Stored data
Public case observations contain receipt identifiers, status text, dates, form type, and derived block fields. Account profiles, tracked cases, nicknames, and alert preferences are private.
Access controls
Supabase Row Level Security restricts profiles, tracked cases, and notification preferences to the authenticated owner. Aggregate analytics and case observations can be publicly readable.
Receipt display
Full receipt numbers are accepted for lookup, but individual-case views mask them where the full identifier is not necessary. Public activity views use masked identifiers.
Credentials
The browser never receives a Supabase service-role key or USCIS client secret. Live collection runs only in the server-side worker.
No certification claims
This MVP does not claim any compliance certification. Review retention, deletion, consent, and incident-response policies before production launch.