Privacy policy
What we collect, why, and how you remain in control
Last updated: July 24, 2026
Privacy by design: we minimize data, disclose the providers actually used, and do not take custody of government-portal credentials.
1. Who we are
USAVPC is a private U.S. and Schengen visa-preparation advisor delivered as a webapp PWA, with a Schengen dossier and DS-160 workspace. We are not a government, law firm, embassy, consulate, or visa application center, and we are not affiliated with or endorsed by them.
This policy describes the data handled when you use usavpc.org and related support services.
2. Data we collect
We collect only the information needed to provide the workspace and support you request.
- Account and contact data, such as your name, email address, language, and authentication identifiers.
- One-way hashes of eight high-entropy recovery codes, plus their creation and use timestamps. The readable codes are displayed to you once and are not stored by USAVPC.
- Consent records containing the accepted Terms and Privacy versions, server timestamp, language, and source. We do not store an IP address or device fingerprint in this ledger.
- The public advisor asks for route, nationality, residence, travel dates, and evidence-readiness answers. It does not ask for your name, passport number, or documents, and its assessment is stored only in your browser until you delete it or choose to use it in authenticated interview practice.
- The free orientation consultation asks for a goal, destination, nationality country, lawful-residence country, preparation stage, and broad immigration-history category. If you opt in, the opening message and confirmed context are sent to an external conversational writing service to phrase a bounded response. Do not enter names, contact details, document numbers, financial data, or criminal details. USAVPC does not persist the consultation transcript; USAVPC rules determine the route, cautions, prices, and official sources.
- Authenticated interview-practice sessions in Supabase contain the selected route, an advisor snapshot without direct identifiers if supplied, the questions, your text answers, bounded consistency feedback, and any accepted conversational note. The snapshot and answers remain personal data even without a name or passport number. After separate opt-in and sensitive-data screening, each bounded answer may be sent to an external conversational writing service with closed USAVPC checks so it can phrase a limited note. That service does not select the next question, change the primary review, predict an outcome, or receive the passport image or profile identifiers. We do not record or store audio. Optional spoken mode plays prepared files created only from public question text; it does not enable the microphone or send your answer, and the on/off preference remains in that browser.
- When you open interview practice, USAVPC derives a recent-progress report from deterministic signals in up to 12 of your unexpired completed sessions. The report is not stored as a separate profile, is not compared with other users, and does not include a score or visa-outcome probability.
- The authenticated Schengen dossier stores nationality, lawful-residence country, trip dates, itinerary stops, previous short-stay entry and exit dates, passport-expiry date, responsible office label, checklist states, and task completion. Its optional Annex I form preparer also stores the identity, contact, travel-document, host, funding, and declaration facts you enter because those fields appear on the harmonised application form. If your account already has a confirmed passport profile, compatible values can fill empty Schengen fields without replacing facts you entered.
- For the documentary Schengen dossier, Supabase privately stores the supporting PDF or image files you choose to upload, server-owned requirement records, links between each file and requirement, coverage declarations, evidence versions, review snapshots and outcomes, and the history of staff-document-access authorization. File validation and a status such as uploaded, validated, system-verified, or ready for applicant review describe preparation coverage only. They do not authenticate a document, detect fraud, predict approval, or guarantee that a consulate will accept it.
- Application data you enter, including identity, passport, family, education, employment, travel, and eligibility answers required for DS-160 preparation.
- A guided study or work case stores its exact route, destination, route-version snapshot, route-specific application packet, checkpoints, filing snapshot, and any decision or reapplication plan you choose to record. It can also privately store the PDF or image files you add under its route-specific document requirements. A separate staff-access grant records when you authorize or revoke review of the completed packet, those files, and the current passport version, along with the exact version reviewed and any applicant action requested.
- Before using authenticated U.S. or Schengen interview practice, the private Schengen dossier, or DS-160 preparation, your account requires a current photograph of the passport biography page and completed OCR. You may complete this capture before payment. We store each accepted image as a private passport version for the relevant person in Supabase Storage. Tesseract.js first reads the selected image in your browser so you can review the result; we do not send it to the external conversational service or an external OCR provider.
