Privacy policy
This policy describes how NIW Bearings collects, uses, stores, and deletes information. It describes what the product does today, not what it is planned to do.
What we do not collect
The shortest way to describe this product is by what it never asks for. There is no field, no form, and no upload path for any of the following, so there is nothing for us to lose, disclose, or be compelled to hand over:
- Your immigration status. We do not ask what visa you hold or when it expires. We used to; we removed both fields rather than hold them for one optional feature.
- Government identifiers. No receipt or case numbers, no A-numbers, no passport numbers, no Social Security numbers.
- Your immigration history beyond this case. Arrests, refusals, and prior status violations are your attorney’s territory, not ours.
- Employer names and salary. We ask for an employer type from a fixed list, never a company name and never a number on a paycheck.
- Documents. The product accepts no uploads at this stage. There is nowhere to attach a petition, a letter, or a passport scan.
We also do not sell your data, do not run advertising or hold any advertising relationship, and do not track you across other sites. We do not verify anything you tell us, and we do not claim to.
What we do hold, and what protects it
Everything below is either something you typed or something the product had to record in order to work. Each is listed with the protection that actually applies to it, not a general assurance.
- Your email address. This one is not optional and we will not pretend otherwise: the email address is the account. Authentication is handled by Supabase, using either a magic link or Google sign-in. If you use Google sign-in, Google returns the basic profile attached to that account — name, email address, and profile picture — to our authentication provider. We do not ask for it, we do not display it, and no feature reads it. Deleting your account deletes the address.
- Your quiz answers. Eight questions about your role, country of birth, case stage, degree, field, evidence, recommendation letters, and how clearly you can describe your endeavor. Before you sign up they live only in your own browser’s local storage; if you create an account they are copied to your profile.
- Your profile fields. The profile page holds 25 fields, of which the eight quiz answers are the first. The rest cover your U.S. state, years of experience, degree and where you earned it, field, employer type, whether you have a spouse, whether you have an attorney, whether this is a first filing or a refile, whether you have a concurrent I-485 or a parallel EB-1A petition, banded counts of publications, citations, patents and funding, whether your evidence reaches beyond your employer, how independent your recommendation letters are, a one-line description of your endeavor that you write yourself, your endeavor domain and employment plan, and an optional target filing date. Every one of them can be skipped, and a skipped field is not asked again for 90 days.
- Your case stage. Whether you are exploring, preparing, filed, holding an RFE, denied, or approved. This is the one piece of case information the product is built around — almost everything you see is selected by it — so we keep it and say so rather than bury it in a list.
- Your country of birth. Optional and skippable. It is never sent to analytics, and the database physically refuses to let it into the statistical copy described below.
- Which case records you have opened. Recorded while you are signed in so the monthly reading limit can be counted, and so that re-opening a record you have already read does not cost you another read.
- Your case tracker, if you use it. If you tell us when you filed, we store the month and year — never the day, and the database refuses a date carrying one. Alongside it we store your service center, whether you used premium processing, your priority month if you give one, and each status update you add, as a status from a fixed list plus its month. There is no free-text box anywhere in the tracker and we never ask for a receipt or case number. From this we keep one categorised copy for the group figures: the QUARTER you filed in rather than the month, the service center, premium processing, the quarter of your priority date, and one band saying roughly how long your first case action took. The month itself never reaches that copy, and the order of your status updates never does either — a case history is identifying in a way that a single band is not.
- Your email preference. If you tick the data-digest checkbox we store that preference. Nothing is sent today — see the retention section.
The protections that apply across all of it: your answers are readable only by you, enforced by database rules tied to your login rather than by application code; sensitive fields are shown in masked form on your own profile; you can delete any section on its own, or the whole account, yourself; and the statistical copy of your data is restricted to fixed categories by the database itself, which rejects a write containing free text, your country, or any sensitive value even when the application layer is bypassed entirely. Those database rules are not a description of intent — they are executed against a real database by our test suite.
