Privacy Policy
Last updated 10 Sep 2026 · Plain-language summaries are guidance, not a substitute for the full text.
01 Our promise
In short: You can use our document check without creating an account. We collect the minimum we need, never sell your data, and tell you plainly what deleting your account does and does not remove.
This policy explains what we collect, why, and the control you have. We've written it in plain language on purpose, grounded in what the product actually does today rather than in what a typical privacy policy says.
02 What we collect
Account (optional for the document check). If you create an account: name, email, phone (optional), and login credentials, held by our authentication provider. Your first name and phone number are encrypted before storage; we never store your password ourselves.
Profile. If you use the country-comparison tools: nationality, immigration goal, budget, and the other inputs that drive your comparisons and country pages.
Documents you submit for review. The proposal/contract check does not require an account or an email address to use — you can upload a document, get your report, and never give us your name. If you type an email address, it is used only to send you a copy of your report; it is encrypted before storage and never displayed back to anyone but you (or to staff who need it to deliver or support your report). See “Your documents” below for what happens to the document itself.
Usage & technical data. Which pages you visit, so we can improve the product. On the document-check upload, we also log the IP address making the request, purely to cap how many free checks one visitor can run per hour and stop abuse — see “Security & retention” below for how long that's kept.
03 Your documents
In short: We keep the full text of what you upload — including your name and any other personal details it contains — so we can generate your report and let you come back to it. It is not anonymised before or after storage.
When you upload a proposal or contract, we extract its text and send that text to our AI provider (Anthropic) to identify the program, compare its terms against official program rules, and write your report. That happens regardless of any choice below — it's how the report gets generated.
The extracted text is then stored, in full, attached to your submission — so your report can be regenerated or reviewed later, by you or, for a paid expert review, by the reviewer. We do not scrub or anonymise it. If your document contains your name, an address, a passport number, a date of birth, or any other personal detail, that stays in the stored text exactly as uploaded. A field exists in our systems to mark a document as scrubbed, but as of this writing nothing in our code ever sets it — so today, no uploaded document has had personal details removed from the copy we keep.
The checkbox you see when you upload (checked by default) asks permission to also use your submission, exactly as uploaded, to help us improve how we check future documents. If you leave it checked, a copy of what our system found in your document — for a contract, the clause text itself, with only the names of the parties involved replaced with placeholders (nothing else is redacted); for a proposal, the individual findings from comparing it against program rules — is added to a separate internal dataset used to refine that checking process. Unchecking it stops that copy from being made. Either way, the full original text stays on your submission as described above — the checkbox only controls whether a derived copy is additionally used for improvement work; it does not control what happens to your original upload, and it does not affect whether Anthropic processes your document to generate your report in the first place.
04 How we use it
To generate your document-check report, country comparisons, and plans; to send you a copy of your report if you asked for one; to send policy alerts you've opted into; to process payments for paid tiers; and to support and secure your account. That's it.
05 What we never do
In short: We never sell your data, and we take no commissions for steering you anywhere.
We don't sell or rent your personal data. We don't accept commissions, kickbacks, or referral fees from programs or agencies — so your recommendations are never influenced by who pays us.
06 Who processes your data, and where
In short: Six outside companies touch your data as part of running the service. None of them may use it for their own purposes.
We run on a small number of outside providers, each under contract to process data only on our instructions. This list is the minimum required under UK/EU data-protection law (a “processor list”); we're not aware of a public sub-processor page any of them keeps that we can link to directly, so we describe what each one handles instead.
- Supabase — hosts our database, handles sign-in, and stores the files you upload for review. Holds your account record, profile, and uploaded documents.
- Neon — hosts our reference database of program rules, country data, and (for readers who leave the improve-future-analysis checkbox checked, described above) the derived copies of document findings used to refine our checking process.
- Vercel — hosts the application itself, runs our background jobs, and provides lightweight page-visit analytics. Sees your traffic (IP address, pages requested) as a normal part of serving the site; a copy of recent request logs is mirrored into our own database for up to 30 days for debugging, then deleted.
- Anthropic — processes your document text (for the document check) and your profile inputs (for country comparisons and plans) to generate reports and recommendations, under Anthropic's own commercial data-handling terms.