- When you confirm the values, USAVPC's own Next.js function privately downloads that exact stored image, verifies its type, size, and cryptographic hash, and performs a second independent MRZ reading with the bundled Tesseract.js engine on Netlify. The complete OCR text is used transiently for validation and is not persisted. For each accepted version, we store the structured identity and document fields, MRZ lines and check results, bounded corrections and visual observations, prefill values, OCR version, integrity metadata, and timestamps. The current confirmed version verifies the passport requirement and can populate compatible DS-160 and empty Schengen fields. OCR does not authenticate the document, detect fraud, or guarantee fields that cannot be confirmed from the image, so you must review the values.
- The Schengen documentary dossier and a paid guided study or work case may contain the supporting PDF or image files you choose to upload. Files must never contain government-portal credentials.
- A DS-160 confirmation-page PDF only if you choose to upload it after personally submitting in CEAC.
- Payment records such as plan, amount, status, Stripe transaction identifiers, and timestamps. Stripe receives the payment-card details; USAVPC does not store full card numbers.
- Support requests you send, including your contact details and message. We do not collect an IP address or device fingerprint with the support request.
- Limited security and diagnostic records, such as timestamps, incident references, error codes, and administrative workflow events. The application does not run behavioral advertising or behavioral analytics.
3. How we use data
We use data to authenticate you, save your answers, validate completeness and consistency, read and reuse confirmed passport facts, provide the local formatting review you request, process payments, deliver files, support users, prevent abuse, and maintain the service.
- Optional DS-160 formatting review uses USAVPC code to adjust only spacing and line breaks. It does not translate, rewrite, or add facts, and no DS-160 answer is sent to an external conversational writing service. The proposed value remains separate until you expressly choose what to save. Interview-practice follow-ups, question selection, and restored primary reviews also use USAVPC-controlled rules; external conversational processing is limited to the disclosed note.
- Passport OCR uses the Tesseract.js engine twice: first in your browser for review and then in USAVPC's own Netlify function to independently read the same private, integrity-checked image. Supabase stores the image and version record. We do not send the image or OCR text to an external conversational or OCR service, and we do not retain the complete OCR text.
- We do not sell personal data and do not use advisor, interview, or DS-160 answers to target advertising.
- We do not collect or store CEAC or appointment-portal passwords, security questions, or security answers.
- Staff access to Schengen document files is off by default. It requires your separate, express opt-in, can be revoked, and is recorded with authorization and revocation timestamps. An active grant permits only authorized staff to access the private case information needed for review; relevant case opens, sensitive-field actions, document actions, review outcomes, and transfer-session events are auditable. Staff are not given complete OCR text or government-portal credentials.
- Staff access to a completed guided study or work case is also off by default, separately revocable, and limited to an active paid case. An active grant includes its route-specific supporting files. Review is bound to the exact application-packet, document-set, and passport versions; a client change invalidates the prior review and any pending transfer session.
- If you expressly authorize staff-assisted transfer, the server releases only currently accepted fields through a single-use five-minute capability. The private Chrome extension keeps the transfer bundle only in browser session memory and fills only recognized empty fields after a staff click.
4. Service providers and disclosure
We disclose data only as needed to operate the service, follow your instructions, protect the service, or comply with law. Current categories of processors include Supabase for authentication, database, and private passport/case-file storage; Stripe for payments; Netlify for hosting, server functions, DS-160 spacing review, and the private second passport-MRZ reading; and an external conversational writing service for opt-in consultation or interview text. Prepared question audio is generated only from public text. Tesseract.js is bundled with the service and runs in both the browser and USAVPC's own Netlify function; the passport image and OCR text are not sent to the conversational service or a separate OCR provider. Account registration and recovery do not use an email-delivery provider.
If you choose the external WhatsApp link, Meta/WhatsApp receives the information you send under its own privacy terms. The in-site support form does not require WhatsApp and does not send your message to WhatsApp.
