MyCasesHub for Firms
Sign in

Privacy Policy

Last updated: August 9, 2026

This policy explains what MyCasesHub for Firms does with data. It covers the service at firm.mycaseshub.com and the accounts, records, and files inside it.

MyCasesHub, Inc. is a Delaware corporation. In this policy, "we" and "us" mean MyCasesHub, Inc. "You" means the law firm or organization that holds an account, and the people at that firm who sign in.

1. Two groups of people

Two different groups have data in this service, and they are treated differently.

  • Firm users. These are the lawyers and staff who sign in. We hold their account data directly.
  • Firm clients. These are the people whose immigration cases a firm tracks. Firm clients do not sign in and do not hold accounts. The firm enters their records, and the firm decides what is entered.

For firm client records, the firm is in charge of the data and we handle it on the firm's instructions. If you are a firm client and want your records changed or removed, ask your law firm first. You can also write to us at privacy@mycaseshub.com and we will pass the request to the firm and help carry it out.

2. What we collect

Account data for firm users

  • Name and work email address.
  • A password, stored only as an Argon2id hash. We never store the password itself. If you use Google Sign-In instead, we store the account identifier Google gives us, not your Google password.
  • Optional profile photo.
  • Sign-in records: the time you were last active, failed sign-in counts, and active session records. We use these to lock out password guessing.
  • Your role at the firm and your notification settings.

Client and case records your firm enters

  • Client name, date of birth, country of birth, country of citizenship, A-Number, email address, phone number, preferred language, tags, notes, and family relationships between clients.
  • Case records: USCIS receipt numbers, form type, case category, status history, and dates returned by government systems.
  • For consular cases only: a passport number and a surname, which are needed to look up a visa case at the U.S. Department of State. These two fields are encrypted before they are written to our database, and the app only ever shows the passport number masked.
  • Files your firm uploads, up to 25 MB each. Files are stored in Amazon S3 and are served through download links that expire after 60 seconds and are locked to the IP address that asked for them.

Billing data

Payments run through Paddle, which acts as the merchant of record. Paddle collects the card details. We never receive or store a full card number. We keep your plan, seat count, invoice history, and billing contact.

Usage data

  • IP address, browser type and version, device type, pages viewed, and the time of each visit.
  • Product analytics events, such as which features are opened. We use these to find broken flows and decide what to build next.
  • An audit log of actions taken in your firm's account: who did what, to which record, and when. This exists so a firm can answer its own security questions.

Cookies

  • Required cookies keep you signed in and block cross-site request forgery. The service does not work without them.
  • Analytics cookies tell us how the product is used. You can turn these off in Settings, under Legal, and the rest of the service keeps working.
  • We do not use advertising or tracking cookies. Your display choices, such as light or dark theme, are kept in your browser's local storage and never sent to us.

What we do not collect

We do not collect geolocation data. We do not collect medical or health information. We do not collect financial account numbers, credit scores, or credit history. We do not read your device contacts, calendar, camera, microphone, or photo library. We do not collect biometric or genetic information. We do not buy data about you from data brokers.

3. How we use data

  • To run the service and show your firm its own cases and clients.
  • To check case status with U.S. government systems on a schedule and alert your firm when something changes.
  • To sign you in and keep your account secure.
  • To bill you and send receipts.
  • To answer support requests. Support staff open firm data only when it is needed to answer a request, and every access is written to the audit log.
  • To find and fix problems, and to decide which features to build.
  • To meet legal obligations and to respond to lawful requests.

We do not use client or case records to train machine learning models. We do not use them for advertising, and we do not run advertising on this service.

De-identified and aggregated data

We produce statistics such as average processing time by form type and service center. To do this we strip names, contact details, receipt numbers, A-Numbers, passport numbers, and every other identifier, and we combine records into group totals. The result describes a group, not a person.

We may publish or share these group statistics. We do not attempt to re-identify anyone from them, and we require anyone who receives them to agree not to try either. If a group is too small to be safely combined, we do not publish it.

4. Who we share data with

We share data only with the companies below, only for the reasons listed, and only to the extent each one needs. Each is bound by a written contract. This is the complete list as of the date at the top of this page.

Amazon Web Services, Inc. (United States)

Hosting, database, file storage, and the email we send you. They store and transmit data for us and do not use it for their own purposes.