- Resend — sends account, verification, and report-delivery emails on our behalf. Sees your email address and the content of those emails.
07 Ad measurement & cookies
In short: We use Google and Reddit to measure whether our ads work. They get click IDs and an event ID — never your name, email, phone, or documents. The home page also loads a Trustpilot review widget.
Every page loads two advertising measurement scripts: the Google tag (gtag.js, Google Ads conversion measurement, run by Google LLC) and the Reddit pixel (Reddit, Inc.). The Reddit pixel reports page visits only. Neither loads on the pages that show your report — see “Your documents” above.
When you complete certain actions — submitting a document for the document check, committing an onboarding stage, or creating an account — we report that a conversion happened. Google is told from your browser; Reddit is told from our own server, via the Reddit Conversions API.
What we share, and what we don't:
- Click identifiers the ad platforms themselves attached to the link you clicked (
gclidfor Google,rdt_cidfor Reddit). - Your IP address and browser user-agent — sent only in the server-to-server report to Reddit.
- An opaque event ID, used only to avoid double-counting the same conversion.
- We never share your name, email address, phone number, document contents, or any other personal or uploaded data with either platform. Advanced/automatic matching features that would collect your email or phone are deliberately switched off.
Three first-party cookies support this: imm_utm (which campaign brought you here, kept 30 days), imm_click_ids (the click identifiers above, kept 30 days), and imm_ref (which link brought you here, kept 90 days). All are HttpOnly (not readable by page scripts) and are not shared with any third party beyond what's described here.
If you're visiting from the EEA or UK, none of this runs until you choose: a banner asks you to accept or decline before any ad measurement tag loads, with declining exactly as easy as accepting. Your choice is stored in a third cookie, imm_consent (kept about 180 days), so we don't ask again on every visit.
Data we do share with Google or Reddit is then handled under their own privacy policies: Google Privacy Policy and Reddit Privacy Policy.
One more third-party script, and it is not ad measurement. The home page — and only the home page — loads a review widget from Trustpilot (Trustpilot A/S), so you can leave a review if you want to. It is there because we cannot edit or delete what you write on it; that is the point of using them rather than publishing testimonials ourselves. Loading it means your browser contacts Trustpilot and they may set their own cookies, under the Trustpilot Privacy Policy. We send them nothing about you: no name, no email, no account, and nothing about any document you uploaded. It does not load on the pages that show your report.
08 Your rights, and how to delete your data
In short: You can access, correct, or export your data from your account settings. Full deletion today runs through a request to us, not a self-serve button — and it works differently depending on whether you ever created an account.
If you have an account: deleting it erases your account record and everything tied to it — your profile, your document-check submissions, and your uploaded files' records — because our database is built so that removing your account cascades through everything owned by it. A self-serve delete button is not live in your account settings yet; until it is, email us at immimaps@immimaps.com asking us to delete your account, from the email address on the account, and we'll action it.
If you used the document check without an account: there is today no self-serve way to find and delete that submission, because nothing ties it to you except the email address you may have typed in (if any) — and that address is encrypted in a way that isn't searchable by us directly. If you email us the address you used and roughly when you submitted, we can look into whether we're able to locate and remove it, but we can't promise it today the way we can for an account. If you signed up afterward using the same email, your submission is automatically linked to your new account the next time you visit — after that, account deletion covers it as described above.
One document belonging to an account can also be deleted on its own, without deleting the whole account: from your past-reviews list, you can remove an uploaded file individually. That removes the stored file and its record; it does not remove the text already extracted into your report.
You can access, correct, or export the rest of your data (profile, account details) at any time from your account settings.
09 Security & retention
Data is encrypted in transit. Your name, phone number, and any email address you give us on a document-check submission are encrypted at rest; the extracted text of a document you upload is not separately encrypted beyond our database's own storage-level protection. Access is limited to staff who need it.
We keep your account data for as long as your account is active. Document-check submissions are kept so you can return to your report; server request logs are kept for up to 30 days for debugging, then deleted. IP addresses logged to cap how many free document checks one visitor can run per hour are kept for that purpose; we don't currently run an automatic job to delete old entries, so treat that log as longer-retained than the other data on this page until that's tightened up.
10 Contact
Questions about your data, or want to exercise a right? Email us at immimaps@immimaps.com. We respond within 30 days.