MyCheck
Sign InStart Free

Privacy Policy

Last updated: September 17, 2026

1. Who We Are

MyCheck is operated by SFDIFY LLC ("we," "us," "our"). We provide the MyCheck app for iPhone and Android, the web app at mycheck.co/app, and the website at mycheck.co. They share one account, and help people track USCIS immigration cases, manage checklists, build personalized roadmaps, and get AI-powered guidance.

2. Information We Collect

2.1 Information You Provide

  • Account information: your email address, name or display name, profile photo, and, if you add them, phone number, country, bio and language. If you sign up with an email and password, we store your password only in hashed form. If you sign in with Google, we receive your email address, name and profile picture link. If you sign in with Apple, we receive your email address (which may be a private relay address) and, the first time, the name you choose to share.
  • USCIS case data: receipt numbers and form types you enter, and the case statuses and history we retrieve for them from USCIS. You can look up a receipt number before creating an account: we send it to USCIS and use your IP address and a random browser ID only to limit repeated lookups.
  • Checklists & roadmaps: checklists, their items, sections, due dates, repeat rules, places, links, notes and attachments, your progress, and checklists you save from Discover.
  • Reminders and notifications: reminders you set (time, repeat, and whether to email you), the notifications we send you and whether you've read or snoozed them, your notification settings per channel, and your time zone so reminders arrive at the right local time. On the web, reminders and alerts appear in the notification center, by email if you turn it on, and as notifications in a browser where you turned them on. For that last one we store what your browser gives us — an address at your browser maker's notification service and the keys that let us encrypt a message for it, plus your browser's name and version. Turning the switch off removes it, and so does your browser when you block notifications.
  • Location: we don't collect your location on the website or in the app. If you turn on location reminders, we only save that choice; reminders near a place need a future app update, which will ask for permission first. Places you add to checklist items are saved with the item.
  • Shared checklists (MyCheck Together): who you share a checklist with, invitations you send, accept or decline, comments you post on shared items, who checked off or was assigned each item, and your settings for a shared checklist (notifications, and whether you are named on group share cards).
  • Creator profile and published checklists: if you create a creator profile, its username, headline, bio, city, languages, expertise, experience entries, social account links and cover photo; checklists you make unlisted or public and each version you publish (title, description, category, items with their tips, places and links, and the cover image); collections; verification requests (including the code you add to a social account bio and the MyCheck team's decision); which creators you follow and what they may notify you about; your "Was it helpful?" answers; and reports you send about profiles, checklists or collections.
  • Documents you upload: files and photos you share with MyCheck for analysis, such as a USCIS notice.
  • AI conversations: messages you send to the AI assistant and the answers it gives.
  • Voice input: if you dictate a message, your device's speech recognition service (provided by Apple or Google) turns your speech into text.
  • Community posts & comments: content you share in community discussions.
  • Feedback: messages you send us from inside the app.
  • Purchases: your subscription status. For Premium bought in the app, this comes from Apple or Google through RevenueCat. For Premium bought on mycheck.co, it comes from Stripe, along with a customer ID and the billing details you give Stripe (for example name, email, and billing country or postal code). We never receive your full card number.

2.2 Information Collected Automatically

  • Device and log information: device type, operating system, app version, and the IP address and request details our servers receive when you use MyCheck.
  • Usage data (phone app): the screens you open and the features you use, collected by Amplitude and linked to your MyCheck user ID.
  • Views of published checklists: to count each person once a day, we store a one-way hash of your user ID, or of your IP address (for IPv6, its network prefix) if you are not signed in. The hash can't be turned back into the ID or address, and it is deleted after two days. Creators see only totals.
  • Session recordings (phone app): Microsoft Clarity records how you move through the app (screens, taps, and scrolling) so we can find and fix confusing or broken parts of the app.
  • Crash reports: error and performance data sent to Sentry when something goes wrong in the phone app or on our servers. Reports are linked to your MyCheck user ID and can include details of the record involved, such as a receipt number. They never include your password or sign-in tokens.
  • Notification token (phone app): an identifier that lets OneSignal deliver push notifications to your device, linked to your MyCheck user ID.
  • Advertising and attribution data (phone app): device and advertising identifiers (where your device settings and consent choices allow) and in-app events, used by Google AdMob to show ads, and by AppsFlyer and Meta (Facebook App Events) to measure which ads and links lead to installs and sign-ups. AppsFlyer receives your MyCheck user ID.
  • Website and web app data: on every page of mycheck.co, including the web app and checklists embedded on other sites, Google Analytics records the pages you open (their address and title) and the features you use, such as creating a checklist or joining a shared one. We don't send Google your name, email or MyCheck user ID, and we replace invitation and share-link addresses with a generic one before they are sent. Google Analytics sets cookies to tell visits apart. We also show ads on public pages of mycheck.co through Google AdSense: Google and its partners use cookies to serve ads based on your visits to this and other websites. You can opt out of personalized ads in Google's Ads Settings or at aboutads.info. The sign-in pages load Google's sign-in service to offer "Continue with Google"; if you use it, Google shares your verified email address, name, and profile picture link with us.