What they receive: All service data, including account data, client and case records, uploaded files, and logs. Data is held in U.S. regions.

Paddle.com Market Ltd (United Kingdom)

Payment processing as merchant of record. They handle the transaction and the tax on it. They do not receive client or case records.

What they receive: Billing contact name and email, company name, billing address, plan, and card details you enter on their form.

PostHog, Inc. (United States)

Product analytics. They tell us which features are used and where the product breaks. They do not use the data for their own purposes and do not sell it.

What they receive: Usage events, page views, browser and device type, IP address, and the signed-in user's account identifier and email. Session replays record the screen as it looked, with the people on it blanked out. Four kinds of text are replaced with asterisks wherever they appear, on every screen: the name of a client or a family member; a USCIS receipt number, Alien Registration Number or passport number; an email address; and a phone number. A name is recognised by matching the names your account has received from us, so it is blanked in ordinary text too, including inside a note or a case update that mentions it. The limits of that method are worth stating plainly. A person named only in free text you typed, and never entered as a client, is not recognised and is recorded. A passport number is recognised the same way — from the value you entered in the consular fields — and not by its shape, because passport numbers have no single format. Everything else stays readable, including the interface, form types, statuses, categories, tags, group and matter names apart from the client surname a family group is captioned with, your own labels for a case, uploaded file names, decision and filing dates, and the case text we receive from USCIS and the Department of State. Passwords and other typed-in field values are never recorded. No client or case records are sent beyond what a replay shows.

Google LLC (United States)

Google Sign-In, only if you choose to sign in that way. Google confirms your identity to us. If you sign in with a password instead, no data goes to Google.

What they receive: Your email address and the account identifier Google issues. We send Google nothing else.

How this list changes

Companies on this list get replaced over time. A payment processor or an analytics vendor may change. When that happens we do three things, in this order.

  • We update this section to name the new company and say what it receives, before it starts handling any data.
  • We email every account owner and admin at least 30 days ahead, with a plain-language note saying who is being added or replaced and why.
  • We hold the new company to the same contract terms as the one it replaces, listed in section 6.

If you do not want your data handled by a replacement, tell us during those 30 days. You can export everything and close your account, and we will refund the unused part of your term.

We also share data when the law requires it, such as a valid subpoena or court order. When we are allowed to tell you first, we will. We may share data to investigate fraud, to enforce our Terms of Service, or to protect someone from harm.

We send case identifiers to U.S. government systems, including U.S. Citizenship and Immigration Services and the U.S. Department of State, in order to look up the status of a case your firm asked us to track. That is the purpose of the product.

5. We do not sell your data

We do not sell data. Not for money, and not for anything else of value. We do not rent, trade, or barter it. We do not share it with data brokers, advertisers, marketers, or list builders. We have never done this and we do not have a plan to start.

This applies to de-identified and aggregated data too. Group statistics are not sold.

6. Limits we place on other companies

Every company named in section 4 is a service provider working on our instructions. Each one is bound by a written contract that holds it to the terms of this policy.

  • They may use the data only to provide their service to us. They may not use it for their own purposes.
  • They are prohibited from using or disclosing your information for any other reason without your active consent. This includes de-identified, anonymized, and pseudonymized data.
  • They may not sell the data.
  • They must delete or return the data when their work for us ends.
  • They must tell us about a security incident so we can tell you.

If we ever need to share data in a way this policy does not already cover, we will ask you first and wait for a yes. Staying silent is not a yes.

7. Your choices about sharing

Here is what you control, and what each choice costs and buys you.

  • Analytics. You can turn product analytics off in Settings, under Legal. The benefit of leaving it on is that we find and fix broken flows faster. The cost is that usage events leave our systems and go to PostHog. Turning it off stops those events, and from your next page load your browser does not contact PostHog at all. It does not change how the product works for you. The switch applies to the browser you set it in.
  • Consular case tracking. Passport number and surname are required to look up a visa case at the Department of State. If you do not want to store them, do not add consular cases. Every other feature still works. The limitation is that we cannot track a consular case without them.
  • Uploaded files. Uploading documents is optional. The benefit is having the file next to the case. The risk is that anyone with access to your firm's account can open it, so grant firm access carefully.
  • Google Sign-In. Optional. A password account works the same way.
  • Notification emails. You can switch off case alerts and summaries in Settings. We will still send billing and security emails, because those are part of holding an account.