Analytics. We are not currently using an analytics provider. No analytics events are sent from this site, no analytics identifier is assigned to your browser, and nothing records what happens on your screen. The product contains the code to send page-and-feature events — which profile node was viewed, which filters were applied, which quiz step you reached — and it is switched off; nothing reaches a third party while it is. If we turn analytics back on, this section will name the provider and describe exactly what is sent before the change is made, and the provider will appear in the list at the end of this page.
How it is stored
Your data is held in two separate places, and the separation is the point. The first holds your account and the answers exactly as you entered them; it is readable only by you, enforced by database rules tied to your login rather than by application code. The second holds a categorised copy used for the aggregate statistics this product is built on — band, role, stage, degree band, field, employer type, experience band, and similar closed-set values. It has no link back to your identity, and the database itself rejects a write containing free text, your country, or any sensitive field. Anything we publish about groups of people is computed from the second copy.
Cookies and local storage
We use local storage to hold your quiz answers before signup and your case-reading count while signed out, and Supabase sets a session cookie once you sign in. Nothing else sets a cookie or writes to local storage. There are no advertising or cross-site tracking cookies.
Data retention
Quiz answers in local storage persist until you clear your browser data. Your account and profile are retained until you delete your account. There are no analytics events to retain, because none are being collected.
If you joined the waitlist, we store the email address you gave us and which page you gave it on. We use it for one thing: to tell you once when the thing you asked about is ready. We delete waitlist addresses 90 days after that message is sent, or after 12 months if it never is.
No message has been sent yet, and sending is switched off. When it is turned on, every message will carry a one-click unsubscribe, and this page and the sub-processor list below will name our mail provider in that same release.
Deleting your data
You do this yourself, not by asking us. Both controls below are on your profile page. There is nobody to contact and nothing to wait for.
One field or one section. The profile page has a delete control on every section. Removing a section removes those values and updates the categorised copy described above.
Your whole account. The bottom of the profile page has an account-deletion panel that asks you to type a confirmation phrase. It removes your account, your profile, your assessment records, and your case-reading history in a single database operation, and signs you out. In the live database this is immediate and cannot be undone.
There are no backups to outlive a deletion. On our current database plan the provider takes no automated backups and we keep none of our own, so there is no copy of your row anywhere behind the live database. Deletion is immediate and complete within our systems. If we ever move to a plan that includes backups, deleted data will persist in them for that plan’s retention window, and this paragraph will say so with the actual number before the change is made.
One thing deletion still does not reach, stated plainly because a deletion promise with silent exceptions is worse than no promise:
- Analytics from another browser. Because we never link your analytics identifier to your account, deletion can only reach the analytics identifier belonging to the browser you delete from. Events generated in a different browser or on a different device cannot be located and are not erased. This is a direct consequence of not identifying users, and we prefer it to the alternative. If you want those events removed as well, write to us and we will remove them by hand.
Your rights
You can see everything we hold about you on your profile page — it is the same record, not a summary of it. You can correct any field by editing it, remove fields and sections yourself, and delete your account yourself. Requests we cannot yet serve through the interface, including an exported copy of your data and the manual analytics erasure described above, are handled by hand when you write to us. Depending on where you live you may have further rights; if you ask us to exercise one, we will act on it rather than argue about whether it applies to us.
Who else processes your data
Supabase hosts our database and handles authentication. Google receives a sign-in request only if you choose Google sign-in. Vercel hosts the site and therefore handles the requests your browser makes to it. Sentry receives a report when the site throws an error — the error itself, the page it happened on, and the browser it happened in. It is configured for errors only: no performance tracing, no session recording, and the setting that would attach your IP address, cookies and headers to a report is off. That is the complete list. Fonts are served from this site rather than from a font provider. We do not sell your data, and we do not share it with anyone outside this list.
Changes
If this policy changes materially, we will note it on this page with the effective date. This policy was last updated on July 25, 2026.