1. The Short Version
- Your passport is never stored on our servers. Your passport details and health declarations are encrypted on your device (WebCrypto AES-GCM) and stay there, apart from the brief OCR transit described below.
- We could not read your passport data if we wanted to. For data kept on your device, the encryption key is generated and kept only on your device. We hold no key that can decrypt it. This includes the passport profile you can save for reuse — it lives encrypted on your device, and our servers cannot decrypt or read it. You retain all rights to your information.
- Your answers stay on your device too. The answers you give while preparing a form — dates, flights, accommodation, purpose of visit, contact details — are saved only in your browser. They are not stored on our servers, so we have no way to read them.
- OCR photos pass through; they do not stay. When you scan a passport photo, the image travels through our API in memory to a cloud OCR provider and is discarded immediately. We never write it to disk.
- Beyond that, our database knows only who you are, your credit balance, what you paid, and a minimal record per draft. The draft record holds the country, arrival date, and number of travelers — no passport details, no health declarations.
- You are charged only when the service succeeds.
- Analytics without cookies. Self-hosted Umami; no cookies, no personal identifiers. Logging in uses strictly necessary session cookies — see Cookies below.
2. Information We Handle
Stored by us (server-side):
- Account identity: email address and login provider. If you use “Sign in with Google”, Google also gives us your name and profile picture, and an identifier for your Google account. We use them only to create and recognize your account. We ask Google for nothing else — not your Gmail, contacts, calendar, or files — and we do not sell or share what Google gives us.
- Credit balance and transactions.
- Payment records, processed by Stripe.
- Draft record: for each arrival-card draft, the country, arrival date, number of travelers, its status, and when we last sent you a reminder email.
- OCR usage audit: timestamp and success or failure only — no passport data, no images.
- Feedback you send: your message, an optional rating, and contact details if you choose to leave them.
Kept on your device (never stored by us): passport details, your saved passport profile, health declarations including vaccine documents, and every answer you give while preparing a form. These are encrypted locally and leave your device only in the OCR transit and extension filling described in section 3.
visayes is the data controller for the server-side data described in this section. We process account, credit, and payment data, and your draft records — including reminder emails about your own drafts — to perform our contract with you; OCR images to provide the scan you request; feedback because you choose to send it; and security and anti-abuse logs in our legitimate interest of keeping the Service safe (GDPR Art. 6).
3. How Information Moves
- OCR: your passport photo transits our API in memory to the OCR provider (section 5), and is immediately discarded. Recognized text returns to your browser and merges into your local, encrypted draft. We keep no copy of either.
- Draft record: as you prepare a form, we record that you have a card in progress for a country, with its arrival date and number of travelers — so your account page can show it and we can remind you when a submission window opens. Your answers themselves are not sent; they stay in your browser.
- Filling official forms: when you use the extension, your prepared data moves from your device directly into the official website’s form fields, inside your browser. It does not pass through our servers.
4. What We Never Do
We do not sell or rent your data. We do not run third-party advertising or trackers. We do not build profiles of you. We do not store your passport details, your health declarations, or your form answers on our servers — we have no way to read them.
5. Third-Party Services
For what we cannot self-host, we use the providers below, under their standard data-processing terms and only for the purposes described here. Review their policies if you want the details.
- OCR — mainland-China passports: Tencent Cloud OCR (operated in mainland China) · policy. All other passports: Microsoft Azure Document Intelligence · policy.
- Payments: Stripe · policy. Stripe handles your card; we never see the full number.
- Authentication: Supabase Auth; optional Google OAuth for “Sign in with Google”.
- Email: Resend, for transactional email such as feedback receipts and the reminder email we send when a draft’s official submission window opens. Every reminder email includes a one-click unsubscribe.
- Error tracking: self-hosted GlitchTip — error logs stay on our own server.
- Analytics: self-hosted Umami, cookie-free.
6. Cookies
We use strictly necessary cookies to keep you logged in. We use no analytics cookies, no advertising cookies, and no third-party trackers.
7. Where Data Lives and Travels
- Account and credit data, and draft records: our PostgreSQL database, hosted with Supabase.
- Passport details, health declarations, and your form answers: your device only (encrypted), except the OCR image transit described in section 3.
- OCR images: transit Tencent Cloud (Guangzhou, mainland China) for mainland-China passports, or Microsoft Azure (global regions) for all others, depending on the passport you select. Recognition happens in the region named here and nowhere else.
- Where account data of EU users is transferred outside the EEA, we rely on our providers’ standard contractual clauses (SCCs).
- If you use visayes from mainland China: by using the Service you consent to your account data (email, credits, payments) and your draft records being stored and processed outside mainland China.
8. Retention
Account data is kept while your account exists and deleted when your account is deleted. Payment records are retained as required by law and by Stripe. Feedback is kept for as long as it is useful for improving the Service, and in any case reviewed for deletion after 24 months. Locally stored data stays on your device until you delete it or clear your browser storage.
Backups: our database backups hold the account data and draft records described above — never your passport details, health declarations, or form answers, because those are never on our servers to begin with. Backup copies are destroyed after up to 30 days as backups rotate.
Draft records: for cards you complete, we keep the draft record (country, arrival date, number of travelers) as your trip history. If you delete a draft yourself, its record is deleted entirely — nothing is kept.
9. Your Rights
You retain all rights to your information. Data-protection laws (GDPR, CCPA, China PIPL, and others) give you the rights to:
- Access a copy of the data we hold about you.
- Delete your account and all associated data (except records we are legally required to keep, such as payment records).
- Export your data in a machine-readable format (JSON).
- Correct inaccurate data.
- Object to specific processing, or restrict it.
- Withdraw consent where processing is based on consent.
Email [email protected]; we respond within 30 days. EU users may also lodge a complaint with their local data-protection authority.
10. Filling In for Others
If you prepare forms for fellow travelers, their information is handled exactly like yours: their passport details, health declarations, and answers stay on your device. You must have their permission — or their guardian’s (see Terms of Service).
If you believe someone entered another person’s data without permission, contact us and we will help. Their details stay on the device that entered them, and are deleted when that draft is deleted.
11. Children
visayes accounts are for adults (18+). We do not knowingly collect children’s data server-side. A traveler profile for a minor — for example your child’s arrival card — is entered under a guardian’s authority and stays encrypted on your device, subject only to the OCR transit described in section 3.
12. Data Breach Notification
If a breach affects your personal data, we will notify the relevant supervisory authority within 72 hours of becoming aware of it where required (GDPR Art. 33), and affected users without undue delay (GDPR Art. 34).
13. Security
Local data is encrypted with WebCrypto AES-GCM. Transport uses TLS. Server-side, we keep only the minimum described in section 2, protected by row-level security and access controls.
Your passport details, health declarations, and form answers are encrypted on your device and never sent to our servers, so there is no key for us to hold and nothing for us to be compelled to hand over.
No security is perfect — that is exactly why our architecture keeps your passport off our servers in the first place.
14. Changes; Contact
We may update this policy. Material changes will be announced by email or in-product notification; continued use after notice constitutes acceptance.
Contact: [email protected]