There is a limit worth stating plainly. Once data has been shared, we cannot always pull it back. If a report has been exported, or a colleague has downloaded a file, that copy is outside our systems and outside our control.

8. How sharing can affect other people

Immigration records rarely describe one person alone. What a firm enters about one client can reveal things about other people.

  • Family relationships in the product link people together. A petition record can show that two people are married, or that one is the parent of another.
  • A record can reveal a relative's country of birth, citizenship, or immigration status, even when that relative is not a client of the firm.
  • An uploaded file often contains other people. A birth certificate names parents. A joint tax return names a spouse.
  • These other people usually did not agree to anything with us, and often do not know a record exists.

So before your firm enters or shares a record, consider who else is in it. Give firm access only to staff who need it. Enter only what the case actually requires. When you export or email a report, check who is named inside it.

9. How we protect data

  • All traffic runs over HTTPS. Data is encrypted in transit.
  • Databases and file storage are encrypted at rest.
  • Passport numbers and surnames are separately encrypted at the application level, before they reach the database.
  • Passwords are stored as Argon2id hashes and are never readable.
  • Every firm's data is separated by firm. A request carrying one firm's session cannot read another firm's records.
  • Access to production systems is limited to the staff who operate the service, and it is logged.
  • File download links expire after 60 seconds and only work from the IP address that asked for them.

No system is perfectly secure, and we will not claim otherwise. What we can promise is that we use current, standard protections and that we tell you when something goes wrong.

10. If there is a data breach

If someone gets unauthorized access to data that identifies you or your firm's clients, we will tell you.

  • We will email the firm's owner and admin users within 72 hours of confirming the breach, and post a notice inside the product.
  • The notice will say what happened, when, which kinds of data were involved, how many records we believe were affected, and what we have done to stop it.
  • It will tell you what to do next. That normally means changing your password, signing out other sessions, reviewing your audit log for activity you do not recognize, and telling any client whose records were involved.
  • We will give you a named contact who can answer follow-up questions.
  • We will notify regulators and affected individuals where the law requires it, and we will keep updating you as we learn more.

11. How long we keep data

  • While your account is open, we keep your account data, client records, case records, and files until you delete them or close the account. We do not delete your working records on a timer, because immigration matters run for years.
  • Deleted records are removed from the live product right away. They are erased from our systems within 30 days, and from encrypted backups within 90 days.
  • Passport numbers and surnames are erased permanently the moment the case is deleted. They are not held in a recoverable state.
  • Audit logs are kept for 24 months, then deleted. Firms need this history for their own security reviews.
  • Records of the terms you accepted are kept for as long as the account exists, and are deleted with it. They are the only proof of which version of these documents you agreed to and when, so they outlive the 24-month audit-log window above.
  • Billing records are kept for 7 years, because tax law requires it. These hold invoices and plan history, not client records.
  • Backups roll on a 90-day cycle and are encrypted.

Dormant accounts

An account is dormant when nobody at the firm has signed in for 24 months.

  • At 24 months we email the account owner to say the account is dormant and that the data is scheduled for deletion.
  • If nobody signs in or replies within 90 days of that email, we permanently delete the account and everything in it.
  • Signing in at any point during those 90 days stops the deletion, and the clock starts again.

12. Delete your data or close your account

Delete individual records

Any firm user with permission can delete a client, a case, or a file from inside the product. Deleting a case erases its passport number and surname at once.

Delete everything

To have all of your data permanently deleted, email privacy@mycaseshub.com from the address on your account, and write "delete my data" in the subject line. Settings, under Legal, has a link that fills in that email for you.

How soon it happens. We confirm your request within 3 business days. We erase the data from our live systems within 30 days of that confirmation, and from encrypted backups within 90 days. We email you when each step is done.

Deletion is permanent. We cannot restore data afterward, so export anything you want to keep first.

Two things survive a deletion request, and only these two. We keep billing records for 7 years because tax law requires it. We keep a one-line record that a deletion happened, so we can prove we honored it. Neither holds client or case data.

