/judge/nationality codes, hearing type, hearing date and time, filing/biometrics/master-hearing dates, and six fixed checklist choices. It never stores the A-number, notes, or documents. There is no automatic upload of an existing local case.
A synced record is encrypted in the database, but our running service can decrypt it. It is not end-to-end encryption. You can ask us to remove a synced record; the account sync endpoint removes it from the active database. Your local record remains until you clear it separately. Exported JSON or calendar files become copies under your control; calendar exports omit A-numbers and notes.
Cookies and browser storage
The site account uses __Secure-asylum-account on HTTPS, or asylum-account on local HTTP. It is host-only, scoped to /account, HttpOnly and SameSite=Lax, and Secure on production HTTPS. It carries an encrypted random session identifier. Sessions expire after 60 minutes idle or 24 hours after sign-in, even with activity. The account cookie is not sent to ordinary statistics pages or /api/v1. We do not set a broad XSRF-TOKEN cookie for this flow.
The separate developer host uses __Host-asylum-developer-session on HTTPS, or asylum-developer-session on local HTTP: host-only, Path=/, HttpOnly, SameSite=Lax, Secure in production, with a 60-minute idle lifetime. Signing in on the public site does not sign you into that host.
Local storage holds display choices (at.settings.v1), language (at.locale), filters (at.filters.v2), and planner data (at.case.v3, with older at.case.v1/v2 records and checklist/dismissal preferences during migration). These persist until you clear them. Session storage caches public API responses and briefly remembers a saved-item action across sign-in, for up to 15 minutes. It does not store your account session credentials.
Cloudflare may use security cookies such as cf_clearance or __cf_bm if a challenge or bot-protection feature is enabled. Those cookies follow Cloudflare’s configured domain scope and expiry; they are separate from our account cookies. Google and Stripe may set their own cookies when you visit their sign-in or payment pages, under their own notices.
The application does not set advertising or analytics cookies, and account pages load no analytics, session-replay tools, or remote avatars. Public pages may request icon/chart/map assets from content delivery services and map tiles from map providers; those services receive normal connection information such as IP address. Browser settings let you block cookies or clear storage. Blocking essential cookies prevents sign-in; clearing local storage can delete your planner.
Purposes and lawful bases
Where the GDPR or UK GDPR applies, we use contract necessity to provide the account, saved items, support, and any purchased service you request. Our legitimate interests are keeping the service secure, preventing abuse, and resolving operational problems, balanced against your rights and the sensitivity of these data.
Optional marketing and optional case sync rely on your separate choice and, where required, consent. You can withdraw consent without affecting earlier lawful processing. Turning off marketing does not stop essential sign-in or service messages. Where a legal obligation requires billing or other records, we retain only what that obligation requires. A privacy acknowledgment is not consent to every possible use of your data.
We do not use your account or case data for advertising profiles, sell access to your interests, or make automated decisions about immigration eligibility or legal outcomes. A local planner calculation is a planning aid, not a decision about your rights.
Who receives data
Hosting and database providers run the website and store its records. Cloudflare provides network delivery and security and may route support email. AWS provides data API infrastructure and email delivery where configured. These providers receive the data needed for their functions, including connection information and email recipients/content for delivery.
Google supplies the identity information needed for Google sign-in. Other sign-in providers receive data only if you choose an available method. Stripe processes payments and related fraud, tax, and billing information when a paid service is offered; we use its returned billing status to manage access. Providers may also act independently for their own security or legal duties.
We limit service-provider access to what their work requires. We may also share necessary records with professional advisers or authorities when legally required, as explained below. We do not sell personal data or share it for cross-context behavioral advertising. We do not send your local A-number or notes to these providers.
How long data stays
We keep an active profile, saved items, preferences, and any opted-in synced case while you use the account, until removed or the account is deleted. Export is generated as a direct JSON download; the account service does not keep a separate downloadable export file.
Email sign-in links expire after 15 minutes; OAuth flows expire after 10 minutes. Daily cleanup removes expired flows, idle site sessions, login tokens expired for at least a day, and unverified site-only registrations older than a day. Expiration prevents use before cleanup runs.
An accepted account deletion disables access immediately and schedules removal of the account and its owned rows from the active database after 14 days, with a daily cleanup sweep as a fallback. This is not a self-service recovery period. Removing a saved item or synced case deletes that row without waiting for the account purge.
Backup copies and provider records can remain longer than active records. Security, support, billing, and dispute records are kept only as needed for their purpose or applicable legal duties. We have not yet established a single verified maximum for all backup and provider retention periods. Ask [email protected] for the periods that apply to a request. We do not claim that deleting a live record instantly erases every backup or third-party record.
