PRIVATE BETA · Review every form carefully before filing.
← Back to home

How we protect your data

A plain-English summary of the security and privacy controls that guard your immigration paperwork on GreenCardsUSA. This system was designed by Thomas Williams, Esq. — a fully licensed U.S. immigration attorney with 35+ years of experience exclusively handling U.S. immigration cases — every safeguard below was chosen with immigrant families in mind. For the formal versions see our Privacy Policy and Terms of Service.

A note for immigrant families

We know why you might be nervous. Putting your immigration paperwork online — sometimes for the first time — feels risky. Here is what we promise, in plain words:

  • Your data stays in the United States. It never leaves our U.S. servers, and it is never sent to any foreign country or third-party marketing company.
  • We do not share with ICE, DHS, or any enforcement agency voluntarily. The only way any government body gets your file from us is with a lawful U.S. subpoena or court order — the same rule that protects your paper attorney's files.
  • If a subpoena arrives, we notify you first whenever the law allows, so you have time to consult your attorney before the file is released.
  • You own your data. You can download or delete your entire case at any time. When you delete it, it's gone from our active systems within 30 days.

Your data lives on U.S. servers only

Your documents and case data are stored on secure, U.S.-based infrastructure. Nothing is ever mirrored or backed up to servers outside the United States. Your immigration file does not travel — ever.

We require a subpoena to release your file

We do not voluntarily share your case with ICE, DHS, USCIS enforcement, or any government agency. We release your data only when we receive a lawful U.S. subpoena or court order — and whenever the law allows, we notify you first so you can consult your attorney.

Your password is never stored

Passwords are hashed with bcrypt before they touch our database. Even our own team — and anyone who ever manages to read our database — cannot recover them.

Sessions live in HttpOnly cookies

Your login token is stored in an HttpOnly, Secure, SameSite=Lax cookie. It cannot be read by JavaScript and it does not travel to other websites — two of the biggest defenses against session theft.

Private beta by default

The site is invitation-only. Registration requires a code you received from us, so opportunistic visitors can’t create accounts to poke around.

Every request checks case ownership

Every API endpoint that touches a case verifies you own it. There is no code path in which one user can read, download, or modify another user’s petition — and this is protected by an automated test suite that runs on every deploy.

HTTPS everywhere

All traffic is encrypted in transit with TLS. The connection between your browser and our server cannot be read or altered by anyone in between — not your coffee shop’s Wi-Fi, not your ISP.

Automated processing — what actually happens

When you upload a document, we send the page images to Anthropic’s Claude Sonnet 4.5 model to read them, translate them, and fill your form fields. That data is used strictly to serve your request. We do not sell your data. We do not train models on it.

Smart Sort staging auto-deletes

When you drop a stack of documents through Smart Sort, the raw page images sit in a temporary staging area only long enough for you to review and apply them. If you don’t confirm within an hour, the staged images are automatically deleted.

No third-party trackers

No Google Analytics. No Facebook pixel. No ad networks. No hidden third parties reading your immigration data. Just you, our servers, and the OCR provider needed to fill your forms.

Every change is logged

Every edit to a case field is recorded to a per-case audit log with timestamp, source (typed, OCR, or corrected), and the person who made the change. If a form goes out with a wrong value, you can trace where it came from.

You can delete your data

Ask us to remove your account and all its data at any time by emailing privacy@greencardsusa.ai. Depending on your jurisdiction (California, EU, others) you may have additional formal rights spelled out in our Privacy Policy.

Hardened HTTP responses

Our server sends security headers on every response —X-Frame-Options,X-Content-Type-Options,Referrer-Policy — to protect against clickjacking, MIME sniffing, and referer leaks.

Externally audited

Our codebase is reviewed by an independent security audit tool before every deploy. Findings are triaged and remediated with automated regression tests that lock in the fixes.

What we ask of you

  • Use a unique password for this account — not one you’ve used elsewhere. A password manager makes this painless.
  • Do not share your invite code with anyone you don’t personally trust. If you suspect a code has leaked, email us and we’ll rotate it.
  • Log out on shared computers, especially at libraries or attorneys’ offices.
  • Review every form before you file it. The system is accurate but not infallible — treat every generated PDF as a first draft, not the final word.

Report a security concern

Found a vulnerability or noticed something unusual? Please email security@greencardsusa.ai — we investigate every report and respond within 48 hours. We do not pursue legal action against good-faith researchers who follow responsible disclosure.

Last reviewed: February 14, 2026 · This page is a plain-English summary. See our Privacy Policy and Terms of Service for the formal versions.

Install GreenCardsUSA
Snap document photos, get case updates — feels like an app.