Export your data first

Before you delete anything, you can download it. Client and case records export to CSV from inside the product. Uploaded files download from the Documents page. If you want a full copy of everything at once, email privacy@mycaseshub.com and we will send you a machine-readable archive within 30 days at no charge.

We do not collect health information. If you have uploaded a document that contains any, you can download it and then delete it, and that deletion follows the same schedule as everything else.

Close your account

The firm owner closes the account by emailing privacy@mycaseshub.com from the address on the account. We confirm within 3 business days. Closing the account cancels billing at the end of the current period and signs out every user.

Closing an account is not the same as deleting the data. We hold your data for 30 days after you close, so you can change your mind and export it. After 30 days we delete it on the schedule above. If you want it gone immediately, say so in the same request and we will start deletion right away.

13. If our business is sold or closes

If MyCasesHub, Inc. is bought, merged, or transferred to another company, your data may move to the new owner. Here is what we commit to.

  • We will tell you before it happens. We will email every account owner and admin at least 30 days before any transfer, and post a notice inside the product.
  • The new owner must keep this policy. We will require, in the sale agreement, that the buyer honors this policy for data that existed before the sale.
  • If the buyer wants different terms, they must ask you. They must obtain your active consent before applying a weaker policy to your existing data.
  • You can leave instead. During those 30 days you can export everything and ask us to delete your data, and we will complete the deletion before the transfer closes.

If we shut the business down instead of selling it, we will email you at least 60 days ahead. During that window you can download everything. At the end of it we securely destroy all customer data, including backups, and we will publish confirmation when that is done.

14. Changes to this policy

We will ask before changing the deal. When we make a material change to this policy or to our Terms of Service, we get your active consent. Here is exactly how.

  • We email every account owner and admin at least 30 days before the change takes effect.
  • The email carries a plain-language summary of what changed, written as a short list: what it said before, what it says now, and why. The full text is linked, with the changes marked.
  • The next time you sign in, the product shows the same summary and asks you to accept. You must click to accept. Continuing to use the service without clicking does not count as acceptance, and closing the box does not either.
  • If you do not accept, tell us. You can export your data and close your account, and we will refund the unused part of your current term.

For small changes that do not affect your rights, such as fixing a typo or renaming a page, we update the "Last updated" date and note it in our release notes. We do not send a consent request for those.

15. California privacy rights

If you live in California, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the rights below. We extend the same rights to everyone, wherever they live.

  • Know. Ask what personal information we have collected about you, where it came from, why we collected it, and who we shared it with.
  • Access. Get a copy in a portable, machine-readable format.
  • Delete. Ask us to delete it, subject only to the legal record-keeping named in section 12.
  • Correct. Ask us to fix information that is wrong.
  • Opt out of sale or sharing. There is nothing to opt out of. We do not sell personal information and we do not share it for cross-context behavioral advertising. We have not done so in the past 12 months, including for anyone under 16.
  • Limit use of sensitive information. We use sensitive personal information, such as A-Numbers and passport numbers, only to provide the service you asked for. We do not use it to infer anything about you.
  • No retaliation. We will not deny you service, change your price, or lower your service quality because you used one of these rights.

To use any of these rights, email privacy@mycaseshub.com. We confirm within 10 business days and answer within 45 days. If we need more time we will tell you why, and we will not take more than 90 days total. We verify your identity by emailing the address on the account. An authorized agent may act for you with your written permission.

Under CCPA terms, we are a "service provider" for the client and case records a firm enters, and a "business" for firm user account data and usage data.

16. Where data is held

Our servers are in the United States, and data is stored and processed there. If you are outside the United States, using this service means your data is transferred to the United States, where privacy law differs from your own country's.

17. Children

This is a tool for law firms. Nobody under 18 may hold an account, and we do not knowingly collect data directly from children.

Firms do enter case records about minors, because immigration cases involve children. Those records come from the firm, not from the child. We treat them the same as any other client record, and the same deletion rules apply.

18. Contact us

Write to privacy@mycaseshub.com with any question about this policy, and with any request to access, correct, export, or delete data. We answer within 3 business days.

MyCasesHub, Inc. is a Delaware corporation. Our registered agent is Harvard Business Services, Inc., 16192 Coastal Highway, Lewes, Delaware 19958.