Privacy Policy
Last updated October 2026. The information you share, how we use it, and the controls you have.
To delete your account and its data, see Delete your account.
Effective October 1, 2026
1. Who we are
Visa Jump is operated by SSR Digital LLC, a Texas limited liability company based in Prosper, Texas, United States. Contact [email protected] for privacy requests. Postal address for legal notices: 3827 Stars Street, Prosper, TX 75078, United States.
On the website we provide educational EB-1A resources, a free checklist, an AI-assisted profile evaluation, a community waitlist and paid educational consultations. We also run a members-only educational community on the website and in our iOS and Android apps; membership is by application and applications may be paused. Petition-preparation tools are not available. This policy covers all of these services.
2. Information you share in the public tools
- Waitlist: first and last name, email, chosen community username, Google identifier if used, verification status, consent records, optional update preference, and campaign source. Joining does not create a community membership.
- Guide and checklist starts: first name, last name and email are required before beginning. With your permission, we save these contact details, the selected tool, consent version, start time and browser-reported finish status, including when you leave without finishing. These records do not verify identity or prove that every page was read or an assessment was completed.
- Saved checklist: your name and email from the start form, professional field, role and area of expertise, selected answers about documentation, separate report-storage permission and the resulting checklist. Older saved checklists may use a full name or include an experience range. These are private acquisition records.
- Detailed evaluation: contact details and the professional context you enter, including your field, experience, education, career focus, achievements, recognition, publications, completed judging, roles, contributions, available records, gaps, goals, and intended work. We store your answers, consent, report status, generated report and report version.
- Consultation: name, email, optional phone, time zone, chosen appointment, payment and calendar references, booking status, consent and delivery status. Stripe collects payment details; we do not receive your full card number.
- Administration: Google identity and a server-issued session for the single authorized business administrator. Google waitlist sign-in is separate from administrative access.
- Please do not enter passport numbers, A-numbers, receipt numbers, Social Security numbers, confidential employer material, or third-party personal information in the public tools. Public workflows do not accept document uploads.
3. Information you share in the community
- Account: if you sign in with Google, your Google account identifier, email, verification status and name; if you sign in with Apple where it is offered, your Apple account identifier and the email Apple shares with us, which can be a private relay address you choose (we request only your email, never your name, and never receive your Apple password); and the sessions that keep you signed in. We use this account data only to sign you in, contact you and, for Google, prefill your application, never for advertising. Other members never see your email or which sign-in you use, and signing in with a different provider does not merge accounts.
- Community identity: the pseudonymous username and display name you choose, and the optional profile fields and directory listing you decide to show.
- Application: your legal first and last name, an optional phone number, your answers and chosen plan, the versions of the terms and rules you accepted, and your card-charge consent (its wording, version and time, and whether you used the website or an app). You may add a resume and up to five supporting files; where resume reading is on, the professional profile read from your resume (which you can review and edit) is kept with your application.
- Identity check: Stripe session and completed-report references, results, check times and failed-attempt counts used to verify membership and prevent abuse. Stripe collects your ID document on its own pages; we do not store ID images, numbers or full verification reports from this check.
- Billing: your Stripe customer, saved-card, subscription and invoice references, membership status, paid periods and payment status. You enter your card on Stripe’s pages: its number and security code go to Stripe only, and of its details we use only the brand and last four digits, to show them on your receipts. Where we use Stripe Tax to work out sales tax, Stripe’s card page also asks for your billing address, and we copy it from your saved card to your customer record at Stripe so Stripe Tax can calculate the sales tax included in your price; our servers pass it on without storing it. If we email you a receipt, we keep the details it is built from: the amount paid, the payment and service dates, the card’s last four digits and any sales tax included, with a label naming only the state or country, such as "Sales Tax (TX)". When you open a receipt in My profile, its amount, any sales tax and the card are read from Stripe at that time, and we do not store that receipt.
- Private workspace, only what you choose to add: personal details such as date and place of birth, nationality, passport number and expiry; immigration details such as current status and expiry, I-94 number, visa and petition history and visits; your address; family details; work history; salary evidence; evidence checklists; and documents you upload to My documents, such as resumes, passports, visas and pay records.
- Community activity: posts, comments, likes, follows, saves, feed choices, opportunity submissions, tracked opportunities and reminders, outcome reports, reports you file, members you block, moderation notices and appeals.
- Messages: your private Inbox chats with the Visa Jump admins, files you share there or for a document review, and Help & support requests. There are no member-to-member direct messages.
