← Back to Inmigreat Pro

Privacy Policy

Last updated: May 25, 2026 · Effective: May 25, 2026

1. Introduction

Inmigreat Inc. ("Inmigreat," "we," "us," or "our") is committed to protecting the privacy and security of your information. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you use the Inmigreat Pro platform and related services (the "Service").

This policy applies to all users of the Service, including attorneys (primary users) and their clients who interact with the coaching features. By using the Service, you consent to the practices described in this policy.

2. Information We Collect

2.1 Account Information. When you create an account, we collect: full name, email address, law firm name, state(s) of bar admission, bar number, phone number (optional), and profile photo (optional).

2.2 Bar Verification Data. We verify your bar status using publicly available bar association records. We store your verification status, state, and bar number.

2.3 Case Data. Information you input about your cases, including: USCIS receipt numbers, EOIR A-numbers, case numbers, client names, hearing dates, attorney notes, documents, and case outcomes.

2.4 Client Data. Information about your clients that you input, including: names, contact information, country of origin, language preference, immigration status, and case-related documents.

2.5 AI Interaction Data. Conversations with Lexi AI, coaching session transcripts, queries, and generated outputs.

2.6 Usage Data. Automatically collected data including: pages visited, features used, session duration, device information, browser type, IP address, and interaction patterns.

2.7 Billing Data. Payment processing is handled by Stripe. We do NOT store credit card numbers, CVVs, or full payment card details. We store: Stripe customer ID, subscription status, billing tier, and invoice history metadata.

2.8 Chrome Extension Data. When using our Chrome extension on government websites (USCIS, EOIR), the extension reads case status information displayed on those pages. See our Extension Privacy Policy for details.

3. How We Use Your Information

We use collected information for the following purposes:

  • Service Delivery: Providing case tracking, judge analytics, AI predictions, coaching, and lead matching
  • Identity Verification: Verifying your bar admission status and professional credentials
  • Billing: Processing payments, managing subscriptions, and sending invoices
  • Communication: Sending case status notifications, deadline alerts, lead notifications, and service announcements
  • AI Model Improvement: Using anonymized, aggregated interaction patterns to improve AI model performance (never using identifiable client data)
  • Analytics: Generating anonymized benchmarks and industry statistics
  • Security: Detecting and preventing fraud, abuse, and unauthorized access
  • Legal Compliance: Complying with applicable laws, regulations, and legal processes

4. Attorney-Client Privilege and Confidential Data

4.1 Acknowledgment. We acknowledge that data you input into the Service may be subject to attorney-client privilege, work product doctrine, or other legal protections.

4.2 Access Restrictions. Inmigreat employees do not access your case data or client information except: (a) when necessary to provide technical support you have requested; (b) to investigate security incidents; or (c) as required by valid legal process.

4.3 No Waiver. Your use of the Service does not constitute a waiver of attorney-client privilege. We maintain appropriate confidentiality safeguards consistent with the duty of a service provider handling privileged information.

4.4 Encryption. All privileged data is encrypted in transit (TLS 1.3) and at rest (AES-256). Access is controlled via role-based permissions with audit logging.

5. Data Sharing and Disclosure

We do NOT sell, rent, or trade your personal information or client data. We share data only in the following limited circumstances:

  • Service Providers (Subprocessors): AWS (cloud infrastructure, us-east-1 region), Stripe (payment processing), Anthropic/AWS Bedrock (AI model inference — no training on your data), Cognito (authentication)
  • Lead Matching: When you claim a lead, limited contact information is shared between you and the potential client, with both parties' consent
  • Firm Members: If on a Firm plan, case data marked as "shared with firm" is visible to other firm members
  • Legal Requirements: When required by law, subpoena, court order, or government request. We will notify you unless legally prohibited
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, with advance notice and continued privacy protections
  • Aggregated Data: We may share anonymized, aggregated statistics that cannot identify any individual attorney or client

6. AI and Machine Learning

6.1 Model Training. We do NOT use your identifiable case data, client information, or AI conversation content to train machine learning models. Our AI features use pre-trained models (via AWS Bedrock) with your data provided only as runtime context.

6.2 Data Retention for AI. AI conversation logs are retained for 90 days for service quality and debugging purposes, then automatically deleted. You may request earlier deletion.

6.3 Third-Party AI Providers. AI inference is processed through AWS Bedrock. Your prompts and responses are not used by the underlying model providers (Anthropic, etc.) for training purposes, per our enterprise agreements.

7. Data Retention

7.1 Active Accounts. We retain your data for as long as your account is active and as needed to provide the Service.

7.2 Account Deletion. Upon account deletion, we permanently delete your personal data and case data within 30 days (grace period for reactivation). Some anonymized, aggregated data may be retained indefinitely.

7.3 Legal Holds. We may retain data longer if required by law, legal proceedings, or regulatory obligations.

7.4 Billing Records. Invoice and transaction records are retained for 7 years for tax and accounting compliance.

8. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of all personal data we hold about you
  • Correction: Request correction of inaccurate personal data
  • Deletion: Request deletion of your personal data ("right to be forgotten")
  • Portability: Export your data in a machine-readable format (JSON/ZIP)
  • Opt-Out: Opt out of anonymized benchmarking, marketing communications, or non-essential data processing
  • Restriction: Request restriction of processing in certain circumstances
  • Objection: Object to processing based on legitimate interests
  • Non-Discrimination: Exercise your rights without discriminatory treatment

To exercise any of these rights, contact us at privacy@inmigreat.com. We will respond within 30 days (or sooner if required by applicable law).

9. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to know what personal information is collected, used, shared, or sold
  • Right to delete personal information held by us
  • Right to opt-out of the sale or sharing of personal information (we do NOT sell your data)
  • Right to non-discrimination for exercising your privacy rights
  • Right to correct inaccurate personal information
  • Right to limit use and disclosure of sensitive personal information

We do not sell personal information as defined by the CCPA. We do not use or disclose sensitive personal information for purposes other than providing the Service.

10. International Data Transfers

Your data is processed and stored in the United States (AWS us-east-1 region). If you access the Service from outside the United States, your information will be transferred to and processed in the United States. We implement appropriate safeguards for international transfers consistent with applicable data protection laws.

11. Security Measures

We implement comprehensive security measures including:

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Multi-factor authentication for administrative access
  • Role-based access controls with principle of least privilege
  • Regular security audits and penetration testing
  • Automated vulnerability scanning
  • Audit logging of all data access
  • Incident response procedures with 72-hour breach notification
  • Employee security training and background checks
  • SOC 2 Type II compliance (in progress)

12. Cookies and Tracking

12.1 Essential Cookies. We use essential cookies for authentication, session management, and language preferences. These cannot be disabled.

12.2 Analytics. We may use privacy-respecting analytics to understand usage patterns. We do not use third-party advertising trackers, Google Analytics, or Facebook Pixel.

12.3 Do Not Track. We honor Do Not Track (DNT) browser signals.

13. Children’s Privacy

The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 30 days before taking effect. The "Last updated" date at the top indicates the most recent revision.

15. Contact Us

For privacy questions, data requests, or concerns:
Email: privacy@inmigreat.com
Inmigreat Inc.
Data Protection Inquiries

Privacy Policy | Inmigreat Pro