2.3 Cookies and Browser Storage

Google Analytics and Google AdSense set cookies (see 2.2). The website also keeps some things in your browser's storage, not on our servers: your sign-in session; if you look up a case before creating an account, its receipt number and status (for up to 7 days, until you finish signing up); a random ID for this browser; and preferences such as language, theme, text size, city, recently viewed lists, collapsed sections and answers you gave. Some unsaved drafts, like a roadmap you haven't saved, last only until you close the tab. Signing out or deleting your account doesn't clear your preferences; clear this site's data in your browser to remove them.

3. How We Use Your Information

  • Provide, maintain, and improve MyCheck services.
  • Look up your USCIS case status and send status change alerts.
  • Power AI features such as the assistant, checklist and roadmap creation, document analysis, case summaries, and processing-time estimates.
  • Manage your subscription and process payments through the app stores or, for purchases on mycheck.co, through Stripe.
  • Send notifications and emails about your account, your cases, reminders, and getting started with MyCheck.
  • Show ads to users on the free tier.
  • Measure how people find MyCheck and which features they use.
  • Detect, prevent, and fix technical problems and abuse.

4. AI Features

MyCheck's AI features run on OpenAI's models. When you use them, we send OpenAI what is needed to answer: your messages, any files or photos you attach, and information from your account that relates to your request, such as your tracked cases (including receipt numbers), checklists, and roadmaps. Some features, such as processing-time estimates, use OpenAI's web search to find current public information. OpenAI processes this data to provide the service under its API terms, which state that data sent through its API is not used to train OpenAI's models by default.

AI apps you connect. You can connect MyCheck to an AI app such as Claude or ChatGPT. You choose what the app may do when you connect, and you can untick any of it: save checklists, see your checklists, and see the status of the USCIS cases you track. A connected app receives only what you allowed:

  • Saving: the checklist the app sends (its title, description, sections and tasks) is stored in your account as a private checklist. MyCheck never receives or stores your conversation with the app.
  • Checklists: the titles, descriptions, sections, tasks, task tips and which tasks are done for checklists you own. Checklists linked to a USCIS case, checklists shared with you, private notes, attachments, reminders, places and due dates are never shared.
  • Case status: for each case you track, the form type, the current USCIS status and its description, when the status last changed and when MyCheck last checked. Receipt numbers and A-numbers are masked, and case history, notes, answers and documents are never shared.

What the app does with that information is governed by its own privacy policy. MyCheck keeps a record of each connection (which app, what you allowed, when it was last used) and logs which tools an app used, never the content. You can disconnect an app at any time in Settings, and it loses access at once. Deleting your account removes all connections.

5. Data Storage & Security

Your account data is stored in our own database, which runs on Amazon Web Services servers in the United States. The website is hosted there too. We protect it with measures including:

  • Encrypted data transmission via HTTPS/TLS.
  • Access rules that keep your private records readable and editable only by your own account.
  • Passwords stored only as secure hashes.

While we strive to protect your information, no method of electronic storage is 100% secure. We cannot guarantee absolute security.

6. Data Sharing

We do not sell your personal information. We share data only in these cases:

  • With service providers that run parts of MyCheck for us, strictly to operate, secure, and improve the service:
    • Amazon Web Services: hosting for our servers and database.
    • OpenAI: AI features (see section 4).
    • RevenueCat, Apple, and Google: in-app subscriptions; Apple and Google also provide Sign in with Apple and Google Sign-In.
    • Stripe: payments on mycheck.co.
    • Resend: sending our emails and keeping our email contact list (your email, name, country, plan and whether you track a USCIS case, and the form type when you add a case). If you sign up for our newsletter from the website footer, we store only that address and where you signed up — no MyCheck account is created, and you can unsubscribe from any email we send.
    • OneSignal: push notifications in the phone app.
    • Amplitude: usage analytics in the phone app.
    • Microsoft Clarity: session recordings in the phone app.
    • Sentry: crash and error reporting.
    • Google AdMob, AppsFlyer and Meta: ads and ad measurement in the phone app; Google AdSense: ads on public pages of mycheck.co (see section 2.2).
    • Google Analytics: website and web app analytics.
    • Telegram: internal alerts to our team with feedback you send (including your email and user ID) and App Store or Google Play subscription changes.
  • With USCIS: to track a case, we send its receipt number to the USCIS case status service.
  • AI apps you connect: only what you allowed when connecting, as described in section 4.
  • Community content: posts and comments you publish in the community are visible to other users.
  • Other MyCheck users: signed-in users can see your display name, profile photo, level and whether you have Premium, for example next to your community posts and on shared checklists.
  • People on a checklist you share: when you do a checklist together, the people on it see its title, description, items (with their tips, due dates, places and links), progress, assignments, comments, the activity on the list, and each member's first name and profile photo. They never see your private notes, attachments or reminders. Before joining, anyone with an active invite link sees only the checklist title, how many items it has (and, when everyone shares one set of ticks, how many are done), how many people are on it, and the owner's first name. If you make someone else the owner, your notes and attachments on its items are deleted first; checklists tied to your USCIS case or roadmap can't be handed over.
  • Creator profiles and published checklists: a public creator profile at mycheck.co/@username shows your display name, profile photo, username and what you add to it (headline, bio, city, languages, expertise, experience, social links and cover photo), badges the MyCheck team verified, your public checklists and collections, and totals of followers, starts and completions. Public checklists and profiles appear in Discover and can be indexed by search engines. An unlisted checklist is visible to anyone with its link (mycheck.co/l/…) but is kept out of Discover, search and your profile. Visitors see only the version you published: never your progress, notes, attachments, due dates or reminders, and never your email, cases, roadmaps, or private or shared checklists. Immigration checklists, and checklists tied to a USCIS case or roadmap, can't be made unlisted or public. Creators see only totals (views, starts, completions, shares and helpfulness answers), never who opened, started, completed or answered. Websites can embed a published checklist; the embed shows the same public version. The people you follow never see that you follow them by name; the follower count on their profile includes you. Reports go to the MyCheck team, and the creator is never told who reported.
  • Share links you create: when you share a checklist's progress, anyone with the link (mycheck.co/c/…) can see the card and the choices you made: the checklist title, your first name and progress if you leave them on, and the list of item titles. Notes, attachments, due dates and reminders are never included. Immigration, legal and case-related checklists are shared only as a generic milestone, without the title, items or category. You can turn a link off at any time, and it stops working at once.
  • Legal requirements: if required by law, court order, or governmental authority.

7. Your Rights & Choices

  • Access: view your data within the app at any time.
  • Correction: update your profile and account information in Settings.
  • Deletion: delete your account in the app (Settings → Delete Account) or at mycheck.co/app/settings. We delete your account and the data linked to it (cases, checklists, roadmaps, reminders, AI conversations, share links, and attachments) from our live database right away. Checklists you own are deleted for everyone they are shared with. You are removed from checklists others shared with you and your comments and own progress on them are deleted; items you checked off on a list where everyone shares one set of ticks stay checked, without your name. Your creator profile, published checklists and their versions, collections, follows, verification requests, helpfulness answers and reports are deleted too. People who started one of your published checklists keep their own copy, and copies others remixed keep the original's title as credit, without a link. Community posts and comments you published stay visible, with the name and photo shown on them, so that discussions other people rely on stay intact; delete them first, or email us to remove them. Notifications already sent to other people (for example "Anna commented on…") stay in their lists. We keep a few records after deletion: feedback you sent us (without the link to your account), records of Stripe payments (which can include the name, email and billing country you gave at checkout), and security and cost logs that hold your former user ID or IP address. Your entry in our email contact list (Resend) and your push notification ID (OneSignal) aren't removed automatically; email us to have them removed. Deleting your account also cancels a subscription bought on mycheck.co; a subscription bought through the App Store or Google Play must be cancelled there (see section 5.3 of our Terms of Service). Records held by the service providers above, such as payment records at Stripe, are kept under their own retention rules and may need to be kept for legal, tax, or accounting reasons.
  • Notifications: turn push notifications off in the app settings or your device settings.
  • Ads: in the phone app, manage ad personalization through the consent options shown in the app (where required) and your device's advertising settings. On mycheck.co, use Google's Ads Settings or aboutads.info (see 2.2). Premium removes ads in the phone app and in the web app (mycheck.co/app); public pages of mycheck.co, such as the blog, may still show ads.
  • Emails: use the unsubscribe link in our marketing emails, or turn case status and reminder emails off in Settings › Notifications at mycheck.co/app/settings. Account and security emails, such as password resets, are always sent.

8. Children's Privacy

MyCheck is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Continued use of MyCheck after changes constitutes acceptance of the updated policy.

10. Contact Us

If you have questions about this Privacy Policy or your data, contact us at info@sfdify.com.