Export, correction, and deletion
In My account, edit your name and language, remove saved items, manage linked sign-in methods, and turn optional alert or marketing preferences off. In Data & privacy, choose Export data for a JSON copy, or Delete my account and type the displayed confirmation. Export, deletion, and unlinking a sign-in method may require you to sign in again within the last 15 minutes. Account management currently requires JavaScript.
The export includes account/profile and consent data, saved items, preferences, any synced case, retained login metadata, and related developer/billing records. It excludes passwords, session credentials, raw authentication tokens, and shared provider webhook payloads. Contact us for help with data held by a processor or with an email correction; there is no self-service email-change control.
Deletion closes the shared AsylumStats account, including its developer profile. It is currently blocked while developer keys, nonterminal subscriptions, pending billing actions, or undelivered access changes exist. Revoke keys and resolve billing in the developer portal first, or email support for help. This technical block does not cancel your legal right to request deletion or justify continuing unwanted renewal.
Account deletion does not clear your device’s planner, other downloaded copies, or public EOIR statistics. Use the planner’s clear action for local data. If you cannot sign in or use these controls, email [email protected]. We verify ownership proportionately, normally through the account email; we do not ask for immigration documents.
International users and your rights
The operator is in the United States. Data may be processed in the United States and other countries where our providers operate; their protections may differ from those where you live. Where GDPR or UK GDPR transfer rules apply, a permitted transfer mechanism and any required safeguards must cover the transfer. Contact us for information about the relevant providers, locations, and safeguards. We do not claim certification under a transfer framework.
Where applicable, you may request access, correction, erasure, a portable copy, or restriction of processing, object to processing based on legitimate interests, and withdraw consent. Some rights have legal exceptions. You may complain to your local data-protection authority or the UK Information Commissioner’s Office. Contact [email protected] to exercise rights; we respond within the time required by applicable law, generally one month for GDPR/UK GDPR requests, subject to lawful extensions.
California privacy disclosures
The categories we collect are identifiers and contact details, account/customer records, internet and network activity, and—if you use a paid product—commercial/billing records. Optional synced dates and saved interests can be sensitive in context. Sources, purposes, recipients, and retention are described above; those descriptions also cover these categories during the preceding 12 months to the extent the features were in use.
We do not sell personal information or share it for cross-context behavioral advertising, and do not knowingly sell or share children’s data. We do not use sensitive personal information to infer characteristics for advertising. There is no sale or advertising sharing to opt out of, including when a browser sends Global Privacy Control.
If the CCPA/CPRA applies to us and your request, you may have rights to know/access, correct, delete, opt out of sale/sharing, limit certain uses of sensitive information, and receive equal treatment for exercising rights. An authorized agent may contact us, with proportionate proof of authority. Use the account controls or [email protected]. We provide those practical controls to all users without claiming that every privacy law applies to this small service.
Security and shared devices
We use restricted access, encrypted account sessions, short-lived single-use sign-in links, and encrypted synced case payloads. Account and authentication responses are designed to be private and not cached publicly. Email, profile, and saved-item metadata are not end-to-end encrypted. No system can guarantee perfect security or protection from lawful disclosure.
Protect your email and device, sign out on shared devices, and use Sign out everywhere if access may be compromised. Clear local case data separately. Do not forward magic links or API keys. Report security concerns to [email protected] without including credentials or private case documents.
Requests from authorities
We do not provide voluntary access to private accounts for immigration enforcement. If we receive a legal request, we will review its validity and scope, seek legal advice when appropriate, and challenge or seek to narrow improper or overbroad demands where there is a lawful basis. We will disclose only the data we hold that we are legally required to provide.
We will notify affected users when legally permitted, unless notice would create a serious safety risk or compromise a lawful investigation. We cannot promise advance notice, immunity from legal process, or anonymity. Data that stays only in your browser is not in our account database, but data you explicitly sync is held by the service.
Children
Accounts and paid services are intended for adults 18 or older. We do not knowingly collect account information from children under 13, or children below a higher age where applicable law requires parental permission. If you believe a child has supplied personal data, contact us so we can review and delete it as appropriate. Do not send the child’s immigration documents.
Changes and contact
We will update this notice as the product or our practices change, with a new date and version. We will give notice of material account changes through the service or email and obtain fresh consent where required. Contact [email protected] for privacy questions or requests. Do not include an A-number, immigration document, or sign-in link.