- Notifications and security: in-app notifications and your notification settings; a device push token only if you turn on push notifications; a bot check (Cloudflare Turnstile) when you apply; rate-limit counters; and server logs.
4. Sensitive information
Some details you may add in the community are sensitive: your nationality, your immigration or citizenship status and history, passport and I-94 numbers and other government identifiers, and identity documents. Apart from the identity check Stripe runs for membership, adding them is your choice.
In Personal information › Personal details we ask for separate permission before you save sensitive identity details, identity records such as passport records, or files classified as identity or immigration documents. This permission is separate from our Terms and from permission to read a particular file with AI. You can withdraw it on the same page after confirming the deletion of identity facts. Withdrawal deletes sensitive personal details and matching stored identity records or facts, removes related extracted drafts, cancels unfinished identity uploads and stops related processing. Completed original files stay in My documents until you separately delete them or delete your account; you can still download or export those retained files. A new permission does not restart canceled work.
We use sensitive information only to show it back to you, to fill in your own private records when you ask, and, if you choose, for private AI document reading. Your private personal information and My documents are not used to decide your application, are never shown to other members, and are never sold or used for advertising. You can remove any of it at any time by deleting it; we stop using it when you do.
5. Why we process it
- To provide the guide or checklist after you give permission to save your contact and start/finish information. Starting either tool does not send an email, join the waitlist or subscribe you to community updates. We separately ask for permission before saving and emailing a checklist report.
- To provide the waitlist confirmation or detailed report you request, with acknowledgement or explicit consent before submission. Joining the waitlist is a request to hear when community applications open on visajump.com, so we email the people on the waitlist when they do; that email is not optional community news.
- To generate and save your detailed report after you affirm the report-creation permission at submission. That permission covers AI processing of your professional answers and storage of your contact details, answers and report for 90 days. It is not permission to join the waitlist or receive marketing.
- To take payment, confirm and manage an appointment, send its preparation information, and resolve booking or refund issues.
- To run the community you join: review your application, check your identity, bill and renew your membership, work out the sales tax included in its price, give you receipts, show your posts to other members, deliver your chats and notifications, and keep your private workspace.
- To keep the community safe: content checks, reports, blocks, moderation, appeals and abuse prevention.
- To let the authorized administrators review submissions and applications, respond to service issues, and understand demand. Guide starts, checklist starts, saved checklist reports, waitlist entries, detailed evaluations and consultations are displayed separately. Browser-reported finishes are distinct from saved reports and anonymous page-view counts.
- To send requested service messages. Optional community news is a separate choice; using a free tool does not subscribe you to unrelated marketing.
- To operate and protect the service, measure aggregate usage, and meet applicable legal, accounting, and recordkeeping obligations.
We do not sell your personal information, share it for targeted advertising, or use it to train AI models. No AI output is an eligibility decision or an automated decision about access to immigration benefits, your membership or any benefit.
6. AI processing
Cloudflare Workers AI runs a Google Gemma model to process your professional answers and produce educational suggestions. The model runs through Cloudflare; we do not send your intake to the Google Gemini service. Your separate contact fields (first name, last name and email) are excluded from the AI prompt. Information you put into narrative answers is still processed, so avoid including personal or confidential details there. Public links you provide are not opened or independently verified.
AI can misunderstand context or make mistakes. Generated suggestions are distinguished from facts you reported and should be checked against the linked primary sources. The report does not verify evidence, establish that a legal criterion is met, predict approval, or set a date when you will qualify.
The report identifies documentation priorities from the states and descriptions you supply, alongside AI-generated tasks. Some category guidance and questions for professional review are written by Visa Jump; category guidance is labeled when it comes from that framework. This is not a ranking of your best legal criteria. Estimated work sessions and ranges are illustrative planning aids for organizing records or beginning an activity, not forecasts of publication, recognition or a successful result. An evidence-building plan describes work you may choose to do during a planning period. The waiting illustration shows a possible journey, not the status of a real petition. Neither predicts USCIS processing or outcomes. Consult qualified immigration counsel before making legal or filing decisions.
