Legal
Privacy Policy
Last updated September 30, 2026
In plain words
- WEBOCTALS LTD, a UK company, is responsible for your personal data under UK data-protection law.
- You can browse decisions, objections and analytics without an account.
- If you sign up for new-decision alerts, we keep only your email address and the topics you chose, until you unsubscribe with the link in any alert.
- If you sign up, we store your name, email, a hashed password and basic sign-in records.
- We store case information only if you use the case tools and give separate, explicit consent. Uploaded documents are kept as encrypted text; the original file is not stored. Case data is not sent to any AI provider.
- We do not sell your data, show ads, or use tracking cookies. We do not send your data to USCIS or any government unless the law requires it.
- You can download your data, withdraw consent, or delete your account yourself from the Account page.
1. Who we are
WEBOCTALS LTD (“PetitionLens”, “we”) is the controller of the personal data described here. We are a company registered in England and Wales (company number 16730955), registered office 54 Dorset Terrace, Leeds, England, LS8 3QR. Contact us about privacy at [email protected].
2. What we collect
- Account data: name, email address, and a one-way hash of your password (we never store the password itself), plus the version and time you accepted our Terms.
- Sign-in and security data: session records, including your IP address and browser user agent, to keep you signed in and detect abuse.
- Technical logs: our hosting provider may keep standard server logs (IP address, pages requested, time) for security and reliability.
- Messages you send us, such as support emails.
- Alert subscriptions (no account needed): your email address, the topics you asked to hear about (for example a field or an objection), when you signed up and confirmed, and when we last emailed you.
- Which decisions you have read: when you open the full text of a decision we record which decision it was and when. We do this so that re-reading a decision never counts against your monthly reading allowance. It is visible only to you, it is included in your account export, and it is deleted when you delete your account. If you are not signed in, this is kept only in a cookie in your own browser.
Case information (only with your separate consent). The case tools ask for your explicit consent the first time you open them. You can use the research tools without giving it. With it, we store:
- Case profile: what you type about yourself and your case, such as your field, degrees, publications and citation counts, your proposed endeavor, and the evidence you plan to submit. This can reveal sensitive details, such as your nationality or immigration situation.
- Uploaded documents: for CVs, drafts and letters you upload, we extract and keep only the text, encrypted at rest. The original file is not stored.
- Results you create: evidence-coverage checks, document reviews and drafts.
- Workspace records: if you join a firm workspace, your membership and role, and an audit log of actions on shared cases (who did what, and when).
Billing records (only if you buy a plan): your plan, subscription status and a Stripe customer reference. During our free launch we do not collect any payment information. Stripe collects card details directly; we never see or store your full card number.
Do not upload passports, visas, A-numbers, receipt notices, or other people’s personal records. The tools do not need them. If you enter information about someone else, you must have their permission.
Public decisions. The AAO decisions in PetitionLens are published by USCIS with personal identifiers already redacted. If you believe a decision shown here still identifies you, email us and we will review it and remove the identifying text promptly.
3. Why we use it, and our legal basis
| Purpose | Legal basis under UK GDPR |
|---|---|
| Creating and running your account, and providing the Service you ask for | Contract (Art. 6(1)(b)) |
| Storing the case information you choose to enter or upload, which may reveal sensitive details | Your explicit consent (Art. 6(1)(a) and Art. 9(2)(a)), asked for separately and withdrawable at any time |
| Emailing you new decisions on the topics you chose (alerts) | Your consent (Art. 6(1)(a)), given when you confirm the subscription and withdrawable with the unsubscribe link in every alert |
| Keeping the Service secure, preventing abuse, and improving it | Our legitimate interests (Art. 6(1)(f)) |
| Recording your acceptance of our Terms, and workspace audit logs | Legitimate interests; and contract for workspaces |
| Billing and tax records, if you buy a plan | Contract, and legal obligation (Art. 6(1)(c)) |
| Responding to legal requests and exercising or defending legal claims | Legal obligation; legitimate interests |
AI. The case tools use rule-based checks and templates that run on our own servers. Your case information and documents are not sent to any AI provider, and we do not use your data to train AI models. If we add a feature that sends your content to an AI provider, we will update this policy first, say so where you use it, ask for your consent, and use only providers that contractually agree not to train on it.
No automated decisions about you. Our checks describe your own records; they do not make decisions with legal or similarly significant effects on you.
4. Cookies
We use only cookies that are strictly necessary to keep you signed in and secure, so we do not show a cookie banner. We do not use analytics, advertising or cross-site tracking cookies. If that changes, we will ask for your consent first. Our fonts are served from our own servers.
5. Who we share it with
- Service providers (processors) who host or operate the Service for us, such as hosting and database providers, under contracts that let them use data only on our instructions.
- Stripe, our payment processor, only if you buy a plan.
- Our email provider (Brevo or Resend) receives your email address and the message when we send you account emails, such as password resets, workspace invitations, purchase confirmations or notice of a price change, and the new-decision alerts you subscribe to.
- Web3Forms delivers messages you send through our contact form (your name, email and message) to our inbox.
- OpenAlex, a public research database: if you use the publication lookup, we send only the name or ORCID you type.
- Members of a workspace can see the cases you choose to share with that workspace, and its audit log.
- Legal requirements: when required by valid legal process, or to protect rights, safety and security. We do not volunteer your data to USCIS or any other agency.
- Business transfers: if we merge or are acquired, under this policy’s protections.
We do not sell personal data or share it for cross-context behavioural advertising.
6. International transfers
Some of our providers may process data outside the UK, for example in the United States. When that happens, we rely on UK-approved safeguards: an adequacy regulation such as the UK Extension to the EU–US Data Privacy Framework (the “UK–US data bridge”) where the provider is certified, or the ICO’s International Data Transfer Agreement or Addendum. Ask us for details.
7. How long we keep it
- Case information: until you delete the case, withdraw consent, or delete your account, or until a workspace’s retention period removes it. Deletion removes it from our live database immediately.
- Alert subscriptions: until you unsubscribe, which deletes them at once. Sign-ups that are never confirmed are deleted after 7 days.
- Account data: while your account is open. When you delete your account, we delete it from our live database immediately.
- Backups expire on a regular cycle, after which deleted data is gone from them too.
- Billing records, if any, are kept for up to six years after the relevant year because UK tax law (HMRC) requires it; Stripe keeps its own records under its policies.
- Session records expire automatically.
8. Security
We use encryption in transit, encryption at rest for uploaded document text, hashed passwords, and access checks so that only you and the workspace members you choose can open a case. No system is perfectly secure; if a breach affects your data, we will notify you and the ICO as the law requires.
9. Your rights
Under UK data-protection law you can ask to access, correct, delete or download (port) your personal data, restrict or object to its use, and withdraw consent at any time without affecting what we did before. You can do the most common ones yourself on the Account page: download your data, withdraw case-data consent (which deletes your case data), or delete your account. For anything else, email [email protected]. We reply within one month.
If you are unhappy with how we handle your data, you can complain to the Information Commissioner’s Office at ico.org.uk. We would appreciate the chance to help first.
If you live in the EU, you may also contact your local data-protection authority. If you live in the United States, you have the rights your state law gives you (for example, California residents can ask to know, delete and correct their data); we honour these requests the same way, and we will not treat you differently for making them.
10. Children
The Service is for adults 18 and over. We do not knowingly collect data from children.
11. Changes
We will post changes here and update the date above. For material changes, we will tell you and, where required, ask for your consent again. See also our Terms of Service.