Legal
Privacy Policy
Last updated: May 2026
What we collect
If you create an account, we collect your name, email address, home country, destination preference, visa category, and optionally a WhatsApp number for reminders. If you use the simulator we store your answers and the AI's feedback so you can review them later. If you use checklists, we store your progress. If you save letters, we store the letter content and form data.
What we do not collect
We do not collect personally identifying documents (passports, ID cards), bank statements, or any other supporting documents. Those documents are between you and the embassy you apply to.
How we use your data
Your data is used to provide the service: personalising guides, saving your progress, sending appointment reminders by email, and showing your simulator history. We never sell your data. We never share it with third parties for marketing.
Third parties we use
- OpenAI (AI model): receives your simulator answers and scam-checker queries to generate feedback. OpenAI does not store these for training without your consent.
- Lemon Squeezy (payments): receives your email and payment details if you upgrade. We never see or store your card details.
- Google (OAuth, optional): if you sign in with Google, we receive your name, email, and profile photo. We do not request additional Google data.
- Gmail SMTP: used to send transactional email (password reset, appointment reminders).
Cookies
We use a single session cookie to keep you logged in. We do not use third-party advertising or behavioural-tracking cookies. We do not run analytics that identify individual users.
Your rights
You can view and edit your profile data at any time from the Settings page. You can delete your account from the Settings page at any time โ this permanently removes all your data within 30 days. You can request a data export by emailing us.
Data security
Passwords are hashed with bcrypt. Sensitive secrets are stored in environment variables on our server, never in code. Our database runs on a self-hosted Linux server in a European data centre, with daily encrypted backups.
Data retention
Account data is retained as long as your account is active. If you delete your account, all data is removed within 30 days. Anonymous scam reports may be retained indefinitely to warn other users.
Contact
Privacy questions? Contact us via the support channels linked from the homepage footer.