In the community, the same Cloudflare-run Gemma model, with request storage turned off, can read documents for you. Where resume reading is on for applications, you choose separately for each file whether Cloudflare may read it with AI; uploading without that permission does not start AI reading. If you agree, Cloudflare may convert the PDF to text before Gemma reads it. Details printed in the resume are saved as application resume details, which admins can review, replace your professional profile and fill empty personal-information fields; review them for mistakes. The reader discards immigration status, ID numbers, birth dates or age, gender, nationality and pay. Removing or replacing the file stops pending results from being saved, but cannot recall requests already sent. The permission record is removed with the file; reviewed profile details and filled personal-information fields stay until you edit or clear them. If you ask it to read a file in My documents, you first agree to a notice that says so, and it prepares private suggestions that are never saved or shown to anyone until you review each one. Cloudflare may convert a PDF to text or crop and rotate a passport image in memory for this; no copy is kept by that step. Suggestions can be wrong.
We do not collect, use, sell or share personal data to train large language models. Cloudflare states that Workers AI does not use customer content to train models.
7. Identity verification
To confirm that members are real people, Stripe Identity checks one government photo ID (a passport, driving licence or national ID card) on Stripe’s own pages. No selfie is taken. Our application keeps only session and completed-report references, results, check times and failed-attempt counts; it does not store ID images, numbers or full verification reports from this check. We request Stripe redaction 30 days after the final application decision, withdrawal or expiry, and at once through the account-deletion process if you delete your account sooner. A check still processing must finish before Stripe can redact it. Stripe may take up to four days to complete redaction and may retain information it controls independently under its own privacy policy; you can contact Stripe about that information.
8. Providers and who can see what
- Cloudflare hosts our website and API, stores application data, community content, documents and sessions, runs the AI models, queues report work, sends email, runs bot checks (Turnstile), keeps server logs for up to 7 days, and processes network/security metadata. Queue messages contain a record identifier rather than your full intake.
- Google authenticates waitlist identities, community members and the authorized administrator. Google Calendar and Meet receive consultation name, email, appointment time, an educational meeting summary and booking reference to create the appointment and invitation. The existing Google host account is the organizer. Our business mailbox, [email protected], is also included as a visible guest on new appointments and receives the invitation and any cancellation updates. The customer and business guest can see the guest list, appointment details and meeting link; evaluation answers and private booking-management credentials are not included.
- Stripe processes the $100 consultation payment and refunds, community membership billing and sales tax, and identity checks. For consultations it receives your email and booking reference, payment details entered on its own checkout, and the purchase amount. For membership it receives your email and an account reference, the card you save on its pages and, where we use Stripe Tax, your billing address. We do not send your evaluation answers, application or private workspace to Stripe.
- Apple authenticates community members who choose Sign in with Apple where it is offered. We send Apple the sign-in code and our app identifier to verify the sign-in. We keep the refresh credential Apple returns, encrypted on our server, only so we can revoke the authorization when you delete your account; it is not an advertising identifier. Apple can tell us when you stop using Sign in with Apple with Visa Jump, delete your Apple Account or change email forwarding; stopping or deleting ends your Apple sign-in sessions. Apple receives none of your application, private workspace, documents or community posts through sign-in.
- Expo relays push notifications, if you turn them on, to Apple or Google. A notification says only that you have a community update.
- Cloudflare Web Analytics measures website page views and performance without advertising cookies or a persistent visitor identifier. Typeface files are served by Visa Jump.
- Email you send to our support or privacy contacts is processed by the mail providers handling those inboxes. Avoid sending sensitive case documents by ordinary email.
Our service providers receive only what they need to provide their service to us and must protect it with safeguards at least as protective as this policy. Stripe also acts independently under its own privacy policy for payments and identity checks.
Other members see only your username, display name, what you post and the profile fields you choose to show. They never see your legal name, email, phone, application, personal information or documents. The Visa Jump admins see your application (names, phone, answers, resume details and application files) to review it, your membership and billing status, your Inbox chats and Help & support requests, files you share with them, reports, and which members block which. They cannot open your personal information page or My documents. Admin downloads of application and review files are recorded.
Your private contact information, intake, and reports from the public tools are not published or shared with other aspirants. Hosting-provider personnel may have access under their service and security processes. Providers operate globally, so processing may occur in the United States and elsewhere. We disclose information to government agencies only when legally required, and may disclose it when necessary to protect people or the service.
9. Cookies, device storage, tracking and Do Not Track
Secure, HTTP-only cookies keep you signed in on the website (community and administrative sessions last up to 30 days and can be revoked sooner) and hold short-lived Google or Apple sign-in state (up to ten minutes). The apps keep your session in the device’s secure storage. These are necessary authentication controls. Public tools do not require a community account.