USAVPC does not automatically lodge or submit a U.S. or Schengen application. If you opt in, authorized staff may transcribe accepted DS-160 answers with the private extension, but it cannot handle credentials, CAPTCHA, navigation, signature, or submission. The applicant remains responsible for identifying assistance where required and for reviewing, signing, and submitting through the applicable official procedure, except where official rules permit a guardian or other authorized person.
5. Security
We use access controls, server-only database boundaries, private storage, restricted file types, file-signature and integrity validation, no-store downloads, security audit events, one-time extension capabilities, transport encryption, authenticated administrative access, and payment-webhook verification. No online service can promise absolute security.
Keep your account password and recovery codes private, store the readable codes outside the PWA, and replace them from your profile if you believe they were exposed.
6. Retention and deletion
Application content, structured passport versions, required passport images, and optional supporting case documents are kept while your account and service remain active so you can resume work and receive the purchased review. Starting or accepting a newer passport version changes the current version without erasing an earlier completed version. A completed version can remain as the immutable passport snapshot linked to an application, including a closed application, so its reviewed evidence is not silently changed.
You may export account and application data, structured passport-version metadata, and case-document metadata or request account deletion from the profile area or by email. Private file bytes are not embedded in the JSON export. When self-service deletion is accepted, ordinary account access is blocked and personal database rows are purged. Private Storage cleanup and deletion of the Supabase Auth identity then finish asynchronously through a retryable deletion ledger. A still-usable signed-upload path is first neutralized, retained only through its short token-expiry safety window, swept again, and then removed. The service does not offer individual deletion of a completed passport snapshot while it remains required for an active case; you may exercise applicable privacy rights or delete the account. One-time autofill capabilities expire after five minutes and cannot be reused.
Interview-practice text is scheduled to expire after 180 days. An automatic database purge runs hourly and removes sessions that have reached their expiration time. Practice is also removed when you delete the linked account. The public advisor remains only in that browser and can be cleared by starting a new assessment or clearing site data.
A saved Schengen dossier is scheduled to expire 365 days after its last update. Saving or editing it renews that period. Its case, requirements, links, snapshots, reviews, access grants, and file metadata are included in account export and deletion. The hourly database purge removes an expired dossier and its personal rows; removal of its private Supabase Storage objects can finish asynchronously through the retryable cleanup ledger and signed-upload safety window.
Guided study and work cases, their packet versions, checkpoints, route-specific file metadata, staff-access grants, and review records are included in account export and deletion. Their private file objects are removed through the retryable cleanup ledger. A one-time transfer session expires after five minutes and is invalidated sooner if access is revoked or the reviewed case or passport version changes.
An open or in-progress support request is scheduled to expire after 180 days; a resolved request, after 30 days. The same hourly database purge removes expired requests. Requests linked to an authenticated account are also deleted with that account; anonymous requests can be deleted after we verify a privacy request.
Recovery-code hashes are removed with the account. Minimal, unlinked payment-ledger records may be retained for accounting, tax, fraud, refund, and dispute obligations. A service-only deletion record may retain the account UUID, exact private object paths, completion and retry timestamps, bounded error codes, and aggregate deletion counts needed to complete and evidence the deletion; it does not retain the deleted passport image, application answers, email address, or support message. Other account data is removed through the account-deletion control, subject to backups, security records, active disputes, fraud prevention, and legal obligations.
7. Your choices and rights
Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to processing. You can review and correct passport values produced by OCR, replace the source image, and withdraw optional DS-160 transfer or Schengen staff-document-access authorization. We will verify requests to protect your information.
You can also withdraw staff access to a guided study or work case from that case workspace.
The service is intended for adults. A parent or lawful guardian should manage any information for a minor in accordance with the official DS-160 rules.
8. International processing and changes
Our providers may process data in the United States and other countries where they operate. Their privacy and security terms also apply to their processing.
We will post material policy changes here and update the date above. We will provide additional notice when required.