The checklist draft is kept on your device for up to seven days. Contact drafts are kept in this tab for up to 24 hours to avoid asking twice. The detailed evaluation also keeps a recoverable draft on this device for up to seven days or until you clear it. Private guide/checklist contact, report, waitlist and booking credentials are held in session storage. Pending start-request drafts are recoverable in this tab for up to 24 hours to avoid duplicate entries after a connection failure. Credential fragments are removed from the visible address before data requests. Anyone with a private link can access that record, so do not forward it and avoid shared devices. The community website and apps may keep unsent drafts, such as a post or an application in progress, on your device until you send or discard them.
We count specific actions such as opening or starting a checklist and store daily totals. These action counts are not unique visitor counts. Random event receipts prevent accidental duplicate counting and are retained for up to two days plus the hourly cleanup interval; daily totals remain for 90 days. These events contain no name, email, intake, or persistent visitor identifier. Rate limits use short-lived counters to reduce abuse.
Cloudflare Web Analytics also receives page addresses and performance measurements. Cloudflare describes this service as cookieless, with no browser storage identifiers or cross-site profiles; detailed measurements are held for seven days before aggregation. Hosting necessarily processes your IP address to serve and secure requests. Blocking analytics scripts does not prevent use of our tools.
We do not track you across other websites or apps, and we do not let other companies track you across sites through our service. Because we do no cross-site tracking, we treat every visitor the same way whether or not their browser sends a Do Not Track or Global Privacy Control signal.
10. Retention
- Guide and checklist start records: 30 days from the initial start, including unfinished visits. In the same tab, use Your saved contact details above the tool to delete that record sooner. Deleting a start record does not delete a separately saved report or waitlist entry.
- Saved checklist: 30 days. Detailed evaluation, professional answers and generated report: 90 days. You can delete either earlier from its private report page.
- Waitlist: seven days if unverified, or 365 days after confirmation. Its private status page lets you remove the entry sooner.
- Hourly cleanup removes expired guide/checklist start, report and waitlist records and their associated access credentials and delivery records. An expired link stops granting access even before cleanup runs.
- Unpaid consultation holds: seven days; a hold is not released for resale until payment status has been reconciled. Paid booking records remain for 365 days after the appointment. Unresolved payment, booking, or refund problems remain until reconciled. Payment processors may retain records longer for tax, fraud-prevention or legal obligations.
- Administrative sessions expire after 30 days and can be revoked sooner. Security and service providers may retain their own operational records under their applicable policies.
- Community documents and application files, including your resume details and the name and phone on your application: kept until you delete them or delete your account. We never delete them because time passes, because your application ends, or because your membership lapses. Private workspace details, records and salary evidence are kept until you edit or delete them, or delete your account.
- Identity checks: we keep the result and session reference with your application; Stripe is asked to redact the check data as described in section 7. Minimal completed-report references, outcomes and times are retained for abuse prevention and cost accounting; account deletion removes the budget ledger’s account link without resetting its unsuccessful-check totals. Admin download records for application and review files: 365 days after each download. Server logs: up to 7 days.
- Safety preservation: where reporting or preservation law requires it, selected reported material and relevant context may be preserved separately with restricted safety-operator access. A reported case is retained for at least one year after the required external report, and longer when a valid legal request requires. Account closure does not delete evidence that must legally be preserved. These restricted copies are not included in the automated account export; you may contact our privacy address about your rights.
- Membership consent, billing and notice records: kept after account deletion, linked to an anonymous profile rather than your email, for at least three years (or one year after your membership ends, if longer), and longer where tax or accounting law requires. Account deletion clears the details of emailed receipts, keeping only a minimal record of each receipt email. It does not delete your customer record at Stripe: your email, any billing address, your saved card and your invoices stay in our Stripe account, and Stripe also keeps information under its own privacy policy. Moderation records are also kept after deletion, linked the same way, to keep the community safe and to answer legal claims.
- Sign in with Apple: sign-in challenges expire after ten minutes. When you delete your account, we ask Apple to revoke your Apple authorization before erasing your data, and keep asking every hour until Apple confirms. If Apple has not confirmed by the time the rest of your account is erased, we keep only the encrypted refresh credential, no longer linked to your email, name or Apple account identifier, and delete it once Apple confirms. Our receipts of Apple account notifications (an event identifier and type, your Apple account identifier and times; no token or email) are kept while your account exists, so an old notification cannot be replayed, and are deleted with it; a receipt for an Apple account identifier that has no Visa Jump account is deleted after 30 days. If you stop using Sign in with Apple with Visa Jump or delete your Apple Account, we delete the credential when Apple tells us.
- Historical community accounts and content created before community access closed remain private. Contact us for access or correction. They are not automatically copied into new public reports or future petition tools.
- Community accounts: kept until you delete the account. Delete account (My profile › Account › Privacy & account, or https://visajump.com/delete-account) signs you out everywhere, cancels any membership at once and deletes your account data within 30 days; your posts and comments are erased and shown as "Deleted member". We keep only billing records, moderation records, the consents you gave, the facts of opportunities you listed that other members saved, and a record of your deletion request (when it was made and finished and, if you asked us by email, how we checked the request was yours), as that page explains. That record is matched to a one-way code made from your email address, never the address itself, and is kept to show the deletion was requested and carried out and to answer any later dispute about it. Deleted data can remain in our database provider's restore history for up to 30 more days.
11. Your controls and rights
Verified account owners can prepare a private account export in My profile › Account › Privacy & account, including retained original files, free of charge even after membership expires or applications are paused. Prepared exports are available for 24 hours and are invalidated when relevant source data changes. Closed accounts cannot start or download exports; contact our privacy address for a rights request. Exported files you save outside Visa Jump remain under your control.
Remove a guide or checklist start record using Your saved contact details above the tool in the tab where you started. To change these details, remove the entry and submit the new details; your checklist answer draft stays on the device. Delete a saved checklist or detailed evaluation from its private results page, and remove your waitlist entry from its private status page. Removing the waitlist entry also withdraws optional updates. Download a PDF first if you want a copy. In the community you can correct or delete your profile, personal information, documents and posts yourself. Delete a community account yourself with Delete account in the app or on the website, or follow https://visajump.com/delete-account if you cannot sign in.
Wherever you live, you can ask to access, correct, delete or get a portable copy of your personal information, and withdraw consent you gave. Email [email protected] from the email you use with us; we may verify your identity. We aim to answer within 30 days and always within 45 days; if the law allows more time and we need it, we will tell you why. If we decline, you can appeal by replying to our answer or writing to [email protected] with "Appeal" in the subject. We decide appeals within 60 days and, if you still disagree, tell you how to contact your state Attorney General. We will not treat you differently for using these rights.
Deleting a report cannot recall copies already downloaded or emails already sent. We may retain information where required for legal obligations or an unresolved dispute. You may have additional rights depending on your location, including the right to complain to a regulator.
12. Security, breaches and age
We use HTTPS, server-side authorization, scoped private links and data minimization. Administrative access is restricted to authorized accounts, and unavailable community endpoints are blocked. Member documents are not malware-scanned; the Security & Data Care page explains how they are protected. No service is perfectly secure.
If a security incident affects your personal information, we investigate promptly and notify affected people, and regulators where required, without unreasonable delay and within the time limits set by applicable law.
Visa Jump is for adults aged 18 and over. We do not knowingly collect children’s information. Contact [email protected] if a child has submitted data, and we will delete it.
Our iOS and Android apps use age ranges and related eligibility signals supplied by Apple or Google to check adult access. The app processes these signals briefly on your device. For this check, we do not ask for your date of birth or save the raw age ranges, store-provided identifiers or approval details, send them to Visa Jump’s servers, or put them in logs or analytics. Only the access decision and any adult confirmation remain in the app’s temporary memory. Apple and Google operate their age services under their own policies.
On older iOS versions without age-range support, or where the platform identifies age sharing as optional, the app asks you to confirm that you are at least 18. This is your declaration, not a verified age result. A required but unresolved check does not permit access, and a reported under-18 age cannot be overridden by adult confirmation. The app checks again when returning to the foreground or changing the signed-in account.
13. Where we operate and changes
Visa Jump is operated from Texas and is intended for adults worldwide where the service is legally available. Hosting and processing may occur outside your country, including in the United States. Mandatory rights under the law applicable to you are not waived by using the service; contact our privacy address about your rights or international processing.
AI-assisted petition-preparation workflows are planned. They are not included with a waitlist entry, free report, consultation or membership. We will publish the applicable terms, data uses, access controls and consent choices before making them available. Existing private intake is not automatically published to a community or submitted to USCIS.
The date above identifies this policy version; it was last updated in October 2026. We will notify you in the service or by email before a material change. If a change would use information you already gave us in a new way, we will ask for your permission first.
Location
Prosper, Texas, United States
Mailing address
3827 Stars Street, Prosper, TX 75078, United States